Data Protection & Cybersecurity
Expertise in all matters related to privacy and data protection law, including cybercrime, data loss, and data management
Experienced data protection lawyers serving CEE
How do you reconcile the free flow of information and the need to be open to the world with the demand to secure your data and protect employee and customer privacy? How does data protection law in Europe help you deal with data breaches and hackers in an ever-changing legal landscape?
We are here to help. We can advise you on handling all types of data protection law and data management issues on a daily basis, from staff member data and patients’ medical records, to restrictions on outsourcing and records retention requirements, through to dealing with data leaks or cyber-attacks.
An efficient way to ensure compliance with data protection regulations and to build customer trust through transparency is to have your IT-products or IT-based services certified through the European Privacy Seal (EuroPriSe). Our admitted legal and technical experts can conduct the necessary evaluation for your certificate.
Key experts
“Excellent expertise in multinational data protection compliance work, and is equally adept at handling security breaches, privacy matters, and local data protection issues.”
– The Legal 500
“Wolf Theiss advises a diverse range of clients across sectors including retail, infrastructure, banking and healthcare. The ‘responsive and very practical’ team brings its ‘excellent expertise in multinational data protection compliance work’ to a mix of contentious and non-contentious matters.”
– The Legal 500
“Up-to-date knowledge about cross-country relations as well taking responsibility for their job, real partnership and consultancy.”
– The Legal 500
What makes our team the best data protection & cybersecurity law firm for you?
Our regional, integrated firm offers distinct advantages, spanning the full spectrum of legal services.
- An established international law firm with 60+ years of experience in Austria and CEE/SEE
- A fully integrated team of jurisdiction-specific qualified lawyers across our offices in 13 countries.
- Collaboration and innovation across multidisciplinary teams and offices
- Excellent client satisfaction – responsive, client-oriented, and consistent
- Experience with complex and cross-border matters covering the full spectrum of legal services
- Knowledge and expertise to add value to deals across industries
Leading the legal field
Our lawyers are involved in key transactions and matters across the region, bringing their industry expertise and specialised business knowledge to add value to our clients’ work.
Advised banking group on GDPR implementation for all CEE/SEE offices
Defended client against a series of data protection violation claims
Successfully advised search engine provider in proceedings before the Austrian Data Protection Authority
Our subsidiary RBS acts as Data Protection Officer for clients in various industries
Leading data protection law firm, experienced in security breaches, local & multinational data protection, & EuroPriSe certification
Successful regional GDPR implementation
Our team advised an Austrian headquartered banking group in setting up their internal data protection management systems for all of their offices in Austria and the CEE/SEE region.
All of our offices worked together to provide solutions for the GDPR implementation in the most practical and efficient manner, taking into account not only data protection but also general banking regulatory and cyber security laws. Our advice also included the application for approval of Binding Corporate Rules (BCRs).
Privacy litigation
We defended a client against the first-ever series of claims in the country, where a larger number of people (allegedly) affected by data protection violations were suing for non-material damages. The main question is now pending before the Court of Justice of the European Union.
With a scalable number of data protection experts, we can also support in mass proceedings at short notice.
Defence before DPAs
Our firm successfully defended a search engine provider in proceedings before the Austrian Data Protection Authority whose decision was lifted by the Federal Administrative Court.
We defend clients against complaints by data subjects / NGOs and against GDPR fines before DPAs across the entire CEE/SEE region.
Data Protection Officer
Our consulting subsidiary Responsible Business Solutions (RBS) acts as an external Data Protection Officer for multiple clients in the areas of public infrastructure services, banks, insurance and healthcare.
Areas of specialisation
GDPR implementation
If you are a data controller or a data processor, you need to implement appropriate technical and organisational measures to safeguard the personal data processed in your business, as well as keeping evidence of your personal data processing operations.
We identify the gaps and suggest the best options to close them, thereby helping your firm to meet EU GDPR requirements and ensure compliance with other local data protection laws. We can assist you in designing a data privacy programme and support you in dealing with the records of processing activities, DPO related tasks, and data protection impact assessment. You benefit from the combination of our legal and technical skills allowing us to offer you comprehensive solutions for all your GDPR data protection law requirements.
EuroPriSe
Having your IT-products and IT-based services certified through an independent third party helps your business maximise transparency and build up trust. The European Privacy Seal (EuroPriSe) is a highly respected certification which is valid in all EU countries and which can be used for consumer marketing or public procurement.
In addition, the fact that its awarding criteria align with the requirements of the GDPR, is an immediate indication to your customers that your business is GDPR-compliant. We have admitted EuroPriSe Legal and Technical Experts in-house. By covering both the legal and the technical side of the certification procedure you avoid having to engage two different firms, saving you both time and money.
Data management
As a response to technological developments and the ever-increasing number of data breaches, new and strict regulations are being enacted that require companies to treat privacy policies and data security as high priorities. Since these regulations are neither always clear nor uniform across different jurisdictions, ensuring compliance with data regulations and drafting the appropriate policies can be a major challenge.
We can assist you in handling all types of data management issues including filing data applications with competent authorities, (cross-border) transfer of data, restrictions on outsourcing, handling data of staff members, customers, suppliers, patients etc., records retention requirements and implementation of whistleblowing hotlines.
Data loss
Do you know what to do if you suffer a data loss? Many European data protection laws and sector regulations provide for a notification duty in case of a data leak or data misuse.
We can advise you on whom, when and how to notify, as well as represent you against potential claims for damages or administrative fines following data security breaches. Better still, we can advise you on the implementation of the best data loss prevention software to protect your business.
IT remediation & review
Take advantage of our tailor-made legal “incident response” service focusing on the first steps to be taken after a security breach is detected (detection, containment, eradication, recovery, follow-up). Depending on your preference, we work together with international and local IT security specialists to recover your systems, whilst preserving evidence for possible criminal and civil actions.
Cybercrime
The internet and e-communication have brought unparalleled opportunities; unfortunately, not just for business. Cybercrime is one of the fastest-growing areas of criminal law with more and more criminals exploiting the anonymity and speed of the electronic world to commit an ever-growing number of crimes.
With offenders ranging from individual hackers to highly complex international cybercriminal networks, you need a team which has the size, the connections, the knowledge and the partners to react immediately. The close cooperation between our Data Protection, White Collar Crime, IT and Crisis Management specialists allows us to provide integrated solutions.
Get in touch
Whether you need an international team with extensive experience, Wolf Theiss can support your business goals through our profound legal practice.
Related experts
Related insights
Beyond VLOPs and Gatekeepers: Countdown to the full application of the EU Digital Services Act (DSA)
The Digital Services Act (DSA) is set to overhaul and expand the EU’s regulatory framework for online intermediary s...
Read moreESG in a nutshell – for the board of directors and management
12- 23 October 2023
09-10 November 2023
30 November – 01 December 2023
In the coming years, sustainability will shape corporate supervision and management like no other topic. ESG has far-reach...
Read moreConvera acquires parts of Western Union business with legal assistance from Wolf Theiss
Vienna, 21 July 2023 – Wolf Theiss advised Convera on the acquisition of parts of the Austrian business of Western Unio...
Read moreCroatian Personal Data Protection Agency imposes a EUR 2.2 million fine on a debt collection company
In early May 2023, the Croatian Personal Data Protection Agency (AZOP) imposed a fine on a debt collection company in the ...
Read moreGDPR international data transfers: Commission’s Draft Privacy Shield Replacement
Transition period for new Standard Contractual Clauses to expire on 27 December 2022 Earlier this week the European Commis...
Read moreRBS Responsible Business Solutions strengthen service portfolio for comprehensive business consulting with acquisition of RE-Structure
Vienna, 31 August 2022 – With the merger of RBS Responsible Business Solutions and its sister company RE-Structure, ...
Read moreMagenta creates largest Austrian private fibre optic network partnership with legal assistance from Wolf Theiss
Vienna, 25 August 2022 – Austrian leading telecommunications operator Magenta relied on the legal advice of Wolf The...
Read moreCovid-19 testing and EU Certificates – rules and options for employers in Croatia
Topics concerning Covid-19 testing and EU Covid-19 certificates raise a number of questions for employers in the private s...
Read moreCovid-19 vaccination and the workplace: Common questions among employers in Croatia
The Croatian government aims to increase the percentage of vaccinated persons (currently approx. 50%). Topics concerning v...
Read moreFollowing in the footsteps of Italy: Will the right to work in Romania be conditional upon holding a Covid-19 Green Pass?
A new draft law in Romania prevents access to the workplace absent a Covid-19 Green Certificate. The new measures are appl...
Read moreWolf Theiss advises Novalpina Capital LLP in the largest transaction in the betting & gaming sector in Romania
Bucharest, 5 July 2021 – Wolf Theiss was the legal advisor of Novalpina Capital LLP, a London based independent European...
Read moreInternational data transfers: EDPB’s final recommendations on ‘supplementary measures’
On 18 June 2021, the European Data Protection Board adopted its final version on ‘supplementary measures’ for ...
Read moreHarmonising consumer protection in the digital context: the EU digital content directive in Austria
The EU Digital Content Directive (EU) 2019/770, which regulates contracts for the supply of digital content and services, ...
Read moreRomania: Minimum network and information systems security requirements to be complied with by the operators of essential services in the next 6 months
On 26 November 2020, Romania adopted new technical rules on minimum requirements to ensure the security of network and inf...
Read moreE-Commerce platforms in the focus of the CJEU / E-Commerce Plattformen im Fokus des EUGH
E-commerce platforms are not obligated in all cases to make a telephone number available to consumers before the conclusio...
Read moreCJEU invalidates EU-US privacy shield framework and introduces further restrictions on data transfers to non-EU countries
On 16 July 2020, the Court of Justice of the European Union (CJEU) issued a long-awaited decision in a dispute between Fac...
Read moreRomanian parliament adopted new law regarding the competences of the local data protection authority
On 24 June Law no. 129/2018 entered into force. It had been published in the Romanian Official Gazette no. 503 of Ju...
Read moreAmendment of the Austrian act against unfair competition (UWG) – The directive on the protection of know-how enters into force in early 2019
Directive (EU) 2016/943 “on the protection of undisclosed know-how and business information (trade secrets) against ...
Read moreRomania: New law 362/2018 on the security of network and information systems / NIS directive
EU Directive 2016/1148 on Security of Network and Information Systems (the “NIS Directive”) regulates the main...
Read moreRomania: Wolf Theiss contributes to the release of two new reports on GDPR for the CPC platform
Wolf Theiss together with other qualified legal professionals from more than 30 European countries, contributed to the rel...
Read moreThe first action plan for the application of the GDPR has been published by the Romanian data protection authority
WHAT IS TO BE DONE BY DATA CONTROLLERS? On September 21st, 2017, the National Supervisory Authority for Personal Data Proc...
Read moreStatus update on the e-privacy regulation –The next key regulatory initiative after GDPR
On 10 January 2017, a proposal for a new Regulation of the European Parliament and of the Council concerning the respect f...
Read moreCyber Attacks: Die ersten 72 Stunden zählen. Die jüngsten Cyberattacken – national und international
Laut aktuellen Schätzungen des FBI liegt der durch Cyber-Delikte verursachte Schaden jenseits der 3 Milliarden US-Dollar-...
Read moreWolf Theiss Round-Up: Unternehmen sollten sich rechtzeitig auf die EU-Datenschutz-Grundverordnung vorbereiten
Die Europäische Datenschutz-Grundverordnung (DSGVO) hat weitreichende Auswirkungen auf das Datenschutzrecht der EU-Mitgli...
Read moreWolf Theiss Warsaw conference sees value in enhancing whistleblowing best practices in Poland
Warsaw, 30 November 2017 – Polish companies should intensify efforts to strengthen their internal whistleblowing systems...
Read moreEuropean privacy seal Europrise: Wolf Theiss CIO Helmut Waitzer and technology lawyer Roland Marko certify data protection fitness
Vienna, November 21, 2017 – Wolf Theiss is offering companies further support in preparing for the EU’s General Data P...
Read moreWolf Theiss continues its expansion in CEE: Lana Sarajilic joins Wolf Theiss Sarajevo
Vienna/Sarajevo, 15. November 2017 - After hiring new partners in Poland and Romania, Wolf Theiss continues its expansion ...
Read moreWolf Theiss strengthens its banking & finance and dispute resolution teams in Warsaw
Warsaw, 1 February 2017 – Wolf Theiss once again added new members to two of its practice groups: Stefan Feliniak joined...
Read moreStay connected
Sign up to receive our latest updates and insights.
You may withdraw your consent at any time by deleting the cookies or by clicking the corresponding button in our privacy policy. A withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. For further information please read our privacy policy.
Functional Always active
Preferences
Statistics
Marketing
Accessibility
Wolf Theiss - Leading Lawyers in CEE&SEE
Accessibility Statement
- www.wolftheiss.com
- 30 September 2023
Compliance status
We firmly believe that the internet should be available and accessible to anyone, and are committed to providing a website that is accessible to the widest possible audience, regardless of circumstance and ability. To fulfill this, we aim to adhere as strictly as possible to the World Wide Web Consortium’s (W3C) Web Content Accessibility Guidelines 2.1 (WCAG 2.1) at the AA level. These guidelines explain how to make web content accessible to people with a wide array of disabilities. Complying with those guidelines helps us ensure that the website is accessible to all people: blind people, people with motor impairments, visual impairment, cognitive disabilities, and more. This website utilizes various technologies that are meant to make it as accessible as possible at all times. We utilize an accessibility interface that allows persons with specific disabilities to adjust the website’s UI (user interface) and design it to their personal needs. Additionally, the website utilizes an AI-based application that runs in the background and optimizes its accessibility level constantly. This application remediates the website’s HTML, adapts Its functionality and behavior for screen-readers used by the blind users, and for keyboard functions used by individuals with motor impairments. If you’ve found a malfunction or have ideas for improvement, we’ll be happy to hear from you. You can reach out to the website’s operators by using the following emailScreen-reader and keyboard navigation
Our website implements the ARIA attributes (Accessible Rich Internet Applications) technique, alongside various different behavioral changes, to ensure blind users visiting with screen-readers are able to read, comprehend, and enjoy the website’s functions. As soon as a user with a screen-reader enters your site, they immediately receive a prompt to enter the Screen-Reader Profile so they can browse and operate your site effectively. Here’s how our website covers some of the most important screen-reader requirements, alongside console screenshots of code examples:- Screen-reader optimization: we run a background process that learns the website’s components from top to bottom, to ensure ongoing compliance even when updating the website. In this process, we provide screen-readers with meaningful data using the ARIA set of attributes. For example, we provide accurate form labels; descriptions for actionable icons (social media icons, search icons, cart icons, etc.); validation guidance for form inputs; element roles such as buttons, menus, modal dialogues (popups), and others. Additionally, the background process scans all of the website’s images and provides an accurate and meaningful image-object-recognition-based description as an ALT (alternate text) tag for images that are not described. It will also extract texts that are embedded within the image, using an OCR (optical character recognition) technology. To turn on screen-reader adjustments at any time, users need only to press the Alt+1 keyboard combination. Screen-reader users also get automatic announcements to turn the Screen-reader mode on as soon as they enter the website.These adjustments are compatible with all popular screen readers, including JAWS and NVDA.
- Keyboard navigation optimization: The background process also adjusts the website’s HTML, and adds various behaviors using JavaScript code to make the website operable by the keyboard. This includes the ability to navigate the website using the Tab and Shift+Tab keys, operate dropdowns with the arrow keys, close them with Esc, trigger buttons and links using the Enter key, navigate between radio and checkbox elements using the arrow keys, and fill them in with the Spacebar or Enter key.Additionally, keyboard users will find quick-navigation and content-skip menus, available at any time by clicking Alt+1, or as the first elements of the site while navigating with the keyboard. The background process also handles triggered popups by moving the keyboard focus towards them as soon as they appear, and not allow the focus drift outside of it.Users can also use shortcuts such as “M” (menus), “H” (headings), “F” (forms), “B” (buttons), and “G” (graphics) to jump to specific elements.
Disability profiles supported in our website
- Epilepsy Safe Mode: this profile enables people with epilepsy to use the website safely by eliminating the risk of seizures that result from flashing or blinking animations and risky color combinations.
- Visually Impaired Mode: this mode adjusts the website for the convenience of users with visual impairments such as Degrading Eyesight, Tunnel Vision, Cataract, Glaucoma, and others.
- Cognitive Disability Mode: this mode provides different assistive options to help users with cognitive impairments such as Dyslexia, Autism, CVA, and others, to focus on the essential elements of the website more easily.
- ADHD Friendly Mode: this mode helps users with ADHD and Neurodevelopmental disorders to read, browse, and focus on the main website elements more easily while significantly reducing distractions.
- Blindness Mode: this mode configures the website to be compatible with screen-readers such as JAWS, NVDA, VoiceOver, and TalkBack. A screen-reader is software for blind users that is installed on a computer and smartphone, and websites must be compatible with it.
- Keyboard Navigation Profile (Motor-Impaired): this profile enables motor-impaired persons to operate the website using the keyboard Tab, Shift+Tab, and the Enter keys. Users can also use shortcuts such as “M” (menus), “H” (headings), “F” (forms), “B” (buttons), and “G” (graphics) to jump to specific elements.
Additional UI, design, and readability adjustments
- Font adjustments – users, can increase and decrease its size, change its family (type), adjust the spacing, alignment, line height, and more.
- Color adjustments – users can select various color contrast profiles such as light, dark, inverted, and monochrome. Additionally, users can swap color schemes of titles, texts, and backgrounds, with over 7 different coloring options.
- Animations – epileptic users can stop all running animations with the click of a button. Animations controlled by the interface include videos, GIFs, and CSS flashing transitions.
- Content highlighting – users can choose to emphasize important elements such as links and titles. They can also choose to highlight focused or hovered elements only.
- Audio muting – users with hearing devices may experience headaches or other issues due to automatic audio playing. This option lets users mute the entire website instantly.
- Cognitive disorders – we utilize a search engine that is linked to Wikipedia and Wiktionary, allowing people with cognitive disorders to decipher meanings of phrases, initials, slang, and others.
- Additional functions – we provide users the option to change cursor color and size, use a printing mode, enable a virtual keyboard, and many other functions.