Data privacy and data protection in Austria
Baker McKenzie • Diwok Hermann Petsche Rechtsanwälte LLP & Co KG stands out for its strength in the contentious space. It recently represented one of Austria’s leading newspapers in a dispute that resulted in a ground-breaking decision where the Austrian Data Protection Authority (DPA) decided that the business model used by the newspaper is valid under data protection law. The team also has a strong record advising on non-contentious matters, including assisting with the implementation of online identity verification, and regulatory obligations when entering the EU market. Practice head Lukas Feiler made partner in July 2019.
‘They just seem to have excellent people.‘
STANDARD Verlagsgesellschaft m.b.H.
- Represented one of Austria’s leading newspapers, resulting in a ground-breaking decision in which the Austrian Data Protection Authority (DPA) decided that the business model used by the newspaper is valid under data protection law.
DORDA Rechtsanwälte GmbH
The team at DORDA Rechtsanwaelte GmbH/span> is praised for its 'unparalleled expertise' in the space. It handles a wide range of contentious and non-contentious data protection matters, including assisting with major international GDPR implementation projects, data protection impact assessments, data breaches, in-house training in relation to GDPR, and handling requests by data subjects. The team also acts as external data protection officer for Vienna Insurance Group. The practice is jointly headed by Felix Hörlsberger and Axel Anderl; the latter is 'a very modern, pragmatic and skilled negotiator'. Nino Tlapak is noted for his 'great expertise, his pleasant and prudent manner and his good knowledge of the local authority structure'.
‘The team was very helpful and competent. At all times we felt like they were delivering excellent service to us.‘
‘High competence and courage to defend our goals in the negotiations.‘
‘The team shows a very strong hands-on mentality. They are extremely solution-oriented and are also willing to think outside the box.‘
‘The team of Dorda delivers straight-to-the-point legal assessments without ever falling short of its own highest standards.‘
‘Axel Anderl has set up a team of highly professional, open-minded and legally gifted individuals that obviously enjoy working together. The team’s key strengths include response times and a perfect sense for the precise needs of the client.‘
‘They have the ability to understand business use-cases of customers very well. They have good insight information when it comes to new GDPR cases.‘
‘Axel Anderl – calm, has the complete picture of things, keeps track of risks and priorities.‘
‘Axel Anderl’s team demonstrates extensive legal experience, provides great industry knowledge and is always a pleasure to deal with. They are a very client-focused firm offering outstanding service and having fabulous people at all seniority levels.‘
‘Axel Anderl is a very modern, pragmatic and skilled negotiator. His approach generates added value in most cases and we appreciate his exemplary mindset to do the best considering our group characteristics and needs. Nino Tlapak as an exceptional Data Protection expert has to be mentioned. He is extraordinarily skilled in this area.‘
‘Although part of a large law firm, the team around Axel Anderl is very approachable and always available, even at short notice, a pleasure and fun to work with.‘
A. Menarini Pharma GmbH
AGES- Österreichische Agentur für Gesundheit und Ernährungssicherheit GmbH
AIG Europe S.A.
Allianz Elementar Versicherungs-Aktiengesellschaft
Bayer Austria GmbH
BKS Bank AG
Do & Co Aktiengesellschaft
Donau Chemie Aktiengesellschaft
EODC Earth Observation Date Centre for Water Resources
Erste Bank Group & sIT Solutions AT Spardat GmbH
Erste Bank und Sparkassen Leasing GmbH
Flughafen Wien AG /Austro Control
FRITZ EGGER GmbH & Co OG
HTM Sport GmbH (HEAD Group)
INTERSPORT AUSTRIA Gesellschaft m.b.H.
ISS Austria Holding GmbH
Liechtensteinische Landesbank (Österreich) AG
L’OREAL Österreich GmbH
MC Toxicology Consulting GmbH
Medical Second Opinion, Ltd
Moët Hennessy Österreich GmbH
Novartis Pharam GmbH
RAYSEARCH LABORATORIES AB (PUBL)
Styria Media Group
TP Holding GmbH
Trodat Trotec Group
VIG – Vienna Insurance Group / twinformatics GmbH (VIG Group’s IT service provider subsidiary)
VVO – Versicherungsverband Österreichs
WKO – Wirtschaftskammer Österreich
WT Wien Ticket GmbH
- Set up and steered a group-wide GDPR compliance project for the Do & Co Group covering its Austrian headquarters and its subsidiaries, which are spread across Europe.
- Advised Austro Control, the public-owned air navigator service provider, on its GDPR implementation project.
- Assisted Ventocom GmbH with its market entry into the Austrian mobile sector by both safeguarding data protection compliance, and settling telecoms and unfair competition issues.
The 'large, highly qualified and very experienced' data privacy team at Cerha Hempel advises on a wide range of GDPR issues, including technical data privacy and privacy by design. Clients include Samsung and Spar. Senior associate Franziska Paefgen has a 'hands-on and solution-oriented approach'. She supports 'highly professional and very friendly' practice head Hans Kristoferitsch in advising a large roster of clients on data protection and security matters.
‘CHSH covers many legal areas. The overall level of service is very high. The response times are short and agreed response dates are kept reliably.’
‘A very competent team that is able to explain complex issues so that you really can follow.’
‘The team of Dr. Kristoferitsch is very professional and competent with practicable solutions.’
‘Outstanding competence and professionality.’
‘Dr. Kristoferitsch combines extensive knowledge with a lot of practical experience in data privacy and data protection law.’
CA Immobilien Anlagen AG
Constantia Industries AG
Dentsu Aegis Network Austria GmbH
FCC Austria Abfall Service AG
Flughafen Wien AG
General Logistics Systems (GLS) Austria GmbH
Hewlett Packard Inc
Institute of Science and Technology Austria (IST Austria)
Samsung Electronics Austria GmbH
Semperit Aktiengesellschaft Holding
SES Spar European Shopping Centers GMBH
SPAR Business Services GmbH
Wien ENERGIE GmbH
Wiener Stadtwerke GmbH
- Advising Austria’s largest food retailer, Spar, on all data protection, data security and IT matters.
- Advised FCC, Austria’s largest waste management company, and its subsidiaries, on legal issues related to the group’s GDPR implementation project.
- Acted for CA Immobilien Anlagen on its group-wide GDPR compliance project and providing ongoing assistance with data privacy questions relating to smart buildings, smart houses, smart offices, and the use of apps providing a platform for a unified interface between occupants and visitors.
Wolf Theiss Rechtsanwalte GmbH & CoKG advises a diverse range of clients across sectors including retail, infrastructure, banking and healthcare. The 'responsive and very practical' team brings its 'excellent expertise in multinational data protection compliance work' to a mix of contentious and non-contentious matters. The group also acted as an external data protection officer for the Austrian holding company of Addiko Group. The 'experienced and pragmatic' Roland Marko, who heads the practice jointly with Kurt Retter, conducted a GDPR compliance audit for the Adverity Platform in order to assess its eligibility for EuroPriSe certification.
‘Great technical knowledge of data protection law, responsive and very practical.‘
‘Excellent expertise in multinational data protection compliance work, and is equally adept at handling security breaches, privacy matters, and local data protection issues.‘
‘Partner Roland Marko is very experienced, pragmatic, and easy to communicate with.‘
Gazprom Neft Trading
Starbucks Coffee Company UK
TQSR Holding und Development
- Advised International Flavours & Fragrances on GDPR compliance following its takeover of the Israeli Frutarom Group.
- Conducted a GDPR compliance audit for the Adverity Platform in order to assess its eligibility for EuroPriSe certification.
- Served as external data protection officer for the Austrian holding company of Addiko Group.
CMS Reich-Rohrwig Hainz Rechtsanwälte GmbH's 'friendly and courteous' team advises national and international clients in the financial, infrastructure, healthcare and media sectors on a variety of GDPR matters, including compliance and data use. Johannes Juranek, who receives praise for his 'high level of expertise', assisted Unser Ö-Bonus Club GmbH/Rewe with all data protection and regulatory issues regarding the setting up of a loyalty scheme.
‘Everyone we worked with answered within the period stipulated, gave a competent, comprehensible analysis and offered further assistance. The team is extremely professional. The atmosphere of the law firm is very pleasant and welcoming, staff is friendly and courteous.‘
‘Dr Johannes Juranek has a high level of expertise and offers pinpoint solutions. He’s easy to reach and if not available he suggests a new near-term appointment. He’s very professional and experienced not only in Austrian law, but also well-connected internationally.‘
Heta Asset Resolution AG
Brunswick Austria & CEE GmbH
Mustafa medical labs
Unser Ö-Bonus Club GmbH, REWE
- Assisted Unser Ö-Bonus Club GmbH/Rewe with all data protection and regulatory issues regarding the setting up of a loyalty scheme.
- Advised Fidelity funds on GDPR issues relating to its client database, intra-group assignment of client data, and the use of such data for marketing purposes.
- Advised Mustafa medical labs on the complete implementation of GDPR, the implementation of health data storage, and data assignment and access questions.
The sizeable team at Eisenberger & Herzog has 'a profound knowledge of IT-related legal questions, in particular data protection law'. Practice head Andreas Zellhofer, who 'comes up with practical solutions without losing sight of the essentials', and the 'professional and knowledgeable' Helmut Liebel act as local counsel for the entire Microsoft Group in Austria. Other matters include assisting clients with GDPR compliance projects, data subject access requests, handling data breaches and data processing agreements.
‘In my experience, the team has a profound knowledge of IT-related legal questions, in particular data protection law, and a solution-oriented approach at all times. The cooperation has always been very positive and professional.‘
‘Andreas Zellhofer is a well-known specialist in IT/IP law who very quickly comes up with practical solutions without losing sight of the essentials.‘
‘Helmut Liebel is a proven data protection expert with whom one can exchange opinions about GDPR and cross-border data traffic. Especially in the drafting of data protection contracts, his accurate way of working is evident.‘
‘The people at Eisenberger & Herzog were very professional and comfortable to work with. Any questions or inquiries where answered immediately. Even if I had issues or questions late in the evening they took the time to help me.‘
‘My main contacts were Helmut Liebel and Alissa Forstner, who were both very professional and knowledgeable.‘
- Acting as local counsel for the entire Microsoft Group in Austria.
Saxinger, Chalupsky & Partners (SCWP Schindhelm) advises clients on a range of data protection matters. In recent work, it assisted durchblicker.at, a comparison website, with the collection, processing and use of customer data, and acted for Veritas, Austria’s largest education sector publisher, on data protection issues arising from the implementation of a new online learning portal. The team also acts as data protection officer for TimeTac, a technology company, and Ringana, a Europe-wide producer of cosmetics based in Hartberg, Styria. Team head Michael Pachinger made partner in October 2019.
VERITAS – Verlags- und Handelsgesellschaft m.b.H. & Co. OG
durchblicker.at YOUSURE Tarifvergleich GmbH
- Advised Veritas, Austria’s largest education sector publisher, on data protection issues arising from the implementation of a new online learning portal.
- Assisted durchblicker.at, a comparison website, with the collection, processing and use of customer data.
- Acted as data protection officer for technology company TimeTac.
Schoenherr (Schönherr Rechtsanwälte)'s team, which is led by newly promoted partner Günther Leissler, is particularly focused on contentious data protection matters. The team represented Facebook Ireland as defendants in the Austrian court proceedings initiated by Austrian citizen Maximilian Schrems in a matter which involved not only several fundamental questions on GDPR interpretation, but it also touched on the interplay between Union law (GDPR) and member state constitutions. The team also defended Österreichische Post in over 100 GDPR-related proceedings. The team also provides comprehensive data protection advice to clients including Novartis Pharma.
‘Dominik Hofmarcher – excellent in data protection.‘
Österreichische Post AG
Vienna Insurance Group
Austrian Insurance Association
HDI Insurance Company
Verkehrsverbund Ost Region
OMV AG Erste Bank AG
Novomatic Group of Companies
- Represented Facebook Ireland Ltd as defendants in the Austrian court proceedings initiated by Austrian citizen Maximilian Schrems.
- Represented Vienna Insurance Group in court proceedings against the Austrian consumer protection association.
- Advising Novartis Pharma on all data protection matters.
The 'extremely engaged' team at Binder Grösswang is able to 'explain complicated topics in a very easy way, making knowledge accessible to everyone'. The focus is mainly on advisory matters including implementation of GDPR, drafting consent declarations and data processing agreements. The team is commended for its 'astonishing technical know-how' in a wide range of sectors including electronics, finance, pharmaceutical and manufacturing. Angelika Pallwein-Prettner, who heads the practice jointly with Ivo Rungg, stands out for her ability to 'explain complicated legal topics in a very easy way'.
‘There are a few principles the team of Binder Groesswang has put in place, which yield results.‘
‘Up to now, we received services in the fields of employment and data protection law from the team of Angelika Pallwein-Prettner. This team not only supported us to comply to the applicable laws and standards, due to their astonishing technical know-how, they also helped to restructure our system, resulting in more efficiency and security.‘
‘Whole team extremely engaged and experts in their fields.‘
‘Always reachable and willing to answer questions at short hand and to give background to the legal framework – every effort made to deliver in time and above the expected quality.‘
‘Big team with experts for different topics. Quick answers which can be easily understood and put in practice.‘
‘The knowledge of the team in the field of data protection is enormous. They are aware of each new law, decision or trend in the field of data protection as applied to the human resources sector and bank sectors. It looks like the team is very well coordinated. What I really appreciate most is their communication skills. They are able to explain complicated topics in a very easy way, making knowledge accessible to everyone.‘
‘Angelika Pallwein-Prettner is very competent and she always tries to find legal solutions that suit our company and our business model. I really appreciate the way she communicates with clients and the ways she explains complicated legal topics in a very easy way.‘
Unilever Deutschland GmbH
Big Bus Vienna GmbH
Yamaha Motor Europe N.V.
Husky Injection Molding Systems
Congress und Messe Innsbruck
Hermes Pharma GmbH
Société Générale Austria
Eversheds Sutherland | Stolitzka & Partner RAe OG's 'experienced' team advises on matters including GDPR implementation, data protection risk analysis, right to be forgotten requests, and international data transfer. The team also assisted the Österreichische Kinderkrebshilfe (Austrian Association supporting children with cancer) with GDPR implementation on a pro bono basis. Georg Roehsner is the practice head.
‘The team at Eversheds & Sutherland is well experienced with the capability to bring the right focus to that topic; their advice is brilliant, considering business needs and always in time and on the highest level.‘
‘The quality is perfect.‘
Avis Budget Group
ORF Enterprise (a subsidiary of the Austrian Public Broadcaster)
MOL Austria GmbH
Legero Schuhfabrik GmbH
Österreichische Kinderkrebshilfe (NGO for the support of children with cancer)
Die Berater Unternehmens- beratungs GmbH
- Advised Legero Group on data protection matters, in particular the privacy implications of the merger of its web-shops.
- Assisted die Berater Unternehmensberatungs with data protection issues, including conducting a data protection risk analysis.
- Assisted the Österreichische Kinderkrebshilfe (Austrian Association supporting children with cancer) with GDPR implementation on a pro bono basis.
Ferdinand Graf and the 'very professional, clear and solution-oriented' Marija Križanac head an 'excellent' team at Graf & Pitkowitz, which has a 'very good understanding of specific business processes'. The group advises on GDPR implementation and compliance issues for longstanding clients including Lukoil International and Velux. It also assisted the former with managing cross-border intra-group data transfer.
‘We always need a very quick response time, which GPP provides. Availability on a day-to-day basis (including weekends!) is also excellent. GPP has a very good relationship to our external accountants and tax advisors and is a team player if bigger matters require a multidisciplinary approach. Advice has always been outstanding and there is also appropriate flexibility with fees for different projects. GPP shows that it is committed to support us as a client. This commitment is not project/matter related only, but GPP was and is our partner in our long term build up in Austria.‘
‘Ferdinand Graf and Marija Križanac have outstanding experience with data privacy and data protection. They form an excellent team on which we can always rely. We have worked with them on several deals and matters and we have been impressed by their overall understanding of legal and business matters and their problem solving attitude and they did not disappoint us when it came to implementation of the new GDPR. Their guidance on how to implement this complex new legislation was outstanding.‘
‘Professional and well structured, clear responsibilities.‘
‘Marija Krizanac – very professional, clear and solution-oriented.‘
‘The individual lawyers have a very good understanding of specific business processes. The statements are also well understandable for people without a juridical education.‘
LUKOIL International GmbH, LUKOIL Holding GmbH
VELUX A/S; VELUX Österreich
- Advised the Lukoil group on implementing GDPR and managing cross-border intra-group data transfer.
- Assisted the Velux group with GDPR implementation and development of GDPR-compliant marketing.
Herbst Kinsky Rechtsanwalte GmbH
The 'highly professional, responsive, friendly' team at Herbst Kinsky Rechtsanwalte GmbH advises on GDPR implementation and compliance issues for clients in a variety of sectors, including education and technology. Practice head Sonja Hebenstreit, who is commended for being 'a good lawyer with extensive experience', also acts as data protection officer for new client Fulbright /Austrian-American Education Commission. The team represented FamiliaAustria before the Austrian Data Protection Authority in a matter regarding the approval of a specific processing of data for archiving purposes in the public interest, or for scientific, historical or statistical research purposes.
‘Herbst Kinsky’s passionate team is always up to date, manages even complicated and demanding issues smoothly and provides us with solutions perfectly matching our needs. Compared with other firms we appreciate their ability to explain difficult concepts in a clear way.‘
‘Sonja Hebenstreit has an excellent knowledge of the legal requirements and always produces high quality work; she is a good and reliable choice with all necessary skills and we benefit from her pragmatic and solution-oriented approach. On top of that, she is a really pleasant person to work with and also my non-legal colleagues enjoy getting her advice.‘
‘The strength of the team lies in the comprehensive legal advice, which can always be implemented well in business practice.‘
‘Sonja Hebenstreit is not only a good lawyer with extensive experience, but also an ideal consultant for companies, because she understands the problems of implementing legal requirements in companies.‘
‘Very dedicated and friendly team; always looking for a feasible solution.‘
‘Highly professional, responsive, friendly, easy to work with, focused on relevant aspects.‘
Fulbright /Austrian-American Education Commission
Greiner Bio-One GmbH
Vorarlberger Illwerke AG
ClassNinjas GmbH (Karim Saad)
Salzburger Osterfestspiele GmbH
FIMA Sportstudio Management GmbH (FitInn)
- Assisted Borealis with GDPR implementation matters as well as with day-to day GDPR compliance questions.
- Advised bitmovin on the introduction of an endpoint protection platform to ensure comprehensive protection against attacks of all kinds on its systems in terms of data protection law.
- Represented FamiliaAustria before the Austrian Data Protection Authority regarding the approval of a specific processing of data for archiving purposes in the public interest, or for scientific or historical research purposes.
'Solution-oriented lawyer' Anna Mertinz, who is particularly recommended for her 'very good knowledge of data protection law', jointly heads the 'very competent, pragmatic' team at KWR Karasek Wietrzyk Rechtsanwälte GmbH with Barbara Kuchar. The team provides 'to the point' advice on GDPR implementation and compliance issues for longstanding clients including Estée Lauder Cosmetics and Coca-Cola. Other work includes advising on questions of personal privacy rights and adjustment of agreements in light of GDPR.
‘Fast, solution-oriented, uncomplicated.‘
‘I appreciate Anna Mertinz as a competent, solution-oriented lawyer who responds and acts quickly.‘
‘Very competent, pragmatic, available if the matter is urgent.‘
‘Anna Mertinz – legal advice to the point, pleasant cooperation and very good knowledge of data protection law.‘
Estee Lauder Cosmetics Ges.mbH
Coca-Cola HBC Austria GmbH
Handler Holding GmbH
AUSTRIA BIO GARANTIE GmbH / agroVet GmbH
Willis Towers Watson Austria GmbH
LYRECO Office & Work Solutions
De’ Longhi Kenwood GmbH
Edizon Innovation GmbH
Ivellio-Vellin IT Services
- Advised Estée Lauder Cosmetics on data protection and employment law issues, particularly in relation to information obligations and customer contacts.
- Assisted Coca-Cola with various aspects of GDPR implementation and compliance issues.
- Assisted Lyreco Office & Work Solutions with GDPR implementation assistance, and assistance with GDPR and GDPR-related employment law questions.
Taylor Wessing enwc Rechtsanwälte GmbH provides data protection advice, predominantly focusing on GDPR implementation and compliance, to clients in a variety of sectors, including Nestlé, Panasonic Electric Works, Bosch Software Innovations and Otto Bock Healthcare Products. Andreas Schütz, who 'always manages to propose pragmatic solutions', prepared internal damage assessment documentation for Hiscox Insurance Company as well as advising on necessary reports to the data subject and/or the data protection authority following a data breach.
‘Andreas Schuetz is our main point of contact and has been so for many years. Particularly in data protection, professional experience and practical relevance are decisive factors for targeted advice. Andreas Schuetz has exactly these skills and always manages to propose pragmatic solutions. The advantage also lies in the fact that Andreas Schuetz and the data protection team have been familiar with our company for many years.‘
TNT (Express) Austria
ZGONC Handel GmbH
Vorwerk & Co KG
Pirelli Österreich GmbH
Nestlé Österreich GmbH
Great Lenghts Haarvertriebs GmbH
FRONERI Austria GmbH
IKEA of Sweden AB
Sky Österreich Fernsehen GmbH
Dr. A. & L. Schmidgall GmbH & Co
Bosch Software Innovations GmbH
Elektra Bregenz Aktiengesellschaft
Casper Sleep GmbH
Hill International GmbH
RELX GROUP PLC
ARGO Personalentwicklung Gesellschaft m.b.H.
Norske Skog Industrier ASA
Eilenberger Consulting SteuerberatungsgmbH
Haberkorn Holding AG
Familie Haberkorn Privatstiftung
Davinci Lab OG
Alois Dallmay OHGr
Wolters Kluwer CENTRAL EUROPE Beteiligungsgesellschaft m. b. H.
Fette Compacting GmbH
Salzgitter Mannesmann Handel GmbH
HoReCA Digital GmbH
Theater Der Jugend
Tyrol Equity AG
Punto Fa, S.L (Mango)
Cythus EXQUIRE Pharmaforschungs GmbH
„Dach und Wand“ Handels GmbH
Tiffany & Co
Urban Massage Limited
Agrana Juice Holding GmbH
Agrana Beteiligungs- Aktiengesellschaft
Bearing Point GmbH
Salonmeister GmbH (Treatwell)
Roland Spedition GmbH
ISO Leadership GmbH
Lafarge Perlmooser GmbH
Lafarge Perlmooser AG
Lafarge Zementwerke GmbH
Perlmooser Beton GmbH
Prema Autozubehör Handelsgesllschaft m. b. H.
Ricoh Europe PLC
Ricoh Austria GmbH
KGAL GmbH & Co. KG
KGAL Asset Management Österreich GmbH
Nuance Communications, Inc.
Otto Bock Healthcare Products GmbH
Stanton Chase International
Avira Operations GmbH & Co. KG
Elektra Bregenz AG
Panasonic Electric Works Austria GmbH
Lafarge Zementwerke GmbH
LexisNexis Verlag ARD ORAC GmbH & Co KG
Hiscox Insurance Company Ltd
- Advised Nestlé Österreich on the implementation of data protection requirements and data protection issues concerning online marketing.
- Acted for Bosch Software Innovations on the implementation of an application offering access to public charging stations for drivers of electric vehicles.
- Prepared an internal damage assessment for Hiscox Insurance Company as well as advising on necessary reports to the data subject and/or the data protection authority following a data breach.