The purpose of this Privacy Notice is to provide information about what personal data GÖRG (hereinafter also “we”) processes in the context of the client relationship and from third parties, and how we use this data. Personal data refers to any information relating to an identified or identifiable natural person, such as name, email address, IP address, or mailing address.
Separate privacy notices apply to the use of our website. Data Protection
1. Data Controller
GÖRG Partnership of Attorneys mbB, Kennedyplatz 2, 50679 Cologne, Phone 0221-33660-0, Fax 0221-33660-80,
Email datenschutz [at] goerg.de (datenschutz[at]goerg[dot]de)
2. Data Protection Officer
You can contact our Data Protection Officer as follows: GÖRG Partnership of Attorneys mbB, Data Protection Officer, Kennedyplatz 2, 50679 Cologne, E-Mail: dsb [at] goerg.de (dsb[at]goerg[dot]de)
3. Types of Data Subjects, Categories of Data, Purposes of Processing
In the course of our legal practice, we process personal data, in particular from the following types of data subjects:
Clients and their employees, representatives, advisors, and other contractual partners of the clients,
Opposing parties and their respective representatives and employees, other advisors/service providers (e.g., auditors, tax advisors, consultants, cooperating law firms, private investigation agencies, translators, experts, etc.) involved in the matter, as well as their respective representatives and employees,
third parties such as court personnel, witnesses, and other individuals involved in the matter.
We process the following categories of personal data, which we collect in part directly from clients and their employees, and in part from third parties (e.g., other GÖRG companies, other advisors, counterparties, government agencies, insurance companies, public sources such as commercial registers, the Internet, etc.):
Data used to identify the client or the third party (e.g., copies of identification documents, data from commercial register extracts),
contact information (salutation, title, first name, last name, address, email address, fax number, phone number, role/position),
communication data,
case-related data, i.e., data that we either receive or generate ourselves in the course of handling the case,
billing data,
information necessary for asserting and defending your rights within the scope of the mandate,
other information necessary to safeguard our legitimate interests or to comply with legal requirements (e.g., financial circumstances, tax and social security data).
You are not legally or contractually obligated to provide this data, with the exception of identification data. However, if the data is not provided, it may not be possible to handle the matter.
We process the data for the following purposes:
Pre-contractual measures to establish the client relationship:
Identification of the (potential) client (including identification of beneficial owners, persons acting on their behalf, and their authorization),
Cross-checking against sanctions lists,
Conflict of interest review to avoid conflicts of interest,
Preparation of proposals and cost estimates.
Execution of the client-lawyer relationship:
Advising and representing the client, including asserting and defending the client’s rights, as well as corresponding with the client and other advisors, opposing parties in proceedings, and courts, authorities, and other third parties,
billing.
Internal Administration:
Case file management,
bookkeeping,
operation of IT and communication systems.
Enforcement of Claims:
Asserting or defending against any statutory or contractual claims against clients.
Compliance with legal requirements:
Conducting anti-money laundering checks,
Retaining documents to comply with professional, anti-money laundering, commercial, and tax law retention obligations, as well as for evidentiary purposes in connection with the assertion, exercise, or defense of legal claims, etc.
Maintaining client relationships and marketing:
Sending promotional materials regarding our firm’s services (e.g., newsletters, information on relevant legal developments, current case law, invitations to professional and social events, etc.),
Publishing deal announcements and other press releases,
Providing references for publications by legal publishers and other media outlets
Data from Third Parties:
Asserting or defending any legal or contractual claims
Identifying the data subject (including, where applicable, determining beneficial owners, persons acting on their behalf, and their authorization),
Communication and correspondence,
Clarification of facts
4. Legal Bases for Processing
Establishment and execution of the client-attorney relationship:
Data processing is carried out at your request and is necessary pursuant to Art. 6(1)(b) of the GDPR for the stated purposes to ensure the proper handling of the client-attorney relationship and the mutual fulfilment of obligations under the client-attorney agreement. Where special categories of personal data are involved (e.g., health data, data regarding trade union membership, religious beliefs, etc.), processing is additionally based on the data subject's consent pursuant to Art. 9(2)(a), (b), and (f) of the GDPR, or, where the processing does not require consent under Art. 9(2)(b) or (f), on those grounds directly. In cases where processing is otherwise based on the data subject's consent, Art. 6(1)(a) of the GDPR applies.
Internal Administration:
To the extent that internal administrative measures do not serve to establish and carry out the client-firm relationship, they are carried out to protect our legitimate interests or the interests of a third party pursuant to Article 6(1)(f) of the GDPR. Our legitimate interest arises from the purposes mentioned above.
Enforcement of Claims:
The use of data to assert or defend against any legal or contractual claims is carried out in accordance with Section 24(1)(2) of the German Federal Data Protection Act (BDSG) or to safeguard our legitimate interests pursuant to Article 6(1)(f) of the GDPR. Our legitimate interest arises from the purposes mentioned above.
Compliance with Legal Requirements:
The use of data to comply with legal requirements is based on Article 6(1)(c) of the GDPR.
Client Relationship Management and Marketing:
The processing of data for these purposes is carried out to safeguard our legitimate interests pursuant to Article 6(1)(f) of the GDPR or, in the case of email marketing, based on the data subject’s consent pursuant to Article 6(1)(a) of the GDPR. Our legitimate interest arises from the purposes mentioned above.
Processing of Third-Party Data:
The processing of data relating to third parties who are not clients is based on a legal obligation within the meaning of Art. 6(1)(c) of the GDPR, or to safeguard our legitimate interests or the interests of a third party pursuant to Art. 6(1)(f) of the GDPR. Our legitimate interest arises from the purposes mentioned above.
5. Categories of Data Recipients
Under certain circumstances, it may be necessary for us to share personal data with third parties. The following categories of recipients are particularly relevant in this context:
other GÖRG companies and GÖRG notary offices,
partnering law firms, tax advisory firms, and/or auditing firms outside the GÖRG companies,
other advisors, service providers, or business partners of the client,
insurers,
opposing parties,
courts, government agencies, and other public authorities,
media publishers,
IT service providers, e.g., service providers who assist us in the operation and maintenance of our IT systems, service providers or providers of audio and video conferencing solutions, cloud service providers (see Section 6 for more details),
other service providers or business partners we engage to support our business operations (e.g., experts, translation agencies, agencies, shipping companies, printing companies, document destruction service providers, banks, credit bureaus, private investigation agencies, auditors/tax advisors, etc.).
6. Cloud Service Providers
In particular, we use the Microsoft 365 cloud service, through which we utilize, among other things, the Microsoft Office applications (Word, Outlook, Excel, PowerPoint, etc.) as well as Microsoft Teams and Microsoft SharePoint. In this context, we rely on Microsoft’s assurances under the “EU Data Boundary” solution offered by Microsoft to ensure that data processed using Microsoft applications is processed and stored within the EU. We will provide you with further information regarding the technical details upon request. Please feel free to contact us.
7. Use of AI Technologies
We use modern AI technologies (e.g., for text analysis or research) to support our legal work and to efficiently handle your matters — thereby also acting in your best interest. This use is carried out exclusively in compliance with our internal AI policy. No personal data of clients is processed via cloud-based AI tools. All results are reviewed by qualified attorneys. They are used on a risk-based basis and documented in an AI register:
Purpose: To assist with document structuring, error checking, and legal research.
No automated decision-making: The AI serves solely as a tool. Every result is personally reviewed by our attorneys; no purely automated decision within the meaning of Article 22 of the GDPR takes place.
Data Security: We exclusively use enterprise solutions that prevent AI models from being trained on client data and ensure the highest security standards.
Data Localisation: Data processing generally takes place on our own servers and, in exceptional cases, via the cloud — but only within the EU.
Legal Basis: Processing is based on our legitimate interest in efficient case management and quality improvement (Article 6(1)(f) of the GDPR) or for the performance of a contract (Article 6(1)(b) of the GDPR), provided that the use of AI is necessary for handling the case. In the case of particularly sensitive data or if the use of AI goes beyond standard processing, your data will be processed only with your consent (Art. 6(1)(a) GDPR).
8. Data Transfer to Third Countries
As a general rule, data is processed exclusively within the EU. However, in individual cases, it may become necessary for us to transfer or disclose data to entities outside the EU if applicable data protection regulations permit this. This may be the case, in particular, when we engage foreign law firms in consultation with the client to handle the matter jointly with them. Data transfers to third countries generally take place on the basis of one or more of the following legal grounds or safeguards:
Performance of our client agreement pursuant to Article 49(1)(b) of the GDPR,
Consent pursuant to Article 49(1)(a) of the GDPR,
an adequacy decision pursuant to Article 45 of the GDPR (e.g., for Switzerland, the United Kingdom, and the United States),
standard contractual clauses of the European Commission pursuant to Article 46(2)(c) of the GDPR.
If you require further information regarding the applicable legal bases or safeguards used, please contact us.
9. Retention Period
The personal data we collect in connection with your retainer will be stored until the expiration of the statutory retention period for attorneys (6 years after the end of the calendar year in which the retainer ended) and will be deleted thereafter. In addition, we retain the data to the extent that statutory retention obligations exist, particularly under professional, anti-money laundering, commercial, social security, and/or tax laws (e.g., pursuant to the BRAO, GWG, AO, EStG, UStG, HGB, and SGB IV). Depending on the type of data, retention obligations may range from up to six to up to ten years. Data will only be retained for a longer period if you have consented to such extended storage pursuant to Art. 6(1)(a) of the GDPR.
10. Photos and Video Recordings at Events
Photos and video recordings are taken during our event. These serve to document the event, to be made available to participants, and for use in our corporate communications and for marketing purposes. Processing is based on our legitimate interest in public relations and event documentation pursuant to Article 6(1)(f) of the GDPR. Once the purpose has been fulfilled, we will delete the photos and records, at the latest after three years. If you do not wish to be photographed or filmed, please contact the event’s on-site organizing team.
11. Rights of the Data Subject
You have the right:
pursuant to Article 7(3) of the GDPR to withdraw your consent at any time. As a result, we may no longer continue processing data based on that consent in the future;
pursuant to Article 15 of the GDPR, to request information about your personal data processed by us. In particular, you may request information regarding the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned retention period, the existence of a right to rectification, erasure, restriction of processing, or objection; the existence of a right to lodge a complaint; the origin of your data, if it was not collected by us; and the existence of automated decision-making, including profiling, and, where applicable, meaningful information regarding its details;
pursuant to Art. 16 of the GDPR to request, without undue delay, the rectification of inaccurate personal data or the completion of your personal data stored by us;
pursuant to Article 17 of the GDPR, to request the erasure of your personal data stored by us, unless processing is necessary for the exercise of the right to freedom of expression and information, to comply with a legal obligation, for reasons of public interest, or to establish, exercise, or defend legal claims;
pursuant to Article 18 of the GDPR to request the restriction of the processing of your personal data, provided that you contest the accuracy of the data, the processing is unlawful but you oppose its erasure and we no longer need the data, but you require it to assert, exercise, or defend legal claims, or you have objected to the processing pursuant to Article 21 of the GDPR;
pursuant to Article 20 of the GDPR to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, or to request that it be transmitted to another controller; and
pursuant to Article 77 of the GDPR to lodge a complaint with a supervisory authority. As a general rule, you may contact the supervisory authority at your usual place of residence, your place of work, or the location of our law firm’s headquarters.
12. Right to Object
If your personal data is processed on the basis of legitimate interests pursuant to Article 6(1)(e) and (f) of the GDPR, you have the right, pursuant to Article 21 of the GDPR, to object to the processing of your personal data, provided there are grounds for doing so arising from your particular situation.
If you wish to exercise your right to object, simply send an email to datenschutz [at] goerg.de
