Our expertise
Compliance – Legal compliance for companies
For companies, complying with legal regulations is of the utmost importance in order to avoid legal risks, sanctions, and reputational damage.
Legal compliance encompasses many areas, including data and environmental protection, labor law compliance, and supply chain monitoring.
A well-structured compliance strategy protects against adverse legal consequences and strengthens the trust of customers, business partners, and investors. Our lawyers specializing in legal compliance can help you develop and implement customized structures.
Summary
- What is (legal) compliance and why is it becoming increasingly important for companies ?
- What requirements apply with regard to data protection in companies ?
- What rules must companies observe in terms of occupational health and safety ?
- What do you need to bear in mind in relation to money laundering prevention ?
- To what extent must companies monitor supply chains ?
- What needs to be considered in relation to whistleblowers ?
What is (legal) compliance and why is it becoming increasingly important for companies ?
Generally, legal compliance means that a company’s internal processes, legal actions, and contracts with third parties align with applicable legal standards. Thus, legal compliance encompasses all the classic legal matters with which a company must deal, e.g.,
- General terms and conditions – Contract management
- Anti-corruption strategies
- Occupational health and safety – Workplace safety – Labor law
- Banking transactions – cash flows – money laundering prevention
- Data protection
- Corporate law – Capital market law – Corporate governance code
- Internal compliance culture and protection of whistleblowers
- AI (artificial intelligence)
- Minority protection – Prohibition of discrimination
- Product safety – Product liability
- Environmental protection – Sustainability
- Distribution systems and supply chains
We would like to limit ourselves to the most common cases of legal compliance in practice when addressing the following questions, insofar as individual legal compliance issues are not already covered in another area of expertise: These include data protection, occupational health and safety, money laundering prevention, supply chains, and whistleblowers.
What requirements apply with regard to data protection in companies ?
Companies must ensure that personal data is processed in accordance with applicable data protection laws. This includes compliance with the principles of data minimization, purpose limitation, and storage limitation, among other things. Additionally, companies must implement technical and organizational measures to safeguard data and prevent unauthorized access or leaks. Violations of data protection regulations can result in significant fines and reputational damage. Our lawyers specializing in legal compliance can help you establish processes that comply with data protection regulations and minimize liability risks.
-
What measures are necessary to comply with the GDPR ?
Expand contentTo meet the requirements of the General Data Protection Regulation (GDPR), companies must take various technical and organizational measures. These measures include appointing a data protection officer, maintaining a record of processing activities, and implementing security measures to protect personal data. Additionally, companies must carry out data protection impact assessments if their data processing poses a high risk to data subjects. Our lawyers specializing in legal compliance will support you in developing a legally compliant data protection strategy and help you adapt to new regulatory requirements.
-
What needs to be considered when using artificial intelligence (AI) ?
Expand contentUsing AI in companies presents unique challenges, particularly with regard to complying with data protection regulations, such as the AI Act. Companies must ensure the traceability of AI-supported systems. Additionally, strict requirements apply to data processing, particularly when sensitive personal data is processed using AI tools like ChatGPT, Gemini, and DeepSeek. Violations of data protection regulations can result in heavy penalties. Our lawyers specializing in legal compliance can advise you on regulatory requirements and help you develop legally compliant AI strategies.
-
When is a data protection officer required and what are their responsibilities ?
Expand contentAccording to European law, companies with at least twenty employees who process personal data on a permanent and automated basis are required to appoint a data protection officer. It may also be necessary to appoint a data protection officer if particularly sensitive data is processed, for example. A data protection officer monitors compliance with data protection regulations, trains employees, and serves as a contact person for supervisory authorities and data subjects. They also advise the company on data protection issues and help identify risks early on. Our lawyers specializing in legal compliance can help you implement effective data protection management.
-
What technical and organizational measures are necessary for secure data processing ?
Expand contentTo ensure the security of personal data, companies must take various measures. These measures include encrypting sensitive data, using secure authentication methods, and conducting regular security audits. Raising awareness and training employees are also crucial in preventing data breaches. Our lawyers specializing in legal compliance will work with you to develop customized security concepts and support you in implementing the appropriate protective measures.
-
Can personal data be transferred abroad ?
Expand contentThe transfer of personal data to countries outside the EU is subject to strict requirements. Companies must ensure that appropriate safeguards are in place to guarantee a comparable level of data protection. These safeguards may include standard contractual clauses or binding corporate rules. Additionally, information and documentation requirements must be observed. Our lawyers specializing in legal compliance provide comprehensive advice on secure, legally compliant international data transfers.
You have any other questions ?
Please feel free to ask them directly here.
What rules must companies observe in terms of occupational health and safety ?
A safe working environment is required by law and crucial for employees’ health and productivity. Companies must comply with occupational health and safety regulations and take appropriate measures to prevent workplace accidents and health hazards.
-
What are an employer’s legal obligations with regard to occupational health and safety ?
Expand contentEmployers are required to ensure the health and safety of their employees. This includes conducting risk assessments, providing safe work equipment, and offering regular training. Additionally, occupational health and safety measures must be continuously reviewed and adapted to new circumstances. Violations of occupational health and safety regulations can lead to significant liability risks and fines. Our lawyers specializing in legal compliance and labor law can help you develop a legally compliant occupational health and safety strategy.
-
How is a risk assessment carried out ?
Expand contentA risk assessment is a systematic process of identifying potential workplace hazards and developing appropriate protective measures. The process involves several steps: identifying hazards, assessing risks, defining and implementing measures, and reviewing these measures. Employers must update the risk assessment regularly. Our lawyers specializing in legal compliance can help you prepare a document assessing occupational risks, known as a DUERP in France, to ensure compliance with legal obligations.
-
Which companies need a company doctor ?
Expand contentIn Germany and France, all companies, regardless of size, must organize occupational health examinations in accordance with national regulations, even if they have only one employee. A company doctor may be a permanent employee or an external contractor. The company doctor supports the employer in matters of occupational safety and accident prevention, conducts health examinations, and advises on workplace health promotion. Our lawyers specializing in legal compliance and labor law can help you determine your specific occupational medicine obligations and assist you in meeting legal requirements.
-
Does the mental health of employees also play a role ?
Expand contentYes, occupational safety covers both physical and mental stress. Employers must take measures to eliminate or minimize stress, overloads, and other mental health risks, such as bullying. This includes considering mental health risks in the risk assessment. Our lawyers specializing in legal compliance and labor law can advise you on implementing effective measures to protect mental health.
-
What rules apply to a subsidiary abroad ?
Expand contentSince occupational health and safety regulations vary from country to country, subsidiaries must comply with national regulations. However, certain group-wide minimum standards remain relevant for international locations. Employers should ensure that their foreign subsidiaries comply with local laws and international best practices in occupational health and safety. Our lawyers specializing in legal compliance and labor law can help you implement occupational health and safety standards for international corporate groups in a legally compliant manner.
You have any other questions ?
Please feel free to ask them directly here.
What do you need to bear in mind in relation to money laundering prevention ?
To detect and prevent illegal financial transactions at an early stage, companies must establish clear structures and control mechanisms. This includes internal control systems, regular training, and thorough risk analysis. Increased vigilance is especially important in cross-border business relationships. Our lawyers specializing in legal compliance can help develop legally compliant preventive measures. These measures minimize the risk of fines and reputational damage.
-
What basic measures must a company take to prevent money laundering ?
Expand contentImportant measures include identifying contractual partners, documenting transactions, and performing internal controls. Companies should also conduct individual risk assessments. Depending on the circumstances, it may also be necessary to appoint a money laundering officer and provide regular internal or external training for employees. Our lawyers specializing in legal compliance can help develop a customized prevention system.
-
What obligations apply when dealing with business partners and customers ?
Expand contentIn certain cases, companies must identify and verify the beneficial owners of their customers and business partners. Compliance with due diligence obligations depends on the respective risk profile. This includes ongoing monitoring of business relationships. Our lawyers specializing in legal compliance can help you implement these obligations in a legally compliant manner.
-
When and how must suspicious transactions be reported ?
Expand contentAny suspicious cases must be reported immediately to the relevant Financial Intelligence Unit (FIU). Companies may not continue carrying out suspicious transactions before receiving a response from the FIU. Therefore, a documented internal reporting chain is essential. Our lawyers specializing in legal compliance can help design efficient reporting processes.
-
What does a compliance program for money laundering prevention consist of ?
Expand contentSuch a program includes a risk analysis, internal guidelines, employee training, and control mechanisms, among other things. Establishing a whistleblower system is also recommended. These measures should be reviewed and updated regularly. Our lawyers specializing in legal compliance develop programs that meet your industry’s requirements.
-
How can you protect yourself against unwitting involvement in money laundering ?
Expand contentThis is achieved through careful selection of business partners, transparent payment processes, and ongoing monitoring. Training helps identify suspicious patterns early on. Companies should also define clear responsibilities. Our lawyers specializing in legal compliance advise on minimizing risk through effective prevention strategies.
You have any other questions ?
Please feel free to ask them directly here.
To what extent must companies monitor supply chains ?
Companies are required to identify and minimize risks within their supply chains. This is particularly true for human rights and environmental standards. Depending on the legal situation at hand, indirect suppliers must also be monitored. Our lawyers specializing in legal compliance can help you set up a legally compliant monitoring system.
-
What legal requirements must be observed with regard to supply chains ?
Expand contentBoth the German Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz – LkSG) and the French “Loi de vigilance” require companies to comply with human rights and environmental due diligence obligations. The EU Supply Chain Directive could impose additional rules. Recently, calls for less bureaucracy have grown louder, leading to a number of changes, suspensions, and postponements. Our lawyers specializing in legal compliance can clarify which rules apply to your company and help you develop a supply chain monitoring concept.
-
Which companies must observe due diligence obligations ?
Expand contentCompanies must identify and minimize human rights and environmental risks in their business processes and supply chains. Depending on the nature, scope, and risk potential of their activities, these due diligence obligations apply to companies of all sizes. Subsidiaries or business units of companies that operate internationally may also be affected. Our lawyers specializing in legal compliance determine the relevance of due diligence obligations and advise on the implementation of appropriate, legally compliant measures.
-
Which areas must be monitored as part of due diligence obligations ?
Expand contentDue diligence obligations require monitoring of human rights risks, such as forced labor, child labor, discrimination, and unfair working conditions. Additionally, environmental aspects, such as the handling of hazardous substances, resource consumption, and emissions, must be considered. Indirect suppliers may also need to be included. Our lawyers specializing in legal compliance can help you identify relevant risk areas and establish effective control and prevention measures.
-
What are the liability risks associated with breaches of due diligence obligations ?
Expand contentViolations can result in hefty fines and reputational damage. Companies may also be excluded from public contracts. Depending on the legal situation, civil lawsuits are also possible. Our lawyers specializing in legal compliance can advise you on risk minimization and legal protection.
-
How can compliance with due diligence obligations be ensured ?
Expand contentStructured risk analysis processes, clear responsibilities, and regular training are necessary. Companies must document their measures, prepare reports, and meet deadlines. Our lawyers specializing in legal compliance develop practical, individualized solutions for these purposes.
You have any other questions ?
Please feel free to ask them directly here.
What needs to be considered in relation to whistleblowers ?
Whistleblowers must be protected, and their reports must be kept confidential. Companies are legally required to establish a secure reporting system. This promotes an open compliance culture and prevents internal risks. Our lawyers specializing in legal compliance can help you establish a whistleblower system that complies with the law.
-
What are the legal requirements for the protection of whistleblowers ?
Expand contentAppropriate legal and organizational measures must be taken to protect whistleblowers from discrimination and reprisals. This includes the confidential treatment and careful processing of reports. Protecting the whistleblower’s identity is an essential component of modern compliance systems. Our lawyers specializing in legal compliance help set up processes that protect whistleblowers and are legally compliant.
-
Which companies are required to set up a whistleblower system ?
Expand contentWhether a company is required to implement a whistleblower system depends on various factors, including its size, industry, and business activities. In many jurisdictions, both private and public organizations are required to establish internal reporting offices. This may also apply to international companies and their subsidiaries. Our lawyers specializing in legal compliance will review the legal requirements and develop a suitable system for your company.
-
What reporting channels are available to whistleblowers ?
Expand contentDepending on the legal situation, whistleblowers may contact either internal reporting offices within the company or external offices at relevant authorities. Companies must provide clear, accessible, and secure channels for internal reporting. In most cases, it is advisable to offer the option of anonymous communication. Our lawyers specializing in legal compliance can support you in selecting and implementing suitable internal and external reporting channels.
-
How do you design a legally compliant whistleblower system ?
Expand contentAn effective whistleblower system must guarantee confidentiality and data protection. It should establish clear responsibilities, transparent processes, and secure communication. Employee training and integration into existing compliance structures are also key to success. Our lawyers specializing in legal compliance develop customized systems that meet both regulatory requirements and internal company needs.
-
What are the consequences of failing to protect whistleblowers ?
Expand contentInadequate protection can result in legal sanctions, financial losses, and a substantial loss of trust. Companies also risk abuses remaining undetected or becoming public. The absence of a whistleblower system may also be considered a structural compliance deficit. Our lawyers specializing in legal compliance help identify risks early on and take appropriate legal action.
You have any other questions ?
Please feel free to ask them directly here.