In an era of rapidly advancing digitalization, a cyberattack often hits companies without warning. Systems are encrypted, customer data may be compromised, employees can no longer work, and attackers threaten to publish sensitive information or demand a ransom. In this situation, management, IT teams, data protection officers, and external service providers must act quickly and in a coordinated manner.
Schlun & Elseven Rechtsanwälte supports companies facing cyberattacks with legal assessment, compliance with data protection reporting obligations, communication with authorities and insurers, and coordination of IT forensic measures. Our goal is to limit legal risk, meet deadlines, preserve evidence, and keep the company able to respond during the acute crisis.
Under the stringent provisions of the General Data Protection Regulation (GDPR), companies are obligated to report cyber incidents to the relevant data protection authorities within 72 hours in qualifying cases. Our lawyers are ready to clarify your reporting obligations and guide you through the necessary steps to meet legal requirements in the event of a breach.
Partner with Schlun & Elseven Rechtsanwälte to fortify your company against cyber threats while facing the German legal landscape with confidence. Contact us directly for expert legal assistance.
What to Do in the First 24 Hours after a Cyberattack in Germany
If your company has just discovered a cyberattack, the following sequence reflects the priorities that matter most on the first day:
- Contain the incident. Work with IT to isolate affected systems without destroying evidence needed for the forensic and legal review.
- Preserve evidence. Document what is known so far: when the attack was discovered, which systems are affected, and what actions have already been taken.
- Get a legal assessment underway immediately. The 72-hour notification clock under Article 33 GDPR starts running from the moment the company becomes aware of the breach, not from the moment the assessment is complete.
- Identify what data may be involved. Determine, as far as possible, whether personal data is affected and what categories are at risk.
- Loop in your data protection officer or legal counsel. They will need to assess both the Article 33 notification to the supervisory authority and, separately, whether the higher Article 34 GDPR threshold for notifying affected individuals is met.
- Notify your cyber insurer. Many policies have their own reporting deadlines and requirements that run independently of the GDPR clock.
- Hold off on public statements until legal counsel has reviewed the situation, to avoid inconsistent or premature disclosures.
This is not a substitute for a full legal assessment, but a starting checklist while that assessment gets underway.
Typical Cases of Cybercrime in Germany
Cybercrime is a pervasive threat targeting modern technologies, including data networks, systems, and tools, and it poses significant challenges for international businesses operating in Germany. Victims of such cyber offenses and attacks encompass companies, private individuals, and public authorities. Perpetrators employ various methods to obtain sensitive data and information:
Ransomware Attacks
In a ransomware attack, systems, servers, or data are encrypted. Attackers typically demand a ransom for restoring access, and often threaten to publish stolen data as well. Companies must quickly determine which data has been affected, whether reporting obligations apply, how to handle the extortion attempt, and what communication is needed with authorities, insurers, customers, and employees.
Data Breaches and Disclosure of Sensitive Information
Attacks involving the potential loss of personal data, trade secrets, client data, patient data, financial data, or confidential business records are especially critical. A precise legal and technical analysis is required to determine whether data has actually been affected, which categories of data are involved, and what risks arise for the individuals concerned or for the company itself.
Phishing and Compromised Email Accounts
Phishing attacks often result in stolen login credentials and compromised email accounts. Attackers can then read internal communications, manipulate payment instructions, or access confidential information. Here too, it must be assessed whether personal data has been affected and whether a data protection notification is required.
CEO Fraud and Payment Fraud
In CEO fraud, attackers impersonate management, supervisors, or business partners to induce employees to make payments or disclose sensitive information. Beyond the criminal law dimension, these cases frequently raise employment law, insurance law, and liability questions.
Attacks on Service Providers and Data Processors
An attack does not always target the company directly. External IT service providers, cloud providers, software vendors, and other data processors are frequently affected instead. In these cases, the company must still determine what obligations apply to it, whether notification is required, and what information must be obtained from the service provider.
Cyberattack: Why Fast Action Is Critical
Legal and economic risks run in parallel during a cyberattack. While the IT department works to isolate and restore systems, legal obligations must be reviewed and documented at the same time. The General Data Protection Regulation (GDPR) is especially relevant here: if personal data has been compromised, the company must determine whether it must notify the competent data protection supervisory authority. Under Article 33 GDPR, notification is required without undue delay and, wherever possible, within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of the individuals affected. Where the 72-hour deadline is missed, the notification must include reasons for the delay.
This tight deadline leaves little room to delay a legal assessment. At the same time, the notification must not be rushed or incomplete. Article 33 requires it to describe the nature of the breach, the categories and approximate number of individuals and records affected, the likely consequences, and the measures already taken or proposed. Even where only a preliminary notification is possible at first, it should still be prepared to a high legal standard, since the remaining details can follow in phases without undue further delay.
Data Protection Obligations Following a Cyberattack
After a cyberattack, the company must first determine whether a personal data breach has occurred. Personal data may include data from customers, employees, applicants, clients, patients, users, or suppliers.
If a breach has occurred, the company must assess:
- Which data is affected?
- How many individuals are affected?
- Was the data encrypted or otherwise protected?
- Was the data only temporarily inaccessible, or was it actually accessed or extracted?
- Does the breach pose a risk to the rights and freedoms of the affected individuals?
- Is notification to the data protection supervisory authority required under Article 33 GDPR?
- Does the breach meet the higher threshold under Article 34 GDPR for notifying the affected individuals directly, which applies only where there is a likely high risk to their rights and freedoms?
- What internal documentation obligations apply?
Under Article 33(5), the company must document every personal data breach, including the facts, its effects, and the remedial action taken, so that the supervisory authority can verify compliance. This assessment should be carefully documented in all cases. Even if the conclusion is that no notification is required, the company must be able to explain and justify that decision.
Notification to affected individuals under Article 34 is not automatic even where a breach is serious. It is not required if the affected data was protected by measures such as encryption that render it unintelligible, if the company has since taken action that removes the high risk, or if individual notification would involve disproportionate effort, in which case a public communication is used instead. A supervisory authority can still require notification to individuals if it disagrees with the company’s assessment.
Communication with Authorities, Insurers, and Affected Individuals
Communication after a cyberattack calls for care. Imprecise or inconsistent statements can increase legal risk, complicate insurance matters, or damage the trust of customers and business partners.
We support companies with the legal preparation and coordination of communication with
- Data protection supervisory authorities,
- Investigating authorities, cyber insurers,
- IT service providers,
- Customers and business partners,
- Employees,
- Affected individuals, and
- Other internal and external stakeholders.
IT Forensics and Legal Coordination
The technical analysis of a cyberattack is a task for specialized IT forensic experts, but the forensic investigation still needs to be coordinated from a legal standpoint. It should be documented which systems were affected, when the attack was discovered, what measures were taken, and what has been established about the cause and scope of the attack.
IT forensic experts commonly preserve evidence by:
- Analysing servers for unknown processes (services crashing, unusual login activity, or failed login attempts),
- Assessing end devices for signs of tampering or conspicuous files,
- Examining network infrastructure for logs of unknown users or unusually high traffic.
It is critical that the state of the attacked system is preserved exactly as the attacker left it, rather than altered during review, since altering it can render evidence inadmissible in court.
We work with experienced IT forensic experts where needed and provide legal guidance on the technical findings. This allows companies to ensure that technical measures, evidence preservation, data protection assessment, and external communication are properly aligned.
Liability, Insurance, and Damage Limitation
Cyberattacks can cause substantial financial damage, including business interruption, recovery costs, IT forensics costs, communication costs, potential fines, damage claims, and reputational harm.
Whether a cyber insurance policy responds to a claim often depends on what security measures were in place, what obligations were set out in the insurance contract, and how the incident was reported and documented. For this reason, communication with insurers should be handled with legal guidance from an early stage.
Our lawyers advise on insurance questions, liability risks, and potential claims against attackers, service providers, or other parties involved.
Prevention After the Incident: Lessons Learned and Compliance
Once the acute phase has passed, the cyberattack should be reviewed in a structured way. Companies should assess what technical and organizational measures need improvement, whether internal processes should be adjusted, and whether existing contracts with IT service providers, data processors, or insurers need to be updated.
We also support companies after the acute crisis phase with
- Data protection and compliance reviews,
- Revision of internal reporting processes,
- Development or updating of incident response plans,
- Review of data processing agreements and IT service provider contracts,
- Legal assessment of technical and organizational measures, and
- Preparation for potential follow-up inquiries from authorities.
Schlun & Elseven: Legal Advice for Cyberattacks
A cyberattack is a legal, technical, and communications crisis for any company. Acting quickly and in a structured way can limit damage, meet deadlines, and reduce legal risk.
Schlun & Elseven Rechtsanwälte supports companies nationwide with cyberattacks, data protection incidents, and IT security crises. Our lawyers combine legal advice with the coordination of technical expertise, guiding companies from the initial assessment through to the final resolution of the incident.
Has your company been affected by a cyberattack? Every hour that passes can deepen the legal and economic consequences. Contact our lawyers for an immediate assessment of your situation.
An Overview: Frequently Asked Questions relating to Cyberattacks in Germany
No, not every cyberattack automatically triggers a reporting obligation. Under Article 33 GDPR, notification is only required where personal data has been affected, and the breach is likely to result in a risk to the rights and freedoms of the individuals concerned. For example, if only an encrypted database that was not extracted is affected, the reporting obligation may not apply. That said, the risk assessment should always be reviewed and documented in consultation with legal counsel. Where notification to the data protection authority is required, it must be made within 72 hours of the incident.
Article 33 GDPR does not treat a missed deadline as an automatic violation, but it does require the notification to be accompanied by reasons for the delay. A late notification can still result in a fine. However, supervisory authorities take into account whether the company can reasonably explain the delay and whether it otherwise acted cooperatively and diligently. A well-documented late notification is significantly better, from a legal standpoint, than no notification at all.
Companies need to determine which data has been affected, how many individuals are affected, whether the data was encrypted or otherwise protected, whether it was only temporarily inaccessible or actually accessed or extracted, and whether there is a risk to the rights and freedoms of the affected individuals under Article 33 GDPR. This assessment should be carefully documented, and Article 33(5) requires the company to document every breach along with its effects and the remedial action taken. Even if the conclusion is that no notification is required, the company must be able to explain and justify that decision.
No. Direct notification to affected individuals under Article 34 GDPR only applies where the breach is likely to result in a high risk to their rights and freedoms, a higher threshold than the one that triggers notification to the supervisory authority. Even then, direct notification is not required if the affected data was encrypted or otherwise rendered unintelligible, if the company has since taken measures that remove the high risk, or if individual notification would involve disproportionate effort, in which case a public communication is used instead. A supervisory authority can still require the company to notify individuals directly if it disagrees with that assessment.

Practice Group: German IT Law & Cybercrime
Practice Group:
Practice Group: German IT Law & Cybercrime
Contact Schlun & Elseven Rechtsanwälte
Please use our online form to outline your request to us. After receiving your request, we will make a brief initial assessment based on the facts described and provide you with a cost offer. You can then decide whether you would like to engage our services.





