Privacy notice
for clients
This English version is a courtesy translation. Only the German version is legally binding.
Information pursuant to Art. 13 and 14 GDPR on the processing of personal data in the client relationship · As of October 2026
This information applies to clients and to persons who contact us about a possible engagement. For the use of our website, our website privacy policy also applies.
1. Controller
Dr. Roth & Kollegen Rechtsanwälte Partnerschaft mbB
Gewürzmühlstraße 5, 80538 Munich, Germany
Phone +49 (0)89 55 26 26 0 · E-mail info@copyroth.de
2. Data we process
(1) As our client, we process in particular: name, address, telephone numbers, e-mail address, date of birth, information on occupation and employer, bank details, details of any legal expenses insurance, and all information and documents relating to the matter that you provide to us or that we receive in the course of the mandate.
(2) Depending on the matter, this may include special categories of personal data, such as health data (e.g. in connection with incapacity for work or severe disability), religious affiliation (e.g. in church employment law) or trade union membership.
(3) In the course of the mandate we also process data of third parties, such as opposing parties, their representatives, witnesses or other persons involved. We generally receive these data from you, from courts, authorities or the opposing side.
3. Purposes and legal bases
- Preparing and performing the mandate – advice, representation, correspondence, invoicing (Art. 6(1)(b) GDPR);
- Legal obligations – in particular conflict checks (§ 43a(4) BRAO), keeping client files (§ 50 BRAO), retention under tax and commercial law and, where applicable, identification duties under the Money Laundering Act (Art. 6(1)(c) GDPR);
- Legitimate interests – e.g. asserting or defending claims arising from the client relationship and processing third-party data where necessary to protect your interests (Art. 6(1)(f) GDPR);
- Special categories of data are processed where necessary for the establishment, exercise or defence of legal claims (Art. 9(2)(f) GDPR);
- Consent – e.g. for communication by unencrypted e-mail or video conference (Art. 6(1)(a) GDPR).
4. Recipients
(1) All data are subject to lawyers' professional secrecy (§ 43a(2) BRAO, § 203 StGB). We disclose them only where necessary for the mandate, where required by law or with your consent.
(2) Recipients may include in particular: courts, authorities and arbitration bodies; the opposing party and its representatives; your legal expenses insurer, provided you have released us from confidentiality; experts, interpreters and bailiffs; banks for payment transactions; our professional liability insurer in the event of a claim; our tax adviser for bookkeeping, limited to billing data.
(3) For practice management software, IT support, data backup, telecommunications and document destruction we use carefully selected service providers. They are contractually bound to confidentiality (§ 43e BRAO) and, where they process data on our behalf, bound as processors (Art. 28 GDPR). Our practice management software and online enquiry form are provided by RA-MICRO. We communicate with courts via the special electronic lawyers' mailbox (beA).
(4) Data are transferred to countries outside the EU/EEA only where the mandate requires it, e.g. where parties are located abroad (Art. 49(1)(b), (c) or (e) GDPR).
5. Retention period
(1) We store your data for the duration of the mandate. Thereafter, we retain client files for six years from the end of the calendar year in which the mandate ended (§ 50(1) BRAO). Invoicing records and accounting vouchers are retained in accordance with tax and commercial law (§ 147 AO, § 257 HGB), for up to ten years depending on the document.
(2) The information required for conflict checks – names of the parties and subject of the mandate – is stored for as long as needed for such checks. For claims established by a court title, retention until the end of the limitation period (up to 30 years, § 197 BGB) may be necessary.
(3) After these periods, data are deleted and documents destroyed in a manner compliant with data protection law.
6. Necessity of the data
Providing your data is necessary for accepting and handling the mandate. Without these data we cannot handle the mandate, or not in full.
7. Your rights
(1) You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20 GDPR). You may withdraw consent at any time with effect for the future (Art. 7(3) GDPR).
(2) Right to object: Where we process data on the basis of legitimate interests, you may object at any time on grounds relating to your particular situation (Art. 21 GDPR).
(3) These rights apply only insofar as statutory retention obligations or lawyers' professional secrecy towards third parties do not preclude them (§ 29 BDSG). Due to our duty of confidentiality, we do not separately inform third parties whose data we process in a mandate (Art. 14(5)(d) GDPR, § 29(1) sentence 1 BDSG).
(4) You may lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority competent for us is the Bayerisches Landesamt für Datenschutzaufsicht, Promenade 18, 91522 Ansbach, Germany.
8. Communication
If you provide us with an e-mail address and nothing else has been agreed, we will also communicate with you by unencrypted e-mail. Unencrypted e-mails can be read or altered by third parties. If you wish to use encrypted communication or another channel, please let us know.
9. No automated decision-making
No decision-making based solely on automated processing, including profiling (Art. 22 GDPR), takes place.