Skip to content
Call, +49 511 47 55 58 10
lexICT GmbH, Home

About us

How we work

In our work the risk is what we put at the centre. We want to put those responsible in a position to take informed decisions and in that way to make IT projects possible instead of holding them up.

The time loop

In a data centre far, far away …

First comes the technology. It promises to do in minutes what used to take weeks, and everyone wants to use it. Then comes the law: data protection, artificial intelligence, platform regulation, IT security. The intention is good every time. What arrives is uncertainty.

In 2009 the uncertainty was called cloud. Nobody knew whether the data was allowed to leave the building, so the servers stayed in the basement. In 2018 it was called GDPR. Doorbell nameplates were anonymised, address books deleted, group photographs taken down. In 2025 it was called artificial intelligence. And the question of how it may lawfully be used is in many places unanswered.

Nobody acted unreasonably in any of this. Whoever releases a project carries the responsibility for it. So it is held up instead. The works council has not consented, the legal department has not answered – the project stalls, though nobody actually prohibited it.

Costs arise all the same, they just appear on no invoice. Decisions that fail to be taken cost more than wrong ones.

In 2026 the uncertainty is called data sovereignty. Back then the question was whether the data may leave the building. Today it is whether it has to come back. The data centre far, far away was once the solution. Now it is the uncertainty. There is no prohibition and no obligation either, and that is precisely the difficulty. A prohibition can be complied with. An open question is feared.

It is this fear we work against. We say what is prohibited and what is possible under which conditions. After that it is a decision like any other.

First comes the technology, then the law, then the uncertainty. Then we come along and make it work.

We make it work

The question is often not whether a project is permitted, but under which conditions it would be.

Pragmatism

A recommendation that nobody in the business follows is not one. What counts is what can be put into practice with the people and systems that are there.

Individuality

A form does not know the organisation it is meant to apply to. That is why the facts come first and not a template.

Legal certainty

The assessment has to be comprehensible and to withstand a question from the supervisory authority. That is why a risk assessment stands at the end, and not an answer of yes or no.

From the facts into everyday operation

  1. Record the facts

    Where things stand, what is to be achieved, which requirements apply. In practice the most underestimated step.

  2. Assess the legal position

    With the emphasis on a risk assessment, because much in data protection law cannot be answered unambiguously.

  3. Recommendation

    Options with their pros and cons, taking strategic considerations and operational risks into account.

  4. Support the implementation

    The decision turns into contracts, templates and procedures.

4 von 4

Fit the pieces in

As a rule the challenge lies in making something fit.

Reihen
0
Züge
0

Pfeil nach oben dreht, die übrigen bewegen, Leertaste hält an.

Get in touch!

Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!

Contact us

Alternatively you can request a call back.

Related pages