Service provided by the Federal Ministry of Justice
and the Federal Office of Justice ‒ www.gesetze-im-internet.de
(8) Additional obligations of the controller regarding notifications of personal data breaches
shall remain unaffected.
Section 66
Notifying data subjects affected by a personal data breach
(1) If a personal data breach is likely to result in a substantial risk to the legally protected
interests of natural persons, the controller shall notify the data subject of the personal data
breach without delay.
(2) The notification of the data subject pursuant to subsection 1 shall describe in clear and
plain language the nature of the personal data breach and contain at least the information
and measures referred to in Section 65 (3) nos. 2 to 4.
(3) Notification shall not be required if any of the following conditions are met:
1.
the controller has implemented appropriate technical and organizational
protection measures, and those measures were applied to the personal data affected by
the personal data breach, in particular those that render the personal data unintelligible to
any person who is not authorized to access them, such as encryption;
2.
the controller has taken subsequent measures which ensure that the substantial
risk referred to in subsection 1 is no longer likely to exist;
3.
it would involve a disproportionate effort; in this case, a public communication
shall be made or a similar measure taken to inform the data subjects in an equally
effective manner.
(4) If the controller has not informed the data subjects of a personal data breach, the Federal
Commissioner may formally determine that, in his or her opinion, the conditions referred to in
subsection 3 have not been met. In doing so, the Federal Commissioner shall consider the
likelihood of the personal data breach resulting in a high risk as referred to in subsection 1.
(5) The notification of data subjects pursuant to subsection 1 may be delayed, restricted or
omitted under the conditions referred to in Section 56 (2) unless the interests of the data
subjects outweigh those of the controller owing to the high risk resulting from the personal
data breach as referred to in subsection 1.
(6) Section 42 (4) shall apply accordingly.
Section 67
Conducting a data protection impact assessment
(1) Where a type of processing in particular using new technologies, and taking into account
the nature, scope, context and purposes of the processing, is likely to result in a substantial
risk to the legally protected interests of data subjects, the controller shall, prior to t he
processing, carry out an assessment of the impact of the envisaged processing operations
on the data subjects.
(2) A joint assessment may address a set of similar processing operations that present
similar substantial risks.
(3) The controller shall involve the Federal Commissioner in carrying out the impact
assessment.
(4) The impact assessment shall take the rights of the data subjects affected by the
processing into account and shall contain at least the following:
1.
a systematic description of the envisaged processing operations and the
purposes of the processing;
2.
an assessment of the necessity and proportionality of the processing operations
in relation to their purposes;
3.
an assessment of the risks to the legally protected interests of the dat a
subjects; and
Page 35 of 43