Service provided by the Federal Ministry of Justice
and the Federal Office of Justice ‒ www.gesetze-im-internet.de
d)
2.
processing is urgently necessary for reasons of substantial public interest;
by public bodies if
a)
processing is necessary to prevent a substantial threat to public security;
b) processing is urgently necessary to prevent substantial harm to the common
good or to safeguard substantial concerns of the common good; or
c) processing is necessary for urgent reasons of defence or to fulfil supra- or
intergovernmental obligations of a public body of the Federation in the field of
crisis management or conflict prevention or for humanitarian measures;
and as far as the interests of the controller in data processing in the cases of no. 1 (d) and
no. 2 outweigh the interests of the data subject.
(2) In the cases of subsection 1, appropriate and specific measures shall be taken to
safeguard the interests of the data subject. Taking into account the state of the art, the cost
of implementation and the nature, scope, context and purposes of processing as well as the
risks of varying likelihood and severity for rights and freedoms of natural persons posed by
the processing, these measures may include in particular the following:
1.
technical organizational measures to ensure that processing complies with
Regulation (EU) 2016/679;
2.
measures to ensure that it is subsequently possible to verify and establish
whether and by whom personal data were input, altered or removed;
3.
measures to increase awareness of staff involved in processing operations;
4.
designation of a data protection officer;
5.
restrictions on access to personal data within the controller and by processors;
6.
the pseudonymization of personal data;
7.
the encryption of personal data;
8.
measures to ensure the ability, confidentiality, integrity, availability and
resilience of processing systems and services related to the processing of personal data,
including the ability to rapidly restore availability and access in the event of a physical or
technical incident;
9.
a process for regularly testing, assessing and evaluating the effectiveness of
technical and organizational measures for ensuring the security of the processing;
10.
specific rules of procedure to ensure compliance with this Act and with
Regulation (EU) 2016/679 in the event of transfer or processing for other purpos es.
Section 23
Processing for other purposes by public bodies
(1) Public bodies shall be permitted to process personal data for a purpose other than the
one for which the data were collected where such processing is necessary for them to
perform their duties and if
1.
it is obviously in the interest of the data subject and there is no reason to
assume that the data subject would refuse consent if he or she were aware of the other
purpose;
2.
it is necessary to check information provided by the data subject because there
is reason to believe that this information is incorrect;
Page 13 of 43