Service provided by the Federal Ministry of Justice and the Federal Office of Justice ‒ www.gesetze-im-internet.de (8) Additional obligations of the controller regarding notifications of personal data breaches shall remain unaffected. Section 66 Notifying data subjects affected by a personal data breach (1) If a personal data breach is likely to result in a substantial risk to the legally protected interests of natural persons, the controller shall notify the data subject of the personal data breach without delay. (2) The notification of the data subject pursuant to subsection 1 shall describe in clear and plain language the nature of the personal data breach and contain at least the information and measures referred to in Section 65 (3) nos. 2 to 4. (3) Notification shall not be required if any of the following conditions are met: 1. the controller has implemented appropriate technical and organizational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those that render the personal data unintelligible to any person who is not authorized to access them, such as encryption; 2. the controller has taken subsequent measures which ensure that the substantial risk referred to in subsection 1 is no longer likely to exist; 3. it would involve a disproportionate effort; in this case, a public communication shall be made or a similar measure taken to inform the data subjects in an equally effective manner. (4) If the controller has not informed the data subjects of a personal data breach, the Federal Commissioner may formally determine that, in his or her opinion, the conditions referred to in subsection 3 have not been met. In doing so, the Federal Commissioner shall consider the likelihood of the personal data breach resulting in a high risk as referred to in subsection 1. (5) The notification of data subjects pursuant to subsection 1 may be delayed, restricted or omitted under the conditions referred to in Section 56 (2) unless the interests of the data subjects outweigh those of the controller owing to the high risk resulting from the personal data breach as referred to in subsection 1. (6) Section 42 (4) shall apply accordingly. Section 67 Conducting a data protection impact assessment (1) Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a substantial risk to the legally protected interests of data subjects, the controller shall, prior to t he processing, carry out an assessment of the impact of the envisaged processing operations on the data subjects. (2) A joint assessment may address a set of similar processing operations that present similar substantial risks. (3) The controller shall involve the Federal Commissioner in carrying out the impact assessment. (4) The impact assessment shall take the rights of the data subjects affected by the processing into account and shall contain at least the following: 1. a systematic description of the envisaged processing operations and the purposes of the processing; 2. an assessment of the necessity and proportionality of the processing operations in relation to their purposes; 3. an assessment of the risks to the legally protected interests of the dat a subjects; and Page 35 of 43

Select target paragraph3