Service provided by the Federal Ministry of Justice and the Federal Office of Justice ‒ www.gesetze-im-internet.de Section 70 Records of processing activities (1) The controller shall keep a record of all categories of processing activities under its responsibility. This record shall contain all of the following information: 1. the name and contact details of the controller and, where applicable, of the joint controller; and the name and contact details of the data protection officer; 2. the purposes of the processing; 3. the categories of recipients to whom the personal data have been or are to be disclosed; 4. a description of the categories of data subjects and of the categories of personal data; 5. where applicable, the use of profiling; 6. where applicable, the categories of transfers of personal data to bodies in a third country or to an international organization; 7. information about the legal basis for the processing; 8. the envisaged time limits for the erasure or for a review of the need to store the various categories of personal data; and 9. a general description of the technical and organizational security measures referred to in Section 64. (2) The processor shall maintain a record of all categories of processing activities carried out on behalf of a controller, containing 1. the name and contact details of the processor, of each controller on behalf of which the processor is acting and, where applicable, the data protection officer; 2. where applicable, transfers of personal data to bodies in a third country or to an international organization, including the identification of that third country or international organization; and 3. a general description of the technical and organizational security measures according to Section 64. (3) The records referred to in subsections 1 and 2 shall be in writing or in electronic form. (4) Controllers and processors shall make these records available to the Federal Commissioner on request. Section 71 Data protection by design and by default (1) The controller, both at the time the means of processing are determined and at the time of the processing itself, shall take appropriate measures to implement data protection principles, such as data minimization, in an effective manner, to ensure compliance with legal requirements and to protect the rights of data subjects. In doing so, the controller shall take into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing, as well as the risks of varying likelihood and severity for the legally protected interests of the data subject posed by the processing. In particular, personal data shall be processed, and processing systems shall be selected and designed in accordance with the aim of processing as few personal data as possible. Personal data shall be rendered anonymous or pseudonymized as early as possible, as far as possibl e in accordance with the purpose of processing. Page 37 of 43

Select target paragraph3