Service provided by the Federal Ministry of Justice
and the Federal Office of Justice ‒ www.gesetze-im-internet.de
7.
ensure that it is subsequently possible to verify and establish which personal
data have been input into automated processing systems and when and by whom the
personal data were input (‘input control’);
8.
ensure that the confidentiality and integrity of personal data are protec ted during
transfers of personal data or during transport of data media (‘transport control’);
9.
ensure that installed systems may, in the case of interruption, be restored
(‘recovery’);
10.
ensure that all system functions perform and that the appearance of faults in the
functions is reported (‘reliability’);
11.
ensure that stored personal data cannot be corrupted by means of a
malfunctioning of the system (‘integrity’);
12.
ensure that personal data processed on behalf of the controller can only be
processed in compliance with the controller’s instructions (‘processing control’);
13.
ensure that personal data are protected against loss and destruction
(‘availability control’);
14.
ensure that personal data collected for different purposes can be processed
separately (‘separability’).
A purpose pursuant to the first sentence, nos. 2 to 5 may be achieved in particular by using
state-of-the-art encryption.
Section 65
Notifying the Federal Commissioner of a personal data breach
(1) In the case of a personal data breach, the controller shall notify the Federal
Commissioner without delay and, if possible, not later than 72 hours after having become
aware of it, of the personal data breach, unless the personal data breach is unlikely to result
in a risk to the legally protected interests of natural persons. If the Federal Commissioner is
not notified within 72 hours, the notification shall be accompanied by reasons for the delay.
(2) A processor shall notify the controller of a personal data breach without delay.
(3) The notification referred to in subsection 1 shall include at least the following information:
1.
a description of the nature of the personal data breach including, where
possible, the categories and approximate number of data subjects concerned and the
categories and approximate number of personal data records concerned;
2.
the name and contact details of the data protection officer or other contact point
where more information can be obtained;
3.
a description of the likely consequences of the personal data breach; and
4.
a description of the measures taken or proposed by the controller to address
the personal data breach, including measures to mitigate its possible adverse effects.
(4) If it is not possible to provide the information pursuant to subsection 3 with the
notification, the controller shall provide this information as soon as it is available.
(5) The controller shall document any personal data breaches. This documentation shall
include all the facts relating to the personal data breach, its effects and the remedial action
taken.
(6) If the personal data breach involves personal data that have been transmitted by or to a
controller in another Member State of the European Union, the information referred to in
subsection 3 shall be communicated to the controller in that Member State without delay.
(7) Section 42 (4) shall apply accordingly.
Page 34 of 43