Service provided by the Federal Ministry of Justice
and the Federal Office of Justice ‒ www.gesetze-im-internet.de
Section 70
Records of processing activities
(1) The controller shall keep a record of all categories of processing activities under its
responsibility. This record shall contain all of the following information:
1.
the name and contact details of the controller and, where applicable, of the joint
controller; and the name and contact details of the data protection officer;
2.
the purposes of the processing;
3.
the categories of recipients to whom the personal data have been or are to be
disclosed;
4.
a description of the categories of data subjects and of the categories of
personal data;
5.
where applicable, the use of profiling;
6.
where applicable, the categories of transfers of personal data to bodies in a
third country or to an international organization;
7.
information about the legal basis for the processing;
8.
the envisaged time limits for the erasure or for a review of the need to store the
various categories of personal data; and
9.
a general description of the technical and organizational security measures
referred to in Section 64.
(2) The processor shall maintain a record of all categories of processing activities carried out
on behalf of a controller, containing
1.
the name and contact details of the processor, of each controller on behalf of
which the processor is acting and, where applicable, the data protection officer;
2.
where applicable, transfers of personal data to bodies in a third country or to an
international organization, including the identification of that third country or international
organization; and
3.
a general description of the technical and organizational security measures
according to Section 64.
(3) The records referred to in subsections 1 and 2 shall be in writing or in electronic form.
(4) Controllers and processors shall make these records available to the Federal
Commissioner on request.
Section 71
Data protection by design and by default
(1) The controller, both at the time the means of processing are determined and at the time
of the processing itself, shall take appropriate measures to implement data protection
principles, such as data minimization, in an effective manner, to ensure compliance with
legal requirements and to protect the rights of data subjects. In doing so, the controller shall
take into account the state of the art, the cost of implementation and the nature, scope,
context and purposes of processing, as well as the risks of varying likelihood and severity for
the legally protected interests of the data subject posed by the processing. In particular,
personal data shall be processed, and processing systems shall be selected and designed in
accordance with the aim of processing as few personal data as possible. Personal data shall
be rendered anonymous or pseudonymized as early as possible, as far as possibl e in
accordance with the purpose of processing.
Page 37 of 43