Service provided by the Federal Ministry of Justice and the Federal Office of Justice ‒ www.gesetze-im-internet.de (2) The controller shall erase personal data without delay if their processing is unlawful, they must be erased to comply with a legal obligation, or knowledge of the data is no longer necessary for the controller to perform its tasks. (3) Section 58 (3) to (5) shall apply accordingly. The recipient shall also be informed if inaccurate personal data have been transmitted, or if personal data have been transmitted unlawfully. (4) Without prejudice to any time limits for storing or erasing data defined in law, the controller shall provide for appropriate time limits for the erasure of personal data or for a periodic review of the need for the storage of personal data and shall take procedural measures to ensure that these time limits are observed. Section 76 Logging (1) Controllers and processors shall provide for logs to be kept for at least the following processing operations in automated processing systems: 1. collection, 2. alteration, 3. consultation, 4. disclosure including transfers, 5. combination, and 6. erasure. (2) The logs of consultation and disclosure must make it possible to ascertain the justification, date and time of such operations and, as far as possible, the identity of the person who consulted or disclosed personal data, and the identity of the recipients of the data. (3) The logs may be used only by the data protection officer, the Federal Commissioner or the data subject to verify the lawfulness of the processing; and for self-monitoring, ensuring the integrity and security of the personal data, and for criminal proceedings. (4) The log data shall be erased at the end of the year following the year in which they were generated. (5) The controller and the processor shall make the logs available to the Federal Commissioner on request. Section 77 Confidential reporting of violations The controller shall ensure that it is able to receive confidential reports of violations of data protection law which have occurred in its area of responsibility. Chapter 5 Transfers of data to third countries and to international organiz ations Section 78 General requirements (1) If all other conditions applicable to data transfers are met, the transfer of personal data to bodies in third countries or to international organizations shall be permitted if 1. the body or international organization is responsible for the purposes referred to in Section 45, and 2. the European Commission has adopted an adequacy decision pursuant to Article 36 (3) of Directive (EU) 2016/680. Page 39 of 43

Select target paragraph3