We must continue to provide stronger and more effective data security and data
protection in Germany. Small and mid-size companies in particular must be
in a position to recognise risks and take precautions in order to take full advantage of the opportunities provided by digitisation. They must receive assistance
in taking suitable protective measures that could significantly raise their level
of data security. Security and data protection should play a role starting at the
initial phases of product development and process design (known as security
by design). Trusted cloud offerings based on certified secure solutions can be a
promising option in many cases for small and medium-sized businesses, which
can then reduce their own IT and become flexible.
It is imperative to offer consumers and businesses legal certainty and a uniform
competition environment. To do so, it is necessary to strike a balance between
consumer, commercial and government security concerns. With the new
European General Data Protection Regulation, a uniform, high level of data
protection will be created for all of Europe in 2018. Fragmented national data
protection rules, legal ambiguities and possibilities for circumvention will be
eliminated.
It will also be important to create viable rules on handling data communication
with non-European countries. Other regions in the world often have a different
approach to finding the balance between consumer and business interests and
security concerns. Up to now, there have been only a few agreements and conventions on these topics. With its Safe Harbour decision, the European Court of
Justice invalidated the agreement between the EU and the USA. The new EU-US
Privacy Shield should ensure that the Court of Justice’s requirements for an appropriate level of data protection are now implemented in the USA and a reliable
regulatory framework for trans-border data transmission is created.
It is the task of the many participants in this technology to work together to
guarantee trust, security and data protection in an increasingly digitised world.
Not only the government, but also business, the scientific community and ulti
mately the users themselves must contribute to this. The following measures
will therefore only succeed if they are agreed upon by all parties concerned:
•W
e will cooperate in exploring whether additional regulations such as product liability rules for IT security flaws and security requirements for hardware and software
manufacturers are necessary and useful. Industrial espionage and cyber attacks must
also be prevented with international regulations that can be enforced beyond German
and European borders.