Section 6
Destruction of personal data
Where the Federal Office collects personal data in the context of exercising its authority, these data are to
be destroyed without delay as soon as they have served the purpose for which they were collected or are
no longer needed for possible judicial review. If destruction is delayed only for possible judicial review of
measures taken under Section 5 (3), the data may be used without the consent of the person concerned
only for this purpose; they are to be blocked for any other purpose. Section 5 (7) shall remain unaffected.
table of contents
Section 7
Warnings
(1) To fulfil its tasks under Section 3 (1) second sentence no. 14, the Federal Office may warn the
affected groups or the public of security gaps in information technology products and services and of
harmful software, or recommend security measures and the use of certain security products. Before
publishing warnings about these products, the makers of the products concerned shall be informed in
advance, as long as doing so will not interfere with achieving the intended aim of the warning. Where
security gaps or harmful software should not be made public in order to prevent their further distribution
or unlawful exploitation, or because the Federal Office is bound to confidentiality with regard to third
parties, the Federal Office may use objective criteria to limit the persons to be warned; in particular, a
special threat to certain facilities or the exceptional reliability of the recipient may constitute objective
criteria.
(2) To fulfil its tasks under Section 3 (1) second sentence no. 14, the Federal Office may include the
name of the product concerned and its manufacturer in its public warnings of security gaps in information
technology products and services and of harmful software or may recommend security measures and the
use of specific security products, if there are sufficient indications of threat to the security of information
technology. If the published information later proves to be false or the circumstances on which it was
based were misrepresented, this shall be published without delay.
table of contents
Section 8
Federal Office guidelines
(1) The Federal Office may set minimum standards for ensuring the security of federal information
technology. With the approval of the Council of Chief Information Officers of the federal ministries, the
Federal Ministry of the Interior may issue the standards set in accordance with the first sentence in full or
in part as general administrative regulations for all federal bodies. Where Federal Office security
standards for interministerial networks and security requirements necessary to protect the relevant
network and which are to be implemented by network users are included in a general administrative
regulation, these standards shall be set with the agreement of the Council of Chief Information Officers of
the federal ministries. For the courts and constitutional bodies referred to in Section 2 (3) second
sentence, regulations in accordance with this subsection shall have the status of recommendations.
8/10