Service provided by the Federal Ministry of Justice
and the Federal Office of Justice ‒ www.gesetze-im-internet.de
(6) The contract referred to in subsection 5 shall be in writing or in an electronic form.
(7) A processor that determines, in violation of this provision, the purposes and means of
processing, shall be considered a controller in respect of that processing.
Section 63
Joint controllers
Where two or more controllers jointly determine the purposes and means of processing, they
shall be considered joint controllers. Joint controllers shall determine their respective tasks
and responsibilities under data protection law in a transparent manner in an agreement,
unless these tasks and responsibilities are already determined by law. In particular, this
agreement must indicate which of them must meet which information obligations, and how
and with respect to whom data subjects may exercise their rights. Such an agreement shall
not prevent data subjects from asserting their rights against each of the joint controllers.
Section 64
Requirements for the security of data processing
(1) The controller and the processor, taking into account the state of the art, the costs of
implementation and the nature, scope, context and purposes of the processing as well as the
risk of varying likelihood and severity for the legally protected interests of natural persons,
shall implement the necessary technical and organizational measures to ensure a level of
security appropriate to the risk when processing personal data, in particular as regards the
processing of special categories of personal data. In doing so, the controller shall take into
account the relevant Technical Guidelines and recommendations from the Federal Office for
Information Security.
(2) The measures referred to in subsection 1 may include pseudonymization and encryption
of personal data, if such means are possible in view of the purposes of processing. The
measures pursuant to subsection 1 should ensure
1.
the ongoing confidentiality, integrity, availability and resilience of processing
systems and services in connection with processing; and
2.
the ability to restore the availability and access to personal data in a timely
manner in the event of a physical or technical incident.
(3) In respect of automated processing, the controller and processor, following an evaluation
of the risks, shall implement measures designed to
1.
deny unauthorized persons access to processing equipment used for
processing (‘equipment access control’);
2.
prevent the unauthorized reading, copying, modification or erasure of data
media (‘data media control’);
3.
prevent the unauthorized input of personal data and the unauthorized
inspection, modification or deletion of stored personal data (‘storage control’);
4.
prevent the use of automated processing systems by unauthorized persons
using data communication equipment (‘user control’);
5.
ensure that persons authorized to use an automated processing system have
access only to the personal data covered by their access authorization (‘data access
control’);
6.
ensure that it is possible to verify and establish the bodies to which personal
data have been or may be transmitted or made available using data communication
equipment (‘communication control’);
Page 33 of 43