Service provided by the Federal Ministry of Justice and the Federal Office of Justice ‒ www.gesetze-im-internet.de (6) The contract referred to in subsection 5 shall be in writing or in an electronic form. (7) A processor that determines, in violation of this provision, the purposes and means of processing, shall be considered a controller in respect of that processing. Section 63 Joint controllers Where two or more controllers jointly determine the purposes and means of processing, they shall be considered joint controllers. Joint controllers shall determine their respective tasks and responsibilities under data protection law in a transparent manner in an agreement, unless these tasks and responsibilities are already determined by law. In particular, this agreement must indicate which of them must meet which information obligations, and how and with respect to whom data subjects may exercise their rights. Such an agreement shall not prevent data subjects from asserting their rights against each of the joint controllers. Section 64 Requirements for the security of data processing (1) The controller and the processor, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing as well as the risk of varying likelihood and severity for the legally protected interests of natural persons, shall implement the necessary technical and organizational measures to ensure a level of security appropriate to the risk when processing personal data, in particular as regards the processing of special categories of personal data. In doing so, the controller shall take into account the relevant Technical Guidelines and recommendations from the Federal Office for Information Security. (2) The measures referred to in subsection 1 may include pseudonymization and encryption of personal data, if such means are possible in view of the purposes of processing. The measures pursuant to subsection 1 should ensure 1. the ongoing confidentiality, integrity, availability and resilience of processing systems and services in connection with processing; and 2. the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident. (3) In respect of automated processing, the controller and processor, following an evaluation of the risks, shall implement measures designed to 1. deny unauthorized persons access to processing equipment used for processing (‘equipment access control’); 2. prevent the unauthorized reading, copying, modification or erasure of data media (‘data media control’); 3. prevent the unauthorized input of personal data and the unauthorized inspection, modification or deletion of stored personal data (‘storage control’); 4. prevent the use of automated processing systems by unauthorized persons using data communication equipment (‘user control’); 5. ensure that persons authorized to use an automated processing system have access only to the personal data covered by their access authorization (‘data access control’); 6. ensure that it is possible to verify and establish the bodies to which personal data have been or may be transmitted or made available using data communication equipment (‘communication control’); Page 33 of 43

Select target paragraph3