Service provided by the Federal Ministry of Justice
and the Federal Office of Justice ‒ www.gesetze-im-internet.de
(2) No transfer of personal data shall be permitted, despite an adequacy decision as referred
to in subsection 1 no. 2 and the public interest in the data transfer to be taken into account, if
in the individual case it cannot be ensured that the data will be handled appropriately in
terms of data protection law and in accordance with fundamental human rights in the area of
responsibility of the recipient, or if a transfer would conflict with other overriding legitimate
interests of a data subject. The controller shall base its assessment on whether the recipient
in the individual case guarantees appropriate protection of the transferred data.
(3)
If personal data which have been transmitted or made available from another
European Union Member State are to be transferred pursuant to subsection 1, the
competent body of the other Member State must provide prior authorization of the transfer.
Transfers without the prior authorization shall be permitted only if the transfer is necessary to
prevent an immediate and serious threat to the public security of a country or to essential
interests of a Member State and the prior authorization cannot be obtained in time. In the
case of the second sentence, the other Member State’s body responsible for giving prior
authorization shall be informed of the transfer without delay.
(4) The controller transferring data pursuant to subsection 1 shall take appropriate measures
to ensure that the recipient will transfer the data onward to other third countries or other
international organizations only with the prior authorization of the controller. When deciding
whether to authorize the transfer, the controller shall take into account all relevant factors,
including the seriousness of the criminal offence, the purpose for which the personal data
were originally transferred and the level of personal data protection in the third country or
international organization to which the data are to be transferred onward. The transfer shall
be authorized only if a direct transfer to the other third country or international organization
would be lawful. The responsibility for issuing authorization may also be otherwise provided
for.
Section 79
Data transfers with appropriate safeguards
(1) In the absence of a decision pursuant to Article 36 (3) of Directive (EU) 2016/680,
transfers which meet the remaining requirements of Section 78 shall be permitted also if
1.
appropriate safeguards with regard to the protection of personal data are
provided for in a legally binding instrument; or
2.
the controller has assessed all the circumstances surrounding the transfer and
concludes that appropriate safeguards exist for the protection of personal data.
(2) The controller shall document transfers pursuant to subsection 1 no. 2. The
documentation shall include the date and time of the transfer, the identity of the recipient, the
reason for the transfer and the personal data transferred. It shall be provided to the Federal
Commissioner on request.
(3) The controller shall file a report to the Federal Commissioner at least once a year
covering transfers conducted on the basis of an assessment pursuant to subsection 1 no. 2.
In this report, the controller may categorize the recipients and the purpose of the transfers
appropriately.
Section 80
Data transfers without appropriate safeguards
(1) If in derogation from Section 78 (1) no. 2, no decision pursuant to Article 36 (3) of
Directive (EU) 2016/680 or appropriate safeguards as referred to in Section 79 (1) exist,
transfers which meet the remaining requirements of Section 78 shall be permitted also if they
are necessary
1.
to protect the vital interests of a natural person;
2.
to safeguard legitimate interests of the data subject;
Page 40 of 43