We must continue to provide stronger and more effective data security and data protection in Germany. Small and mid-size companies in particular must be in a position to recognise risks and take precautions in order to take full advantage of the opportunities provided by digitisation. They must receive assistance in taking suitable protective measures that could significantly raise their level of data security. Security and data protection should play a role starting at the initial phases of product development and process design (known as security by design). Trusted cloud offerings based on certified secure solutions can be a promising option in many cases for small and medium-sized businesses, which can then reduce their own IT and become flexible. It is imperative to offer consumers and businesses legal certainty and a uniform competition environment. To do so, it is necessary to strike a balance between consumer, commercial and government security concerns. With the new Euro­pean General Data Protection Regulation, a uniform, high level of data protection will be created for all of Europe in 2018. Fragmented national data protection rules, legal ambiguities and possibilities for circumvention will be eliminated. It will also be important to create viable rules on handling data communication with non-European countries. Other regions in the world often have a different approach to finding the balance between consumer and business interests and security concerns. Up to now, there have been only a few agreements and conventions on these topics. With its Safe Harbour decision, the European Court of Justice invalidated the agreement between the EU and the USA. The new EU-US Privacy Shield should ensure that the Court of Justice’s requirements for an appropriate level of data protection are now implemented in the USA and a reliable regulatory framework for trans-border data transmission is created. It is the task of the many participants in this technology to work together to guarantee trust, security and data protection in an increasingly digitised world. Not only the government, but also business, the scientific community and ulti­ mately the users themselves must contribute to this. The following measures will therefore only succeed if they are agreed upon by all parties concerned: •W  e will cooperate in exploring whether additional regulations such as product liability rules for IT security flaws and security requirements for hardware and software manufacturers are necessary and useful. Industrial espionage and cyber attacks must also be prevented with international regulations that can be enforced beyond German and European borders.

Select target paragraph3