1.4 Tasks and Powers of the Different Supervisory
Authorities
The federal structure of Germany excludes the possibility of one single supervisory
body, see Art. 83 GG. Instead, administrative supervision of private bodies is usually
organized by the regional agencies in the federal states. Only federal public bodies
(and public enterprises) are controlled by the federal agency. Beyond the split
between public and non-public bodies as well as between federal and regional
entities, there is a (federal) sectorial supervisory body in the communication sector,
the Federal Network Agency.
26
The powers of supervisory authorities are laid down in Art. 58 para. 1 to para.
3 GDPR. Supervisory authorities shall have investigative, corrective and authorization as well as advisory powers. Member states may provide for additional powers,
Art. 58 para. 6 GDPR. Sec. 16 new BDSG specifies the provisions of Art. 58 GDPR
for the federal agency; for the regional agencies the state laws do or will do it
similarly.
Under the GDPR administrative fines have increased tremendously in Germany.
While the scope was formerly under German law up to 300,000 Euros,
27 supervisory
bodies can now impose fines up to 20 million Euros or 4% of the annual group
turnover, Art. 83 GDPR. Key element thereby is their independence and being
subject only to the law, Art. 52 GDPR.
1.5 The Role of Self-Regulation Instruments
The GDPR introduces self-regulation instruments.
28 Enterprises shall be encouraged
to the drawing up of codes of conduct to promote the implementation of data
protection provisions, Art. 40 GDPR. Moreover, the GDPR seeks the establishment
of data protection certification mechanisms and of data protection seals and marks
for the purpose of demonstrating compliance with data protection rules, Art.
42 GDPR. The adherence to such measurements may be used as an element by
which to demonstrate compliance with the obligations under the GDPR, Art.
24 para. 3 GDPR and can thus lead to privileged treatment.
26 Sec. 116 et seq. TKG. For the constitutional basis see Art. 87 et seq. GG.
27 Sec. 43 para. 3 old BDSG.
28 For more information on self-regulation instruments see Spindler (2016), p. 407; Kranig and
Peintinger (2014), p. 3.
Data Protection in the Internet: National Report Germany
187
Précédent

- 195/540

Suivant