Protection for Minors
Art. 8 para. 1 GDPR states that a child must at least be 16 years old to give valid
consent in the processing of its personal data in relation to the offer of information
society services. Where the child is younger, the consent of a legal representative is
necessary. Member states may lower down that age, nonetheless not below 13 years,
Art. 8 para. 2 GDPR. The fundamental rights and freedoms of a child being a data
subject have explicitly to be considered in determining the necessity of processing
for purposes of the legitimate interests of the controller, Art. 6 para. 1 lit. f) GDPR.
Minors are furthermore protected by general rules of contract law. Under German
law, legal capacity and thus the ability to enter into a valid contract starts from the
age of 18, sec. 104 et seq. German Civil Code. There are, of course, exceptions but
these do mainly only work combined with the consent of a legal representative.
Whether these contract law rules apply to consent of the minor, was subject to
discussion under the old BDSG.
The “Right to Be Forgotten”
The right to be forgotten is explicitly guaranteed in Art. 17 GDPR. It comprises two
rights. First, the data subject has the right to obtain erasure of its personal data
without undue delay if a special ground, e.g. withdrawal of consent, applies. The
controller has the corresponding obligation to erase its personal data without undue
delay, Art. 17 para. 1 GDPR. Second, if the personal data has been made public,
reasonable steps have to be taken by the controller to inform other controllers that the
data subject has requested the erasure by such controllers of any links to, or copy or
replication of, those personal data, Art. 17 para. 2 GDPR. The right to be forgotten is
limited to the extent that the processing is necessary for specific reasons like for the
right of freedom of expression and information, Art. 17 para. 3 GDPR.
The ECJ hold in Google vs. Spain, that an internet search engine operator is
responsible for the processing that it carries out of personal data which appear on
web pages published by third parties. Thus the data subject may approach the
operator directly in order to obtain the removal of a link to a web page, which
contains information on the data subject, from the list of results.
42
2.1.3 Electronic Communications for Marketing Purposes
There is general legislation covering the protection of personal data in the context of
electronic communications for marketing purposes. Recital 47 of the GDPR states
that direct marketing purposes may be regarded as carried out for a legitimate
interest. Marketing purposes may thus be a legitimate interest in terms of Art.
42 ECJ, judgment of 13 May 2014—Google vs. Spain—C-131/12 ¼ EuZW 2014, 541.
Data Protection in the Internet: National Report Germany
191
Précédent

- 199/540

Suivant