25 GDPR, strengthens the protection of personal data stored and conveyed through
electronic means additionally as they minimize the personal data stored at all from
the very beginning.
2.1.9 Particular Obligations to Inform About Data Breaches or
Incidents Concerning the Security of Personal Data
In case of data breaches or incidents concerning the security of personal data
processed by electronic means there might be an obligation to inform the supervisory
authority and the data subject. Obviously, there may be additional duties under tort
law and contract law.
The supervisory authority has to be informed if the data breach is not unlikely to
result in a risk to the rights and freedoms of natural persons. The notification shall be
given without undue delay and, where feasible, not later than 72 h after having
become aware of the breach, Art. 33 GDPR.
A data breach is to be communicated to the data subject under the following
presuppositions: First, the breach is likely to result in a high risk to the rights and
freedoms of natural persons. Second, the controller has not implemented appropriate
technical and organizational protection measures, such as encryption, or has not
taken subsequent measures which ensure that the high risk is no longer likely to
materialize. Third, the communication wouldn’t involve disproportionate effort, Art.
34 GDPR.
2.1.10 Specific Sectorial Rules for the Processing of Personal Data by
Electronic Means
There is specific legislation regarding the processing of personal data by electronic
means in the health sector. The Social Security Code, Part V, specifies the requirements of a valid consent, coherent information duties and the withdrawal of the same
in connection with the electronic health card. It also provides for technical precautions to guarantee protection from unauthorized access.
52
The principle of legal prohibition, reserving the right of permission and the
comprehensive but general set of rules, under which processing without consent is
allowed, offers a wide legal basis of data processing.
53 This leads in an indirect way
to sectorial special legislation.
52 See sec. 291 lit. a) Social Security Code, Part V (SGB V).
53 Concerning the principle of legal prohibition reserving the right of permission See the section
“The Role of Previous Consent of the Data Subject”.
Data Protection in the Internet: National Report Germany
195
electronic means additionally as they minimize the personal data stored at all from
the very beginning.
2.1.9 Particular Obligations to Inform About Data Breaches or
Incidents Concerning the Security of Personal Data
In case of data breaches or incidents concerning the security of personal data
processed by electronic means there might be an obligation to inform the supervisory
authority and the data subject. Obviously, there may be additional duties under tort
law and contract law.
The supervisory authority has to be informed if the data breach is not unlikely to
result in a risk to the rights and freedoms of natural persons. The notification shall be
given without undue delay and, where feasible, not later than 72 h after having
become aware of the breach, Art. 33 GDPR.
A data breach is to be communicated to the data subject under the following
presuppositions: First, the breach is likely to result in a high risk to the rights and
freedoms of natural persons. Second, the controller has not implemented appropriate
technical and organizational protection measures, such as encryption, or has not
taken subsequent measures which ensure that the high risk is no longer likely to
materialize. Third, the communication wouldn’t involve disproportionate effort, Art.
34 GDPR.
2.1.10 Specific Sectorial Rules for the Processing of Personal Data by
Electronic Means
There is specific legislation regarding the processing of personal data by electronic
means in the health sector. The Social Security Code, Part V, specifies the requirements of a valid consent, coherent information duties and the withdrawal of the same
in connection with the electronic health card. It also provides for technical precautions to guarantee protection from unauthorized access.
52
The principle of legal prohibition, reserving the right of permission and the
comprehensive but general set of rules, under which processing without consent is
allowed, offers a wide legal basis of data processing.
53 This leads in an indirect way
to sectorial special legislation.
52 See sec. 291 lit. a) Social Security Code, Part V (SGB V).
53 Concerning the principle of legal prohibition reserving the right of permission See the section
“The Role of Previous Consent of the Data Subject”.
Data Protection in the Internet: National Report Germany
195
