Particular Rules on Data Breaches
Besides the duty to information about detected security risks laid down in Art.
17 ePR,
60 the Regulation does not contain any specific legal rules about data
breaches, including any obligations to notify the data subject, a supervisory body
or any other third party in case a data breach occurs. This situation falls within the
subsidiary general rules of the GDPR, which establishes such duties in Art. 33 and
34 GDPR.
61
2.2.3 The Federal Network Agency as Supervising Body
Under current national legislation, the Federal Network Agency monitors the adherence to the provisions laid down in the TKG. The ePR states that the processing of
personal data in the context of electronic communications is monitored by the
independent supervisory authorities responsible for monitoring the application of
the GDPR, Art. 18 ePR. The provisions laid down in the GDPR shall be applicable
mutatis mutandis.
62
2.2.4 Powers Vested in the Federal Network Agency
If the ePR is adopted, there will probably be no specific supervisory body for the
electronic communications context. The main types of powers vested in this supervisory body, including sanctioning powers, are the same as those of the supervisory
authorities monitoring the GDPR.
63
2.3 Data Protection and Inheritance
In July 2018 the BGH had to apply the GDPR for the first time.
64 The judgment
brings clarification to the digital inheritance.
65 According to the key statement of the
decision, the contract of a user account of social networks is transferred to the heirs
by universal succession. In the case at hand, a girl was killed in an unsolved metro
accident. The mother of the child claimed access to her Facebook account which was
set into the so-called memorial state. In this state it is no longer possible to log in to
60 Directive on security of network and information systems (EU) 2016/1148.
61 See for the presuppositions for such duties Sect. 2.1.9.
62 See for the provisions concerning the supervisory authorities monitoring the GDPR Sect. 1.3.
63 See for the main powers of the supervisory authorities monitoring the GDPR Sect. 1.4.
64 BGH, judgment of 12 July 2018, III ZR 183/17 ¼ NZFam 2018, 800.
65 See discussions of the judgement by Litzenburger (2018); Goratsch (2018), p. 810.
198
C. Breunig and M. Schmidt-Kessel
Besides the duty to information about detected security risks laid down in Art.
17 ePR,
60 the Regulation does not contain any specific legal rules about data
breaches, including any obligations to notify the data subject, a supervisory body
or any other third party in case a data breach occurs. This situation falls within the
subsidiary general rules of the GDPR, which establishes such duties in Art. 33 and
34 GDPR.
61
2.2.3 The Federal Network Agency as Supervising Body
Under current national legislation, the Federal Network Agency monitors the adherence to the provisions laid down in the TKG. The ePR states that the processing of
personal data in the context of electronic communications is monitored by the
independent supervisory authorities responsible for monitoring the application of
the GDPR, Art. 18 ePR. The provisions laid down in the GDPR shall be applicable
mutatis mutandis.
62
2.2.4 Powers Vested in the Federal Network Agency
If the ePR is adopted, there will probably be no specific supervisory body for the
electronic communications context. The main types of powers vested in this supervisory body, including sanctioning powers, are the same as those of the supervisory
authorities monitoring the GDPR.
63
2.3 Data Protection and Inheritance
In July 2018 the BGH had to apply the GDPR for the first time.
64 The judgment
brings clarification to the digital inheritance.
65 According to the key statement of the
decision, the contract of a user account of social networks is transferred to the heirs
by universal succession. In the case at hand, a girl was killed in an unsolved metro
accident. The mother of the child claimed access to her Facebook account which was
set into the so-called memorial state. In this state it is no longer possible to log in to
60 Directive on security of network and information systems (EU) 2016/1148.
61 See for the presuppositions for such duties Sect. 2.1.9.
62 See for the provisions concerning the supervisory authorities monitoring the GDPR Sect. 1.3.
63 See for the main powers of the supervisory authorities monitoring the GDPR Sect. 1.4.
64 BGH, judgment of 12 July 2018, III ZR 183/17 ¼ NZFam 2018, 800.
65 See discussions of the judgement by Litzenburger (2018); Goratsch (2018), p. 810.
198
C. Breunig and M. Schmidt-Kessel
