In 2006, the Data Retention Directive
74 has been adopted on EU level to ensure
prosecution of serious crimes. Its provisions have been implemented in Germany by
the Telecoms Data Retention Act in 2008. However, this Act was declared unconstitutional by the BVerfG in 2010.
75 Due to a lack of political consent, a new
Telecoms Data Retention Act has not been adopted before 2015. In the meantime,
the ECJ declared the Data Retention Directive to be invalid in 2014 because it entails
a serious interference with the fundamental rights to privacy and data protection
without limiting that interference to what is strictly necessary.
76 The BGH then
declared that data storage for internal use up to 7 days is valid.
77 Now, the ECJ has
again decided in matters of data retention, namely, that groundless data retention is
invalid and that member states may not impose a general obligation to retain data on
providers of electronic communications services.
78 The verdict can be seen as an end
of the data retention in the traditional sense.
79
2.5 Data Protection and Electronic Surveillance for Security
and Defence Purposes
2.5.1 Electronic Processing of Personal Data for Security and National
Defence Purposes
The electronic processing of personal data for security and national defence purposes
is subject to both, federal level and state level specific legislation.
Security and national defence fall within the remit of different entities, the Federal
Intelligence Service, the Federal Office for the Protection of the Constitution and the
Military Counterespionage Service. The powers and tasks of these entities are laid
down in corresponding legislation, e.g. the Act on the Federal Office for the
Protection of the Constitution (“BVerfSchG”).
80 The BVerfSchG can be seen as
starting point, as the other respective Acts partially refer to it in data protection
matters. It will therefore exemplary be examined in regard to the following questions. Restrictions on the right to privacy of correspondence, posts and telecommunications are stipulated in the Art. 10 Act.
74 Directive 2006/24/EC.
75 BVerfG, judgment of 2 March 2010, 1 BvR256/08 ¼ JuS 2008, 737.
76 ECJ, judgment of 8 April 2014—Digital Rights Ireland—C-293/12, C-594/12 ¼ MMR 2014,
412.
77 BGH, judgment of 3 July 2014, III ZR 391/13 ¼ NJW 2014, 2500.
78 ECJ, judgment of 21 December 2016, C-203/15, C-698/15 ¼ EuZW 2017, 153.
79 Priebe (2017), p. 136.
80 The Federal Intelligence Service is subject to the rules of the Act on the Federal Intelligence
Service (BNDG); the Military Counterespionage Service to the Act on Military Counterespionage
Service (MADG).
202
C. Breunig and M. Schmidt-Kessel
74 has been adopted on EU level to ensure
prosecution of serious crimes. Its provisions have been implemented in Germany by
the Telecoms Data Retention Act in 2008. However, this Act was declared unconstitutional by the BVerfG in 2010.
75 Due to a lack of political consent, a new
Telecoms Data Retention Act has not been adopted before 2015. In the meantime,
the ECJ declared the Data Retention Directive to be invalid in 2014 because it entails
a serious interference with the fundamental rights to privacy and data protection
without limiting that interference to what is strictly necessary.
76 The BGH then
declared that data storage for internal use up to 7 days is valid.
77 Now, the ECJ has
again decided in matters of data retention, namely, that groundless data retention is
invalid and that member states may not impose a general obligation to retain data on
providers of electronic communications services.
78 The verdict can be seen as an end
of the data retention in the traditional sense.
79
2.5 Data Protection and Electronic Surveillance for Security
and Defence Purposes
2.5.1 Electronic Processing of Personal Data for Security and National
Defence Purposes
The electronic processing of personal data for security and national defence purposes
is subject to both, federal level and state level specific legislation.
Security and national defence fall within the remit of different entities, the Federal
Intelligence Service, the Federal Office for the Protection of the Constitution and the
Military Counterespionage Service. The powers and tasks of these entities are laid
down in corresponding legislation, e.g. the Act on the Federal Office for the
Protection of the Constitution (“BVerfSchG”).
80 The BVerfSchG can be seen as
starting point, as the other respective Acts partially refer to it in data protection
matters. It will therefore exemplary be examined in regard to the following questions. Restrictions on the right to privacy of correspondence, posts and telecommunications are stipulated in the Art. 10 Act.
74 Directive 2006/24/EC.
75 BVerfG, judgment of 2 March 2010, 1 BvR256/08 ¼ JuS 2008, 737.
76 ECJ, judgment of 8 April 2014—Digital Rights Ireland—C-293/12, C-594/12 ¼ MMR 2014,
412.
77 BGH, judgment of 3 July 2014, III ZR 391/13 ¼ NJW 2014, 2500.
78 ECJ, judgment of 21 December 2016, C-203/15, C-698/15 ¼ EuZW 2017, 153.
79 Priebe (2017), p. 136.
80 The Federal Intelligence Service is subject to the rules of the Act on the Federal Intelligence
Service (BNDG); the Military Counterespionage Service to the Act on Military Counterespionage
Service (MADG).
202
C. Breunig and M. Schmidt-Kessel
