{"id":18705,"date":"2007-04-12T11:45:13","date_gmt":"2007-04-12T09:45:13","guid":{"rendered":"https:\/\/fiala.de\/data-protection-law-new-minimum-requirements-for-companies\/"},"modified":"2007-04-12T11:45:13","modified_gmt":"2007-04-12T09:45:13","slug":"data-protection-law-new-minimum-requirements-for-companies","status":"publish","type":"post","link":"https:\/\/www.fiala.de\/en\/data-protection-law-new-minimum-requirements-for-companies\/","title":{"rendered":"Data protection law: new minimum requirements for companies"},"content":{"rendered":"\n<h2>The patron saint of Germans must be called &#8220;St.B\u00fcrokratius&#8221;. A president of the Steinbei\u00df Foundation put it in a nutshell during a speech: &#8220;Germans have an almost erotic relationship with forms&#8221;.<\/h2>\n<p>The legislator has placed further burdens on companies, some of which are merely formal.<\/p>\n<p>According to the &#8220;Article 1 of the First Law for the Reduction of Bureaucratic Obstacles, especially in the Medium-Sized Economy (BGBl. I S. 1970) of 22.08.2006&#8221;, additional burdens have been imposed on small and medium-sized enterprises since a few days.<\/p>\n<p>In many companies, the regulations have not yet been implemented, even in their own electronic data processing (EDP). This may result, for example, in a fine and a warning with costs under the Unfair Competition Act (UWG).<\/p>\n\n<h3>Public register of procedures &#8211; more bureaucracy?<\/h3>\n<p>Already since 23.05.2004 the obligation applies to all entrepreneurs after the Federal Law for Data Protection (BDSG) to possess a public procedure listing. Every freelancer is also affected by this obligation, <a href=\"https:\/\/dejure.org\/gesetze\/BDSG\/4e.html\" rel=\"nofollow noopener\" target=\"_blank\" class=\"external\">\u00a7 4 e BDSG<\/a>.<\/p>\n\n<h3>Contents of the list of proceedings:<\/h3>\n<p>In particular, the directory of procedures sets out which data is collected for which purposes, to whom the data is transmitted, and when the data is deleted again. Example: <a href=\"https:\/\/www.fiala.de\/cms\/index.php\/datenschutzinformation\/777\/0\/\">https:\/\/www.fiala.de\/cms\/index.php\/datenschutzinformation\/777\/0\/<\/a> According to a ruling of the Gie\u00dfen Administrative Court of 16.07.2004 (Ref. <a href=\"https:\/\/dejure.org\/dienste\/vernetzung\/rechtsprechung?Text=22%20L%202286\/04\" title=\"VG Gie&szlig;en, 16.07.2004 - 22 L 2286\/04: Verarbeitung von Personaldaten der zur Personalvermittlun...\" rel=\"nofollow noopener\" target=\"_blank\" class=\"external\">22 L 2286\/04<\/a>), the deletion of data can be demanded if the procedural directory has not been drawn up or has not been drawn up properly, because then the EDP is unlawful.<\/p>\n\n<h3>Legal Principle:<\/h3>\n<p>Notification to the supervisory authority prior to the use of EDP Pursuant to \u00a7 4d para. 1 BDSG, there is, in principle, a duty to notify the supervisory authority for &#8220;procedures of automated processing of data&#8221;, i.e. the use of an EDP system.<\/p>\n<p>The notification to the supervisory authority has the practical consequence that the authority will urge the entrepreneur to appoint a data protection officer (DPO). This is because the authority will want to continue to pursue only the &#8220;problem cases&#8221; for capacity reasons.<\/p>\n<p>Exceptions to the obligation to notify The obligation to notify may be waived pursuant to Section 4 d III BDSG if<\/p>\n<p style=\"padding-left: 40px\">(a) data are processed only with the consent of the data subject; or<\/p>\n<p style=\"padding-left: 40px\">b) the processing is only successful for contractual purposes, <a href=\"https:\/\/dejure.org\/gesetze\/BDSG\/28.html\" title=\"&sect; 28 BDSG: Datenverarbeitung zu im &ouml;ffentlichen Interesse liegenden Archivzwecken\" rel=\"nofollow noopener\" target=\"_blank\" class=\"external\">\u00a7 28 I 1 BDSG<\/a>.<\/p>\n<p style=\"padding-left: 40px\">\n<p>If neither of these alternatives applies to all data, a DPO should be appointed as a rule from the first person who automatically processes personal data. Otherwise, a DPO must be appointed only if there are more than nine persons.<\/p>\n<p>If a bDSB has been appointed, the notification obligation does not apply, <a href=\"https:\/\/dejure.org\/gesetze\/BDSG\/4d.html\" rel=\"nofollow noopener\" target=\"_blank\" class=\"external\">\u00a7 4d II BDSG<\/a>. However, business performance cannot be appointed as the bDSB. A standard employment contract is not sufficient for the appointment as a BDSB. Often a so-called external bDSB is appointed.<\/p>\n\n<h3>Duty to provide information to everyone:<\/h3>\n<p>Everybody can apply to the bDSB for the so-called procedure directory to be handed over to him, <a href=\"https:\/\/dejure.org\/gesetze\/BDSG\/4e.html\" rel=\"nofollow noopener\" target=\"_blank\" class=\"external\">\u00a7\u00a7 4e S.1<\/a> No. 1 to 8, <a href=\"https:\/\/dejure.org\/gesetze\/BDSG\/4g.html\" rel=\"nofollow noopener\" target=\"_blank\" class=\"external\">4g<\/a> II S.2 BDSG. If no DPO has been appointed, this duty is incumbent on the company itself. However, if the public procedure directory is stored on the homepage of the entrepreneur for inspection, reference can be made to it.<\/p>\n\n<h3>Data protection officer is missing:<\/h3>\n<p>At the latest as soon as more than nine persons (including freelancers, trainees, part-time employees, company owners or managers) process personal data on a regular basis (i.e. not occasionally, e.g. as a substitute in the event of illness), a data protection officer must be appointed or the data processing must be reported to the supervisory authority before the IT system is put into operation. Otherwise the solution of unauthorized data storage can be required, <a href=\"https:\/\/dejure.org\/gesetze\/BDSG\/35.html\" title=\"&sect; 35 BDSG: Recht auf L&ouml;schung\" rel=\"nofollow noopener\" target=\"_blank\" class=\"external\">\u00a7 35 BDSG<\/a>.<\/p>\n\n<h3>Competition law<\/h3>\n<p>There are opinions according to which it constitutes unfair competition if the appointment of a DPO has not taken place, although such a DPO should be appointed according to the law. The unfair competitive advantage consists in the fact that, by violating the law, one gains an advantage over entrepreneurs who comply with the law.<\/p>\n<p>Information rights, criminal data disclosure, data blocking and correction: If, for example, a debtor is unjustifiably threatened with a &#8220;Schufa&#8221; entry, this may constitute attempted coercion (<a href=\"https:\/\/dejure.org\/gesetze\/StGB\/240.html\" title=\"&sect; 240 StGB: N&ouml;tigung\" rel=\"nofollow noopener\" target=\"_blank\" class=\"external\">\u00a7\u00a7 240<\/a>, <a href=\"https:\/\/dejure.org\/gesetze\/StGB\/22.html\" title=\"&sect; 22 StGB: Begriffsbestimmung\" rel=\"nofollow noopener\" target=\"_blank\" class=\"external\">22 StGB<\/a>) or extortion (<a href=\"https:\/\/dejure.org\/gesetze\/StGB\/253.html\" title=\"&sect; 253 StGB: Erpressung\" rel=\"nofollow noopener\" target=\"_blank\" class=\"external\">\u00a7\u00a7 253<\/a>, <a href=\"https:\/\/dejure.org\/gesetze\/StGB\/22.html\" title=\"&sect; 22 StGB: Begriffsbestimmung\" rel=\"nofollow noopener\" target=\"_blank\" class=\"external\">22 StGB<\/a>).<\/p>\n<p>After a request, credit and credit rating agencies must also disclose to whom which data has been transmitted. Exceptionally, a trade secret may take precedence here, <a href=\"https:\/\/dejure.org\/gesetze\/BDSG\/34.html\" title=\"&sect; 34 BDSG: Auskunftsrecht der betroffenen Person\" rel=\"nofollow noopener\" target=\"_blank\" class=\"external\">\u00a7 34 I S.1. BDSG<\/a>. Incorrect data must be blocked, corrected and, if necessary, deleted (judgement of 16.05.2002 of the LG Munich I).<\/p>\n<p>Doctors and tax consultants are not allowed to obtain credit information about their patients or clients without permission. The mere fact of a business relationship is subject to the duty of confidentiality, \u00a7 3 para. 9 BDSG, \u00a7 203 para. 1 No. 1 StGB.<\/p>\n\n<h3>Hostile takeovers and &#8220;communities of interest&#8221; (IG)<\/h3>\n<p>Occasionally, &#8220;communities of interest&#8221; or legal advisors get in touch with serial letters, for example with shareholders, financial service providers, apartment owners, limited partners of investment companies. The IG then pursues as objectives, for example, the hostile takeover of companies with proxy voting rights, the replacement of key positions on the board of directors, supervisory board or WEG advisory board, as well as its own procurement of orders.<\/p>\n<p>The unauthorized disclosure of data, such as in particular the sale of data by former employees, is punishable under German law, \u00a7\u00a7 44 I in conjunction with 43 II No. 3 BDSG.<br \/>\nThe processing and use of personal data collected through data theft (e.g. of shareholders, members, limited partners) is regularly inadmissible, \u00a7 4 para. 1 BDSG. The data subjects have a claim against the IG for information about the stored data, also about the origin (\u00a7 34 I 1 sentence 1 no. 1 BDSG), and additionally a claim for deletion according to <a href=\"https:\/\/dejure.org\/gesetze\/BDSG\/35.html\" title=\"&sect; 35 BDSG: Recht auf L&ouml;schung\" rel=\"nofollow noopener\" target=\"_blank\" class=\"external\">\u00a7 35 II 2 nos. 1 and 3 BDSG<\/a>.<\/p>\n<p>Possible actions for those affected: An exemplary procedure for dealing with spam with sample texts can be found at <a href=\"https:\/\/www.safer-networking.org\/de\/articles\/spamandthelaw.html.\" class=\"external\" rel=\"nofollow\">https:\/\/www.safer-networking.org\/de\/articles\/spamandthelaw.html.<\/a> A first measure can also be to report the breach of law to the &#8220;Wettbewerbszentrale&#8221;. It can then check whether it is sending out a warning because, for example, there is no public register of procedures. These efforts are then put in writing, served, and a bill of costs attached.<\/p>\n<p>There may also be a fine of up to 250,000 euros, <a href=\"https:\/\/dejure.org\/gesetze\/BDSG\/43.html\" title=\"&sect; 43 BDSG: Bu&szlig;geldvorschriften\" rel=\"nofollow noopener\" target=\"_blank\" class=\"external\">\u00a7 43 III BDSG<\/a>. The Federal and State Data Protection Commissioners will examine this matter after notification. <a href=\"https:\/\/www.datenschutz-berlin.de\/recht\/de\/bdsg\/bdsg01.htm#\" class=\"external\" rel=\"nofollow\">https:\/\/www.datenschutz-berlin.de\/recht\/de\/bdsg\/bdsg01.htm#<\/a>\u00a74d Typical cases which a data protection officer will question are serial letters and e-mails to investors in liability cases, or when file inspections are used to obtain targeted new data for an acquisition.<\/p>\n<p>Some companies have recognised that the provision of a public procedure directory can be combined with other information as part of a professional public relations campaign to promote trust.<\/p>\n\n<p>by Dr. Johannes Fiala<\/p>\n\n<p>by courtesy of<\/p>\n<p><a href=\"https:\/\/www.channelpartner.de\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" class=\"external\">www.channelpartner.de<\/a> (posted 10\/02\/2006)<\/p>\n<p>and<\/p>\n<p>Confectionery production (issue 17\/2006)<\/p>\n<p>and<\/p>\n<p><a href=\"http:\/\/www.experten.de\" class=\"external\" rel=\"nofollow\">www.experten.de<\/a> (Article from 27.09.2006)<\/p>\n<p>and<\/p>\n<p><a href=\"http:\/\/www.bvd-cedi.de\" class=\"external\" rel=\"nofollow\">www.bvd-cedi.de<\/a><\/p>\n<p>and<\/p>\n<p><a href=\"https:\/\/www.venatus.de\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" class=\"external\">www.venatus.de <\/a>(published in gunsmith.knife &amp; scissors, issue 2\/2007, page 6)<\/p>\n<p>and<\/p>\n<p><a href=\"https:\/\/www.competence-site.de\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" class=\"external\">www.competence-site.de<\/a> (published 09-2006)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The patron saint of Germans must be called &#8220;St.B\u00fcrokratius&#8221;. A president of the Steinbei\u00df Foundation put it in a nutshell during a speech: &#8220;Germans have an almost erotic relationship with forms&#8221;. The legislator has placed further burdens on companies, some of which are merely formal. According to the &#8220;Article 1 of the First Law for [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":"","rank_math_focus_keyword":"","rank_math_description":"","rank_math_title":""},"categories":[492],"tags":[740,660,617],"class_list":["post-18705","post","type-post","status-publish","format-standard","hentry","category-veroeffentlichungen-en","tag-auskunftspflicht-en","tag-kapitalanleger-en","tag-privacy"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.fiala.de\/en\/wp-json\/wp\/v2\/posts\/18705","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.fiala.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.fiala.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.fiala.de\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.fiala.de\/en\/wp-json\/wp\/v2\/comments?post=18705"}],"version-history":[{"count":0,"href":"https:\/\/www.fiala.de\/en\/wp-json\/wp\/v2\/posts\/18705\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.fiala.de\/en\/wp-json\/wp\/v2\/media?parent=18705"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.fiala.de\/en\/wp-json\/wp\/v2\/categories?post=18705"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.fiala.de\/en\/wp-json\/wp\/v2\/tags?post=18705"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}