TwitterDeutsche Version
Act
Cookies

Bundesrat passes TTDSG

Bundesrat passes TTDSG
Datum10. June 2021

On May 28, 2021, the Bundesrat passed the “Act on Data Protection and the Protection of Privacy in Telecommunications and Telemedia” (TTDSG). It is scheduled to take effect on December 1, 2021.

According to the Federal Ministry for Economic Affairs and Energy, which is leading the initiative, the goal of the law is to “create legal clarity for data protection and the protection of privacy in the digital world.” The TTDSG is also intended to bridge the gap between German law and EU requirements.

Legal Framework

Compared to the GDPR, the TTDSG—insofar as both apply—will constitute a so-called “prevailing special provision” and will supersede conflicting provisions of the GDPR or supplement them with specific regulations. 

With regard to existing German regulations, the TTDSG consolidates data protection provisions from the Telecommunications Act (TKG) and the Telemedia Act (TMG) into a single law. The distinction generally made under German law between communication services and telemedia (e.g., messaging apps or emails) therefore remains in place: While for telecommunications services, signal transmission via telecommunications systems is essential (e.g., phone or text message), telemedia services focus on electronic information or communication (e.g., emails, messaging apps, or websites). The TTDSG therefore applies to anyone who operates a website or app.

According to § 1(3) TTDSG, all companies and individuals that have a place of business within the scope of the TTDSG, provide services or contribute to such services, or make goods available on the market. Violations may be punishable under § 28(2) TTDSG with a fine of up to 300,000€ or under § 27 TTDSG with imprisonment of up to two years. The former would be imposed by the BNetzA or the BfDI. It is striking that the range of fines is significantly lower compared to the GDPR (up to 20,000,000€ or 4% of annual revenue).

Telecommunications Secrecy, Traffic and Location Data

Similar to the ePrivacy Directive, the TTDSG applies not only to personal data but rather to all information collected in the course of using telemedia and telecommunications services. In contrast to § 96 TKG in conjunction with § 9 TTDSG, the processing of traffic data will in future only be permitted if it is necessary for the purposes specified in § 9(1) of the TTDSG (such as to maintain telecommunications or for billing purposes). The legislature excludes any processing beyond this scope in Section 9(1), Sentence 3 of the TTDSG under the new regulation.

However, this provision does not affect the obligation to process traffic data based on other legal provisions. Furthermore, in Section 9(2) of the TTDSG now specifies the requirements for the necessary consent through a direct reference to the GDPR.

The TTDSG also extends the confidentiality of telecommunications to certain telemedia (e.g., emails, messaging apps, Internet telephony). In the future, technology service providers such as Google or Facebook will therefore no longer generally permitted to analyze the communication taking place on their platforms. It remains to be seen what this regulation will mean in practice.

Information on existing data

Furthermore, providers of commercialtelemedia service providers may in the future be required, under certain circumstances (see &§ 22(3) and § 24(3) TTDSG) must provide public authorities with information regarding inventory and user data upon request. However, passwords or other data that would allow access to end devices or storage devices are exempt from this obligation to provide information pursuant to § 22(1), sentence 1, of the TTDSG.

§ Section 24(2) of the TTDSG provides that requests for information shall generally be answered in writing or electronically and only by citing the relevant statutory provision, although in cases of imminent danger pursuant to § 24(2), sentence 3, of the TTDSG, a legal basis may be provided subsequently. In such cases, however, the risk is borne by the entity requesting the information.

Regulations on Cookies and Tracking Technologies

With a delay of nearly ten years, § 25 TTDSG the “cookie regulation” of Art. 5(3) of the European ePrivacy Directive, which has been in effect since 2009, into national law. This finally clarifies what had previously already been evident from the case law of the Federal Court of Justice (BGH): Unless one of the narrowly defined exceptions applies (e.g., cookies that are technically necessary for the operation of the site), website operators must obtain active and informed consent from each visitor if they use cookies or comparable technologies, such as local storage or session storage, on their website. Accordingly, providers of telemedia are also required to obtain consent before cookies may be stored on users’ devices or data already stored may be read. 

Consent Management

Furthermore, § 26 TTDSG contains requirements for „recognized consent management services and end-user settings” (so-called “Personal Information Management Services” – PIMS), which, according to § 26(1) TTDSG must be accredited by an independent body. PIMS are intended to enable the monitoring and evaluation of the effectiveness of consent management. 

Providers of PIMS services must be accredited and may not have any financial self-interest in the granting of consent. Foundations, for example, would be suitable candidates for this role. Website operators must then take into account the consent settings made by users who use a PIMS provider. The goal is to strengthen Internet users’ informational self-determination and control over their personal data. 

Impact on Businesses

First of all, the TTDSG contains numerous revised provisions for the telecommunications industry. Companies operating in this sector are already required to comply with the provisions of the TKG, but must adapt their internal processes accordingly to the TTDSG.

The changes regarding telemedia affect nearly every company, because anyone who operates a website or app will have to assess compliance with data protection requirements under the TTDSG in the future. The scope of application is broad, meaning that companies are also subject to the TTDSG if they provide services in Germany without having a branch office there (for more details, see Carlo Piltz).

In § 19(4) of the TTDSG, the legislature clarifies that technical and organizational measures must be taken to prevent disruptions, and these measures must take the state of the art into account. Recognized encryption methods are mentioned in this context, but they are only examples. Companies are therefore not only obligated with regard to data protection but must also implement appropriate measures with respect to information security.

In the context of technical and organizational measures, the legislature also reiterates the principle of data minimization, which is already familiar from the GDPR: According to § 19(2) of the TTDSG, the use of telemedia and payment for such services must be made possible anonymously or under a pseudonym, to the extent that this is technically feasible.

A long-awaited update can be found in the provisions regarding § 25 TTDSG: These provisions state that website operators must obtain active and informed consent from each visitor if they use cookies or comparable technologies on their website to store or retrieve data on end devices. Therefore, anyone who uses such technologies that are not necessary for technical implementation must obtain prior consent via a consent banner on the website (or a corresponding equivalent in smartphone apps).

Sources