In Federal Law Gazette, Part I, No. 41 dated November 25, 2019, the amendments to data protection law were published. Specifically, the “Second Act to Adapt Data Protection Law to Regulation (EU) 2016/679 and to Implement Directive (EU) 2016/680 (Second EU Data Protection Adaptation and Implementation Act – 2nd DSAnpUG-EU)” and the “Act on the Implementation of Directive (EU) 2016/680 in Criminal Proceedings and on the Adaptation of Data Protection Provisions to Regulation (EU) 2016/679.” The amendments take effect on November 26, 2019.
The DSAnpUG-EU was passed by the German Bundestag on June 27, 2019 passed by the German Bundestag on June 27, 2019, and adopted. At first, it remained unclear whether the law would be published in the Federal Law Gazette. The reason for this was the lack of a quorum, which requires more than half of the 709 members of parliament to be present. However, according to the AfD, no more than 100 members of parliament were present at the time of the vote at 1:27 a.m. on June 28, 2019. Consequently, a preliminary injunction was filed with the Federal Constitutional Court in Karlsruhe. The purpose of the injunction was to prevent Federal President Frank-Walter Steinmeier from signing three laws passed during that session. This motion was rejected by the Federal Constitutional Court on September 17, 2019, according to Press Release No. 58/2019 dated September 24, 2019.
The DSAnpUG-EU introduces significant changes regarding the obligation to appoint a data protection officer, as well as the expansion of the written form to include electronic form for consent in employment relationships. The other adjustments primarily involve technical amendments to existing laws. The Telemedia Act and the Telecommunications Act are not affected by the changes.
In particular, the change to the requirement to appoint a data protection officer only when at least 20 people are permanently engaged in the automated processing of personal data has drawn criticism from data protection. Ulrich Kelber, the Federal Commissioner for Data Protection and Freedom of Information, warns: “Abolishing these appointment requirements will not ease the burden on companies; rather, it will harm them in the medium term, as expertise will be lost while the companies’ data protection obligations remain.” The Federal Association of Data Protection Officers (BvD) also criticizes, in its press release dated June 28, 2019 the increase in the threshold for the appointment requirement. Thomas Spaeng, Chairman of the BvD, states: “This clearly represents a reduction in autonomy and thus inevitably increases bureaucracy, since all requirements of the EU GDPR must still be met.”
In addition to the requirement to appoint a data protection officer pursuant to§ 38 of the Federal Data Protection Act (BDSG), the GDPR sets forth in Art. 37 three additional criteria that may result in a designation requirement:
With modern IT methods and new technologies such as artificial intelligence (AI), even a small number of people can process large amounts of data. The WhatsApp example clearly illustrates these scales. Facebook reported on February 16, 2016, that with only 57 developers, the service supports 1 billion users and delivers 42 billion messages daily. Given the scale of data processing, the requirements for conducting a data protection impact assessment pursuant to Article 35 of the GDPR. Even in these cases, sentence 2 of § 38(1) BDSG provides that a data protection officer must be appointed.
Even while the old Federal Data Protection Act was in effect, there was a persistent misconception that data protection laws only had to be complied with if the threshold forthe obligation to appoint a data protection officer is exceeded. A look at the data from GENESIS-Online database of the Federal Statistical Office reveals that even the original threshold of 10 employees had already exempted 80.4 percent of German companies from the obligation to appoint a data protection officer. This group, classified as “micro-enterprises,” employs a maximum of 9 people. Under the new regulation, parts of the group designated as “small enterprises” (up to 49 employees) are now also exempt from the obligation to appoint a data protection officer. These represent an additional 15.89 percent of the German business landscape. Assuming that this misconception is widespread, it is likely that over 90 percent of companies have limited their efforts to implement the GDPR to the publication of privacy notices on their websites. As reported the industry association bitkom reported on September 17, 2019, that only 25 percent had largely implemented the new data protection rules in their entirety. However, only companies with 20 or more employees were surveyed.
It is to be feared that, with the change in the requirement to appoint a data protection officer, approximately 9 out of 10 German companies will no longer have the expertise needed to implement the General Data Protection Regulation and that the resulting lack of support in implementing the requirements will lead to data breaches, numerous fine proceedings, and claims for damages.