Data protection principles
The processing of personal data has become an integral part of our everyday lives. It brings us particular benefits in the digital sphere: for example, when we are offered products tailored precisely to our needs, when a sat-nav system uses our location to find the shortest route home, or when we use social media – none of this, and much more besides, would be possible without the processing of personal data.
However, the more personal data third parties hold about an individual – and consequently the more they know about that person – the more predictable and therefore susceptible to influence that person becomes in their eyes. It is therefore essential that personal data is handled in a transparent, confidential, secure, conscientious and, above all, data protection-compliant manner!
The primary aim of data protection is therefore to safeguard the right to informational self-determination as part of data subjects' general right to privacy – for data protection is the protection of fundamental rights1. At the same time, this protection should be reconciled as effectively as possible with the interests of data controllers (e.g. research, public relations, event planning, etc.).
The following section is intended to provide you with an initial overview of the most important terms, concepts, and legal bases of data protection.
What are the legal bases?
As a general rule, whenever personal data is to be processed, data protection regulations must be observed.
The relevant provisions under data protection law are essentially:
- the European General Data Protection Regulation GDPR, which has been applicable throughout Europe since 25 May 2018
- the German Federal Data Protection Act (BDSG) and, in the Free State of Bavaria, the Bavarian Data Protection Act (BayDSG)
- other so-called sector-specific law (e.g. the Social Security Codes)
What is personal data?
The GDPR defines personal data in Article 4 No. 1 of the GDPR as any information relating to an identified or identifiable natural person. A natural person is regarded as identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
These include, amongst others:
- name, date and place of birth, gender, age
- contact details such as address, e-mail address, telephone number
- uniquely assigned identification codes such as identity card numbers, social security numbers, or student registration numbers
- as well as, for example, vehicle registration numbers, IP addresses, fingerprints, eye colour, exam results, bank account details, etc.
When does processing take place?
According to Article 4 No. 2 of the GDPR, the term processing describes any operation or set of operations which is carried out on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, distribution, or any other form of making available, the matching or linking, the restriction, erasure or destruction.
When is the processing of personal data permitted?
An important fundamental principle of data protection is the so-called ban with permit reservation(2). This means that the processing of personal data is, in principle, prohibited and only becomes lawful if3
- it is expressly permitted or required by law (processing may, for example, be permissible if it is necessary to protect the vital interests of the data subject, Article 6 (1) Sentence 1 lit. d of the GDPR, or to carry out a task carried out in the public interest, Article 6 (1) Sentence 1 lit. e of the GDPR) or
- the data subject has given their consent
Consent is generally the more relevant basis for legitimising practical projects and surveys carried out as part of a degree programme where personal data is to be processed. Further information on consent under data protection law can be found here.
What information obligations must be met?
Regardless of the basis on which personal data is processed (whether by consent or another form of legal basis), the information requirements set out in Article 13 of the GDPR must be met. Accordingly, the data subject must be provided with at least the following information – even in the case of photographs or video recordings:
- What personal data is to be processed?
- For what purpose is this data to be processed?
- Who is the data controller / contact person / data protection officer?
- Will the data collected be disclosed? If so, to whom? (If the data is intended to be transferred to a third country or an international organisation, this must also be explicitly stated.)
- How long will the data be stored?
- Information on the data subject’s rights: right of access, erasure, restriction, objection, data portability, and the right to lodge a complaint with the competent supervisory authority (in Bavaria: the Bavarian State Office for Data Protection Supervision
- Information on the right to withdraw consent at any time
If there are plans to publish personal data, it is also appropriate, in the interests of transparent communication, to provide information on the scope of the publication. If, for example, the photographs or videos are to be made publicly available on the internet , this can be done by stating that the data will be accessible without restriction in terms of time or location.
All this information and these notices must be provided to data subjects in accordance with Article 12 (1) of the GDPR in a precise, transparent, comprehensible, and easily accessible form, using clear and plain language. This may be done either in writing or in another form (e.g. electronically).
1) BfDI (ed.): Datenschutz ist, p. 3 et seq., accessible online at: www.bfdi.bund.de/SharedDocs/Publikationen/Faltblaetter/Datenschutz-ist.pdf, last accessed on 16 June 2020.
2) Bretthauer in: Specht, Louisa/Mantz, Reto (eds.): Handbuch Europäisches und deutsches Datenschutzrecht, § 2 marginal no. 31, Munich, 2019.
3) BfDI (ed.): Sozialdatenschutz, p. 15 et seq., accessible online at: www.bfdi.bund.de/SharedDocs/Publikationen/Infobroschueren/INFO3.pdf, last accessed on 15 June 2020.
