(1) The processing of personal data by the BSI is admissible where the processing is necessary to perform its tasks carried out in the public interest.
(2) The processing of personal data by the BSI for purposes other than that for which the data was originally collected is admissible, without prejudice to Article 6(4) of Regulation (EU) 2016/679, in its respective current version, and to section 23 of the Federal Data Protection Act, where 1. the processing is necessary a) for collecting, evaluating or investigating information on security risks or security precautions for information technology, or b) for support, advice or warning on questions of IT security, and 2. no reason exists to assume that the data subject's interest worthy of protection in the exclusion of the processing outweighs this.
(3) The processing of special categories of personal data by the BSI is admissible, by way of derogation from Article 9(1) of Regulation (EU) 2016/679 and without prejudice to section 22(1) of the Federal Data Protection Act, where 1. the processing is necessary to avert a significant danger to network, data or information security, 2. excluding that data from processing would render performance of the BSI's tasks impossible or significantly endanger it, and 3. no reason exists to assume that the data subject's interest worthy of protection in excluding that data from processing outweighs this.
(4) The BSI provides for appropriate and specific measures to safeguard the interests of the data subject under section 22(2), second sentence of the Federal Data Protection Act.
Home› Cybersecurity & IT Security› BSIG-EN
Part 2 · The BSI › Chapter 2 · Data Processing › Section 20
Processing of personal data
←→ also move between sections