[eu]cite

Home› Cybersecurity & IT Security› BSIG-EN

Part 2 · The BSI  ›  Chapter 1 · Tasks and Powers › Section 8

Averting malware and dangers to the Federation's communications technology

(1) To avert dangers to the Federation's communications technology, the BSI may 1. collect and automatically evaluate protocol data arising from the operation of the Federation's communications technology, insofar as necessary for detecting, containing or eliminating disruptions or faults in the Federation's communications technology, or attacks on the Federation's information technology, 2. automatically evaluate the data arising at the interfaces of the Federation's communications technology, insofar as necessary for detecting and averting malware and other significant dangers to the Federation's communications technology. Unless the following subsections permit further use, the automated evaluation of this data and its subsequent complete and non-recoverable deletion must take place without delay. The use restrictions do not apply to protocol data insofar as it contains neither personal data nor data subject to the secrecy of telecommunications. Federal administration entities are obliged to support the BSI in measures under the first sentence and, in doing so, to ensure the BSI's access to internal protocol data under the first sentence, no. 1 and to interface data under the first sentence, no. 2. Protocol data of the federal courts may be collected only with their agreement.
(2) Protocol data under subsection (1), first sentence, no. 1 may be stored beyond the period necessary for the automated evaluation under subsection (1), first sentence, no. 1, for at most 18 months, insofar as actual indications exist that, if a suspicion under subsection (4), second sentence is confirmed, the data may be necessary to avert dangers arising from the malware found, or to detect and avert other malware or other significant dangers to the Federation's communications technology. Organisational and technical measures must ensure that an evaluation of the data stored under this subsection takes place only in automated form, and that access to data stored for longer than three months takes place only where actual findings exist that the Federation is affected by malware or another significant danger to the Federation's communications technology. The data must be pseudonymised insofar as this is possible in automated form. Non-automated processing is admissible only in accordance with the following subsections. Insofar as this requires the restoration of pseudonymised protocol data, this must be ordered by the President of the BSI or the President's deputy in office. The decision must be documented.
(3) Protocol data may, before its pseudonymisation and storage under subsection (2), be processed manually to ensure error-free automated evaluation. Where indications exist that error-free automated evaluation is impeded by a significant fault, the personal reference of protocol data may be restored to ensure error-free automated evaluation, insofar as necessary in the individual case. Subsection (2), third to sixth sentences applies accordingly.
(4) A use of personal data going beyond subsections (1) and (2) is admissible only where specific facts give rise to suspicion that 1. that data contains malware, 2. that data was transmitted by malware, 3. that data is connected with another significant danger to the Federation's communications technology, or 4. that data may give rise to indications of malware or another significant danger to the Federation's communications technology, and insofar as the data processing is necessary to confirm or refute the suspicion. Where the suspicion is confirmed, further processing of personal data is admissible insofar as necessary 1. to avert the malware or the other significant dangers to the Federation's communications technology, 2. to avert dangers arising from the malware found, or 3. to detect and avert other malware or dangers to the Federation's communications technology. Malware may be eliminated or hindered in its functioning. The technical measures necessary to eliminate another significant danger to the Federation's communications technology may be taken. The BSI may transmit the data to the federal administration entity concerned, insofar as necessary for a use under the first to fourth sentences. The non-automated use of the data under the first and second sentences may be ordered only by a member of the BSI's staff qualified for judicial office. The order under the fourth sentence must take into account the resulting transmission powers under subsection (6).
(5) The parties to the communication must be notified, at the latest after detection and averting of malware or its effects, or of other significant dangers to the Federation's communications technology arising from malware, where they are known or their identification is possible without disproportionate further investigation, and no predominant interests of third parties worthy of protection preclude this. Notification may be dispensed with where the person was affected only insignificantly and it may be assumed that they have no interest in being notified. The BSI must submit cases in which it dispenses with notification to the BSI's official data protection officer and to a further member of the BSI's staff qualified for judicial office, for review. Where the official data protection officer objects to the BSI's decision, the notification must be made subsequently. The decision not to notify must be documented. The documentation may be used exclusively for data-protection review purposes. It must be deleted after twelve months. In the cases of subsections (6) and (7), notification is made by the authorities named there, by corresponding application of the provisions applicable to those authorities. Where those provisions contain no rules on notification obligations, the provisions of the Code of Criminal Procedure apply accordingly.
(6) The BSI may transmit the personal data used under subsection (4) to the prosecuting authorities for the prosecution of an offence committed by means of malware or in connection with another significant danger to the Federation's communications technology under sections 202a, 202b, 303a or 303b of the Criminal Code. It may further transmit that data 1. to the police forces of the Federation and of the Länder for averting a danger to public security arising directly from malware, 2. to the Federal Office for the Protection of the Constitution, to inform it of facts indicating security-endangering or intelligence activities for a foreign power, and to the Military Counter-Intelligence Service, where those activities are directed against persons, agencies or facilities within the portfolio of the Federal Ministry of Defence, 3. to the Federal Intelligence Service, to inform it of facts indicating an international criminal, terrorist or state attack by means of malware or comparable harmful information technology means on the confidentiality, integrity or availability of IT systems, in cases of significant importance with a connection to the Federal Republic of Germany.
(7) For other purposes, the BSI may transmit the data under subsection (4), first sentence 1. to the prosecuting authorities, for prosecuting an offence of significant importance including in the individual case, in particular an offence named in section 100a(2) of the Code of Criminal Procedure, 2. to the police forces of the Federation and of the Länder, for averting a danger to the existence or security of the state, or to the life, limb or liberty of a person, or to items of significant value whose preservation is required in the public interest, 3. to the authorities for the protection of the constitution of the Federation and of the Länder and to the Military Counter-Intelligence Service, where actual indications exist of activities in the Federal Republic of Germany directed, through the use of force or preparatory acts aimed at such use, against the interests protected under section 3(1) of the Federal Act on the Protection of the Constitution or section 1(1) of the Military Counter-Intelligence Service Act, 4. to the Federal Intelligence Service, where actual indications exist of a suspicion that someone is planning, committing or has committed offences under section 3(1), no. 8 of the Article 10 Act and this is of significance for the foreign and security policy of the Federal Republic of Germany. The transmission under the second sentence, nos. 1 and 2 requires prior judicial consent. The provisions of the Act on Proceedings in Family Matters and in Matters of Non-Contentious Jurisdiction apply accordingly to the procedure under the second sentence, nos. 1 and 2. The Local Court in whose district the BSI has its seat has jurisdiction. The transmission under the second sentence, nos. 3 and 4 takes place on the order of the Federal Ministry of the Interior. Sections 9 to 16 of the Article 10 Act apply accordingly.
(8) A content-related evaluation for other purposes going beyond the preceding subsections, and the passing on of personal data to third parties, are inadmissible. Insofar as technically possible, it must be ensured that data concerning the core area of private life is not collected. Where findings from the core area of private life, or data under Article 9(1) of Regulation (EU) 2016/679, are obtained as a result of the measures under subsections (1) to (4), those findings and data may not be used. Findings from the core area of private life must be deleted without delay. This also applies in cases of doubt. The fact of obtaining and deleting those findings must be documented. The documentation may be used exclusively for data-protection review purposes. It must be deleted once no longer necessary for those purposes, but at the latest at the end of the calendar year following the year in which the documentation was created. Where, within the framework of subsections (5) or (6), the content or circumstances of communications of persons named in section 53(1), first sentence of the Code of Criminal Procedure are transmitted, to which those persons' right to refuse to testify extends, the use of that data for evidentiary purposes in criminal proceedings is admissible only insofar as the subject matter of those criminal proceedings is an offence carrying a maximum penalty of at least five years' imprisonment.
(9) Before commencing the collection and use of data, the BSI must draw up a data collection and use concept and keep it available for review by the Federal Commissioner for Data Protection and Freedom of Information. The concept must take account of the particular protection needs of government communications. The criteria used for the automated evaluation must be documented. The Federal Commissioner for Data Protection and Freedom of Information also communicates the result of their reviews under section 16 of the Federal Data Protection Act to the departments.
(10) The BSI informs the Federal Commissioner for Data Protection and Freedom of Information, each calendar year by 30 June of the year following the reporting year, of 1. the number of cases in which data was transmitted under subsection (6), first sentence, (6), second sentence, no. 1 or subsection (7), no. 1, broken down by the individual transmission powers, 2. the number of personal evaluations under subsection (4), first sentence in which the suspicion was refuted, 3. the number of cases in which the BSI dispensed with notifying the persons concerned under subsection (5), second or third sentence.
(11) The BSI informs the Interior Committee of the German Bundestag, each calendar year by 30 June of the year following the reporting year, of the application of this provision.

←→ also move between sections