(1) A "data protection cockpit" is an IT component with which natural persons can obtain information about data transmissions between public bodies. Until the technical and legal conditions exist for capturing further data transmissions, only those data transmissions in which an identification number under section 5 of the Identification Number Act is used are initially captured.
(2) In the data protection cockpit, in accordance with subsection (4) sentence 3, only log data under section 9 of the Identification Number Act are displayed, including the content data transmitted for that purpose by the register modernisation authority and the registers, together with the master data of the registers. This data is stored in the data protection cockpit only for the duration of the respective use; it must be deleted without delay once the use has ended. The right to information under Article 15 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1; L 314, 22.11.2016, p. 72; L 127, 23.5.2018, p. 2; L 74, 4.3.2021, p. 35) remains unaffected. The data protection cockpit must be designed to be simple and functional from the user's perspective. Technical and organisational measures must be provided so that state interventions to the user's disadvantage are not possible.
(3) Any natural person may register for a data protection cockpit with the public body operating it. On registration and use of the data protection cockpit, they must identify themselves using a means of identification at the level of assurance "high". For establishing identity, the service- and card-specific identifier may be processed on registration and use. In addition, the user may also register with the data protection cockpit using a user account of the portal network. In that case, the body responsible for the user account may transmit the service- and card-specific identifier to the body responsible for the data protection cockpit.
(4) The data protection cockpit may process the identification number under section 139b of the Fiscal Code as an identifier for the request to collect and display the data under subsection (2). For the request under section 6 of the Identification Number Act, the data protection cockpit shall collect the following data upon registration of the user: 1. surname, 2. first names, 3. address, 4. birth name, and 5. date of birth. The user determines the extent to which the data protection cockpit may collect and display log data, including the content data transmitted, as well as the master data of the registers, under subsection (2). Only the user has access to this data. The user must be able to delete their account in the data protection cockpit themselves at any time. The account in the data protection cockpit is automatically deleted if it has not been used for three years.
(5) The data protection cockpit is established and operated by a public body determined by statutory ordinance of the Federal Ministry of the Interior and Community, in consultation with the IT Planning Council and with the consent of the Bundesrat. Further details on the technical procedures, the technical formats of the data records, and the transmission channels are laid down by the Federal Ministry of the Interior and Community, in consultation with the IT Planning Council and with the consent of the Bundesrat, by statutory ordinance.
Home› E-Government & Public Sector Digitalisation› OZG (EN)
Section 10
Data protection cockpit; authorisation to issue an ordinance
←→ also move between sections