(1) Identity card holders aged 16 or over may use their identity cards to verify their identity vis-à-vis public and private-sector bodies electronically. In derogation from the first sentence, electronic identification shall not be permitted if the conditions of Section 3a (1) of the Administrative Procedure Act, of Section 87a (1) first sentence of the German Fiscal Code or Section 36a (1) of the Social Code, First Book are not met.
(2) Electronic identification shall take place via transmission of data from the electronic storage and processing medium of the identity card. State-of-the-art technical measures shall be taken to ensure data protection and data security, in particular ensuring data confidentiality and integrity. If generally accessible networks are used, encryption shall be applied. Persons other than the identity card holder shall not be permitted to use the electronic identification function.
(3) The blocking attribute and the indication as to whether the identity card is valid shall always be transmitted for checking whether the identity card has expired or been blocked. The following additional data may be transmitted:
1. family name,
2. given names,
3. doctoral degree
4. date of birth,
5. place of birth,
6. address,
7. type of document,
8. service- and card-specific identifier,
9. the abbreviation “D” for the Federal Republic of Germany,
10. indication whether the card holder is older or younger than a particular age,
11. indication whether a place of residence matches the requested place of residence, and
12. religious name / stage or pen name.
(4) Data shall be transmitted only if the service provider transmits a valid authorization certificate to the identity card holder, who then enters his/her PIN code. Before the card holder enters the PIN code, the following information from the authorization certificate must be transmitted for display:
1. name, address and e-mail address of the service provider,
2. categories of data to be transmitted pursuant to subsection 3 second sentence,
3. purpose of the transmission,
4. indication of the bodies responsible for the service provider checking compliance with data protection regulations,
5. the authorization certificate's date of expiry.
(5) Transmission shall be limited to the data categories listed on the authorization certificate. In individual cases, the identity card holder may refuse the transmission of data also in these categories.