[eu]cite

Home› Identity Documents & Civil Registration› PAuswG (EN)

Part 4 · Authorizations; electronic signature › Section 21

Issuing and suspending authorizations of service providers

(1) Under the conditions of subsection 2, upon written application service providers shall be authorized to request the data necessary to perform their tasks or business via electronic identification of the identity card holder using an authorization certificate. The responsible body pursuant to Section 7 (4) first sentence shall issue the authorizations to service providers in accordance with the following provisions, and shall issue service providers with the necessary authorization certificates via public communication channels available at all times. The application shall contain the data pursuant to Section 18 (4) second sentence nos. 1 through 4.

(2) Authorization pursuant to subsection 1 shall be issued if

1.  the purpose given is not unlawful;

2.  the purpose does not consist of commercial transmission of the data, and no indications of commercial or unauthorized transmission of the data exist;

3.  the service provider submitting the application has demonstrated the need for the data to be transmitted for the purpose described;

4.  the requirements, in particular of data protection and data security, in accordance with Section 34 no. 7 of the statutory instrument, are met; and

5.  there are no indications that the authorization will be misused.

The service provider shall voluntarily agree to confirm the requirements pursuant to no. 4 in writing and to demonstrate compliance upon request.

(3) The authorization shall be valid for a limited period. The length of validity may not exceed three years. The authorization may be used only by the service provider specified in the authorization certificate and only for the purpose specified therein. The authorization may be made subject to additional conditions and renewed upon application.

(4) Changes to the data and information pursuant to subsection 1 third sentence shall be reported immediately to the responsible body pursuant to Section 7 (4) first sentence.

(5) The authorization shall be withdrawn if it was issued on the basis of false or incomplete information given by the service provider. It shall be revoked if it should not have been issued at all or not with the same extent. The authorization should be withdrawn or revoked if the data protection supervisory authority responsible for the service provider so requests because there is reason to believe that the service provider has unlawfully processed or used personal data received on the basis of the authorization certificate.

(6) After notification that the authorization has been withdrawn or revoked, the service provider may no longer use any authorization certificates in its possession. This shall not apply as long and to the extent that immediate enforcement (Section 30) has been suspended.

←→ also move between sections