(1) Insofar as necessary, persons under a duty pursuant to section 3(2), first sentence may process end-users' traffic data, as well as the control data of an information-technology protocol for data transmission that is transmitted independently of the content of a communications process or stored on the servers involved in the communications process and that is necessary to ensure communication between recipient and sender, in order to detect, localise or remedy faults or errors in telecommunications installations. This also applies to faults that may lead to a restriction of the availability of information and telecommunications services or to unauthorised access to users' telecommunications and data processing systems. Processing of the traffic data and control data for other purposes is impermissible. Insofar as the traffic data are not collected and used in an automated manner, the data protection officer of the person under a duty pursuant to section 3(2), first sentence must be informed without delay of the procedures and circumstances of the measure. Affected end-users must be notified by the person under a duty pursuant to section 3(2), first sentence, insofar as they can be identified.
(2) The traffic data and control data must be deleted without delay as soon as they are no longer necessary for remedying the fault.
(3) For the purpose of carrying out switchovers and of detecting and localising faults in the network, the operator of telecommunications networks, or its agent, is permitted to connect into existing connections insofar as operationally necessary. Any recordings made in the course of such connecting-in must be deleted without delay. The connecting-in must be indicated and expressly communicated to the communication participants concerned, at the same time, by an acoustic or other signal. Where this is not technically possible, the operational data protection officer of the operator of the telecommunications network must be informed without delay and in detail of the procedures and circumstances of the measure. The operational data protection officer must retain this information for two years.
(4) Where actual indications exist of the unlawful use of a telecommunications network or telecommunications service, in particular of obtaining services by deception or of fraud, or of unreasonable harassment within the meaning of section 7 of the Act Against Unfair Competition, the person under a duty pursuant to section 3(2), first sentence may, in order to secure its claim to payment and to protect end-users against unlawful use of the telecommunications service or telecommunications network, process traffic data necessary to detect and prevent the unlawful use of the telecommunications network or telecommunications service. The person under a duty pursuant to section 3(2), first sentence must document the indications of unlawful use of the telecommunications network or telecommunications service. The person under a duty pursuant to section 3(2), first sentence may compile from the traffic data under the first sentence a pseudonymised aggregate data set that shows the revenue generated by individual end-users and that, applying suitable criteria, enables the identification of such connections in the network as are suspected of unlawful use. The traffic data of other connections must be deleted without delay. The supervisory authority must be informed without delay of the introduction and amendment of a procedure under the first sentence.
Home› Data Protection› TDDDG (EN)
Part 2 · Data Protection and Protection of Privacy in Telecommunications › Chapter 2 · Traffic Data, Location Data › Section 12
Faults in telecommunications installations and misuse of telecommunications services
←→ also move between sections