[eu]cite

Home› Data Protection› TDDDG (EN)

Part 3 · Data Protection in Digital Services, Terminal Equipment  ›  Chapter 1 · Technical and Organisational Precautions, Processing of Data for the Purpose of the Protection of Minors and for Providing Information › Section 19

Technical and organisational precautions

(1) Providers of digital services must ensure, by technical and organisational precautions, that the user of digital services
1. can end the use of the service at any time, and
2. can use digital services protected against third parties taking cognisance of them.
(2) Providers of digital services must make it possible to use digital services and to pay for them anonymously or under a pseudonym, insofar as this is technically possible and reasonable. The user of digital services must be informed of this possibility.
(3) The user must be shown any onward referral to another provider of digital services.
(4) Providers of digital services must, insofar as technically possible and economically reasonable, ensure, within the scope of their respective responsibility for digital services offered on a commercial basis, by technical and organisational precautions, that
1. no unauthorised access to the technical facilities that they use for offering their digital services is possible, and
2. the technical facilities under no. 1 are secured against faults, including those caused by external attacks. Precautions under the first sentence must take account of the state of the art. A precaution under the first sentence is, in particular, the application of an encryption procedure recognised as secure. Orders of the Federal Office for Information Security under section 17, first sentence of the BSI Act remain unaffected.

←→ also move between sections