(1) Services for managing consent given under section 25(1) that 1. have user-friendly and competition-compliant procedures and technical applications for obtaining and managing consent, 2. have no economic interest of their own in the giving of consent or in the data managed, and are independent of undertakings that may have such an interest, 3. process the personal data and the information on consent decisions for no purposes other than consent management, and 4. present a security concept that enables an assessment of the quality and reliability of the service and of the technical applications, and from which it is apparent that the service fulfils, both technically and organisationally, the legal requirements for data protection and data security arising in particular from Regulation (EU) 2016/679, may be recognised by an independent body in accordance with the statutory instrument under paragraph 2.
(2) The Federal Government shall determine, by statutory instrument requiring the consent of the Bundestag and the Bundesrat, the requirements 1. for the user-friendly and competition-compliant procedure and technical applications under paragraph 1 no. 1, and 2. for the recognition procedure, in particular a) the necessary content of the application for recognition, b) the content of the security concept under paragraph 1 no. 4, and c) the independent body responsible for recognition, and 3. the technical and organisational measures ensuring that a) software for retrieving and displaying information from the internet aa) complies with end-users' settings regarding consent under section 25(1), and bb) takes into account the integration of recognised consent management services, and b) providers of digital services, in managing the consent given by end-users, take into account the integration of recognised consent management services and settings made by end-users.
(3) The Federal Government shall, within two years of the entry into force of a statutory instrument under paragraph 1, assess the effectiveness of the measures taken with regard to establishing user-friendly and competition-compliant consent procedures, and shall submit a report on this to the Bundestag and the Bundesrat.
Home› Data Protection› TDDDG (EN)
Part 3 · Data Protection in Digital Services, Terminal Equipment › Chapter 2 · Terminal Equipment › Section 26
Recognised consent management services, end-user settings
←→ also move between sections