[eu]cite

Home› Telecommunications & Digital Services› VDG (EN)

Part 2 · General provisions for qualified trust services › Section 11

Identity verification

(1) The Bundesnetzagentur, after consulting the circles concerned and in agreement with the Federal Office for Information Security, shall determine, by decree published in the Official Gazette, which other identification methods within the meaning of Article 24(1) subparagraph 2(d) sentence 1 of Regulation (EU) No 910/2014 are recognised, and which minimum requirements apply to each.
(2) The Bundesnetzagentur shall review the decree under subsection (1) regularly, at intervals of four years, and also 1. where there is reasonable grounds to assume that methods are no longer sufficiently secure, or 2. at the request of the Federal Office for Information Security.
(3) Innovative identification methods not yet recognised by decree in the Official Gazette may be provisionally recognised by the Bundesnetzagentur, in agreement with the Federal Office for Information Security and after consulting the Federal Commissioner for Data Protection and Freedom of Information, for a period of up to two years, provided that a conformity assessment body has confirmed the equivalent security of the identification method within the meaning of Article 24(1) subparagraph 2(d) of Regulation (EU) No 910/2014. The Bundesnetzagentur shall publish the provisionally recognised identification methods on its website. The Bundesnetzagentur and the Federal Office for Information Security shall monitor the suitability of the provisionally recognised identification methods throughout the entire period of provisional recognition. Where monitoring identifies security-relevant risks in the provisionally recognised identification method, the supervisory body may, in agreement with the Federal Office for Information Security, require the qualified trust service provider to remedy those risks by supplementary measures, insofar as this is appropriate from a security standpoint. Where supplementary measures cannot ensure sufficient security of the provisionally recognised identification method, the supervisory body should prohibit the qualified trust service provider from using that identification method.
(4) The qualified trust service provider may, in accordance with the data-protection provisions, use personal data collected at an earlier point in time in the course of a proper identity verification, provided and insofar as this data, at the time the application is made, ensures reliable identification of the applicant.

←→ also move between sections