[eu]cite

Home› Telecommunications & Digital Services› VDG (EN)

Part 2 · General provisions for qualified trust services › Section 16

Termination plan; permanently verifiable trust services

(1) In the termination plan under Article 24(2)(i) of Regulation (EU) No 910/2014, a qualified trust service provider must provide for all measures necessary to ensure that, upon cessation of its activity, withdrawal of its qualification status, or where the opening of insolvency proceedings is applied for and the activity is not continued, all qualified certificates it has issued in connection with electronic signatures and seals, as well as certificates in connection with Annex I letter g, Annex III letter g and Article 42(1)(c) of Regulation (EU) No 910/2014, including revocation information, can be 1. taken over by another qualified trust service provider, or 2. taken over by the Bundesnetzagentur into the trust infrastructure under subsection (5). In the case of sentence 1 number 2, the qualified trust service provider must revoke the still-valid certificates before transmitting them to the Bundesnetzagentur. In every case, it must ensure that the associated records under Article 24(2)(h) of Regulation (EU) No 910/2014 are transmitted to the party taking over.
(2) In the termination plan, the qualified trust service provider must also make arrangements to notify the holders of the certificates referred to in subsection (1) sentence 1, insofar as possible, at least two months in advance, of the cessation of its activity and of the takeover of its certificates.
(3) In the cases under subsection (1) sentence 1 number 2, the Bundesnetzagentur shall, where a legitimate interest exists, provide information on the records, insofar as this is technically possible without disproportionate effort. Any further right to information under section 19 of the Federal Data Protection Act and under Article 15 of Regulation (EU) 2016/679 remains unaffected.
(4) Qualified trust service providers must, for the entire duration of their operation, 1. maintain the certificates referred to in subsection (1) sentence 1, even beyond their period of validity, together with the associated revocation information, in a certificate database under Article 24(2)(k) and (4) of Regulation (EU) No 910/2014, and 2. retain the associated records under Article 24(2)(h) of Regulation (EU) No 910/2014.
(5) The Bundesnetzagentur must establish, maintain and continuously update a trust infrastructure for the permanent verifiability of qualified electronic certificates and qualified electronic time stamps. Further details are governed by the statutory ordinance under section 20(2) number 5.

←→ also move between sections