Zum Inhalt

Germany BDSG Specifics on Top of GDPR — EPPA

BDSG layers on top of GDPR — both must be satisfied

For deployments in Germany, GDPR (Regulation (EU) 2016/679) sets the baseline and the BDSG ("Bundesdatenschutzgesetz" of 2018, as amended) layers Germany-specific rules on top, often stricter. The GDPR DPIA in 30-gdpr-dpia.md is the primary instrument; this document records BDSG-specific deltas that EPPA must satisfy in a German deployment.

1. Document identity

Field Value
Document title Germany BDSG Specifics — EPPA
Document ID EPPA-DE-BDSG-001
Version 0.1 (draft)
Status Draft — not approved
Effective date n/a
Owner LABIS UCA — Germany Privacy lead (to be appointed)
Linked documents 00-overview.md, 30-gdpr-dpia.md, 50-secdev-checklist.md

2. Regulatory anchors

  • Regulation (EU) 2016/679 — GDPR.
  • Bundesdatenschutzgesetz ("BDSG") of 30 June 2017, in force since 25 May 2018, as amended.
  • Medizinprodukterecht-Durchführungsgesetz (MPDG) — German implementing law for EU MDR.
  • Patientenrechtegesetz (BGB §§ 630a–630h) — patient-rights provisions including § 630f (documentation of treatment).
  • State-specific Krankenhausgesetze (KHG) — for hospital deployments, state hospital laws layer additional obligations.
  • BSI IT-Grundschutz — German Federal Office for Information Security baseline-protection methodology (referenced by § 8 BSI-Gesetz).
  • TKG / TMG — telecommunications and telemedia laws (e.g. cookie-rule framework after Cookie-OWiG).

3. § 22 BDSG — Processing of special categories of personal data

§ 22 BDSG implements GDPR Art. 9(2)(b), (g), (h), (i) and (j) for German law. It permits processing of special-category data (including health) by non-public bodies in defined cases.

3.1 § 22(1)(1)(b) BDSG — for healthcare and social-care purposes

The processing of special categories of personal data … is permitted if processing is necessary for the purposes of preventive medicine, the assessment of the working capacity of the employee, medical diagnosis, the provision of healthcare or treatment, or the management of healthcare or social-care systems and services, by employees subject to the obligation of secrecy under § 203 of the Criminal Code (StGB), or under their responsibility.

For EPPA in a treating-clinician deployment, § 22(1)(1)(b) provides the domestic basis for Art. 9(2)(h) GDPR.

3.2 § 22(1)(2)(c) BDSG — for scientific research purposes

The processing of special categories of personal data is also permitted if it is necessary for scientific or historical research purposes or for statistical purposes; the interest of the controller in the processing substantially outweighs the data subject's interest in excluding processing, and the controller takes appropriate and specific measures to safeguard the interests of the data subject.

For EPPA in a research-use deployment, § 22(1)(2)(c) provides the domestic basis for Art. 9(2)(j) GDPR.

3.3 § 22(2) BDSG — appropriate safeguards

Specific safeguards required (non-exhaustive):

  • Technical and organisational measures.
  • Measures to ensure that it is subsequently possible to verify and establish whether and by whom personal data were inputted, altered or removed.
  • Measures to increase the awareness of staff involved in processing.
  • Designation of a data-protection officer.
  • Restrictions on access to personal data within the controller and the processor.
  • Pseudonymisation of personal data.
  • Encryption.
  • Securing of the ability to ensure confidentiality, integrity, availability and resilience.
  • Ability to restore the availability of and access to personal data.
  • A process for regularly testing, assessing and evaluating the effectiveness of measures.
  • Specific rules of procedure to ensure compliance with this Act and the GDPR in the event of a transfer or processing for other purposes.

These map to the TOMs (technische und organisatorische Maßnahmen) detailed in §6 below.

4. § 38 BDSG — DPO mandate

GDPR Art. 37 requires a DPO when the core activities consist of processing on a large scale of special categories of data. § 38 BDSG additionally requires a DPO for non-public bodies under either of these German-specific triggers:

  • § 38(1) sentence 1 BDSG — the controller / processor as a rule permanently employs at least 20 people dealing with the automated processing of personal data. (Note: the threshold was raised from 10 to 20 by the "Drittes Gesetz zur Änderung des BDSG", in force since 26 November 2019.)
  • § 38(1) sentence 2 BDSG — irrespective of the number of persons engaged, the controller / processor performs processing subject to a DPIA under GDPR Art. 35 (special-category data, systematic monitoring, etc.) or commercially processes personal data for the purpose of transfer, for the purpose of anonymised transfer or for purposes of market or opinion research.

EPPA processes special-category health data → DPIA is mandatory under Art. 35(3)(b) GDPR (see 30-gdpr-dpia.md) → DPO is mandatory for any German deployment irrespective of headcount, per § 38(1) sentence 2.

4.1 DPO requirements (Art. 38, Art. 39 GDPR + § 38(2) BDSG)

  • Appointed in writing.
  • Contact details published and communicated to the supervisory authority.
  • Independent — no instructions on the exercise of the role.
  • Cannot be dismissed for the performance of the role.
  • Has resources to perform the role.
  • May be an employee or external (Dienstleister).

5. § 64 BDSG — Technical and organisational measures (TOMs)

§ 64 BDSG applies to processing for the purposes of Part 3 of the BDSG (prevention, investigation, detection, prosecution of criminal offences and threats to public security) — not directly applicable to EPPA.

However, the TOM list in § 64 (modeled on Art. 32 GDPR plus additional items) is the de facto German market standard for AV-Vertrag annexes (processor contracts). The TOM categories are:

§ 64 BDSG measure EPPA mapping
Zugangskontrolle (access control to systems) RBAC (Epic E3); MFA
Zugriffskontrolle (access control to data) Database-level RBAC; row-level security per clinic
Weitergabekontrolle (transmission control) TLS 1.3; signed pre-signed URLs
Eingabekontrolle (input control) AuditLog (Epic E3) records who created/modified each record
Auftragskontrolle (job control) Processor contracts (AV-Verträge) with hosting provider
Verfügbarkeitskontrolle (availability control) Daily backups, 90-day retention, quarterly restore drill
Trennungskontrolle (separation control) Per-tenant organization_id scoping; separate environments dev / staging / prod
Pseudonymisierung Patient UUID; mapping stored separately
Verschlüsselung TLS 1.3 in transit; pgcrypto for Patient.full_name (Epic E3)
Wiederherstellbarkeit Documented restore procedure; RTO 4h, RPO 24h
Regelmäßige Überprüfung Quarterly tabletop; annual penetration test
Datenschutz durch Technikgestaltung (Privacy by Design) OWASP ASVS L2 alignment in 50-secdev-checklist.md

6. Processor contract (Auftragsverarbeitung, AV-Vertrag) template

Required content per Art. 28(3) GDPR with German market additions. Skeleton sections (full text via legal review):

Vereinbarung zur Auftragsverarbeitung (AV-Vertrag)
zwischen
  [Verantwortlicher = treating clinic or LABIS UCA] ("Auftraggeber")
und
  [Auftragsverarbeiter = hosting provider / SMTP / backup] ("Auftragnehmer")

§ 1 Gegenstand, Dauer und Spezifizierung
    Beschreibung des Auftrags: Hosting + Verarbeitung von patientenbezogenen
    Aufnahmen und abgeleiteten klinischen Metriken für die postural-
    fotografische Auswertung (EPPA).
    Dauer: solange Auftraggeber EPPA betreibt.
    Verarbeitungstätigkeiten: siehe Anlage 1.

§ 2 Verarbeitete Daten und betroffene Personenkreise
    Daten: Patientendaten (Identifikator, Aufnahmen, klinische Metriken).
    Personen: Patienten, klinisches Personal.

§ 3 Technische und organisatorische Maßnahmen (Anlage 2 / TOMs)
    Verweis auf TOMs gemäß Art. 32 DSGVO und § 64 BDSG; siehe §5 dieses Dokuments.

§ 4 Berichtigung, Löschung und Sperrung
    Verfahren zur Bearbeitung von Betroffenenanfragen (Art. 12–22 DSGVO).

§ 5 Unterauftragsverhältnisse
    Liste in Anlage 3. Änderungen erfordern Zustimmung des Auftraggebers.

§ 6 Mitwirkung des Auftraggebers
    Verantwortlich für die rechtliche Zulässigkeit der Verarbeitung und
    Wahrung der Betroffenenrechte.

§ 7 Mitwirkungspflichten des Auftragnehmers
    Mitwirkung an DSGVO Art. 32–36, Meldepflicht innerhalb von 24 Stunden bei
    Kenntnis von Verstößen.

§ 8 Kontrollrechte und Audits
    Audit-Recht des Auftraggebers; alternativ Anerkennung von Zertifizierungen
    (ISO 27001, C5).

§ 9 Vertraulichkeit
    Mitarbeiter des Auftragnehmers verpflichtet zur Vertraulichkeit
    (§ 53 BDSG) und ggf. zur Verschwiegenheit nach § 203 StGB.

§ 10 Beendigung
    Rückgabe oder Löschung aller Daten nach Vertragsende; Bestätigung in
    Textform.

§ 11 Haftung
    Haftungsregelung gemäß Art. 82 DSGVO.

§ 12 Sonstiges
    Gerichtsstand: [Sitz Auftraggeber]. Anwendbares Recht: deutsches Recht.

Anlage 1 — Beschreibung der Verarbeitung
Anlage 2 — TOMs gemäß § 64 BDSG / Art. 32 DSGVO
Anlage 3 — Liste der Unterauftragnehmer

AV-Vertrag muss vor Verarbeitung unterzeichnet sein

Per Art. 28(3) GDPR the processor contract must be in place before the processor begins to process personal data. Any verbal arrangement is non-compliant.

7. Joint-controller arrangement (Art. 26 GDPR) — multi-site clinical research

In a multi-site research configuration where, for example, LABIS UCA collaborates with a German university hospital on a postural-assessment study, GDPR Art. 26 may apply.

7.1 When are LABIS UCA and the German site joint controllers?

Per Art. 26(1) GDPR, two or more controllers are joint when they jointly determine the purposes and means of processing. EDPB Guidelines 07/2020 clarify that "jointly" requires either common decisions on essential elements (purposes and means) or converging decisions that complement each other.

For a multi-site research protocol with shared research questions and shared analysis pipeline, joint controllership is likely, but the specific allocation depends on the protocol. The fact pattern needs case-by-case analysis with the German DPO and the LABIS UCA Argentina DPO.

7.2 Joint-controller agreement contents

The Art. 26(1) agreement must determine respective responsibilities, particularly with regard to:

  • Exercising data-subject rights (who handles a Subject Access Request).
  • Information duties under Art. 13/14 (who provides the privacy notice).
  • Notification of breaches.
  • Maintenance of records of processing.

Per Art. 26(2), the essence of the agreement shall be made available to the data subject.

7.3 Joint-controller agreement skeleton

Joint Controller Agreement under Art. 26 GDPR
between
  LABIS UCA — Universidad Católica Argentina
and
  [German Klinikum or University Hospital]

1. Scope and purpose
   Joint processing of patient photographic records and derived clinical
   metrics for the EPPA multi-site postural-assessment study, in accordance
   with the protocol [TBD reference].

2. Determination of purposes and means
   Both parties jointly determine the research questions; protocol-defined
   capture procedure; central analysis kernel hosted by LABIS UCA.

3. Allocation of responsibilities under Art. 26(1)
   (a) Information duties (Art. 13/14) — each party towards its own enrolled
       patients.
   (b) Data-subject rights — each party for its own enrolled patients,
       with mutual cooperation.
   (c) Security incidents — coordinated response; each party towards its
       own supervisory authority; lead notification by the party in whose
       systems the incident occurred.
   (d) Records of processing — each party maintains its own.

4. Lawful basis
   Art. 9(2)(j) GDPR + § 22(1)(2)(c) BDSG for the German site;
   Art. 9(2)(j) GDPR + § 22(1)(2)(c) BDSG (or applicable AR basis for
   LABIS UCA's patients).

5. Data transfers
   AR → DE via the EU Argentina adequacy decision (Commission Decision
   2003/490/EC).

6. Public-facing summary
   The essence of this agreement is published at [URL TBD] in accordance
   with Art. 26(2).

8. Hospital deployments — state Krankenhausgesetz layer

Each German federal state (Land) has its own Krankenhausgesetz (KHG) that may regulate processing of patient data within hospitals. A non-exhaustive list:

  • Bayern — BayKrG, with patient-data provisions in Art. 27 BayKrG.
  • Nordrhein-Westfalen — KHGG NRW.
  • Berlin — LKG Bln.

For a hospital deployment, the state KHG layer must be reviewed in addition to BDSG. This is typically the responsibility of the hospital DPO.

9. § 203 StGB — Professional secrecy

§ 203 of the German Criminal Code criminalises unauthorised disclosure of secrets entrusted to a professional, including doctors and persons auxiliary to medical practice. § 203(4) extends to persons engaged in "data-processing tasks" who become aware of the secrets in that capacity — this includes IT vendors processing patient data.

Practical consequence for EPPA: any LABIS UCA personnel processing German patient data may fall within § 203(4) StGB. The AV-Vertrag must:

  • Bind the processor's personnel to § 203 confidentiality.
  • Provide a clear training procedure on § 203 obligations.
  • Document the chain of confidentiality through any subprocessors.

This is more stringent than the Art. 28 GDPR confidentiality obligation — § 203 is criminal law.

10. TTDSG and cookies (peripheral but relevant)

For EPPA's marketing site and authenticated app, the Gesetz über den Datenschutz und den Schutz der Privatsphäre in der Telekommunikation und bei Telemedien (TTDSG) — in force since December 2021 — governs cookies and similar technologies. TTDSG § 25 implements ePrivacy Art. 5(3): no storage of or access to information in the user's terminal equipment without consent, except for strictly necessary purposes.

EPPA's session cookie is strictly necessary for the app's functioning and does not require consent. Any analytics or marketing cookies on the marketing site require consent.

11. Cross-references

Topic Reference
Base GDPR DPIA 30-gdpr-dpia.md
EU MDR classification (BfArM is the German competent authority for Class IIa) 10-eu-mdr-saMD-classification.md
Security checklist (OWASP ASVS L2 mapping informs TOMs) 50-secdev-checklist.md
MPDG (German MDR implementation) 00-overview.md §2 row "DE (BfArM)"

12. Open questions

  1. Confirm DPO sourcing model. Internal hire vs external Dienstleister.
  2. Confirm joint-controller agreement counterparties. Depends on actual German research sites.
  3. Confirm § 203 StGB binding mechanism. Per-person Verpflichtungserklärung.
  4. Confirm hospital state-law overlay. Per deployment.
  5. Confirm BfArM UDI registration prerequisites.

References