Germany BDSG Specifics on Top of GDPR — EPPA¶
BDSG layers on top of GDPR — both must be satisfied
For deployments in Germany, GDPR (Regulation (EU) 2016/679) sets the
baseline and the BDSG ("Bundesdatenschutzgesetz" of 2018, as amended)
layers Germany-specific rules on top, often stricter. The GDPR DPIA in
30-gdpr-dpia.md is the primary instrument; this
document records BDSG-specific deltas that EPPA must satisfy in a German
deployment.
1. Document identity¶
| Field | Value |
|---|---|
| Document title | Germany BDSG Specifics — EPPA |
| Document ID | EPPA-DE-BDSG-001 |
| Version | 0.1 (draft) |
| Status | Draft — not approved |
| Effective date | n/a |
| Owner | LABIS UCA — Germany Privacy lead (to be appointed) |
| Linked documents | 00-overview.md, 30-gdpr-dpia.md, 50-secdev-checklist.md |
2. Regulatory anchors¶
- Regulation (EU) 2016/679 — GDPR.
- Bundesdatenschutzgesetz ("BDSG") of 30 June 2017, in force since 25 May 2018, as amended.
- Medizinprodukterecht-Durchführungsgesetz (MPDG) — German implementing law for EU MDR.
- Patientenrechtegesetz (BGB §§ 630a–630h) — patient-rights provisions including § 630f (documentation of treatment).
- State-specific Krankenhausgesetze (KHG) — for hospital deployments, state hospital laws layer additional obligations.
- BSI IT-Grundschutz — German Federal Office for Information Security baseline-protection methodology (referenced by § 8 BSI-Gesetz).
- TKG / TMG — telecommunications and telemedia laws (e.g. cookie-rule framework after Cookie-OWiG).
3. § 22 BDSG — Processing of special categories of personal data¶
§ 22 BDSG implements GDPR Art. 9(2)(b), (g), (h), (i) and (j) for German law. It permits processing of special-category data (including health) by non-public bodies in defined cases.
3.1 § 22(1)(1)(b) BDSG — for healthcare and social-care purposes¶
The processing of special categories of personal data … is permitted if processing is necessary for the purposes of preventive medicine, the assessment of the working capacity of the employee, medical diagnosis, the provision of healthcare or treatment, or the management of healthcare or social-care systems and services, by employees subject to the obligation of secrecy under § 203 of the Criminal Code (StGB), or under their responsibility.
For EPPA in a treating-clinician deployment, § 22(1)(1)(b) provides the domestic basis for Art. 9(2)(h) GDPR.
3.2 § 22(1)(2)(c) BDSG — for scientific research purposes¶
The processing of special categories of personal data is also permitted if it is necessary for scientific or historical research purposes or for statistical purposes; the interest of the controller in the processing substantially outweighs the data subject's interest in excluding processing, and the controller takes appropriate and specific measures to safeguard the interests of the data subject.
For EPPA in a research-use deployment, § 22(1)(2)(c) provides the domestic basis for Art. 9(2)(j) GDPR.
3.3 § 22(2) BDSG — appropriate safeguards¶
Specific safeguards required (non-exhaustive):
- Technical and organisational measures.
- Measures to ensure that it is subsequently possible to verify and establish whether and by whom personal data were inputted, altered or removed.
- Measures to increase the awareness of staff involved in processing.
- Designation of a data-protection officer.
- Restrictions on access to personal data within the controller and the processor.
- Pseudonymisation of personal data.
- Encryption.
- Securing of the ability to ensure confidentiality, integrity, availability and resilience.
- Ability to restore the availability of and access to personal data.
- A process for regularly testing, assessing and evaluating the effectiveness of measures.
- Specific rules of procedure to ensure compliance with this Act and the GDPR in the event of a transfer or processing for other purposes.
These map to the TOMs (technische und organisatorische Maßnahmen) detailed in §6 below.
4. § 38 BDSG — DPO mandate¶
GDPR Art. 37 requires a DPO when the core activities consist of processing on a large scale of special categories of data. § 38 BDSG additionally requires a DPO for non-public bodies under either of these German-specific triggers:
- § 38(1) sentence 1 BDSG — the controller / processor as a rule permanently employs at least 20 people dealing with the automated processing of personal data. (Note: the threshold was raised from 10 to 20 by the "Drittes Gesetz zur Änderung des BDSG", in force since 26 November 2019.)
- § 38(1) sentence 2 BDSG — irrespective of the number of persons engaged, the controller / processor performs processing subject to a DPIA under GDPR Art. 35 (special-category data, systematic monitoring, etc.) or commercially processes personal data for the purpose of transfer, for the purpose of anonymised transfer or for purposes of market or opinion research.
EPPA processes special-category health data → DPIA is mandatory under
Art. 35(3)(b) GDPR (see 30-gdpr-dpia.md) → DPO is
mandatory for any German deployment irrespective of headcount, per
§ 38(1) sentence 2.
4.1 DPO requirements (Art. 38, Art. 39 GDPR + § 38(2) BDSG)¶
- Appointed in writing.
- Contact details published and communicated to the supervisory authority.
- Independent — no instructions on the exercise of the role.
- Cannot be dismissed for the performance of the role.
- Has resources to perform the role.
- May be an employee or external (Dienstleister).
5. § 64 BDSG — Technical and organisational measures (TOMs)¶
§ 64 BDSG applies to processing for the purposes of Part 3 of the BDSG (prevention, investigation, detection, prosecution of criminal offences and threats to public security) — not directly applicable to EPPA.
However, the TOM list in § 64 (modeled on Art. 32 GDPR plus additional items) is the de facto German market standard for AV-Vertrag annexes (processor contracts). The TOM categories are:
| § 64 BDSG measure | EPPA mapping |
|---|---|
| Zugangskontrolle (access control to systems) | RBAC (Epic E3); MFA |
| Zugriffskontrolle (access control to data) | Database-level RBAC; row-level security per clinic |
| Weitergabekontrolle (transmission control) | TLS 1.3; signed pre-signed URLs |
| Eingabekontrolle (input control) | AuditLog (Epic E3) records who created/modified each record |
| Auftragskontrolle (job control) | Processor contracts (AV-Verträge) with hosting provider |
| Verfügbarkeitskontrolle (availability control) | Daily backups, 90-day retention, quarterly restore drill |
| Trennungskontrolle (separation control) | Per-tenant organization_id scoping; separate environments dev / staging / prod |
| Pseudonymisierung | Patient UUID; mapping stored separately |
| Verschlüsselung | TLS 1.3 in transit; pgcrypto for Patient.full_name (Epic E3) |
| Wiederherstellbarkeit | Documented restore procedure; RTO 4h, RPO 24h |
| Regelmäßige Überprüfung | Quarterly tabletop; annual penetration test |
| Datenschutz durch Technikgestaltung (Privacy by Design) | OWASP ASVS L2 alignment in 50-secdev-checklist.md |
6. Processor contract (Auftragsverarbeitung, AV-Vertrag) template¶
Required content per Art. 28(3) GDPR with German market additions. Skeleton sections (full text via legal review):
Vereinbarung zur Auftragsverarbeitung (AV-Vertrag)
zwischen
[Verantwortlicher = treating clinic or LABIS UCA] ("Auftraggeber")
und
[Auftragsverarbeiter = hosting provider / SMTP / backup] ("Auftragnehmer")
§ 1 Gegenstand, Dauer und Spezifizierung
Beschreibung des Auftrags: Hosting + Verarbeitung von patientenbezogenen
Aufnahmen und abgeleiteten klinischen Metriken für die postural-
fotografische Auswertung (EPPA).
Dauer: solange Auftraggeber EPPA betreibt.
Verarbeitungstätigkeiten: siehe Anlage 1.
§ 2 Verarbeitete Daten und betroffene Personenkreise
Daten: Patientendaten (Identifikator, Aufnahmen, klinische Metriken).
Personen: Patienten, klinisches Personal.
§ 3 Technische und organisatorische Maßnahmen (Anlage 2 / TOMs)
Verweis auf TOMs gemäß Art. 32 DSGVO und § 64 BDSG; siehe §5 dieses Dokuments.
§ 4 Berichtigung, Löschung und Sperrung
Verfahren zur Bearbeitung von Betroffenenanfragen (Art. 12–22 DSGVO).
§ 5 Unterauftragsverhältnisse
Liste in Anlage 3. Änderungen erfordern Zustimmung des Auftraggebers.
§ 6 Mitwirkung des Auftraggebers
Verantwortlich für die rechtliche Zulässigkeit der Verarbeitung und
Wahrung der Betroffenenrechte.
§ 7 Mitwirkungspflichten des Auftragnehmers
Mitwirkung an DSGVO Art. 32–36, Meldepflicht innerhalb von 24 Stunden bei
Kenntnis von Verstößen.
§ 8 Kontrollrechte und Audits
Audit-Recht des Auftraggebers; alternativ Anerkennung von Zertifizierungen
(ISO 27001, C5).
§ 9 Vertraulichkeit
Mitarbeiter des Auftragnehmers verpflichtet zur Vertraulichkeit
(§ 53 BDSG) und ggf. zur Verschwiegenheit nach § 203 StGB.
§ 10 Beendigung
Rückgabe oder Löschung aller Daten nach Vertragsende; Bestätigung in
Textform.
§ 11 Haftung
Haftungsregelung gemäß Art. 82 DSGVO.
§ 12 Sonstiges
Gerichtsstand: [Sitz Auftraggeber]. Anwendbares Recht: deutsches Recht.
Anlage 1 — Beschreibung der Verarbeitung
Anlage 2 — TOMs gemäß § 64 BDSG / Art. 32 DSGVO
Anlage 3 — Liste der Unterauftragnehmer
AV-Vertrag muss vor Verarbeitung unterzeichnet sein
Per Art. 28(3) GDPR the processor contract must be in place before the processor begins to process personal data. Any verbal arrangement is non-compliant.
7. Joint-controller arrangement (Art. 26 GDPR) — multi-site clinical research¶
In a multi-site research configuration where, for example, LABIS UCA collaborates with a German university hospital on a postural-assessment study, GDPR Art. 26 may apply.
7.1 When are LABIS UCA and the German site joint controllers?¶
Per Art. 26(1) GDPR, two or more controllers are joint when they jointly determine the purposes and means of processing. EDPB Guidelines 07/2020 clarify that "jointly" requires either common decisions on essential elements (purposes and means) or converging decisions that complement each other.
For a multi-site research protocol with shared research questions and shared analysis pipeline, joint controllership is likely, but the specific allocation depends on the protocol. The fact pattern needs case-by-case analysis with the German DPO and the LABIS UCA Argentina DPO.
7.2 Joint-controller agreement contents¶
The Art. 26(1) agreement must determine respective responsibilities, particularly with regard to:
- Exercising data-subject rights (who handles a Subject Access Request).
- Information duties under Art. 13/14 (who provides the privacy notice).
- Notification of breaches.
- Maintenance of records of processing.
Per Art. 26(2), the essence of the agreement shall be made available to the data subject.
7.3 Joint-controller agreement skeleton¶
Joint Controller Agreement under Art. 26 GDPR
between
LABIS UCA — Universidad Católica Argentina
and
[German Klinikum or University Hospital]
1. Scope and purpose
Joint processing of patient photographic records and derived clinical
metrics for the EPPA multi-site postural-assessment study, in accordance
with the protocol [TBD reference].
2. Determination of purposes and means
Both parties jointly determine the research questions; protocol-defined
capture procedure; central analysis kernel hosted by LABIS UCA.
3. Allocation of responsibilities under Art. 26(1)
(a) Information duties (Art. 13/14) — each party towards its own enrolled
patients.
(b) Data-subject rights — each party for its own enrolled patients,
with mutual cooperation.
(c) Security incidents — coordinated response; each party towards its
own supervisory authority; lead notification by the party in whose
systems the incident occurred.
(d) Records of processing — each party maintains its own.
4. Lawful basis
Art. 9(2)(j) GDPR + § 22(1)(2)(c) BDSG for the German site;
Art. 9(2)(j) GDPR + § 22(1)(2)(c) BDSG (or applicable AR basis for
LABIS UCA's patients).
5. Data transfers
AR → DE via the EU Argentina adequacy decision (Commission Decision
2003/490/EC).
6. Public-facing summary
The essence of this agreement is published at [URL TBD] in accordance
with Art. 26(2).
8. Hospital deployments — state Krankenhausgesetz layer¶
Each German federal state (Land) has its own Krankenhausgesetz (KHG) that may regulate processing of patient data within hospitals. A non-exhaustive list:
- Bayern — BayKrG, with patient-data provisions in Art. 27 BayKrG.
- Nordrhein-Westfalen — KHGG NRW.
- Berlin — LKG Bln.
For a hospital deployment, the state KHG layer must be reviewed in addition to BDSG. This is typically the responsibility of the hospital DPO.
9. § 203 StGB — Professional secrecy¶
§ 203 of the German Criminal Code criminalises unauthorised disclosure of secrets entrusted to a professional, including doctors and persons auxiliary to medical practice. § 203(4) extends to persons engaged in "data-processing tasks" who become aware of the secrets in that capacity — this includes IT vendors processing patient data.
Practical consequence for EPPA: any LABIS UCA personnel processing German patient data may fall within § 203(4) StGB. The AV-Vertrag must:
- Bind the processor's personnel to § 203 confidentiality.
- Provide a clear training procedure on § 203 obligations.
- Document the chain of confidentiality through any subprocessors.
This is more stringent than the Art. 28 GDPR confidentiality obligation — § 203 is criminal law.
10. TTDSG and cookies (peripheral but relevant)¶
For EPPA's marketing site and authenticated app, the Gesetz über den Datenschutz und den Schutz der Privatsphäre in der Telekommunikation und bei Telemedien (TTDSG) — in force since December 2021 — governs cookies and similar technologies. TTDSG § 25 implements ePrivacy Art. 5(3): no storage of or access to information in the user's terminal equipment without consent, except for strictly necessary purposes.
EPPA's session cookie is strictly necessary for the app's functioning and does not require consent. Any analytics or marketing cookies on the marketing site require consent.
11. Cross-references¶
| Topic | Reference |
|---|---|
| Base GDPR DPIA | 30-gdpr-dpia.md |
| EU MDR classification (BfArM is the German competent authority for Class IIa) | 10-eu-mdr-saMD-classification.md |
| Security checklist (OWASP ASVS L2 mapping informs TOMs) | 50-secdev-checklist.md |
| MPDG (German MDR implementation) | 00-overview.md §2 row "DE (BfArM)" |
12. Open questions¶
- Confirm DPO sourcing model. Internal hire vs external Dienstleister.
- Confirm joint-controller agreement counterparties. Depends on actual German research sites.
- Confirm § 203 StGB binding mechanism. Per-person Verpflichtungserklärung.
- Confirm hospital state-law overlay. Per deployment.
- Confirm BfArM UDI registration prerequisites.
References¶
- Regulation (EU) 2016/679 (GDPR) — https://eur-lex.europa.eu/eli/reg/2016/679/oj
- Bundesdatenschutzgesetz (BDSG) — https://www.gesetze-im-internet.de/bdsg_2018/
- BDSG § 22 (special categories) — https://www.gesetze-im-internet.de/bdsg_2018/__22.html
- BDSG § 38 (DPO mandate for non-public bodies) — https://www.gesetze-im-internet.de/bdsg_2018/__38.html
- BDSG § 64 (technical and organisational measures) — https://www.gesetze-im-internet.de/bdsg_2018/__64.html
- StGB § 203 (professional secrecy) — https://www.gesetze-im-internet.de/stgb/__203.html
- TTDSG — https://www.gesetze-im-internet.de/ttdsg/
- Medizinprodukterecht-Durchführungsgesetz (MPDG) — https://www.gesetze-im-internet.de/mpdg/
- BfArM — Bundesinstitut für Arzneimittel und Medizinprodukte — https://www.bfarm.de/
- BSI IT-Grundschutz — https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/IT-Grundschutz/it-grundschutz_node.html
- EDPB Guidelines 07/2020 on the concepts of controller and processor — https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-072020-concepts-controller-and-processor-gdpr_en
- Patientenrechtegesetz (BGB §§ 630a–630h) — https://www.gesetze-im-internet.de/bgb/BJNR001950896.html