Verordnungen - Gesetze

Digital Markets Act (DMA)

The Digital Markets Act (DMA) is a regulation of the European Union that is intended to ensure greater fairness and competition in digital markets. It is primarily aimed at large online platforms that have a particularly strong market position.

Objectives of the DMA

Create fairer competitive conditions for companies, provide consumers with more choices, and prevent large platforms from abusing their market power.

What does this mean for users?

  • More control over personal data
  • Easier switching between digital services
  • Greater transparency on online platforms

Note

The DMA applies to certain large platform providers in the European Union. Violations of the regulations can result in significant sanctions.

Digital Services Act (DSA)

The Digital Services Act (DSA) is a regulation of the European Union that aims to improve the transparency and safety of online services. It applies to online platforms, marketplaces, social networks, and other digital intermediary services within the EU.

In brief

The Digital Services Act creates a regulated and uniform framework for digital services within the European Union.

The aim is to promote a safer, more transparent, and more trustworthy digital environment while strengthening the rights of users and ensuring fair competitive conditions for companies.

Objectives of the DSA

Better protection of users online, faster removal and/or blocking of illegal content, greater transparency regarding advertising and recommendation algorithms, stronger accountability requirements for large online platforms, and improved protection of fundamental rights and consumers.

Benefits for users

The DSA strengthens the rights of users through:

  • greater transparency regarding recommendation and ranking mechanisms,
  • simplified procedures for reporting illegal content,
  • better traceability of personalized advertising, and
  • effective complaint and legal remedy procedures regarding moderation decisions.

Obligations for companies

Providers of digital services are required, among other things, to:

  • provide effective procedures for handling reports of illegal content,
  • assess potential risks to users and implement appropriate measures to reduce those risks,
  • formulate terms and conditions clearly, transparently, and above all understandably,
  • comply with additional regulatory requirements if they operate particularly large platforms.

e-Privacy

What does e-Privacy mean?

e-Privacy is a general framework for regulating the protection of electronic communications within the EU. The e-Privacy Directive has existed since 2002, while the planned e-Privacy Regulation is intended to replace the current directive. It is intended to protect electronic communications and regulate the processing of communication data as well as the storage of and access to information on end devices.

e-Privacy Directive:

The e-Privacy Directive regulates data protection in electronic communications and must therefore be implemented by the European Member States, as the directive applies throughout the EU. It regulates the processing of private data and the storage of information on end devices and also covers the confidentiality of telecommunications.

e-Privacy Regulation:

The planned regulation is intended to replace the current directive. Its purpose is to further strengthen and protect data privacy in electronic communications so that private and/or sensitive data continue to be protected and receive even stronger protection. The new regulation is also intended to apply directly in all EU Member States and therefore ensure comprehensive and uniform application and protection of data privacy.

Objectives of e-Privacy:

The upcoming e-Privacy Regulation is intended to provide even greater protection for the privacy of citizens in EU Member States in electronic communications, particularly with regard to the use of cookies, tracking, and advertising. It is also intended to strengthen rights relating to the processing of personal data.

Scope of application:

The e-Privacy Directive, and subsequently the e-Privacy Regulation, apply throughout the EU and, under certain conditions, also to companies outside the EU if they offer services or similar activities within the EU. Therefore, the company's headquarters do not necessarily have to be located within the EU.

GDPR

What is the GDPR?

The GDPR stands for the General Data Protection Regulation and has been in force since May 25, 2018. It regulates and protects personal and personally identifiable data within the EU.

1. Lawfulness:

Personal data may only be processed if there is a clear and legal basis for doing so, such as a contract, consent, authorization, or similar legal basis.

Without a clear legal basis and your consent, your data may not simply be stored, used, processed, or even published.

2. Information and Transparency:

You must always be informed about why your data is being used, which data is being used, and where it has been or is being used.

3. Your Rights:

  • Right to access information
  • Right to rectification, e.g. in the case of incorrect data or information
  • Right to erasure
  • Right to object to certain types of processing

Every person, whether a child, teenager, or adult, has the right to request information, and the relevant organization is required to provide it.

This means that you have the right to receive information and also the right to have statements or information corrected, or even deleted.

For example:

The press publishes false information or data about you publicly.

You then have the right to receive information about this and, where applicable, have the information or data corrected or even deleted.

4. Data Protection and Security by Design:

Responsible persons, organizations, or similar entities must take appropriate organizational and technical measures to ensure data protection. They are required to protect your data comprehensively and may therefore not simply pass it on to “third parties.”

5. Notification Requirement in the Event of Data Protection Breaches:

Data breaches must be reported to the relevant data protection authority within 72 hours.

The competent supervisory authority should be identified in the legal notice and always provided there.

6. Penalties and Fines:

Violations can result in substantial fines or other penalties as sanctions against the relevant individuals, companies, or organizations.

Does the GDPR also apply to companies outside the European Union?

Yes! If the data of individuals in the EU is processed, the GDPR can also apply to companies outside the EU, subject to certain conditions. For example, if a company offers goods and/or services within the EU, it may be subject to the GDPR regardless of where its headquarters are located.

Does the GDPR apply to private individuals?

Not necessarily. If you use personal data exclusively for personal and/or family purposes, the GDPR generally does not apply to you. This is known as the “household exemption.”

For example, this applies when you keep your own contact list on your phone, take photos at family celebrations, or send emails to friends, acquaintances, or family members. In these cases, private individuals are generally excluded from the GDPR.

When does the GDPR apply to private individuals?

It applies as soon as you stop using the data exclusively for your own and/or private purposes.

For example, if you publicly collect contact details through a contact form, run a public blog or publish articles through your social media account, or manage personal data through an association, the GDPR applies. In such cases, the same obligations generally apply as to companies.

(Provide a privacy policy, obtain consent where required, secure data, and comply with rights and legal requirements.)

What exactly is personal data?

Personal data includes your full name, address, date of birth, email address(es), telephone number(s), location data, photos showing recognizable faces, and also your IP address.

State Data Protection Act

What is the State Data Protection Act?

The State Data Protection Act (LDSG) is a law of an individual German federal state that regulates data protection for public authorities and, in certain cases, for private companies.

It applies within the respective federal state.

It supplements and defines the requirements of the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG).

Purpose:

The State Data Protection Act (LDSG) supplements the Federal Data Protection Act (BDSG) and the General Data Protection Regulation (GDPR). It serves to implement and put the GDPR and BDSG into practice in the respective German federal states.

It therefore regulates data protection for public authorities and, under certain conditions, for private companies within the federal state and establishes requirements to ensure that data protection is implemented correctly.

Scope of Application:

The LDSG applies to authorities, institutions, organizations, and other public bodies within the respective federal state.

Regulations:

The LDSG regulates the collection, processing, and use of personal data, the rights of data subjects, the responsibilities of state data protection authorities, and sanctions for violations.

Differences between the GDPR and BDSG:

The GDPR is a European law that regulates data protection for individuals in the EU.

The BDSG is a German law that supplements the GDPR and therefore applies at the national level.

The GDPR is considerably more comprehensive and applies to companies and organizations that process the personal data of individuals in the EU, while the BDSG applies specifically in Germany and contains additional rules for German authorities and companies.

Federal Data Protection Act

What is the Federal Data Protection Act?

The Federal Data Protection Act (BDSG) is a German law that regulates the protection of personal data. It regulates the handling of personal data in relation to companies, authorities, and organizations and establishes requirements for how such data must be handled. It forms an important foundation for data protection in Germany.

Regulation of the Handling of Personal Data:

The Federal Data Protection Act establishes the conditions under which personal data may be collected, stored, processed, or transferred. This is an important point because personal data may not simply be used or stored without a legal basis.

Protection of Personal Data:

The BDSG serves to protect against the misuse of personal and private data and therefore supports the right to self-determination.

Data Protection Officer:

Companies or organizations that generally employ at least 10 people who are involved in the electronic or automated processing of personal data are required, under the stated conditions, to appoint a data protection officer. This person is responsible for implementation, compliance, and monitoring and also serves as a contact person for the public.

Application of the BDSG:

The BDSG applies to companies, authorities, organizations, and also private individuals who process personal data. It regulates the handling of data in information and communication networks.

It is an important law that ensures the protection of private and personal data in Germany and therefore also serves to protect against misuse.

More Articles