Auteur
Paul Voigt

Dr. Paul Voigt, Lic. en Derecho, CIPP/E

Associé

Read More
Auteur
Paul Voigt

Dr. Paul Voigt, Lic. en Derecho, CIPP/E

Associé

Read More

7 mars 2023

Information Security Considerations (Germany)

  • In-depth analysis

A Practice Note describing the laws, regulations, enforcement practices, and local resources to consider when developing, implementing, and maintaining an information security program in Germany or as applied to data originating from Germany. It discusses the Federal Data Protection Act (BDSG) and critical infrastructure provider obligations under the IT Security Act and IT Security Act 2.0. It addresses related EU law, such as the EU General Data Protection Regulation (Regulation (EU) 2016/679) (GDPR), the EU Directive on the Security of Network and Information Systems (Directive 2016/1148/EC) (NIS Directive), and Germany's implementing laws. It also discusses Federal Office for Information Security (BSI) regulations, standards, and resources. Finally, the Practice Note also addresses the requirements in light of recent legislative developments such as the NIS 2 Directive (Directive (EU) 2022/2555) and the DORA Regulation (Regulation (EU) 2022/2554). The Germany-specific guidance in this Note may be used with the generally applicable resources listed in the Global Information Security Toolkit.

Download the entire article (pdf)

Reproduced from Thomson Reuters Practical Law with the permission of the publishers. For further information, visit the Global Home page at uk.practicallaw.thomsonreuters.com

Call To Action Arrow Image

Latest insights in your inbox

Subscribe to newsletters on topics relevant to you.

Subscribe
Subscribe

Related Insights

Protection des données et cybersécurité

China: A practical insight into China SCCs and their impact on businesses

Michael Tan, Julian Sun, Paul Voigt and Wiebke Reuter look at what China's new SCCs mean for businesses looking to export personal data from China to the EU.

24 avril 2023
In-depth analysis

par plusieurs auteurs

Cliquer ici pour en savoir plus
Protection des données et cybersécurité

Cyber Incident Response and Data Breach Notification (Germany)

8 mars 2023
In-depth analysis

par Dr. Paul Voigt, Lic. en Derecho, CIPP/E

Cliquer ici pour en savoir plus
Technologie, Médias et Communications (TMC)

The EU-U.S. Data Privacy Framework (DPF) is coming

21 décembre 2022
In-depth analysis

par plusieurs auteurs

Cliquer ici pour en savoir plus