T 2.167 Lack of or inadequate prior checking
If processing personal data is characterised by specific risks for the rights and freedoms of the persons concerned, e.g. the processing of specific types of data (information about racial or ethnic origin, political beliefs, religious or philosophical beliefs, trade union membership, health, or sex life) or if the personal data is to be used to assess the personality of the person concerned, including his/her skills, performance, or behaviour, a prior check must be performed before starting processing (§ 4d Para. 5 BDSG). However, this is not applicable if a statutory obligation or a consent of the person concerned is present or if the collection, processing, or use serves for the purposes of a contractual relationship or quasi-contractual trust relationship with the person concerned. Some state data protection acts specify general prior checks for all procedures used by public agencies in order to process personal data. The prerequisites for the aforementioned may deviate from the regulations specified by the Federal Government.
If a specified prior check is not implemented at all or only insufficiently, this may cause risks for the informational right of self-determination.
Examples:
- If data processing systems used to process personal data can be used by unauthorised persons, for example because they can gain access to the system and its data due to insufficient protection safeguards and gain knowledge of data this way, this may cause specific risks for the rights and freedoms of the persons concerned.
- The confidentiality and integrity of the data may be violated during processing and/or data transmission if the data is protected inadequately (e.g. by encryption).
- Personal data processed on behalf of a third party may be processed by the contractor to a far greater extent than specified within the contract causing damage to the persons concerned.
- Personal data may be processed avoiding the limit of use and may be connected inadmissibly to the disadvantage of the persons concerned.