S 2.245 Determination of the legal influencing factors for electronic archiving

Initiation responsibility: IT Security Officer

Implementation responsibility: Archive Administrator, IT Security Officer

There are different legal requirements for the retention of certain information, the non-compliance of which may have consequences under civil or criminal law. Therefore, the persons in charge should obtain information as to the legal requirements applicable in their case. This will identify the requirements for the design of the archiving concept that must be taken into consideration when planning electronic archiving. Amongst other things, these refer to:

The applicable basic legal principles must be clarified on a case-by-case basis.

Some sources typically to be taken into consideration in Germany are mentioned below:

Furthermore, there are laws and regulations to be observed specifically in government agencies and in the administration, for example:

Moreover, numerous further legal and organisation-internal regulations (e.g. regulations for social insurance carriers, hospitals, pharmaceutical industry, military, or banking) to be determined on a case-by-case basis are applicable specifically to each organisation. Normally, the retention period and the confidentiality and integrity requirements constitute essential regulation criteria, with the latter also including the period of protection requirement along with the intensity.

Furthermore, the public administration is subject to the statutory obligation of also offering digital documents to the competent archives (duty to offer).

Review questions: