German Coalition Proposes Drastic Data Protection Reforms, Sparking Criticism
netzpolitik.org
- The German governing coalition (Union and SPD) has proposed a reform package to overhaul data protection, aiming to exempt 99% of German companies from GDPR.
- Proposals include removing SMEs and non-profits from data protection requirements, reducing internal data protection officers, and centralizing oversight under the federal authority (BfDI).
- Experts, civil society, and data protection commissioners criticize these plans, arguing that risk levels should dictate compliance rather than company size.
Key Controversies
- Exemption for SMEs and Non-profits: Covering over 99% of German businesses, critics argue that size does not equate to risk, as small companies can still handle highly sensitive data.
- Reduction of Data Protection Officers: Removing internal experts is seen as a regression that would leave companies without necessary guidance while increasing liability for management.
- Centralization of Oversight: Shifting authority to the BfDI is criticized for weakening localized oversight and potentially making institutions more vulnerable to corporate capture and democratic deficits.
Proposed Alternatives and Criticisms
- Risk-Based Approach: Experts argue that regulations should focus on the actual risk of data processing rather than arbitrary firm-size thresholds.
- Manufacturer Accountability: Data protection commissioners suggest shifting legal responsibility to software manufacturers by requiring "privacy by design" at the product development stage.
- Institutional Reform: Instead of centralization, authorities propose formalizing the Data Protection Conference and adopting an "one-for-all" principle to improve efficiency among existing state authorities while maintaining local expertise.