Ailance Alt TM Logo

Annual data protection conference

Data protection conference

Association for Data Protection and Data Security (GDD) e.V.

On November 18, 2021, the annual Data Protection Conference (45th DAFTA) of the Society for Data protection and Data security (GDD) e.V. took place.

This year, the symposium, which was once again held digitally due to the pandemic, once again impressed with its diverse selection of topics and thus provided added value for all participants in the office, Home office or to the sofa at home.

Even in its digital format, DAFTA featured a large number of participants and speakers from the „Who’s Who“ of the data protection world, who shared their insights on the most pressing data protection issues of the day:

The DAFTA was characterized by three current and practice-relevant topics. The new Telecommunications Telemedia Data Protection Act (TTDSG), which came into force on 01.12.2021, was a topic that played just as big a role on the agenda as the ongoing implementation issues regarding the "Schrems II" decision of the ECJ. Another topic at this year's DAFTA was the developments in connection with claims for damages under data protection law in accordance with Art. 82 GDPR.

About the history of its development, key new provisions of the TTDSG, and the fact that it applies not only to telecommunications providers but to virtually every company or public agency is affected by the implementation of the TTDSG, Rolf Bender from the BMWi informed the participants.

On Implementation Issues Related to the SchremsDr. Stefan Brink of the LfDI Baden-Württemberg commented on the -II decision. Brink described a new agreement between the EU and the U.S. as the only viable solution to the challenges posed by Schrems-II, since the business community could not afford transfer impact assessments. This is because the requirement for supplementary reviews and measures in connection with data exports no longer applies—as is well known, even after the publication of the new EU—Standard contractual clauses – No.  

In an engaging presentation, Steffen Weiß, GDD, also demonstrated to the participants that, in countries with data protection laws, there are generally a multitude of data transfer restrictions that must be observed, and that companies are therefore required to enter into agreements or to organize and secure their data flows and data exports accordingly at an early stage.

It was also debated whether compensation for damages due to a GDPR breach must exceed a materiality threshold. However, it was clarified that the GDPR does not have such a threshold. The question of a so-called materiality threshold for GDPR claims for damages will nevertheless only be conclusively clarified by the ECJ, as this question has been referred to the ECJ for a decision (decision of January 14, 2021, 1 BvR 2853/19). In general, however, the following still applies Affected parties must provide reliable evidence of the damage (burden of proof).

Clemens Dörner of 2B Advice GmbH also gave a presentation at the Vendor Forum on the topic of Transfer Impact Assessment, in which he outlined to the audience—from 2B Advice’s perspective—the key factors for how Responsible persons can reduce their data protection risk and thus the risk of data protection breaches when using new technologies. A risk arises in particular when companies integrate technologies into the Cloud migrate or use new technologies such as Video Surveillance introduce. He pointed out that companies must conduct an appropriate data protection risk assessment when implementing new technologies. Among other things, participants were shown when a risk assessment should be conducted and which types of risk assessments are suitable for different scenarios (e.g., PIA, CMIA, DTIA, or DSFA).

The 45th DAFTA thus demonstrated to its participants that the uncertainties surrounding case law, data protection oversight, and the legislature pose significant economic challenges for companies.

As became clear toward the end of the DAFTA, in the future, in addition to data protection law, the IT Security Act—which currently applies only to critical infrastructure—will increasingly become one of the challenges facing companies.  To mitigate these challenges and turn them into opportunities for competitive advantage, companies must therefore professionalize their data protection and information security practices in the areas of technology, organization, strategy, and legal affairs.

As a trusted partner, we are happy to support you in professionalizing your data protection efforts. We’re already looking forward to the next DAFTA—hopefully we’ll see you there in person again soon.

Picture of Marcus Belke

Marcus Belke

Marcus Belke is the CEO of 2B Advice GmbH. He drives innovation in data protection compliance and risk management and is responsible for the further development of Ailance, the next-generation compliance platform.

Share this post:

Annual data protection conference