<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Datenschutzrecht Archive - R&amp;U</title>
	<atom:link href="https://ru.law/en/tag/datenschutzrecht/feed/" rel="self" type="application/rss+xml" />
	<link>https://ru.law/en/tag/datenschutzrecht/</link>
	<description>Consumer lawyers</description>
	<lastbuilddate>Thu, Jul 24, 2025 07:04:23 +0000</lastbuilddate>
	<language>en-GB</language>
	<sy:updateperiod>
	hourly	</sy:updateperiod>
	<sy:updatefrequency>
	1	</sy:updatefrequency>
	<generator>https://wordpress.org/?v=6.8.5</generator>

<image>
	<url>https://ru.law/wp-content/uploads/2020/12/favicon-150x150.png</url>
	<title>Datenschutzrecht Archive - R&amp;U</title>
	<link>https://ru.law/en/tag/datenschutzrecht/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Überwachungskameras am Haus: Was ist erlaubt?</title>
		<link>https://ru.law/en/ueberwachungskameras-am-haus-was-ist-erlaubt/</link>
		
		<dc:creator><![CDATA[ommatic]]></dc:creator>
		<pubdate>Thu, Jul 24, 2025 07:04:21 +0000</pubdate>
				<category><![CDATA[Datenschutzrecht]]></category>
		<category><![CDATA[Datenschutz]]></category>
		<category><![CDATA[Überwachungskamera]]></category>
		<category><![CDATA[Videoüberwachung]]></category>
		<guid ispermalink="false">https://ru.law/?p=90848</guid>

					<description><![CDATA[<p>The use of surveillance cameras on one&#039;s own property is generally permitted, as long as no public areas or neighboring properties are filmed. The cameras may only record one&#039;s own […]</p>
<p>Der Beitrag <a href="https://ru.law/en/ueberwachungskameras-am-haus-was-ist-erlaubt/">Überwachungskameras am Haus: Was ist erlaubt?</a> erschien zuerst auf <a href="https://ru.law/en">R&amp;U</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The use of surveillance cameras on one&#039;s own property is generally permitted, as long as no public areas or neighboring properties are filmed. The cameras may only view one&#039;s own property, and persons entering the property must be informed of the surveillance. In apartment buildings, the surveillance of common areas or other people&#039;s apartments is prohibited.</p>



<p>Dummy cameras are only permitted if they don&#039;t appear deceptively real and don&#039;t monitor unfamiliar areas. Doorbells with camera functionality are permitted if they only transmit images after the doorbell is pressed and if they are not permanently stored.</p>



<p>Recordings may not be stored for longer than 72 hours, and the storage technology used must comply with data protection requirements. Following these rules can help avoid legal problems and fines.</p>



<p>Read more about this in this <a href="https://www.zdfheute.de/ratgeber/ueberwachungskamera-haus-datenschutz-100.html?at_medium=Social%20Media&amp;at_campaign=ZDFheuteApp&amp;at_specific=ZDFheute&amp;at_content=iOS">Article</a>.</p><p>Der Beitrag <a href="https://ru.law/en/ueberwachungskameras-am-haus-was-ist-erlaubt/">Überwachungskameras am Haus: Was ist erlaubt?</a> erschien zuerst auf <a href="https://ru.law/en">R&amp;U</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FOCUS online &#8211; Elektronische Patientenakte birgt Datenschutz-Risiken</title>
		<link>https://ru.law/en/focus-online-elektronische-patientenakte-birgt-datenschutz-risiken/</link>
		
		<dc:creator><![CDATA[Marco Rogert]]></dc:creator>
		<pubdate>Fri, 28 Feb 2025 14:01:02 +0000</pubdate>
				<category><![CDATA[Datenschutzrecht]]></category>
		<category><![CDATA[Datenschutz]]></category>
		<category><![CDATA[ePA]]></category>
		<category><![CDATA[Gesundheitsdaten]]></category>
		<guid ispermalink="false">https://ru.law/?p=88187</guid>

					<description><![CDATA[<p>The EU Commission is responding to criticism from the business community and postponing the introduction of the supply chain law by one year to 2028. In addition, companies should fulfil fewer bureaucratic obligations</p>
<p>Der Beitrag <a href="https://ru.law/en/focus-online-elektronische-patientenakte-birgt-datenschutz-risiken/">FOCUS online &#8211; Elektronische Patientenakte birgt Datenschutz-Risiken</a> erschien zuerst auf <a href="https://ru.law/en">R&amp;U</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Dr. Marco Rogert has, as part of a <a href="https://www.focus.de/gesundheit/datenschutz-bedenken-warum-die-elektronische-patientenakte-datenschutz-risiken-birgt_id_260708482.html">Contribution as an expert at FOCUS Online </a>Assessments of the data protection risks of the electronic patient record (ePA) have been made. The introduction of the ePA is intended to make medical care more efficient and improve communication between physicians. However, there are significant concerns, particularly regarding its planned use by Federal Health Minister Karl Lauterbach.</p>



<h2 class="wp-block-heading" id="h-ziel-der-elektronischen-patientenakte">Goal of the electronic patient record</h2>



<p>The introduction of the ePA is being celebrated as a milestone in the digitalization of the German healthcare system. According to a report by &quot;heise.de,&quot; Federal Health Minister Karl Lauterbach stated at Bitkom&#039;s Digital Health Conference: &quot;After 20 years of sluggish development, we have successfully caught up. On January 15, the electronic patient record will be launched for 70 million insured persons. It is the centerpiece of digitalization in the healthcare system and will significantly improve patient care.&quot;</p>



<p>Lauterbach acknowledged that the ePA in its original form had significant weaknesses, but the delay made it possible to integrate state-of-the-art technological solutions that make the system more efficient.</p>



<h2 class="wp-block-heading" id="h-ein-umfassender-datenschatz-entsteht">A comprehensive treasure trove of data is created</h2>



<p>In the future, all health data will be automatically stored in the ePA: from lab results and x-rays to medication information and hospital stays. &quot;This data set is gigantic – there are one billion doctor-patient contacts in Germany every year,&quot; Lauterbach emphasized. The collected data will be combined at the Research Data Center for Health (FDZ) with additional information from over 400 medical registries and genome databases. Billing data from health insurance companies will also be part of the system, with all information linked via a pseudonymized health insurance number.</p>



<h2 class="wp-block-heading" id="h-einsatz-von-kunstlicher-intelligenz">Use of artificial intelligence</h2>



<p>A central element of the ePA is the use of artificial intelligence (AI). &quot;This data set is made analyzable with the help of AI systems,&quot; Lauterbach explained. The structure of the ePA is already designed to be &quot;AI-ready.&quot;</p>



<p>A central element of the ePA is the use of artificial intelligence (AI). &quot;This data set is made analyzable with the help of AI systems,&quot; Lauterbach explained. The structure of the ePA is already designed to be &quot;AI-ready.&quot;</p>



<h2 class="wp-block-heading" id="h-interesse-internationaler-technologiekonzerne">Interest of international technology companies</h2>



<p>Lauterbach indirectly confirmed this fear. &quot;All major AI companies are interested in this treasure trove of data,&quot; the minister said. Meta, OpenAI, and Google, among others, are in discussion. The companies are interested in training their language models with German health data. Furthermore, the healthcare sector is a significant growth industry. &quot;While many economic sectors are stagnating, we are experiencing dynamic growth here,&quot; Lauterbach said. With other data sources, pseudonymized health data could be attributed to a specific individual.</p>



<h2 class="wp-block-heading" id="h-chancen-und-risiken-der-epa">Opportunities and risks of the ePA</h2>



<p>The advantages of the EHR are obvious: Important medical documents such as x-rays, reports, and doctor&#039;s letters are centrally accessible and can be accessed at any time. This can improve the quality of treatment and avoid duplicate examinations.</p>



<p>However, IT security experts have discovered serious security vulnerabilities in the ePA. This is particularly alarming given that it involves highly sensitive health data—perhaps the most vulnerable information a citizen has.</p>



<h2 class="wp-block-heading" id="h-mangelhafte-datenverarbeitung-im-gesundheitswesen">Poor data processing in healthcare?</h2>



<p>Doubts about the professional processing of health data have existed since the coronavirus pandemic. The Paul Ehrlich Institute (PEI) was criticized for failing to provide reliable interfaces with health insurance companies and for publishing only incomplete data on side effects. While other countries such as the Netherlands, Denmark, and the USA created detailed side effect databases, the PEI merely provided an inaccurate Excel spreadsheet.</p>



<h2 class="wp-block-heading" id="h-datenschutzmassnahmen-und-ihre-schwachen">Data protection measures and their weaknesses</h2>



<p>Lauterbach assured that Israeli experts had reviewed the data security of the ePA and that a balance had been struck between data protection and usability. A key point was the use of &quot;confidential computing,&quot; in which data is processed within a protected environment without being encrypted. However, this statement raises questions: Wouldn&#039;t a truly confidential data set be precisely an encrypted data set?</p>



<p>Researchers can access health data upon request – the research purpose, not the identity of the requester, is crucial. The data should not leave the secure research environment. But how secure is this &quot;trusted environment&quot; really?</p>



<h2 class="wp-block-heading" id="h-lauterbachs-vision-ein-weltweit-fuhrender-gesundheitsdatensatz">Lauterbach&#039;s vision: A world-leading health data set</h2>



<p>The minister sees the ePA as the most important digital project in Germany and a breakthrough innovation. His goal: to build the largest and most comprehensive health dataset worldwide.</p>



<p>However, based on previous experiences with security deficiencies in the ePA and the ineffective data management of the PEI, there are legitimate concerns: Is the health data of 70 million insured persons really adequately protected?</p>



<h2 class="wp-block-heading" id="h-politische-diskussion-merz-will-finanzielle-anreize-schaffen">Political discussion: Merz wants to create financial incentives</h2>



<p>Lauterbach isn&#039;t the only one pursuing ambitious plans for the ePA. CDU leader Friedrich Merz has floated the idea of financially rewarding insured individuals for entrusting their data to the ePA. This could make the healthcare system more efficient.</p>



<div class="wp-block-uagb-advanced-heading uagb-block-8c88a3b3"><h2 class="uagb-heading-text">Criticism from IT experts</h2></div>



<p>According to a report in the &quot;Berliner Zeitung,&quot; IT specialists are warning of significant security risks. Organized crime could steal patient data on a large scale. Intelligence agencies are also interested in this sensitive information. The Chaos Computer Club recently demonstrated at a conference how easily security vulnerabilities can be exploited.</p>



<p>&quot;Experts have repeatedly pointed out security risks,&quot; said IT specialist Manuel Atug. &quot;Yet only minimal improvements have been made. The responsible ministry is resistant to advice.&quot;</p>



<div class="wp-block-uagb-advanced-heading uagb-block-2a9f1f6c"><h2 class="uagb-heading-text">Opt-out procedures and data protection concerns</h2></div>



<p>The ePA will be implemented via an opt-out procedure – those who do not opt out will automatically receive a digital patient record. Privately insured individuals, however, must actively apply for the ePA.</p>



<p>This is problematic from a data protection perspective. The GDPR requires explicit consent for health data. However, this uses an objection mechanism that is hostile to data protection, which many insured persons are likely unaware of.</p>



<div class="wp-block-uagb-advanced-heading uagb-block-bf75e7e9"><h2 class="uagb-heading-text">Possible abuse scenarios</h2></div>



<p>Experts see four main scenarios in which the ePA could be misused:</p>



<p><strong>Decryption of pseudonymized data</strong>: With the appropriate key, data could be re-identified.</p>



<p><strong>Incorrect anonymization</strong>: Names or other identifying features may be inadvertently retained in medical reports or X-ray images.</p>



<p><strong>Data reconstruction</strong>: By combining extensive information, individuals could be identified.</p>



<p><strong>Tracking via service providers</strong>: A particular doctor&#039;s visit could allow conclusions to be drawn about a person&#039;s identity.</p>



<div class="wp-block-uagb-advanced-heading uagb-block-ebf9a309"><h2 class="uagb-heading-text">Consequences of a data breach</h2></div>



<p>If health data falls into the wrong hands, there is a risk of serious consequences, ranging from unwanted advertising for medications to job loss, rejection of loans or insurance, blackmail by third parties or social exclusion.</p>



<div class="wp-block-uagb-advanced-heading uagb-block-5febcc77"><h2 class="uagb-heading-text">How can you defend yourself?</h2></div>



<p>Those affected can object to the electronic personal data (ePA) or have stored data deleted. There are also legal options to prevent the transfer of data to foreign companies.</p>



<p></p><p>Der Beitrag <a href="https://ru.law/en/focus-online-elektronische-patientenakte-birgt-datenschutz-risiken/">FOCUS online &#8211; Elektronische Patientenakte birgt Datenschutz-Risiken</a> erschien zuerst auf <a href="https://ru.law/en">R&amp;U</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Mögliche Datenschutzverstöße bei VW: Betroffene könnten Anspruch auf Schadenersatz haben</title>
		<link>https://ru.law/en/moegliche-datenschutzverstoesse-bei-vw-betroffene-koennten-anspruch-auf-schadenersatz-haben/</link>
		
		<dc:creator><![CDATA[Marco Rogert]]></dc:creator>
		<pubdate>Fri, 10 Jan 2025 09:44:40 +0000</pubdate>
				<category><![CDATA[Datenschutzrecht]]></category>
		<category><![CDATA[Verkehrsrecht]]></category>
		<category><![CDATA[Elektrofahrzeug]]></category>
		<category><![CDATA[Schadensersatz]]></category>
		<category><![CDATA[VW]]></category>
		<guid ispermalink="false">https://ru.law/?p=86024</guid>

					<description><![CDATA[<p>Ein neuer Datenschutzvorfall bei Volkswagen, bei dem Daten von 800.000 Elektrofahrzeugen, einschließlich Bewegungsprofilen und persönlichen Informationen, ungesichert online zugänglich waren, stellt ernsthafte Fragen bezüglich der [&#8230;]</p>
<p>Der Beitrag <a href="https://ru.law/en/moegliche-datenschutzverstoesse-bei-vw-betroffene-koennten-anspruch-auf-schadenersatz-haben/">Mögliche Datenschutzverstöße bei VW: Betroffene könnten Anspruch auf Schadenersatz haben</a> erschien zuerst auf <a href="https://ru.law/en">R&amp;U</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>A recent data breach at Volkswagen, in which data from 800,000 electric vehicles, including movement profiles and personal information, was exposed online without security, raises serious questions about the company&#039;s compliance with the General Data Protection Regulation (GDPR) and its IT security measures. A thorough investigation into the case is being called for to assert the rights of those affected.</p>



<p>The disclosure of location data and personal details such as email addresses and phone numbers highlights a worrying weakness in security measures. It is both legally and ethically imperative to protect such information, especially when it provides deep insights into individuals&#039; private lives.</p>



<h3 class="wp-block-heading" id="h-unterstutzung-bei-datenschutzrechtlichen-anliegen">Support with data protection issues</h3>



<p>We offer affected vehicle owners comprehensive support in enforcing their data protection rights. Our services include:</p>



<ul class="wp-block-list">
<li>Support in the deletion of personal data: We help with the claim to the “right to be forgotten” under Article 17 GDPR.</li>



<li>Requests for information in accordance with Article 15 GDPR: We determine which personal data has been stored and how it has been used.</li>



<li>Review of legal options: This includes examining the possibilities for a class action declaratory judgment or individual claims for damages.</li>



<li>Assertion of claims for damages: In case of financial or immaterial damages caused by unprotected data publication.</li>
</ul>



<h3 class="wp-block-heading" id="h-datenschutzverletzung-bei-vw-rechtliche-schritte-und-erhohte-sicherheitsanforderungen" style="margin-top:var(--wp--preset--spacing--20);margin-bottom:var(--wp--preset--spacing--20)">Data breach at VW: Legal steps and increased security requirements</h3>



<p>The data leak could give rise to claims against subsidiaries such as VW Financial Services and VW Bank. Volkswagen Bank GmbH is a wholly owned subsidiary of Volkswagen Financial Services AG.</p>



<p>The disclosure of customer data provides criminals with the opportunity to launch phishing emails or other fraudulent activities. Customers who suffer financial losses as a result may have the right to claim compensation.</p>



<p>The potential dangers of phishing attacks or identity theft associated with VW Financial Services and VW Bank data are serious. It is imperative that companies treat the security of customer data as a top priority.</p>



<p><strong>Demand for stricter data protection standards</strong> It also calls on companies to improve data protection and IT security standards. The push toward electric vehicles and advanced connected technologies should not compromise user privacy. Manufacturers must ensure that personal data is not only collected legally but also comprehensively protected.</p>



<p><strong>Need for action at the political level</strong> This incident highlights the need for strict enforcement of regulatory requirements such as the upcoming EU Data Act. Manufacturers should be expected to provide consumers with clear and secure data management. Data protection should be an integral part of modern mobility.</p>



<h3 class="wp-block-heading" id="h-kostenlose-ersteinschatzung"><strong>Free initial assessment</strong> </h3>



<p>Those affected can contact specialist lawyers for a non-binding initial assessment of their legal options. The goal is to take the necessary steps under data protection and civil law together with the affected parties.</p><p>Der Beitrag <a href="https://ru.law/en/moegliche-datenschutzverstoesse-bei-vw-betroffene-koennten-anspruch-auf-schadenersatz-haben/">Mögliche Datenschutzverstöße bei VW: Betroffene könnten Anspruch auf Schadenersatz haben</a> erschien zuerst auf <a href="https://ru.law/en">R&amp;U</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>