Module CS3510-KP04

Data protection law and information security (DatInfoSec)


Duration

1 Semester

Turnus of offer

every summer semester

Credit points

4 (Typ B)

Course of studies, specific fields and terms:

  • Bachelor Interdisciplinary Courses for health sciences, optional suject, Interdisciplinary modules
  • Master Medical Informatics 2019, optional subject, Interdisciplinary modules
  • Bachelor Medical Informatics 2019, optional subject, Interdisciplinary modules
  • Master Interdisciplinary Courses, optional subject, Interdisciplinary modules
  • Bachelor Interdisciplinary Courses, optional subject, Interdisciplinary modules

Classes and lectures:

  • CS3510-Ü: Data protection law and information security (exercise, 1 SWS)
  • CS3510-V: Data protection law and information security (lecture, 2 SWS)

Workload:

  • 40 hours in-classroom work
  • 60 hours private studies
  • 20 hours exam preparation

Contents of teaching:

  • Basic Concepts of Personal Data Protection and Information Security
  • The General Data Protection Regulation (GDPR) as a Framework for Data Protection Law / Information Security: The material and territorial scope of the GDPR, principles of the GDPR, legal bases for data processing, including relevant examples (e.g., disclosure of data to third parties, data analysis), rights of data subjects, particularly notification obligations and rights of access, documentation requirements, particularly the record of processing activities, Fundamentals of “Privacy by Design” and “Privacy by Default,” data protection principles for engaging external service providers in light of various data processing roles (data processing, separate controller status, joint controller status), data protection principles for cross-border data transfers (transfers to third countries, “Standard Contractual Clauses,” U.S. data transfers in light of the U.S.-EU Data Privacy Framework), explanation of the fundamentals of technical and organizational measures, explanation of possible consequences of errors and violations (overview of the obligation to report data breaches, risks of fines, and liability for damages)
  • Overview and excerpts of supplementary/sector-specific regulations on data protection and information security: Regulation on the Establishment of the European Cybersecurity Competence Center, Cybersecurity Regulation, Cyber Resilience Regulation (draft), NIS2 Directive, CER Directive, KRITIS Framework Act, IT Security Act 2.0, BSI Act, Regulation on Data Access and Data Use (Data Act), AI Regulation (AI Act), ePrivacy Directive, Telecommunications and Telemedia Data Protection Act, Trade Secrets Act, Criminal Code

Qualification-goals/Competencies:

  • Students can recognize and apply the legal framework for data protection and information security for persons who are responsible for a data processing system.
  • Students can assess what they need to consider legally when developing, implementing and operating data processing systems.

Grading through:

  • written exam

Responsible for this module:

Teacher:

Literature:

  • Kühling / Buchner : Datenschutz-Grundverordnung, Bundesdatenschutzgesetz: DS-GVO / BDSG – Kommentar, 4. Auflage. 2024
  • Taeger / Gabel : DSGVO - BDSG – TTDSG – Kommentar, 4., neu bearbeitete Auflage. 2022
  • Bernhard Freund, Bernd Schmidt, Sebastian Heep, Anna-Kristina Roschek : Praxis-Kommentar DSGVO, 1. Auflage 2022
  • Kipker / Reusch / Ritter : Recht der Informationssicherheit, 1. Auflage 2023
  • Kipker : Cybersecurity - 2. Auflage. 2023

Language:

  • offered only in German

Notes:

Admission requirements for taking the module(s):
- None

Admission requirements for participation in module examination(s)
- None

Module examination:
- CS3510-KP04 Data protection law and information security Written exam, 100 % of the module grade

Last Updated:

13.07.2026