Module CS3510-KP04
Data protection law and information security (DatInfoSec)
Duration
1 Semester
Turnus of offer
every summer semester
Credit points
4 (Typ B)
Course of studies, specific fields and terms:
- Bachelor Interdisciplinary Courses for health sciences, optional suject, Interdisciplinary modules
- Master Medical Informatics 2019, optional subject, Interdisciplinary modules
- Bachelor Medical Informatics 2019, optional subject, Interdisciplinary modules
- Master Interdisciplinary Courses, optional subject, Interdisciplinary modules
- Bachelor Interdisciplinary Courses, optional subject, Interdisciplinary modules
Classes and lectures:
- CS3510-Ü: Data protection law and information security (exercise, 1 SWS)
- CS3510-V: Data protection law and information security (lecture, 2 SWS)
Workload:
- 40 hours in-classroom work
- 60 hours private studies
- 20 hours exam preparation
Contents of teaching:
- Basic Concepts of Personal Data Protection and Information Security
- The General Data Protection Regulation (GDPR) as a Framework for Data Protection Law / Information Security: The material and territorial scope of the GDPR, principles of the GDPR, legal bases for data processing, including relevant examples (e.g., disclosure of data to third parties, data analysis), rights of data subjects, particularly notification obligations and rights of access, documentation requirements, particularly the record of processing activities, Fundamentals of Privacy by Design and Privacy by Default, data protection principles for engaging external service providers in light of various data processing roles (data processing, separate controller status, joint controller status), data protection principles for cross-border data transfers (transfers to third countries, Standard Contractual Clauses, U.S. data transfers in light of the U.S.-EU Data Privacy Framework), explanation of the fundamentals of technical and organizational measures, explanation of possible consequences of errors and violations (overview of the obligation to report data breaches, risks of fines, and liability for damages)
- Overview and excerpts of supplementary/sector-specific regulations on data protection and information security: Regulation on the Establishment of the European Cybersecurity Competence Center, Cybersecurity Regulation, Cyber Resilience Regulation (draft), NIS2 Directive, CER Directive, KRITIS Framework Act, IT Security Act 2.0, BSI Act, Regulation on Data Access and Data Use (Data Act), AI Regulation (AI Act), ePrivacy Directive, Telecommunications and Telemedia Data Protection Act, Trade Secrets Act, Criminal Code
Qualification-goals/Competencies:
- Students can recognize and apply the legal framework for data protection and information security for persons who are responsible for a data processing system.
- Students can assess what they need to consider legally when developing, implementing and operating data processing systems.
Grading through:
- written exam
Responsible for this module:
Teacher:
- Institute for IT Security
- Dr. Christoph Aust
Literature:
- Kühling / Buchner : Datenschutz-Grundverordnung, Bundesdatenschutzgesetz: DS-GVO / BDSG Kommentar, 4. Auflage. 2024
- Taeger / Gabel : DSGVO - BDSG TTDSG Kommentar, 4., neu bearbeitete Auflage. 2022
- Bernhard Freund, Bernd Schmidt, Sebastian Heep, Anna-Kristina Roschek : Praxis-Kommentar DSGVO, 1. Auflage 2022
- Kipker / Reusch / Ritter : Recht der Informationssicherheit, 1. Auflage 2023
- Kipker : Cybersecurity - 2. Auflage. 2023
Language:
- offered only in German
Notes:
Admission requirements for taking the module(s):- None
Admission requirements for participation in module examination(s)
- None
Module examination:
- CS3510-KP04 Data protection law and information security Written exam, 100 % of the module grade
Last Updated:
13.07.2026