Take-Aways (AI)
  • Art. 4 GDPR requi­res pri­va­te indi­vi­du­als to record exten­si­ve, auto­ma­ted pro­ce­s­sing of par­ti­cu­lar­ly sen­si­ti­ve per­so­nal data or high-risk profiling.
  • Logs must record all acce­s­ses (human and machi­ne) with iden­ti­ty, action, date/time and must be kept sepa­ra­te­ly for at least one year.
  • FDPIC recom­mends tech­ni­cal mea­su­res: stan­dar­di­zed for­mats, parsing/indexing, time syn­chro­nizati­on, access con­trols, anoma­ly detec­tion and con­cept documentation.

The FDPIC has published a new ver­si­on dated Sep­tem­ber 15, 2023 (but pro­ba­b­ly not available until the end of Octo­ber). Tech­ni­cal recom­men­da­ti­ons for log­ging in accordance with Art. 4 GDPR of the FDPIC published.

The recom­men­da­ti­ons are not legal­ly bin­ding. They appear to be tail­o­red to pri­va­te indi­vi­du­als; in any case, only pri­va­te indi­vi­du­als are men­tio­ned, and the file name is “Recom­men­da­ti­on on log­ging accor­ding to DSV – Private.pdf”, even though the­re is no expli­cit rest­ric­tion to this effect in the document.

Art. 4 regu­la­tes the fol­lo­wing in the pri­va­te sec­tor:

  • Accor­ding to Art. 4 GDPR, pri­va­te indi­vi­du­als – inclu­ding con­tract pro­ces­sors – must keep records if they pro­cess par­ti­cu­lar­ly sen­si­ti­ve per­so­nal data auto­ma­ti­cal­ly on a lar­ge sca­le or car­ry out high-risk profiling.
  • This does not app­ly if the pre­ven­ti­ve mea­su­res “ensu­re data protection”.
  • The log must at least record the sto­rage, modi­fi­ca­ti­on, rea­ding, dis­clo­sure, dele­ti­on and des­truc­tion of the data and “pro­vi­de infor­ma­ti­on about the iden­ti­ty of the per­son who car­ri­ed out the pro­ce­s­sing, the type, date and time of the pro­ce­s­sing and, if appli­ca­ble, the iden­ti­ty […] of the reci­pi­ent of the data”.
  • Logs must be stored sepa­ra­te­ly from the pro­duc­ti­ve system for at least one year.

This pro­vi­si­on rai­ses Various que­sti­ons for example:

  • What is “lar­ge-sca­le” processing?
  • When is pro­ce­s­sing “auto­ma­ted”? Is it suf­fi­ci­ent that it invol­ves elec­tro­ni­cal­ly stored data, or is auto­ma­ti­on also requi­red for the con­tent of the pro­ce­s­sing procedure?
  • Under what con­di­ti­ons can pre­ven­ti­ve mea­su­res gua­ran­tee data protection?
  • How are the logs stored sepa­ra­te­ly? In par­ti­cu­lar: Do logs have to be trans­fer­red to a sepa­ra­te system in real time when they occur in the pro­duc­ti­ve system, or only at inter­vals, and if so, at what inter­vals? May the logs also remain stored in the pro­duc­tion system?
  • To what ext­ent or under what con­di­ti­ons is the pro­ces­sor obli­ged to keep logs, sin­ce he often does not even know whe­ther the log­ging requi­re­ments are met and whe­ther the pre­ven­ti­ve mea­su­res of the con­trol­ler ensu­re data pro­tec­tion within the mea­ning of Art. 4 para. 1 GDPR? Can or should he the­r­e­fo­re obli­ge the con­trol­ler to cla­ri­fy the log­ging obli­ga­ti­on, to obtain an optio­nal log­ging ser­vice if neces­sa­ry and to pro­vi­de the pro­ces­sor with cor­re­spon­ding pro­of for docu­men­ta­ti­on pur­po­ses on request?
  • Do the log­ging requi­re­ments con­sti­tu­te mini­mum data secu­ri­ty requi­re­ments, the inten­tio­nal vio­la­ti­on of which is punis­ha­ble by law (see here)?

The non-bin­ding recom­men­da­ti­ons of the FDPIC aim to “pro­vi­de an over­view of what is inclu­ded in this log­ging and what must be done for tech­ni­cal com­pli­ance with Art. 4 GDPR”. The system-side imple­men­ta­ti­on is not the sub­ject of the recommendations.

The fol­lo­wing points should be emphasized:

  • Read” – a pro­cess that must be log­ged except in the case of publicly acce­s­si­ble data – means “access wit­hout ‘modi­fi­ca­ti­on’ ”. It is the­r­e­fo­re suf­fi­ci­ent “if the access to per­so­nal data and the modi­fi­ca­ti­on of this data are logged”.
  • It must all acce­s­ses are log­ged not only human access, but also machi­ne access (e.g. by peri­phe­ral systems).
  • In accordance with the pur­po­se of log­ging Log data ana­ly­zed on demand beco­me can. This is an under­stan­da­ble con­cern, but the ana­ly­sis of log data is not a requi­re­ment of the DPA or the GDPR. If log data is not ana­ly­zed becau­se the con­trol­ler is unable or unwil­ling to do so, this does not in its­elf con­sti­tu­te a breach of data pro­tec­tion. It can only rai­se que­sti­ons about data secu­ri­ty. Howe­ver, the FDPIC’s state­ments are also to be under­s­tood as recom­men­da­ti­ons and not as an inter­pre­ta­ti­on of the mini­mum standard.
  • It is a “Con­cept for log­ging which should “con­tain a com­pre­hen­si­ve and syste­ma­tic descrip­ti­on of the log­ging poli­cy and pro­ce­du­res”. The FDPIC makes recom­men­da­ti­ons for the con­tent of such a concept.

In tech­ni­cal aspects the FDPIC recom­mends the following:

  • Stan­dar­di­zed log­ging for­mats should be used, such as Sys­log or the Com­mon Event For­mat (CEF).
  • Logs “should not only be stored, but also read and inter­pre­ted (par­sing and index­ing)”. In doing so, “all infor­ma­ti­on ele­ments should be extra­c­ted during rea­ding (inge­sti­on) using pat­tern extra­c­tion and sup­ple­men­ted with infor­ma­ti­on from exi­sting logs whe­re appro­pria­te (cor­re­la­ti­on). Unu­sed infor­ma­ti­on fields should be omit­ted in this pro­cess in order to save sto­rage space, among other things.”
  • The log data should be “checked regularly”.
  • Mecha­nisms for detec­ting anoma­lies in the log data should be implemented”.
  • Sui­ta­ble access con­trols for the log data” are to be implemented.
  • Log data must be time-stam­ped. All systems in the net­work should also have “relia­ble and accu­ra­te time synchronization”.
  • Log data should be enri­ched with addi­tio­nal infor­ma­ti­on (data enrich­ment) to enable a bet­ter under­stan­ding of the events.
  • The pro­to­col ana­ly­sis appli­ca­ti­ons should inform you imme­dia­te­ly if anoma­lies or known secu­ri­ty-rele­vant events occur.

Go to Sto­rage of log data the FDPIC recom­mends, among other things, kee­ping log data available for ana­ly­sis for as long as it is nee­ded to detect and respond to indi­ca­tors. They can then be moved to a lon­ger-term sto­rage system. Long-term sto­rage – within the limits of what is per­mit­ted – is also an “important part of the data pro­tec­tion stra­tegy”. Unfort­u­n­a­te­ly, this lea­ves open the que­sti­on of how the sepa­ra­te sto­rage requi­red by law is to be under­s­tood in con­cre­te terms.

At the Tran­si­tio­nal pro­vi­si­on (Art. 46 GDPR), the FDPIC seems to assu­me that they also for pri­va­te indi­vi­du­als app­ly. This is wel­co­me, albeit surprising:

  • Art. 46 para. 1 DPA sets out the tran­si­tio­nal pro­vi­si­ons for exi­sting applications:

    1 For data pro­ce­s­sing ope­ra­ti­ons that do not fall within the scope of Direc­ti­ve (EU) 2016/6804, Artic­le 4(2) shall app­ly at the latest three years after the ent­ry into force of this Regu­la­ti­on or at the latest after the end of the life cycle of the system. In the mean­ti­me, the­se pro­ce­s­sing ope­ra­ti­ons shall be sub­ject to Artic­le 4(1).

    With new appli­ca­ti­ons, it is rela­tively easy to log all acti­vi­ties with per­so­nal data right from the start. With exi­sting, older appli­ca­ti­ons, howe­ver, it is not always pos­si­ble to adapt the appli­ca­ti­on its­elf. Howe­ver, the­re are various solu­ti­ons for the­se cases.

    The imple­men­ta­ti­on of log­ging depends on many aspects such as the pro­gramming lan­guage, the run­time envi­ron­ment and the deve­lo­p­ment methods used for the appli­ca­ti­on. Our recom­men­da­ti­ons are the­r­e­fo­re gene­ric in natu­re, but can sup­port plan­ning for spe­ci­fic applications.

  • The FDPIC fol­lows this up with recom­men­da­ti­ons for deal­ing with lega­cy systems. If pro­ce­s­sing only takes place local­ly at the user, i.e. wit­hout com­mu­ni­ca­ti­on with a ser­ver, it is suf­fi­ci­ent, for exam­p­le, to log the initi­al down­load. If no other log­ging is alre­a­dy pos­si­ble and none takes place at net­work level, the appli­ca­ti­on must be expanded.

Final­ly, you will find FAQwith, among other things, the fol­lo­wing refe­ren­ces, which appar­ent­ly ori­gi­na­te from the NCSC:

  • Data is “gene­ral­ly publicly available” within the mea­ning of Art. 4 para. 1 GDPR if it is “wide­ly acce­s­si­ble wit­hout authen­ti­ca­ti­on, such as an address search via a website”.
  • A back­up of the log data satis­fies the requi­re­ment for sepa­ra­te sto­rage in accordance with Art. 2 para. 5 GDPR (see abo­ve: the inter­val is open, but obvious­ly not meant to be real-time – accor­din­gly, a cer­tain risk is accept­ed that log data may be com­pro­mi­sed befo­re the back­up in the event of a ran­som attack).
  • Access in uns­truc­tu­red data repo­si­to­ries (e.g. ope­ning a docu­ment in a local dri­ve) does not have to be log­ged, but only access “in auto­ma­ted data pro­ce­s­sing systems”. Here, the FDPIC and the NCSC rely on Art. 3 para. 3 lit. a GDPR.
  • Not all logs need to be stored in the same place. It is suf­fi­ci­ent if they can be mer­ged in a meaningful way.