Between
Technische Universität Carolo-Wilhelmina zu Braunschweig
represented by the President
and the
Staff Council of Technische Universität Carolo-Wilhelmina zu Braunschweig
represented by the Chairperson
in accordance with § 78 and in conjunction with § 67 (1) No. 1 NPersVG
the following
IT Framework TU Braunschweig/Staff Council Agreement
Regarding the Implementation, Application, and Substantial Modification of IT Procedures (IT-Framework Agreement)
is concluded at Technische Universität Carolo-Wilhelmina zu Braunschweig:
(1) When introducing, implementing, or making significant changes to IT procedures, the protection of employees is a top priority.
The university management represented by the Executive Board, and the Staff Council of TU Braunschweig agree that the introduction of new IT procedures, as well as the further development or significant modification of existing IT procedures, serve to maintain, create, and secure jobs. This requires a close cooperation of all parties involved.
(2) The parties agree that data protection, the quality of work, and the health and safety of employees can be ensured, in particular, through employee training. When using IT systems, data protection and information security have to be ensured for all employees in every respect. No other rights are adversely affected. In particular when personal data are being processed, the Data Protection Officer of TU Braunschweig and the university management will also be involved with regard to data protection. Care is taken to ensure that, at every stage of the expansion of existing technologies and IT processes—as well as when introducing new technologies—the health and safety of employees remains a top priority, and that work supported and influenced by information technology is designed in a way that is humane. The organization should support employees by structuring their work in connection with IT processes in a way that protects them from physical and mental overload. The agreement sets forth the qualification requirements for employees, who have to be supported through adequate instruction, supervision, and continuing education.
(3) The university management, represented by the Executive Board, as well as the Staff Council agree that both the institutional interests of Technische Universität Braunschweig and the interests of all employees will be taken into account, among other things, through the use and development of accessible information technologies.
(4) It has to be ensured that the use of information technology does not result in the implementation of impermissible personalized monitoring of behavior and performance. IT processes are intended to reduce employees' workloads and can help improve both the quality and quantity of their work.
(5) To ensure the implementation of the fundamental principles and objectives set forth in the preamble, the following IT Framework Staff Council Agreement (IT Framework Agreement) regarding the introduction, application, and substantial modification of IT procedures is concluded between the university management, represented by the Executive Board, and the Staff Council of TU Braunschweig, pursuant to § 78 in conjunction with § 67 (1) of NPersVG (Niedersächsisches Personalvertretungsgesetz [Lower Saxony Staff Representation Act]).
(1) The purpose of the IT Framework Agreement is to establish uniform, simple (form-based), and transparent (with specific provisions set forth in appendixes, definitions, etc.) rules for both new and existing IT procedures. In addition to the applicable laws and regulations, as well as the civil servants’ regulations and the regulations of Technische Universität Braunschweig, this staff council agreement has to be observed as a supplementary provision.
(2) An IT process is defined as an organizationally self-contained unit of IT-supported workflows designed for the long term. An IT process is the responsibility of the organizational unit (OU) that operates it. The responsible OU is generally the operating OU at TU Braunschweig, even if the implementation of the IT process has been outsourced to external service providers.
(3) The IT Framework Agreement applies, in terms of subject matter, to all IT procedures, provided that no separate staff council agreement exists or is agreed upon for the IT procedure in question, and, in terms of persons, to all employees of TU Braunschweig represented by the Staff Council within the meaning of the NPersVG, as well as, if necessary, to other groups of persons. It also applies to IT processes developed or operated by external parties, provided that no separate staff council agreement exists or is entered into for the IT process.
(1) The project profile prepared by the IT Multiproject Management Board serves as the basis for submitting an IT procedure to the Staff Council.
(2) The following templates are established as mandatory for the participation process; their contents are described below.
(3) Appendix 0 contains a template for an agreement specifying the details of the IT Framework Agreement. Based on this template, a draft has to be prepared for each IT procedure if the Staff Council so requests, and any resulting agreement will be published university-wide.
(4) Appendix 1 contains a standardized checklist for the IT procedure, which, once fully completed and approved, will be published together with the corresponding agreement specifying the IT Framework Agreement pursuant to § 2 (3).
(5) A sample standardized outline for an operational concept is included in Appendix 2. The organizational unit responsible for operating the IT process (in accordance with the organizational management system) has to prepare the operational concept for the respective IT process. The operating concept is part of the relevant agreement specifying the IT Framework Agreement. It may be accessed at the operating unit responsible for the IT process upon demonstration of a legitimate interest, but it is not made public.
(6) Appendix 3 contains a glossary for this IT Framework Agreement. Any additional necessary definitions have to be included in the respective Appendixes 0 through 2.
(7) The project profile and all attachments (see paragraph (3), where applicable, and paragraphs (4) and (5)) have to be made available to the Staff Council as part of the respective participation process.
(1) The implementation of an IT process generally requires the successful completion of a pilot operation. A test operation may precede the pilot operation.
(2) A substantial change to an IT process includes, in particular, a significant expansion or other significant modification of an IT process that affects employees, work processes, or the protection of employees' personal data.
(3) A change to an IT procedure is considered minor if its impact on employees or their work processes is negligible. The requirement to submit such changes to the Staff Council is governed by § 4 (6). Insignificant changes typically result from minor version updates to the software used (minor release) or from changes in the number of affected employees due to the expansion of the system’s use to additional organizational units.
(4) For the purposes of this IT Framework Agreement, “test operation” refers to tests of IT procedures that take place separately from the normal operation of the procedure and in which the individuals involved participate voluntarily.
Test operations are intended solely for development, initial evaluation, or troubleshooting and are therefore clearly distinguished from both pilot operations and productive operations based on their definitions (§ 3 (5) and § 3 (6)). For test operations there is no reporting requirement.
(5) For the purposes of this IT Framework Agreement, a “pilot operation” is defined as a temporary, proper operation using real data that—in addition to fulfilling operational tasks—serves to evaluate and optimize the process. A pilot operation is considered to exist, in particular, when employees repeatedly perform operational tasks using the IT system as part of their job duties
(6) For the purposes of this IT Framework Agreement “productive operation” means the continuous, proper operation of the IT system. The commencement of productive operation is subject to prior Staff Council participation.
(1) The following paragraphs define the processes for the implementation, operation, and significant modification of IT procedures for the operating modes defined above and the transitions between them.
(2) It is not necessary to notify the Staff Council when initiating or terminating a trial run of an IT process. A trial run may transition into a pilot operation.
(3) The Staff Council has to be notified of the pilot operation of an IT process by submitting the project profile through official channels. The Staff Council is authorized to issue an operating ban in the event of unauthorized pilot operations. TU Braunschweig is required to enforce the operating ban issued by the Staff Council within one month of receiving the Staff Council’s resolution.
(4) A pilot operation reported to the Staff Council is permitted for a maximum period of 12 months and serves to initiate the co-determination process under staff representation law. During this period, the IT process is designed, and any provisions of the agreement requested by the Staff Council to specify the IT Framework Agreement are finalized. For new IT procedures of particular complexity, a separate staff council agreement may be concluded, provided that the university management and the Staff Council agree to do so. The Staff Council has to be permitted to participate in shaping the process by providing early supervision during the pilot phase. The Staff Council will determine the scope of this supervision. In particular, the Staff council has to be granted access to project documentation, minutes, and expert reports, and a member of the Staff Council has to be allowed to participate in meetings and topic-specific working groups.
(5) Before transitioning to productive operation, it has to be verified that all necessary requirements have been met. To this end, the organizational unit operating the IT process has to prepare the agreement specifying the details of the IT Framework Agreement—to the extent that the Staff Council has requested this during the pilot phase—as well as the required standardized checklist for the IT process and the operational concept in accordance with § 2, and submit them to the Staff Council for co-determination through the official channels. If the co-determination process is not initiated by the end of the period specified in § 4 (4), the Staff Council is entitled either to extend the pilot operation of the IT procedure for a period it deems appropriate or to prohibit it, subject to a notice period.
(6) During productive operation, the organizational unit operating the IT system may make only minor changes. These changes have to be reported to the Staff Council through the official channels by submitting a revised operation plan. However, if, following notification of a minor change to an IT process, the Staff Council determines that the change is significant, the Staff Council’s decision will place the IT process in question into pilot operation.
(7) The operating organizational unit has to notify the Staff Council of any significant changes to IT procedures through the official channels. The notification includes the templates for the documents listed in Appendixes 0 through 2, which may need to be amended. If the Staff Council also concludes that the proposed change is significant, the IT process is returned to the pilot phase. The organizational unit responsible for the IT process will be informed of the staff council's decision through the official channels.
(8) If, during the productive phase, the Staff Council determines that it is necessary to revise or draft an agreement to specify the IT Framework Agreement, it will notify TU Braunschweig of its decision, and the IT process will thereby be returned to the pilot phase.
(9) To terminate and shut down an IT process, whether in pilot or productive mode, the operating organizational unit has to notify the Staff Council through the official channels.
(1) The current data protection laws and regulations have to be observed.
(2) The successful completion of the data protection review, including the data protection impact assessment in accordance with the NDSG (Niedersächsisches Datenschutzgesetz/Lower Saxony Data Protection Act), is a prerequisite for the Staff Council’s approval of an IT procedure and has to be confirmed in accordance with Appendix 1 (Standardized Checklist for IT Procedures).
(3) The Staff Council is entitled to seek advice and information from the Data Protection Officer regarding IT procedures.
(4) Data analyses conducted for the purposes of quality assurance and statistics have to be anonymized or pseudonymized without delay in accordance with the applicable data protection regulations.
(5) Even if an IT procedure under data protection law requires employees to provide consent, the provisions of this staff council agreement remain unaffected.
(6) The current legal and TU Braunschweig regulations regarding data security—in particular, data integrity and protection against unauthorized access—as well as information security—in particular, protection against external interference—have to be observed. These aspects have to be examined in advance by the organizational unit operating the IT process and documented in an appropriate and traceable manner in accordance with the appendixes to this IT Framework Agreement—in particular, the standardized checklist for the IT process (Appendix 1) and the operational concept (Appendix 2)—and have to be safeguarded during operation.
(7) Log data collected to ensure proper operation and information security may not be stored for longer than 540 days, and § 7 (1) has to be strictly observed.
(1) If the operation of an IT system requires the processing of personal data outside TU Braunschweig, such processing has to be carried out under an external data processing agreement in compliance with the relevant legal provisions and, in particular, the applicable data protection regulations. To this end, the TU Braunschweig ensures that the obligations arising from this IT Framework Agreement are transferred from the respective contracting authorities within TU Braunschweig to the contractors.
(2) The existence of such a provision has to be documented in the relevant agreement according to Appendix 1 (Standardized Checklist for IT Procedures). The provision regarding commissioned data processing will not be published.
(1) Data collected, processed, or used within IT systems for administrative purposes within the employment relationship may not be used for the purpose of monitoring performance and conduct without the participation of the Staff Council (pursuant to § 67 (1) NPersVG). Findings derived from this information may not be used to take disciplinary action under labor law. Disciplinary measures that are detrimental to employees—such as terminations (including terminations for cause) and written warnings—would be invalid. This does not apply to facts and actions that are relevant under criminal law.
(2) IT procedures that are primarily intended to achieve the objective of increasing work performance (pursuant to § 67 (1) NPersVG) are not permitted without the participation of the Staff Council.
(3) Anonymous analyses may not be traced back to individuals or groups; there is no authority to issue instructions to that effect. Exceptions to this rule exist in the context of security measures, in cases involving criminal acts or conduct, or where there is reasonable suspicion of such acts, which may be investigated exclusively by TU’s authorized institution or by external investigative authorities.
(4) Layoffs for operational reasons are prohibited in connection with the introduction and implementation of IT procedures or related organizational measures.
(5) The Staff Council is provided with instructions on the use of and working with specific IT procedures for its information.
(6) Employees may be held liable only in cases of gross negligence or willful misconduct.
(1) Employees are offered appropriate training tailored to their specific needs during regular working hours to ensure that they can use and operate the relevant IT systems safely and competently.
(2) During the pilot phase, appropriate training programmes tailored to the target groups have to be developed.
(3) Before an IT system goes live, it has to be ensured that sufficient training courses as specified in (1) are offered.
(4) Members of the Staff Council are entitled to participate in or observe the training sessions referred to in (1) in order to perform their duties.
(5) The costs incurred for the required qualifications and training under (1) have to be included in the operating organization’s budget.
(1) The Staff Council has the right to have a knowledgeable employee from the organizational unit operating an IT system explain all of its functionalities and to have printouts or digital copies provided of any displays that help clarify the matter at hand.
(2) In justified cases, the Staff Council may request access to information regarding the configuration and administrative status of IT systems, particularly with regard to assigned roles and permissions. The Data Protection Officer may be consulted for this purpose.
(3) The Staff Council has the right to engage internal or external expert consultants of its choice. The Staff Council is responsible for providing technical guidance. The necessary access and review privileges has to be granted to enable the consultants to carry out their consulting assignment.
(4) If costs are incurred for expert consultation, it has to be clarified before the engagement whether those costs will be covered. As a rule, the organizational unit operating the IT system bears the costs.
(1) All employees have to be granted read-only access to the digital inventory of the respective agreements maintained at TU Braunschweig and to the standardized checklist for the IT procedure (Appendixes 0 through 1) for all IT procedures established in accordance with this IT Framework Agreement, to the extent applicable.
(2) The Staff Council is entitled to have read-only access to the digital inventory maintained at TU Braunschweig of the respective project profiles, agreements, standardized checklists, and operational concepts (Appendixes 0 through 2), as well as all associated documents and expert opinions pertaining to the IT procedures covered by the scope of the IT Framework Agreement.
(1) The staff council agreement will take effect on September 22, 2022, and has to be published in an appropriate manner in accordance with § 78 (2) of the NPersVG. If any provision of this agreement conflicts with higher-ranking law, the validity of the remaining provisions will remain unaffected. The parties agree to replace any invalid provision with a valid provision that most closely corresponds to it. The staff council agreement may be terminated no earlier than 12 months after it takes effect and, from that point on, at any time with nine months' notice. A mutually agreed-upon amendment is possible at any time. Termination and amendments have to be in writing.
(2) In light of the experimental nature of these provisions, TU Braunschweig representatives and the Staff Council will review this agreement for any necessary adjustments no later than 24 months after its entry into force and will jointly discuss and agree on the next steps—for example, during the joint meetings held pursuant to § 62 (1) of the NPersVG.
(3) Existing staff council agreements regarding productive IT processes are not affected by this staff council agreement. However, the contracting parties aim to review the existing service agreements on an ongoing basis—for example, when adjustments are needed—to determine whether they should be brought within the scope of this staff council agreement or—for example, due to their complexity—remain separate.
(4) The contracting parties agree that separate staff council agreements may be concluded for new IT processes of particular complexity, in accordance with the provisions of § 4 (4).
Braunschweig, September 21, 2022
For TU Braunschweig
The President
For the Staff Council of TU Braunschweig
The Chairperson
Note: For the definition of the appendices see § 2.
Appendix 0 Template for an agreement setting out the details of the IT framework regulations (to be completed where necessary; please consult the Staff Council beforehand)
Appendix 1 standardised checklist (to be completed)
Appendix 2 Template for a standardised outline of an operational concept (to be completed)
Appendix 3 Note on the glossary for this framework agreement
Template Project Profile (German) of the IT Multi-Project Management Board