Germany

Comprehensive

GDPR + Bundesdatenschutzgesetz (BDSG)

Authority: BfDI (Federal) + 16 State DPAs | Enforcement: Active | Enacted: May 2018

Overview

Germany has among the strictest data protection cultures in Europe. The GDPR is supplemented by the BDSG and 16 state-level data protection laws. Germany has 17 data protection authorities (1 federal + 16 state), making it one of the most enforcement-active jurisdictions. German courts have been at the forefront of GDPR interpretation.

14-Topic Coverage

Data Protection Authority

Fully Addressed

BfDI oversees federal authorities and telecoms. 16 state DPAs handle private sector and state government. Known for rigorous enforcement and detailed guidance.

BDSG Part 3, GDPR Articles 51-59

Data Subject Rights

Fully Addressed

Full GDPR rights apply. BDSG provides some limitations for archiving, research, and public interest. Works councils have role in employee data matters.

GDPR Articles 12-22, BDSG Sections 32-37

Cross-Border Transfer

Fully Addressed

GDPR transfer rules apply. German DPAs are among the strictest interpreters of Schrems II. SCCs require supplementary measures.

GDPR Chapter V, BDSG Section 78

Breach Notification

Fully Addressed

GDPR 72-hour notification applies. Additional BDSG provisions for federal agencies. State DPAs have published detailed breach handling guidance.

GDPR Articles 33-34, BDSG Section 65

DPO Requirements

Fully Addressed

GDPR DPO rules plus BDSG requirement: DPO mandatory when 20+ persons regularly process personal data (lower threshold than GDPR alone).

GDPR Articles 37-39, BDSG Section 38

Children's Data

Fully Addressed

Germany has set the GDPR Article 8 age at 16. Parental consent required for information society services targeting children.

GDPR Article 8 (no German derogation — 16 default applies)

Penalties & Enforcement

Fully Addressed

Active enforcement by state DPAs. Notable fines include H&M (EUR 35.3M by Hamburg DPA for employee surveillance) and Deutsche Wohnen (EUR 14.5M by Berlin DPA).

GDPR Article 83, BDSG Sections 41-43

Sector-Specific Rules

Fully Addressed

TTDSG (Telecom/Telemedia Data Protection Act) for digital services. Employee data protection under BDSG Section 26. Healthcare, banking, and telecom have additional rules.

TTDSG, BDSG Section 26

AI & Automated Decisions

Fully Addressed

GDPR Article 22 rights apply. EU AI Act implementation underway. Germany active in AI governance discussions.

GDPR Article 22, EU AI Act

Data Localisation

Not Addressed

No data localisation requirement beyond GDPR transfer restrictions. Some government data may have residency requirements.

GDPR Chapter V

Significant Data Fiduciary

Partially Addressed

No direct equivalent. DPO requirement threshold (20+ regular data processing employees) acts as a de facto distinction for larger processors.

BDSG Section 38

Government Data

Fully Addressed

BDSG Part 2 governs federal public bodies. State data protection laws govern state/local government. Strict oversight by respective DPAs.

BDSG Part 2, State DPA laws

Key Statistics

Maximum Penalty
EUR 20 million or 4% of global turnover (GDPR)
Sections in Law
86
Authority
BfDI + 16 State DPAs

Coverage Summary

Fully Addressed12/14
Partially Addressed1/14
Not Addressed1/14
Pending0/14

Need Compliance Help?

Our data privacy team can help you navigate Germany's regulations.

Book a Consultation