Germany
ComprehensiveGDPR + Bundesdatenschutzgesetz (BDSG)
Authority: BfDI (Federal) + 16 State DPAs | Enforcement: Active | Enacted: May 2018
Overview
Germany has among the strictest data protection cultures in Europe. The GDPR is supplemented by the BDSG and 16 state-level data protection laws. Germany has 17 data protection authorities (1 federal + 16 state), making it one of the most enforcement-active jurisdictions. German courts have been at the forefront of GDPR interpretation.
14-Topic Coverage
Data Protection Authority
Fully AddressedBfDI oversees federal authorities and telecoms. 16 state DPAs handle private sector and state government. Known for rigorous enforcement and detailed guidance.
Consent Requirements
Fully AddressedGDPR consent rules apply strictly. BDSG adds specific provisions for employment data consent. German DPAs take strict interpretation of legitimate interests.
Data Subject Rights
Fully AddressedFull GDPR rights apply. BDSG provides some limitations for archiving, research, and public interest. Works councils have role in employee data matters.
Cross-Border Transfer
Fully AddressedGDPR transfer rules apply. German DPAs are among the strictest interpreters of Schrems II. SCCs require supplementary measures.
Breach Notification
Fully AddressedGDPR 72-hour notification applies. Additional BDSG provisions for federal agencies. State DPAs have published detailed breach handling guidance.
DPO Requirements
Fully AddressedGDPR DPO rules plus BDSG requirement: DPO mandatory when 20+ persons regularly process personal data (lower threshold than GDPR alone).
Children's Data
Fully AddressedGermany has set the GDPR Article 8 age at 16. Parental consent required for information society services targeting children.
Penalties & Enforcement
Fully AddressedActive enforcement by state DPAs. Notable fines include H&M (EUR 35.3M by Hamburg DPA for employee surveillance) and Deutsche Wohnen (EUR 14.5M by Berlin DPA).
Sector-Specific Rules
Fully AddressedTTDSG (Telecom/Telemedia Data Protection Act) for digital services. Employee data protection under BDSG Section 26. Healthcare, banking, and telecom have additional rules.
Cookie/Tracking
Fully AddressedTTDSG Section 25 implements strict cookie consent requirements. Planet49 CJEU ruling originated from German case. Active enforcement of cookie rules.
AI & Automated Decisions
Fully AddressedGDPR Article 22 rights apply. EU AI Act implementation underway. Germany active in AI governance discussions.
Data Localisation
Not AddressedNo data localisation requirement beyond GDPR transfer restrictions. Some government data may have residency requirements.
Significant Data Fiduciary
Partially AddressedNo direct equivalent. DPO requirement threshold (20+ regular data processing employees) acts as a de facto distinction for larger processors.
Government Data
Fully AddressedBDSG Part 2 governs federal public bodies. State data protection laws govern state/local government. Strict oversight by respective DPAs.
Key Statistics
- Maximum Penalty
- EUR 20 million or 4% of global turnover (GDPR)
- Sections in Law
- 86
- Authority
- BfDI + 16 State DPAs
Coverage Summary
Quick Navigation
Related Guides
Need Compliance Help?
Our data privacy team can help you navigate Germany's regulations.
Book a Consultation