Data Protection Atlas

Bundesdatenschutzgesetz (Federal Data Protection Act)

Tier 1 In force

The BDSG is Germany's federal act implementing and supplementing the GDPR (cross-refer instrument id gdpr). It exercises the GDPR's opening clauses to set stricter or additional national rules — most notably a headcount-based DPO trigger the GDPR does not impose, detailed employee-data rules, and, unusually for the EU, criminal offences that can carry custody. The regulatory architecture is the German outlier: substantive private-sector law does not fork, but supervision is split across 16 Land authorities plus the federal BfDI, with jurisdiction allocated by establishment and sector.

Identity

Citation
BDSG of 30 June 2017 (BGBl. I p. 2097), as amended
Jurisdiction
Germany
Type
implementing
Structure
Four Parts covering general provisions, GDPR implementation, Law Enforcement Directive implementation, and special provisions.
Royal assent
30 June 2017
Main commencement
25 May 2018

Entered into force alongside the GDPR on 25 May 2018, replacing the previous BDSG.

← Germany overview

Reads together with

  • GDPR (Regulation (EU) 2016/679)

    The BDSG supplements the directly-applicable GDPR; it does not restate it. Cross-refer instrument id gdpr.

Asymmetry checklist

All ten points answered explicitly. "None found — checked" is a recorded answer, not a gap.

# Point Finding Notes
1 Territorial extent Asymmetry found The substantive law applies uniformly across the Federal Republic, but supervisory competence is territorially and sectorally divided: each of the 16 Länder has its own data protection authority for the private and public sectors in that state, while the federal BfDI supervises federal public bodies and the telecommunications and postal sectors. A company's lead authority is generally the authority of the Land in which it is established.
2 Commencement None found — checked Fully in force since 25 May 2018; no material pending-commencement asymmetry identified.
3 Sunset / mandatory review None found — checked No sunset or mandatory review clause identified.
4 Criminal liability Asymmetry found Section 42 BDSG creates criminal offences and, unlike the UK, custody IS available. Section 42(1) provides imprisonment of up to three years or a fine for knowingly transferring, without authorisation, personal data of a large number of people that is not publicly accessible, for commercial purposes; section 42(2) provides imprisonment of up to two years or a fine for processing non-public personal data without authorisation, or obtaining it by deception, for payment or with intent to enrich or harm. Offences are prosecuted only on complaint (by the data subject, controller, BfDI or supervisory authority).
5 Civil liability None found — checked Compensation flows principally from Article 82 GDPR; the BDSG does not create a separate private right of action beyond the GDPR baseline.
6 Regulatory enforcement toolkit Asymmetry found Administrative fines follow the GDPR ceiling (higher of EUR 20m or 4% of global turnover). The distinctive feature is institutional: enforcement is exercised by the competent Land authority or the BfDI depending on establishment and sector, not by a single national regulator.
7 Personal / director liability Asymmetry found Section 42 offences attach to natural persons who carry out the prohibited conduct, so individuals (including staff and officers) can face personal criminal liability, including imprisonment.
8 Public vs private sector split Asymmetry found The split is regulatory, not substantive. Private-sector data protection law is uniform nationwide, but supervision divides: Land authorities for private and Land-public bodies; BfDI for federal public bodies and the telecoms/postal sectors. This is the defining feature of Pattern 3 (uniform-private-devolved-public).
9 Legal-person coverage None found — checked Protects natural persons only, consistent with the GDPR.
10 Exemptions — with conditions Asymmetry found The BDSG's exemption regime operationalises the GDPR's opening clauses: research, statistics and archiving derogations conditional on safeguards (ss. 27-28), restrictions on transparency and data subject rights for disproportionate effort or statutory retention (ss. 32-37), employment processing (s. 26) and professional secrecy (s. 29). Triggers are necessity and proportionality conditions set nationally under Articles 23, 85 and 89 GDPR, applied case by case. The s. 26 employment provisions are under CJEU-driven doubt (see liveIssues), so that exemption's continuing scope is unsettled.

Regulatory enforcement

Penalty ceiling
GDPR administrative fines (higher of EUR 20m or 4% of global annual turnover). Separately, section 42 BDSG criminal penalties: up to three years' imprisonment or a fine (sec. 42(1)); up to two years or a fine (sec. 42(2)).

Exemptions

Recorded with their trigger conditions, not as bare names — most are conditional tests applied case by case rather than blanket carve-outs.

sec. 26 BDSG — Employee data processing

Trigger

Permits processing of employee personal data where necessary for decisions on establishing, carrying out or terminating the employment relationship, or to exercise rights/obligations under collective agreements. Necessity is assessed case by case; special rules apply to detecting criminal offences (documented suspicion, necessity, proportionality). The Court of Justice has cast doubt on the compatibility of the German employee-data provisions with the GDPR, so the current position is unsettled.

Following CJEU scrutiny, reliance on section 26 as an independent legal basis should be treated with caution.

sec. 38 BDSG — Mandatory DPO threshold

Trigger

A German outlier: a controller or processor must appoint a DPO where it constantly employs, as a rule, at least 20 persons dealing with the automated processing of personal data — a headcount trigger the GDPR does not impose. Below 20, a DPO is still required where processing is subject to a DPIA, or where personal data is processed commercially for transfer, anonymised transfer, or market or opinion research.

"Automated processing" is read broadly by German authorities to cover essentially any employee working with a computer.

Live issues

Sources

Never independently verified — seeded from the prototype.