Data Protection Atlas

Germany

Tier 1 Comprehensive law Europe

Germany applies the GDPR (cross-refer instrument id gdpr) supplemented by the federal BDSG and 16 Land data protection acts. It is the canonical Pattern 3 jurisdiction: the substantive private-sector law does not fork, but the regulator does — 16 Land authorities plus the federal BfDI, with competence split by establishment and sector. Germany is also a rare EU member imposing criminal data-protection offences that can carry imprisonment, and sets a stricter headcount-based DPO trigger than the GDPR requires.

At a glance

Principal law
GDPR supplemented by the Bundesdatenschutzgesetz (BDSG) and 16 Land acts
Regulator
16 Land data protection authorities plus the federal BfDI
Maximum penalty
GDPR ceiling (higher of EUR 20m or 4% global turnover); plus BDSG sec. 42 criminal penalties up to 3 years' imprisonment
DPO required
Yes — at 20+ persons in automated processing (sec. 38 BDSG), stricter than GDPR
National implementing act
Bundesdatenschutzgesetz (BDSG) 2017

Structure

Structural pattern
Pattern 3 — uniform private law, devolved public sector
Sub-jurisdictions
0 (regulator-and-public-sector-only)
ISO code
DE

Regulators

Transfers and adequacy

EU member
Yes
EEA member
Yes
Holds EU adequacy
Yes

Intra-EU; not a third country. GDPR applies directly.

Instruments

Sources

Never independently verified — seeded from the prototype.