Law note · Germany

Bundesdatenschutzgesetz (BDSG), Federal Data Protection Act

cite Bundesdatenschutzgesetz (BDSG), BGBl. I S. 2097 (2017), as amended stage In effect since 2018-05-25 reviewed 2026-08-24

The General Data Protection Regulation (GDPR) applies directly in Germany, and the Bundesdatenschutzgesetz (BDSG), BGBl. I S. 2097 (2017) as amended, supplies domestic derogations and procedural rules, most significantly Section 26 (employment data) and Sections 31 and 37 (credit-scoring automated decisions). Lawful bases otherwise follow GDPR Article 6 unmodified.

Enforcement is fragmented across 17 separate authorities: the federal BfDI, whose jurisdiction is limited to the federal public sector, telecommunications carriers, and postal providers, and 16 state Landesdatenschutzbehorden, which supervise the private sector and are each independent of the BfDI and of their own state government.

What it asks of an app

  • Establish and document a lawful basis under General Data Protection Regulation (GDPR) Article 6 before processing any personal data of a person in Germany.
  • Where you process employee data, including biometric data for workplace access or time and attendance, satisfy BDSG Section 26(3)'s stricter conditions rather than relying on employee consent alone.

When LexLint raises it

Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics

Primary source: Gesetze im Internet (official federal law portal), consolidated BDSG text

← Back to the example  ·  Lint your app →