Law note · Germany

GDPR Article 82, BDSG Sections 41-43, and BfDI and Landesdatenschutzbehorden Enforcement in Germany

cite Regulation (EU) 2016/679, Arts. 82-83; Bundesdatenschutzgesetz (BDSG) §§41-43 stage In effect since 2018-05-25 reviewed 2026-08-24

Germany's enforcement structure is 17 separate authorities: the federal BfDI and 16 state Landesdatenschutzbehorden, coordinated on fine calculation by the Datenschutzkonferenz's shared fining model.

BDSG Sections 41 to 43 add domestic criminal offenses on top of General Data Protection Regulation (GDPR) Article 83's administrative fine regime; total BfDI and state fines reached roughly EUR 160 million from 2018 to 2024, with the largest single BfDI action to date, against Vodafone GmbH, totaling EUR 45 million across two March 2025 decisions. Article 82 arms an individual directly, on the same no-seriousness-threshold terms established EU-wide by CJEU C-300/21.

Germany also has a functioning collective-redress channel: the CJEU (Case C-319/20, Verbraucherzentrale Bundesverband v Meta Platforms Ireland) held that Article 80(2) does not preclude a national provision letting consumer-protection associations sue for a GDPR violation without an individual data subject's mandate, and Germany's Verbraucherrechtedurchsetzungsgesetz (VDuG) lets the Verbraucherzentralen bring representative actions on behalf of an unlimited group of consumers for an infringement affecting at least 50 consumers.

What it asks of an app

  • Expect a German data protection authority to have jurisdiction and fining power, up to the higher of EUR 20,000,000 or 4 percent of global annual turnover, over your processing of personal data of a person in Germany.
  • Expect any person who suffered material or non-material damage from an infringement to have a direct right to claim compensation from you as controller or processor, under General Data Protection Regulation (GDPR) Article 82, and expect a qualifying consumer-protection association to be able to bring a representative claim on behalf of a group of affected consumers under the VDuG.

When LexLint raises it

Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics

Primary source: Official Journal text, EUR-Lex, Regulation (EU) 2016/679
BDSG §§41-43; CJEU C-319/20; VDuG

← Back to the example  ·  Lint your app →