Law / Germany

Germany

privacy

Germany's private-sector regime is the General Data Protection Regulation (GDPR) plus the Bundesdatenschutzgesetz (BDSG), BGBl. I S. 2097 (2017) as amended.

The BDSG's most consequential addition on top of GDPR is Section 26, which supplies Germany's employee-data regime and specifically constrains how biometric data may be processed in employment, and a fragmented, 17-authority enforcement structure, the federal BfDI plus 16 state Landesdatenschutzbehorden, that has no equivalent among the other GDPR-family jurisdictions in this wave.

18 instruments named 6 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

GDPR Articles 33-34, Breach Notification in Germany

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

A controller must notify the competent Landesdatenschutzbehorde, or the BfDI for the federal public sector and telecommunications and postal providers, without undue delay and within 72 hours where feasible, after becoming aware of a personal data breach, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No BDSG derogation from this timeline was identified.

What it asks of an app

Comprehensive regime

Bundesdatenschutzgesetz (BDSG), Federal Data Protection Act

cite Bundesdatenschutzgesetz (BDSG), BGBl. I S. 2097 (2017), as amended stage In effect since 2018-05-25 source Gesetze im Internet (official federal law portal), consolidated BDSG text

The General Data Protection Regulation (GDPR) applies directly in Germany, and the Bundesdatenschutzgesetz (BDSG), BGBl. I S. 2097 (2017) as amended, supplies domestic derogations and procedural rules, most significantly Section 26 (employment data) and Sections 31 and 37 (credit-scoring automated decisions). Lawful bases otherwise follow GDPR Article 6 unmodified.

Enforcement is fragmented across 17 separate authorities: the federal BfDI, whose jurisdiction is limited to the federal public sector, telecommunications carriers, and postal providers, and 16 state Landesdatenschutzbehorden, which supervise the private sector and are each independent of the BfDI and of their own state government.

What it asks of an app

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Germany

cite Regulation (EU) 2016/679, Arts. 44-49 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

Transferring personal data of a person in Germany outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the highest Article 83(5) fine tier. The BfDI publishes its own guidance on international transfers but adds no additional national restriction layer beyond General Data Protection Regulation (GDPR). This is a real, structured condition on outbound transfer, not an absence of restriction.

What it asks of an app

Data subject rights

GDPR Article 22 and BDSG Sections 31 and 37, Automated Decisions and Credit Scoring in Germany

cite Regulation (EU) 2016/679, Art. 22; Bundesdatenschutzgesetz (BDSG) §§31, 37 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

General Data Protection Regulation (GDPR) Articles 12 to 23 apply, including Article 22 rights against solely automated decision-making. BDSG Section 31 supplements this for credit-reporting and scoring agencies specifically.

The CJEU's SCHUFA ruling, Case C-634/21 (OQ v Land Hessen, judgment 7 December 2023), held that automated credit-score generation used determinatively by a third party such as a bank constitutes a decision based solely on automated processing within Article 22(1), which cast doubt on BDSG Section 31's compatibility with the narrow exceptions in Article 22(2)(b). No subsequent German court ruling resolving the Wiesbaden Administrative Court's remand from that reference was found in this research.

What it asks of an app

Enforcement supervision

GDPR Article 82, BDSG Sections 41-43, and BfDI and Landesdatenschutzbehorden Enforcement in Germany

cite Regulation (EU) 2016/679, Arts. 82-83; Bundesdatenschutzgesetz (BDSG) §§41-43 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

Germany's enforcement structure is 17 separate authorities: the federal BfDI and 16 state Landesdatenschutzbehorden, coordinated on fine calculation by the Datenschutzkonferenz's shared fining model.

BDSG Sections 41 to 43 add domestic criminal offenses on top of General Data Protection Regulation (GDPR) Article 83's administrative fine regime; total BfDI and state fines reached roughly EUR 160 million from 2018 to 2024, with the largest single BfDI action to date, against Vodafone GmbH, totaling EUR 45 million across two March 2025 decisions. Article 82 arms an individual directly, on the same no-seriousness-threshold terms established EU-wide by CJEU C-300/21.

Germany also has a functioning collective-redress channel: the CJEU (Case C-319/20, Verbraucherzentrale Bundesverband v Meta Platforms Ireland) held that Article 80(2) does not preclude a national provision letting consumer-protection associations sue for a GDPR violation without an individual data subject's mandate, and Germany's Verbraucherrechtedurchsetzungsgesetz (VDuG) lets the Verbraucherzentralen bring representative actions on behalf of an unlimited group of consumers for an infringement affecting at least 50 consumers.

What it asks of an app

Sensitive categories

GDPR Article 9 and BDSG Section 26(3), Special Categories and Employment Biometric Data in Germany

cite Regulation (EU) 2016/679, Art. 9; Bundesdatenschutzgesetz (BDSG) §26(3) stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

General Data Protection Regulation (GDPR) Article 9(1) governs biometric data as a special category. BDSG Section 26(3), the provision governing special category data in employment, was upheld as GDPR-compatible and is the controlling provision for a workplace-deployed biometric time clock, access control, or voice-authentication system; Section 26(1), the general employment lawful-basis clause, was found incompatible with GDPR's own conditions and cannot be relied on alone.

Consent is disfavored as the legal basis in an employment relationship because of the power imbalance, so employers typically rely on necessity under Section 26(3) or Article 9(2) rather than Article 9(2)(a) consent. A voiceprint or faceprint captured for identification is covered identically to a fingerprint; GDPR draws no distinction by modality.

Germany's leading biometric enforcement precedent is the Hamburg Commissioner for Data Protection and Freedom of Information's 2021 order against Clearview AI to delete a German complainant's biometric identifier, the first such order against Clearview worldwide.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.