
Why data protection in Germany requires a closer look
Organizations doing business in Germany have to navigate both European and German data protection laws. The EU General Data Protection Regulation (GDPR) provides the primary legal framework, while Germany’s Federal Data Protection Act (Bundesdatenschutzgesetz, or BDSG) adds national requirements in areas where the GDPR allows Member States to introduce more specific rules.
For international organizations, understanding both is essential. The GDPR can apply even when an organization is not established in the European Union, while the BDSG introduces Germany-specific considerations around areas such as employee data and the appointment of data protection officers (DPOs).
This guide explains how Germany’s data protection laws work together, the requirements organizations should understand and how emerging technologies such as artificial intelligence are adding another layer to the compliance landscape.
What data protection laws apply in Germany?
The GDPR is the primary data protection law in Germany, but it does not operate alone. Organizations may also need to comply with the BDSG and other national rules governing specific types of data processing and electronic communications.
The EU General Data Protection Regulation
The GDPR establishes the central framework for processing personal data within the EU. It defines principles for lawful processing, establishes rights for individuals, and places obligations on organizations that control or process personal data.
Important: The GDPR applies not only to companies based in the EU, but also to anyone who offers their goods or services to EU citizens.
Among other requirements, organizations need to consider principles such as lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, security, and accountability.
Individuals also receive extensive rights over their personal data, including rights of access, rectification and erasure, as well as rights relating to data portability and certain forms of automated decision-making.
The German Federal Data Protection Act
The German Federal Data Protection Act (BDSG) supplements the GDPR in areas where European law permits Member States to establish more specific national provisions.
This does not make the BDSG an alternative to the GDPR. Organizations operating in Germany generally need to assess the two together.
One of the most important examples is employee data. Article 88 GDPR allows Member States to establish more specific rules for processing personal data in the employment context. Germany uses this flexibility through Section 26 BDSG, which addresses processing for employment-related purposes.
The BDSG also contains Germany-specific provisions relating to areas including DPO appointments and the structure of data protection supervision.
Other relevant German privacy laws
Organizations operating websites, apps and other digital services should also understand Germany’s Telecommunications Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, or TDDDG).
The law was previously known as TTDSG. Its name changed in 2024 following changes to Germany’s digital-services legislation.
Among other matters, Section 25 TDDDG regulates storing information on or accessing information from an end user’s device. Consent is generally required unless an exemption applies, including where access is strictly necessary to provide a digital service explicitly requested by the user.
For organizations, this means GDPR compliance alone may not resolve every question surrounding cookies, tracking technologies and digital communications.
GDPR vs. BDSG: What is the difference?
Simply put: The GDPR establishes the EU-wide framework, while the BDSG supplements it with Germany-specific provisions where national rules are permitted.
| Area | GDPR | BDSG |
| Geographic scope | Applies throughout the EU/EEA and can apply to organizations outside the EU
| Applies within the German legal framework
|
| Primary purpose | Establishes EU-wide rules for processing personal data
| Supplements the GDPR with permitted German provisions
|
| Employee data | Allows Member States to establish more specific employment rules
| Section 26 contains specific provisions for employment-related processing
|
| DPO requirements | Requires DPOs in circumstances defined by Article 37
| Adds an additional German threshold and other triggers under Section 38
|
| Supervision | Requires independent supervisory authorities in Member States
| Establishes additional rules for Germany's federal and state-level structure
|
For businesses, the practical takeaway is straightforward: compliance with the GDPR does not automatically mean every Germany-specific obligation has been addressed.
Germany-specific data protection requirements
Several aspects of German data protection law deserve particular attention from international organizations. Employee data, DPO requirements and Germany’s decentralized supervisory structure are among the most important.
Employee data under Section 26 BDSG
Employee privacy is a particularly important consideration in Germany.
Section 26 BDSG addresses when organizations may process personal data for employment-related purposes. This can affect processes throughout the employment lifecycle, including recruitment, personnel administration, and internal investigations.
The issue becomes particularly sensitive when organizations process information about alleged misconduct, health, or other sensitive aspects of an employee’s life.
Organizations should therefore avoid treating employee data as simply another category of business information. HR, Legal, Compliance and privacy teams should understand what information is collected, why it is necessary, who can access it and how long it should be retained.
Workplace monitoring and internal investigations also require careful assessment. The existence of a legitimate business objective does not remove the need to consider proportionality, necessity, and the rights of the employees concerned.
Appointment of a DPO
Germany has an additional statutory threshold for appointing a data protection officer.
Under Section 38 BDSG, private organizations generally must appoint a DPO when they regularly employ at least 20 people who continuously perform automated processing of personal data.
However, headcount is not the only consideration. A DPO may be mandatory regardless of the number of employees, where, for example, processing activities require a data protection impact assessment under Article 35 GDPR. The GDPR itself also contains separate DPO triggers.
Organizations should therefore conduct a proper DPO assessment rather than relying solely on employee numbers.
Core compliance requirements for organizations
Effective compliance with data protection laws requires more than a privacy policy. Organizations need documented processes that connect legal requirements with everyday decisions about how personal data is collected, used, shared, retained, and deleted.
Key areas include:
Privacy by design and privacy by default
Privacy should be built into a process rather than added after implementation.
Privacy by design means considering data protection when systems, products, and processes are being developed. Teams should ask early what personal data is actually necessary, who requires access and how risks can be reduced.
Privacy by default means configuring services so that, by default, only personal data necessary for the specific purpose is processed.
For organizations introducing new technology, these principles can help prevent privacy problems from becoming embedded in systems that are difficult or expensive to change later.
Data-subject rights
Organizations need reliable processes for responding when individuals exercise their GDPR rights.
Depending on the circumstances, these may include rights to access personal data, correct inaccurate information, request deletion, restrict or object to certain processing and receive data in a portable format.
Requests generally need to be addressed without undue delay and normally within one month.
Data protection impact assessments
A data protection impact assessment (DPIA) is required when planned processing is likely to create a high risk for individuals’ rights and freedoms.
This is particularly relevant when introducing certain new technologies, conducting systematic monitoring or processing sensitive information at scale.
A DPIA should not simply document a decision that has already been made. Its purpose is to identify risks before processing begins and determine how those risks can be reduced.
Third-party processors
Using an external service provider does not eliminate an organization’s data protection responsibilities.
When a third-party processes personal data on the organization’s behalf, the organization should assess that provider and establish the contractual safeguards required by Article 28 GDPR.
That makes privacy an important component of third-party due diligence. Organizations need visibility into what data vendors receive, how they use it, where it is processed, and whether the relationship changes over time.

What happens after a personal data breach?
A personal data breach requires a quick, risk-based response. The GDPR’s 72-hour notification rule makes it particularly important to have responsibilities and escalation processes established before an incident occurs.
Organizations should:
- Assess the incident and potential impact.
- Notify the relevant supervisory authority when required.
Under Article 33 GDPR, notification must be made without undue delay and, where feasible, within 72 hours of becoming aware of a breach unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. - Inform affected individuals when required.
Where a breach is likely to result in a high risk, Article 34 can require communication to the affected individuals without undue delay. - Document the breach and response.
Fines and enforcement in Germany
GDPR violations can lead to significant financial penalties, but enforcement risk goes beyond fines.
The GDPR provides two levels of fines: If companies violate organizational obligations, penalties of up to €10 million or 2% of their global annual turnover are due. In the case of violations of fundamental principles or the rights of those affected, the fine is up to €20 million or 4% of the global annual turnover.
Organizations may also face compensation claims, remediation costs, operational disruption, and reputational damage.
Employee monitoring: €35.3 million H&M fine
In 2020, the Hamburg Commissioner for Data Protection and Freedom of Information imposed a €35.3 million fine on H&M following extensive monitoring of employees at its Nuremberg service center.
According to the authority, information about employees’ private lives – including health information and family circumstances – had been extensively recorded and stored. Some of the information was collected following employee absences through so-called “Welcome Back Talks.”
The practical lesson extends beyond the size of the penalty: employee information requires clear limits, appropriate access controls and a defensible purpose for processing.
Advertising without valid consent
German enforcement has also addressed the use of personal data for marketing without appropriate consent.
In one case, a Baden-Württemberg health insurer was fined approximately €1.24 million after personal information collected in connection with a prize draw was used for advertising purposes without valid consent.
For organizations, the lesson is to understand the legal basis for each processing purpose. Data collected lawfully for one purpose cannot automatically be repurposed for another.
How do GDPR and the EU AI Act work together?
Organizations using artificial intelligence in Germany may need to comply with both data protection law and the EU AI Act. The AI Act does not replace the GDPR, and using an AI system does not remove existing obligations governing personal data.
This overlap is particularly important when AI systems process employee, customer or other identifiable information.
Lawful basis, transparency and data minimization
The use of AI does not create a new lawful basis for processing personal data.
Organizations still need to establish why personal data can lawfully be processed and consider GDPR principles such as transparency, purpose limitation, and data minimization.
Automated decision-making
Article 22 GDPR establishes protections relating to decisions based solely on automated processing that produce legal or similarly significant effects on individuals, subject to specified exceptions.
Organizations using AI for areas such as recruitment, employee management or customer decisions therefore need to determine whether automated decision-making rules apply and what safeguards are required.
Human oversight should be meaningful rather than simply procedural.
DPIAs and high-risk processing
AI deployments can also trigger the need for a DPIA where processing is likely to result in a high risk for individuals.
Organizations should assess privacy implications before deployment, particularly when AI is used for systematic evaluation, monitoring, or processing sensitive personal information.
Separately, the EU AI Act introduces requirements for AI systems based on their risk classification. Organizations should therefore avoid treating an AI Act risk assessment and a GDPR DPIA as interchangeable exercises: they address overlapping but distinct regulatory requirements.
AI literacy and human oversight
The AI Act also places growing emphasis on the people who develop, deploy, and use AI.
Article 4 requires providers and deployers of AI systems to take measures to support the development of sufficient AI literacy among staff and others operating AI systems on their behalf, taking account of factors such as knowledge, experience and the context of use.
Organizations should continue monitoring the implementation and enforcement of the AI Act in Germany as responsibilities and supervisory arrangements evolve.
Data protection compliance checklist
Germany’s data protection framework rewards preparation. Organizations should be able to demonstrate not only that policies exist, but that the processes behind them work consistently.
Use this checklist as a starting point:
- Map personal data
- Document lawful bases
- Maintain clear privacy notices.
- Review employee data controls
- Assess DPO obligations.
- Review processors.
- Identify high-risk processing
- Prepare for rights requests
- Maintain a breach-response process
- Review international transfers
- Integrate AI governance
- Document compliance decisions
The objective is not simply to produce more documentation. It is to create repeatable processes that allow the organization to demonstrate accountability when regulators, employees, customers, or business partners ask how personal data is protected.
Make data protection part of the wider compliance program
Data protection in Germany is not a one-time legal exercise. Organizations need to manage changing processing activities, employee information, third parties, incidents, and emerging technologies while maintaining evidence that their controls work in practice.
The most resilient approach connects privacy requirements with the wider compliance program – including policies, training, incident management, third-party oversight and governance.
GRC Software Platform for Complete Confidence | NAVEX One®
NAVEX One is an AI-powered GRC platform that unifies your compliance program. Manage risk, training, whistleblowing, policies and disclosures in one powerful tool.

Frequently asked questions
Does GDPR apply in Germany?
Yes. The GDPR applies directly in Germany as an EU regulation and provides the country’s primary framework for protecting personal data.
International organizations may fall within the GDPR’s territorial scope even without an EU establishment when the relevant conditions under Article 3 are met.
What is the German Federal Data Protection Act?
The Bundesdatenschutzgesetz (BDSG) is Germany’s Federal Data Protection Act. It supplements the GDPR in areas where EU law allows Member States to introduce national provisions.
What is the difference between GDPR and BDSG?
The GDPR is the EU-wide data protection framework, while the BDSG contains supplementary German rules.
When is a DPO required in Germany?
A DPO is required whenever the relevant conditions under the GDPR or BDSG are met.
For private organizations, Section 38 BDSG adds a requirement where the organization generally employs at least 20 people continuously engaged in automated processing of personal data. Other triggers can make a DPO mandatory regardless of that threshold, including certain processing requiring a DPIA.
Must every German data breach be reported?
No. A personal data breach does not automatically require notification to the supervisory authority.
Under Article 33 GDPR, notification is generally required unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. Where notification is required, it must be made without undue delay and, where feasible, within 72 hours after the organization becomes aware of the breach. If the breach is likely to create a high risk, affected individuals may also need to be informed.


