Datenschutz in Germany: The DSGVO, the BDSG and Who Enforces Them

Germany applies the DSGVO, the same regulation as every other EU member state, and then adds its own national layer on top of it. Understanding that this is two layers rather than one is what makes the rest of German data protection legible, and it is where most English-language explanations stop too early.
The regulation sets the substance: the lawful bases, the rights of the individual, the obligations of a controller. The Bundesdatenschutzgesetz then fills the gaps the regulation deliberately left to member states, and it is the BDSG, not the DSGVO, that answers several of the questions people actually search for. When must a German business appoint a Datenschutzbeauftragter. Which authority supervises it. What a purely national fine attaches to.
Information last verified on 20 July 2026. This page provides general legal information and does not constitute legal advice in an individual case.
The two layers, and which one answers your question
The DSGVO applies directly. It is not transposed into German law, and there is no German statute that restates it. So when a rule comes from the regulation, the citation is to an Artikel: Art. 15 DSGVO for the right of access, Art. 28 DSGVO for processor contracts.
The Bundesdatenschutzgesetz sits alongside it and is cited with the section sign, as § 38 BDSG or § 40 BDSG. It does not repeat the regulation. It occupies the openings the regulation left, and it governs areas the regulation does not reach at all, such as processing for police and criminal justice purposes.
That division is why a question can look like a DSGVO question and have a German answer. Whether a company must appoint a data protection officer is the clearest example: the DSGVO sets grounds that apply everywhere, and then § 38 BDSG adds a German threshold that catches far more organisations than the regulation alone would.
Who supervises whom
This is the single most useful thing on this page, because the widely repeated version of it is wrong.
Germany does not have one data protection regulator, and the BfDI and the seventeen Land authorities do not enforce jointly. The split is drawn by statute and by entity type. § 40 Abs. 1 BDSG puts non-public bodies under the supervision of the Land authorities, which means essentially the whole private economy. § 9 Abs. 1 BDSG confines the BfDI to federal public bodies plus telecommunications processing.
So for an ordinary German company, a shop, an agency, a landlord, an employer, the competent authority is the one for the Land where it is established. Not the BfDI. Complaining to the wrong authority does not destroy a complaint, but it costs time.
Read the full page: who supervises whom, and how a complaint works.
The Datenschutzbeauftragter, and the limb everyone forgets
§ 38 BDSG is usually summarised as the twenty-person rule, and that summary is incomplete in a way that matters.
The first limb is the headcount: a non-public body that permanently employs at least twenty people in the automated processing of personal data must appoint a Datenschutzbeauftragter. The second limb ignores headcount completely and turns instead on what the organisation does, including processing that requires a Datenschutz-Folgenabschätzung and commercial processing for the purpose of transfer or for market and opinion research.
A three-person business can therefore be obliged to appoint one. Reading only the first limb is how an organisation concludes it is exempt when it is not.
Read the full page: when German law requires a Datenschutzbeauftragter.
The right of access
Art. 15 DSGVO gives any person the right to ask an organisation whether it processes their data and, if so, to receive it along with a defined set of information about the processing.
It needs no form and no reason, and it costs nothing. The controller has one month to respond, extendable by two further months where the request is complex or where there are many of them, and a fee or a refusal is possible only for a manifestly unfounded or excessive request.
Read the full page: what a company must actually hand over.
Processor contracts
Where one organisation processes personal data on another's instructions, Art. 28 DSGVO requires a written contract, the Auftragsverarbeitungsvertrag. Almost every German business has several without thinking about it, because ordinary business software usually involves one.
The recurring mistake is not the drafting. It is the classification: deciding whether the other party is a processor acting on instructions or an independent controller making its own decisions. Get that wrong and the contract is the wrong instrument for the relationship.
Read the full page: when an AVV is required and what it must contain.
What a breach costs, stated carefully
The DSGVO sets two distinct fine tiers, in Art. 83 Abs. 4 and Art. 83 Abs. 5, with the higher tier reserved for breaches of the core principles and of the rights of the individual. This page does not quote the ceilings, because the official EU text could not be retrieved at the time of verification and we do not restate figures from secondary sources.
Separately, § 43 BDSG is a purely national fine capped at 50.000 Euro. It is narrow: it attaches to mishandled Auskunftei requests under § 30 BDSG, and § 43 Abs. 3 BDSG excludes public bodies from it altogether. It is frequently quoted as though it were the general German data protection penalty. It is not, and treating it as the ceiling would badly understate the exposure under the regulation.
Where this connects to the rest of the site
Data protection is one of three separate regimes that can apply to a single act of recording or observation. The other two are the criminal protection of the spoken word and the image, and the civil personality right.
| The question | Where it is answered |
|---|---|
| Is it a criminal offence to record this | § 201 StGB and the recording cluster |
| Can a camera at work be lawful | workplace surveillance |
| Can a neighbour point a camera at my garden | neighbour surveillance cameras |
| Is a secret recording usable in court | secret recordings as evidence |
| Was a false statement about me unlawful | the defamation cluster |
For the wider picture of German law, courts and other legal topics, see German law explained.
Frequently asked questions
Frequently Asked Questions
Does the DSGVO or German law apply in Germany?
Both. The DSGVO applies directly and sets the substance. The Bundesdatenschutzgesetz fills the openings the regulation left to member states and governs areas the regulation does not reach. Several of the most searched German questions, including when a Datenschutzbeauftragter is required and which authority supervises a business, are answered by the BDSG rather than by the regulation.
Which data protection authority is responsible for my company?
For a private company, the authority of the Land where it is established. Under 40 Abs. 1 BDSG the seventeen Land authorities supervise non-public bodies, which covers essentially the whole private economy. The BfDI supervises federal public bodies plus telecommunications processing under 9 Abs. 1 BDSG. The common claim that the BfDI and the Land authorities enforce jointly is inaccurate and sends people to the wrong desk.
Does a small company need a Datenschutzbeauftragter?
It depends on both limbs of 38 BDSG, not just the headcount. The first limb catches a non-public body permanently employing at least twenty people in automated processing. The second limb ignores headcount entirely and turns on the nature of the processing, so a very small organisation can still fall within it. The DSGVO adds its own grounds that apply regardless of the German threshold.
How long does a company have to answer a data request?
One month, extendable by two further months where the request is complex or where the controller has received many requests. The request needs no particular form, no reason and no fee, and a fee or refusal is possible only where a request is manifestly unfounded or excessive.
What is the maximum fine under German data protection law?
The DSGVO sets two distinct tiers in Art. 83 Abs. 4 and Abs. 5, with the higher tier reserved for breaches of the core principles and of individual rights. This page does not restate the ceilings because the official EU text could not be retrieved at the time of verification. Note separately that the 50.000 Euro figure in 43 BDSG is a narrow national fine tied to mishandled Auskunftei requests, not the general ceiling.
Do I need a lawyer to complain to a data protection authority?
No. A Datenschutzbeschwerde is free and requires no lawyer. It is a regulatory process rather than a claim, so it can lead the authority to investigate and to act against the organisation, but it is not itself a route to compensation. A damages claim is a separate matter for the civil courts.
What is an Auftragsverarbeitungsvertrag and when do I need one?
It is the contract Art. 28 DSGVO requires where one organisation processes personal data on another's instructions. Most businesses need several, because ordinary business software usually creates that relationship. The recurring mistake is classifying the other party wrongly, treating an independent controller as a processor or the reverse, rather than any defect in the drafting.
Is the German employee data protection law about to change?
No change is in force and none is imminent. 26 BDSG remains on the books, though the Court of Justice held in C-34/21 that a national general clause of this kind is not a more specific rule for the purposes of the regulation. The proposed Beschäftigtendatengesetz did not advance: the draft lapsed with the previous coalition and the project does not appear in the current coalition agreement.
Sources and References
- § 9 BDSG, Zuständigkeit der oder des Bundesbeauftragten(gesetze-im-internet.de).gov
- § 38 BDSG, Datenschutzbeauftragte nicht-öffentlicher Stellen(gesetze-im-internet.de).gov
- § 40 BDSG, Aufsichtsbehörden der Länder(gesetze-im-internet.de).gov
- § 30 BDSG, Verbraucherkredite und Auskunfteien(gesetze-im-internet.de).gov
- § 43 BDSG, Bußgeldvorschriften(gesetze-im-internet.de).gov
- § 26 BDSG, Datenverarbeitung für Zwecke des Beschäftigungsverhältnisses(gesetze-im-internet.de).gov
- § 34 BDSG, Auskunftsrecht der betroffenen Person(gesetze-im-internet.de).gov
- Bundesdatenschutzgesetz (BDSG), Gesamttext(gesetze-im-internet.de).gov
- Bundesbeauftragte für den Datenschutz und die Informationsfreiheit, Zuständigkeiten(bfdi.bund.de).gov