Datenschutzbehörde: Which German Data Protection Authority Is Competent

Germany has no single data protection regulator. It has a federal one and seventeen Land level ones, and the line between them is not a matter of practice or convenience. It is drawn in the Bundesdatenschutzgesetz, by entity type, and it decides which desk a complaint or a notification has to go to.
The version of this that circulates in English is that the BfDI and the Land authorities enforce German data protection law jointly. That description is wrong in the way that matters. § 40 Abs. 1 BDSG gives supervision of nichtöffentliche Stellen, non-public bodies, to the competent authorities of the Länder. § 9 Abs. 1 BDSG confines the Bundesbeauftragte für den Datenschutz und die Informationsfreiheit to federal public bodies and to a defined slice of telecommunications processing.
The practical consequence is blunt. For almost any German company, the competent regulator is the Land authority where the company is established, and the BfDI is not competent at all. Sending a complaint about a private employer, a webshop or a landlord to the BfDI sends it to the wrong desk.
There is also a counting trap in the usual summary. Germany has sixteen Länder but seventeen Land level data protection authorities, because Bavaria runs two of them, split by the same public and non-public logic that runs through the rest of this page.
This page sets out the statutory split, a rule for working out which authority is competent for a given organisation, the seventeen Land authorities by name, the bodies that sit outside the system entirely, and what a Datenschutzbeschwerde is and is not.
Information last verified on 20 July 2026. This page provides general legal information and does not constitute legal advice in an individual case.
The split is by entity type, and it is statutory
Start with the two sections, because everything else follows from them.
§ 40 Abs. 1 BDSG, headed Aufsichtsbehörden der Länder, provides that the competent authorities of the Länder supervise the application of data protection rules at nichtöffentliche Stellen within the scope of the DSGVO. Nichtöffentliche Stellen are defined in § 2 Abs. 4 BDSG as natural and legal persons, companies and other associations of persons under private law. That is essentially the entire private economy: the GmbH, the AG, the sole trader, the association, the private practice, the private landlord acting commercially.
§ 9 Abs. 1 BDSG then sets the federal side. The BfDI is competent for supervision of the öffentliche Stellen des Bundes, the public bodies of the Federation, including where they take part in competition as undertakings governed by public law, and over undertakings to the extent that they process data of natural or legal persons for the commercial provision of telecommunications services and competence does not already follow from § 29 des Telekommunikation-Digitale-Dienste-Datenschutz-Gesetzes.
The BfDI describes its own remit in the same terms and fills in the detail. On its tasks page it presents itself as the data protection supervisory authority over all public bodies of the Federation, and names in addition certain social security institutions, the tax authorities, and telecommunications and postal undertakings in respect of the services they provide. That is a wider list than the bare statutory wording suggests, but it is still a list of federal public bodies plus two regulated network sectors. It is not the private economy.
Read the two together and the picture is a split, not a shared jurisdiction. Federal public bodies and a defined telecommunications carve out go to the BfDI. The private economy goes to the Land authorities. Public bodies of a Land go to that Land's own authority under Land data protection law.
There is even an express exclusion on the federal side. § 9 Abs. 2 BDSG states that the BfDI is not competent for supervision of processing carried out by the federal courts in the exercise of their judicial activity. Judicial activity is supervised through the judicial system, not by the data protection regulator.
So the Land authorities are not junior partners of a national regulator. In the field almost every reader cares about, private sector processing, they are the only regulator, and the BfDI has no supervisory role over the company at all.
Why the joint enforcement version keeps getting repeated
Two things feed the confusion, and both are real.
The first is that the BfDI is genuinely the most visible data protection body in Germany. It publishes an annual report, it appears in national media, it sits on the European Data Protection Board, and it is the authority people can name. Visibility is not competence.
The second is that the authorities do work together, and § 18 BDSG says so. § 18 Abs. 1 BDSG requires the BfDI and the Land authorities to cooperate in matters of the European Union with the aim of a uniform application of the DSGVO and of Directive (EU) 2016/680, and it provides for a common position to be agreed before it is passed on. § 18 Abs. 2 BDSG sets out what happens when they cannot agree, including a vote in which the Federation and each Land have one vote each and abstentions are not counted.
Cooperation on a common position is not the same as concurrent jurisdiction over a company. § 18 BDSG coordinates how the German authorities speak in Europe. It does not move a Bavarian retailer onto the BfDI's desk.
Working out which authority is competent
For an organisation, the sequence is short.
First, ask whether the body is public or non-public in the sense of § 2 BDSG. A federal public body goes to the BfDI under § 9 Abs. 1 BDSG. A public body of a Land goes to that Land's supervisory authority under that Land's own data protection act.
Second, if the body is non-public, § 40 Abs. 1 BDSG puts it under the Land authorities, and the question becomes which Land. The ordinary answer is the Land in which the organisation is established.
Third, deal with the organisation that has sites in more than one Land. § 40 Abs. 2 Satz 1 BDSG provides that where there are several domestic establishments, Art. 4 Nr. 16 DSGVO applies accordingly. That article is the DSGVO definition of the main establishment, and § 40 Abs. 2 BDSG imports it verbatim for the purely domestic case. The effect is that a company with branches in five Länder does not answer to five regulators for the same processing. The authority of the Land containing the main establishment leads.
Fourth, there is a tie breaker built into the statute for the case where that still does not settle it. § 40 Abs. 2 Satz 2 BDSG provides that where several authorities consider themselves competent or not competent, or where competence is doubtful for other reasons, the authorities take a joint decision under § 18 Abs. 2 BDSG. The reader does not have to solve a competence dispute; the statute makes the authorities solve it between themselves.
A worked example. A GmbH has its registered office and management in Stuttgart, a warehouse in Rheinland-Pfalz and a small sales office in Sachsen. The processing decisions about customer and staff data are taken in Stuttgart. Baden-Württemberg contains the main establishment for the purposes imported by § 40 Abs. 2 BDSG, so the Baden-Württemberg authority is the one that supervises, and the same authority is the one that receives the notification of a Datenschutzbeauftragter. If instead the group were run from a Hamburg holding company with the Stuttgart site merely executing instructions, the analysis would move with the decision making, not with the square metres.
Fifth, if the Land is Bavaria, there is one more step, and it is the subject of the next section.
The Bavarian split, which is why the count is seventeen
Bavaria is the structural exception every reader should know about, because it is the only Land that divides data protection supervision between two entirely separate authorities. The division follows exactly the public and non-public logic that § 40 Abs. 1 BDSG and § 9 Abs. 1 BDSG apply at the federal level, simply repeated one tier down.
Der Bayerische Landesbeauftragte für den Datenschutz, at datenschutz-bayern.de, is the authority for Bavarian public bodies: the state administration, municipalities, public hospitals, police, the courts in their administrative activity, and the rest of the Bavarian public sector.
Das Bayerische Landesamt für Datenschutzaufsicht, at lda.bayern.de, is the authority for the non-public sector in Bavaria. It describes its own remit as covering nicht-öffentliche Stellen, so it is the address for a Bavarian company, association, freelancer or private practice, and it is where a Bavarian controller notifies a Datenschutzbeauftragter.
A reader in Bavaria therefore has to make the choice actively rather than looking up a single name. Complaining about a Munich retailer means the Landesamt für Datenschutzaufsicht; complaining about a Munich city office means the Landesbeauftragte für den Datenschutz. Sixteen Länder, seventeen Land authorities, and the seventeenth exists because Bavaria drew the public and non-public line institutionally rather than internally.
The seventeen Land authorities
Every Land has its own authority, with its own name, its own head and its own published guidance. Names differ, and several of them are not the obvious construction: Schleswig-Holstein has an Unabhängiges Landeszentrum für Datenschutz, the Saarland an Unabhängiges Datenschutzzentrum, and Sachsen a Datenschutz- und Transparenzbeauftragte.
| Land | Authority | Website |
|---|---|---|
| Baden-Württemberg | Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg | baden-wuerttemberg.datenschutz.de |
| Bayern (public bodies) | Der Bayerische Landesbeauftragte für den Datenschutz | datenschutz-bayern.de |
| Bayern (non-public bodies) | Bayerisches Landesamt für Datenschutzaufsicht | lda.bayern.de |
| Berlin | Berliner Beauftragte für Datenschutz und Informationsfreiheit | datenschutz-berlin.de |
| Brandenburg | Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg | lda.brandenburg.de |
| Bremen | Der Landesbeauftragte für Datenschutz und Informationsfreiheit | datenschutz.bremen.de |
| Hamburg | Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit | datenschutz-hamburg.de |
| Hessen | Der Hessische Beauftragte für Datenschutz und Informationsfreiheit | datenschutz.hessen.de |
| Mecklenburg-Vorpommern | Der Landesbeauftragte für Datenschutz und Informationsfreiheit Mecklenburg-Vorpommern | datenschutz-mv.de |
| Niedersachsen | Der Landesbeauftragte für den Datenschutz Niedersachsen | lfd.niedersachsen.de |
| Nordrhein-Westfalen | Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen | ldi.nrw.de |
| Rheinland-Pfalz | Landesbeauftragte für Datenschutz und Informationsfreiheit Rheinland-Pfalz | datenschutz.rlp.de |
| Saarland | Unabhängiges Datenschutzzentrum Saarland | datenschutz.saarland.de |
| Sachsen | Die Sächsische Datenschutz- und Transparenzbeauftragte | datenschutz.sachsen.de |
| Sachsen-Anhalt | Landesbeauftragte für den Datenschutz Sachsen-Anhalt | datenschutz.sachsen-anhalt.de |
| Schleswig-Holstein | Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein | datenschutzzentrum.de |
| Thüringen | Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit | tlfdi.de |
Two naming details are worth carrying. Several authorities are also the freedom of information body for their Land, which is why Informationsfreiheit appears in so many of the titles, and it means the same office handles a very different second body of law. The Brandenburg authority carries the Recht auf Akteneinsicht, the right to inspect files, in its title for the same reason.
Titles also move when the officeholder changes, because most of these names are grammatically gendered. The same office can appear as Der Landesbeauftragte or Die Landesbeauftragte depending on who currently holds it, which is why a Land authority sometimes looks renamed when nothing has changed but the postholder.
The bodies outside the system
Two groups sit outside the federal and Land structure described above, and both are commonly missed.
The first is the churches. The Catholic Church and the Evangelische Kirche in Deutschland run their own data protection supervision under their own data protection law rather than under the BDSG, and they have their own supervisory bodies. § 18 Abs. 1 BDSG acknowledges this obliquely by requiring the specific supervisory authorities set up under Art. 85 and Art. 91 DSGVO to be involved in the cooperation procedure where they are affected. For a reader, the point is narrow but decisive: a matter concerning a church employer or a church run institution is generally not one for the Land authority, and the church's own data protection body is the address.
The second is broadcasting. The public service broadcasters have their own data protection supervision for the journalistic part of their activity rather than being supervised by the general authority, again reflected in the reference to Art. 85 DSGVO in § 18 Abs. 1 BDSG. The boundary between the journalistic part and the ordinary administrative part of a broadcaster is not always obvious, and this page does not attempt to draw it.
Beyond noting that these two systems exist and that they take their matters outside the ordinary route, this page does not set out their internal rules. They are separate legal orders with their own procedures.
What a Datenschutzbeschwerde actually is
A Datenschutzbeschwerde is a complaint by a data subject to a supervisory authority about the processing of their personal data. It is a regulatory step, and it is deliberately low friction.
It costs nothing. The authorities do not charge a fee for handling a complaint from a data subject.
It needs no lawyer. Legal representation is not a condition of making a complaint or of the authority acting on it.
It needs no particular form. There is no prescribed template, and the authorities accept complaints in writing by post, by their own online forms and, in most Länder, by email. Many authorities publish a web form precisely to make the step easier, but using it is a convenience rather than a requirement.
What does help is content rather than format. A complaint is easier for an authority to act on when it identifies the responsible organisation clearly, describes the processing that is objected to and when it happened, and attaches whatever correspondence already exists, for example an access request that went unanswered. The route through an access request is set out at the right of access.
What the authority can do, and what it cannot
Once a complaint is in, the authority has real investigative powers, and two of them come straight out of § 40 BDSG.
§ 40 Abs. 4 BDSG obliges the supervised bodies to provide the authority with the information necessary for the performance of its tasks, with a limited right for the person obliged to answer to refuse where the answer would expose them to prosecution risk. § 40 Abs. 5 BDSG allows persons appointed by the authority to enter business premises and to access data processing equipment. § 40 Abs. 3 BDSG restricts what the authority may then do with the data it stores, and allows it in defined situations to inform affected persons, to report infringements and, in serious cases, to involve the trade supervisory bodies.
§ 40 Abs. 6 BDSG also gives the authority the power to demand the removal of a Datenschutzbeauftragter who lacks the necessary expertise or, in the case covered by Art. 38 Abs. 6 DSGVO, where a serious conflict of interest exists. The appointment rules themselves are set out at Datenschutzbeauftragter.
Now the limits, which matter just as much.
A complaint is a regulatory process, not a claim. The authority acts in the public interest to bring processing into line with the law. It does not act as the complainant's representative, and it does not award the complainant money.
Compensation is a separate civil matter. A claim for damages is brought against the controller before the ordinary civil courts, on its own timetable and with its own costs, and it does not run through the supervisory authority. A regulatory outcome and a damages outcome are not substitutes for each other, and neither one produces the other automatically.
A complaint also does not undo the processing by itself, does not force a company to reinstate an account or an employee, and does not decide a contractual dispute that happens to involve data.
What a complaint does produce is an answer. The complainant is informed of the outcome, and where the complainant considers the authority has not dealt with the complaint properly there is a judicial route: § 20 Abs. 1 BDSG provides that disputes between a natural or legal person and a supervisory authority of the Federation or of a Land about rights under Art. 78 Abs. 1 and Abs. 2 DSGVO fall to the administrative courts, the Verwaltungsrechtsweg.
If the complaint goes to the wrong authority
This is the part that makes the earlier competence analysis less frightening than it looks, and it is expressly regulated.
§ 19 Abs. 2 BDSG deals with the misdirected complaint. The authority with which a data subject has lodged a complaint passes it to the lead supervisory authority determined under § 19 Abs. 1 BDSG, or otherwise to the competent authority. Where the receiving authority is not competent as to subject matter, the complaint is forwarded to the authority at the complainant's place of residence. The authority that takes it over then handles it under the cooperation and consistency rules and discharges the associated obligations.
So a complaint filed at the wrong German authority is not lost and does not have to be started again. It is passed on.
§ 19 Abs. 1 BDSG is the related rule for the lead authority. The lead supervisory authority of a Land in the cooperation and consistency procedure is the authority of the Land in which the controller or processor has its main establishment within the meaning of Art. 4 Nr. 16 DSGVO, or its single establishment in the European Union within the meaning of Art. 56 Abs. 1 DSGVO. Where the authorities disagree about which of them leads, § 19 Abs. 1 BDSG sends the question to the procedure in § 18 Abs. 2 BDSG.
The practical reading of all of this: identify the Land of establishment and go there first, and if the identification turns out to be wrong, the statute moves the file rather than closing it.
Where this sits in the wider picture
Supervision is one of several German data protection topics that behave differently from the European default. The appointment threshold for a Datenschutzbeauftragter has a national layer in § 38 BDSG, supplier relationships are governed by written processing arrangements described at data processing agreements, monitoring at work is a field of its own and is covered at workplace surveillance, and the individual rights route starts at the right of access.
The wider set of German data protection material is collected at the data privacy overview, and the country guide at Germany.
This page describes the system and the statutory rules that allocate competence within it. It does not assess any particular organisation's position, advise any reader on whether to complain, or evaluate the prospects of a complaint or a claim. In Germany that kind of individual assessment is a regulated activity under § 2 RDG.
Frequently asked questions
Frequently Asked Questions
Which authority supervises data protection at a German company?
The supervisory authority of the Land in which the company is established. § 40 Abs. 1 BDSG places nichtöffentliche Stellen, non-public bodies, under the competent authorities of the Länder. The BfDI is not competent for an ordinary private company, because § 9 Abs. 1 BDSG limits it to federal public bodies and to undertakings processing data for the commercial provision of telecommunications services.
What is the BfDI actually responsible for?
Under § 9 Abs. 1 BDSG, supervision of the public bodies of the Federation, including where they take part in competition as undertakings governed by public law, and of undertakings to the extent that they process data for the commercial provision of telecommunications services and competence does not already follow from § 29 des Telekommunikation-Digitale-Dienste-Datenschutz-Gesetzes. § 9 Abs. 2 BDSG excludes processing by the federal courts in their judicial activity.
Which authority applies when a company has sites in several Länder?
§ 40 Abs. 2 Satz 1 BDSG provides that where there are several domestic establishments, Art. 4 Nr. 16 DSGVO applies accordingly, so the main establishment determines the leading Land authority. Where several authorities consider themselves competent or not competent, or competence is doubtful for other reasons, § 40 Abs. 2 Satz 2 BDSG sends the question to a joint decision under § 18 Abs. 2 BDSG.
Why does Bavaria have two data protection authorities?
Bavaria applies the public and non-public division institutionally rather than inside one office. Der Bayerische Landesbeauftragte für den Datenschutz supervises Bavarian public bodies, and das Bayerische Landesamt für Datenschutzaufsicht supervises the non-public sector, which is the address for a Bavarian company, association or freelancer. That is why Germany has sixteen Länder but seventeen Land level authorities.
Does a Datenschutzbeschwerde cost anything or require a lawyer?
No. A complaint to a supervisory authority is free, legal representation is not a condition of making it, and no particular form is prescribed. Most authorities publish an online form as a convenience, and post and email are also used. What helps is naming the responsible organisation, describing the processing objected to, and enclosing any existing correspondence.
Can a data protection complaint get me compensation?
No. A complaint is a regulatory process in which the authority acts in the public interest to bring processing into line with the law. A claim for damages is a separate civil matter brought against the controller before the ordinary civil courts, with its own procedure and costs. Neither outcome produces the other automatically.
What happens if a complaint goes to the wrong authority?
It is passed on rather than rejected. § 19 Abs. 2 BDSG requires the authority that received the complaint to give it to the lead supervisory authority under § 19 Abs. 1 BDSG or otherwise to the competent authority, and where the receiving authority is not competent as to subject matter, to forward it to the authority at the complainant's place of residence.
Which authority covers churches and public broadcasters?
Neither group sits inside the ordinary federal and Land structure. The Catholic Church and the Evangelische Kirche in Deutschland apply their own data protection law and run their own supervisory bodies, and public service broadcasters have separate supervision for the journalistic part of their activity. § 18 Abs. 1 BDSG reflects this by requiring the specific authorities established under Art. 85 and Art. 91 DSGVO to be involved in the cooperation procedure where they are affected.
Sources and References
- § 40 BDSG, Aufsichtsbehörden der Länder(gesetze-im-internet.de).gov
- § 9 BDSG, Zuständigkeit der oder des Bundesbeauftragten für den Datenschutz und die Informationsfreiheit(gesetze-im-internet.de).gov
- § 2 BDSG, Begriffsbestimmungen, einschließlich der nichtöffentlichen Stellen in § 2 Abs. 4 BDSG(gesetze-im-internet.de).gov
- § 18 BDSG, Verfahren der Zusammenarbeit der Aufsichtsbehörden des Bundes und der Länder(gesetze-im-internet.de).gov
- § 19 BDSG, Zuständigkeiten, einschließlich der Abgabe einer Beschwerde nach § 19 Abs. 2 BDSG(gesetze-im-internet.de).gov
- § 20 BDSG, Gerichtlicher Rechtsschutz und der Verwaltungsrechtsweg(gesetze-im-internet.de).gov
- § 38 BDSG, Datenschutzbeauftragte nichtöffentlicher Stellen(gesetze-im-internet.de).gov
- BfDI, Aufgaben der oder des Bundesbeauftragten für den Datenschutz und die Informationsfreiheit(bfdi.bund.de).gov
- Bayerisches Landesamt für Datenschutzaufsicht, Aufsicht über nichtöffentliche Stellen in Bayern(lda.bayern.de).gov
- Der Bayerische Landesbeauftragte für den Datenschutz, Aufsicht über bayerische öffentliche Stellen(datenschutz-bayern.de).gov
- Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg(baden-wuerttemberg.datenschutz.de).gov
- Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen(ldi.nrw.de).gov
- Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein(datenschutzzentrum.de).gov
- Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit(datenschutz-hamburg.de).gov