Dashboard / Global Laws / DE-BDSG

🇩🇪Federal Data Protection Act (BDSG)

← Back to laws in Germany

Federal Data Protection Act (BDSG)

Federal Data Protection Act (BDSG)

Germany applies this national law alongside the GDPR. The summary below concentrates on the national overlay so that the GDPR baseline is not duplicated.

Current official version

Status: Current consolidated text; last amended by Article 3 of the Act of 3 July 2026

Citation: Bundesdatenschutzgesetz, especially ss. 4, 22, 26-31 and 38

Regulator: Federal Commissioner (BfDI) and the competent Land supervisory authorities

Source basis: Official Federal Ministry of Justice Gesetze im Internet consolidated German PDF checked on 22 August 2026.

How the national law fits with GDPR

The BDSG supplements the GDPR for German federal public bodies and, in specified provisions, private bodies. It must be applied with the GDPR and relevant Land law, not as a replacement for them.

National additions and variations

  • Section 26 supplies a detailed national framework for employee and applicant data, including necessity, collective agreements, consent and sensitive data.
  • Sections 22 and 27-30 add rules for special-category data, research and statistics, archiving, secrecy obligations and consumer credit.
  • Section 31 regulates scoring and creditworthiness information used for contractual decisions.
  • Section 4 addresses video surveillance of publicly accessible spaces.
  • Section 38 generally requires a private body to appoint a DPO where at least 20 persons are continuously engaged in automated personal-data processing, and also in specified DPIA or commercial processing cases.
Implementation boundary

German data protection is also federalised. Land public bodies and sector-specific activities may be governed by additional Land or specialist legislation.

Operational approach

First maintain the GDPR control set. Then document whether this country is in scope and apply the national controls to the affected people, systems and processing. Keep article-level evidence for child consent, employment, special-category or criminal data, research, electronic communications, identifiers, surveillance and any rights restriction relied upon.

What this means for you

Do not treat GDPR compliance as automatic compliance with BDSG. Record the national trigger, the responsible owner, the local procedure and the current official source reviewed.