Germany Federal Data Protection Act (BDSG)
Germany's Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG) of 2017, the national law that implements and supplements the GDPR and transposes the Law Enforcement Directive. It sets the German rules on employee data (s 26, read after the Court of Justice's C-34/21 ruling as a necessity test on top of a GDPR legal basis), video surveillance of publicly accessible spaces (s 4), the 20-person data protection officer threshold (s 38), special categories, scoring and the limits on data subject rights, and the full regime for police and prosecution authorities. Built from the current German consolidation (to 3 July 2026) read with the official English translation.
Germany Federal Data Protection Act (BDSG) is a compliance framework from Germany with 4 domains and 68 controls that map to 2 other frameworks. The largest domains are Part 3: processing by competent authorities for law enforcement (Directive (EU) 2016/680) – Germany Federal Data Protection Act (BDSG) (33 controls), Part 2: implementing provisions for processing under the GDPR (employment, special categories, rights, private-sector DPOs) – Germany Federal Data Protection Act (BDSG) (23 controls), Part 1: common provisions (public bodies, video surveillance, data protection officers) – Germany Federal Data Protection Act (BDSG) (10 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (4)
Part 1: common provisions (public bodies, video surveillance, data protection officers) – Germany Federal Data Protection Act (BDSG)
| Code | Title |
|---|---|
| germany-federal-data-protection-act-bdsg::s16-4 | s 16(4) Give the Federal Commissioner access to premises, equipment, data and information |
| germany-federal-data-protection-act-bdsg::s3 | s 3 Public bodies process personal data only where needed for their task or official authority |
| germany-federal-data-protection-act-bdsg::s4-1 | s 4(1) Video surveillance of publicly accessible spaces only where necessary for a listed purpose |
| germany-federal-data-protection-act-bdsg::s4-2 | s 4(2) Make video surveillance and the controller identifiable at the earliest possible point |
| germany-federal-data-protection-act-bdsg::s4-3 | s 4(3) Store and use video data only for the stated purpose, with narrow onward uses |
| germany-federal-data-protection-act-bdsg::s4-4 | s 4(4) Inform a person when video data are attributed to them |
| germany-federal-data-protection-act-bdsg::s4-5 | s 4(5) Delete video data without delay once no longer needed |
| germany-federal-data-protection-act-bdsg::s5 | s 5 Public bodies designate a qualified data protection officer and publish the contact details |
| germany-federal-data-protection-act-bdsg::s6 | s 6 Involve, resource and protect the data protection officer |
| germany-federal-data-protection-act-bdsg::s7 | s 7 Give the data protection officer at least the statutory tasks and avoid conflicts |
Part 2: implementing provisions for processing under the GDPR (employment, special categories, rights, private-sector DPOs) – Germany Federal Data Protection Act (BDSG)
| Code | Title |
|---|---|
| germany-federal-data-protection-act-bdsg::s22 | s 22 Process special categories only on a listed national ground and with specific safeguards |
| germany-federal-data-protection-act-bdsg::s23 | s 23 Public bodies further process data for another purpose only on a listed ground |
| germany-federal-data-protection-act-bdsg::s24 | s 24 Private bodies reuse data for another purpose only for security, prosecution or legal claims |
| germany-federal-data-protection-act-bdsg::s25 | s 25 Public bodies transfer data to other bodies only on the listed conditions and with purpose binding |
| germany-federal-data-protection-act-bdsg::s26-1 | s 26(1) sentence 1 Process employee data only where necessary for the employment relationship, on a GDPR legal basis |
| germany-federal-data-protection-act-bdsg::s26-1-s2 | s 26(1) sentence 2 Investigate suspected crimes by employees only on documented suspicion and proportionately |
| germany-federal-data-protection-act-bdsg::s26-2 | s 26(2) Rely on employee consent only where it is genuinely voluntary, in the required form and with text-form notice |
| germany-federal-data-protection-act-bdsg::s26-3 | s 26(3) Process employees' special category data only for labour and social law duties, or on explicit consent |
| germany-federal-data-protection-act-bdsg::s26-4 | s 26(4) Where a collective or works agreement governs employee data, meet GDPR Art. 88(2) |
| germany-federal-data-protection-act-bdsg::s26-5 | s 26(5) Take measures to ensure the GDPR principles are met in employee data processing |
| germany-federal-data-protection-act-bdsg::s27 | s 27 Research and statistics: balance interests, safeguard, anonymise early and separate identifiers |
| germany-federal-data-protection-act-bdsg::s28 | s 28 Archiving in the public interest: safeguard special categories and record counter-statements |
| germany-federal-data-protection-act-bdsg::s29 | s 29 Apply the secrecy exceptions to information, access and breach notice narrowly |
| germany-federal-data-protection-act-bdsg::s30 | s 30 Treat EU lenders' credit enquiries like domestic ones, and tell consumers promptly when credit is refused |
| germany-federal-data-protection-act-bdsg::s31 | s 31 Use scores for contract decisions only on the statutory conditions |
| germany-federal-data-protection-act-bdsg::s32 | s 32 Withhold collection-time information on further use only in the listed cases, with compensating steps |
| germany-federal-data-protection-act-bdsg::s33 | s 33 Withhold information on data obtained from others only in the listed cases, with compensating steps |
| germany-federal-data-protection-act-bdsg::s34 | s 34 Refuse access only on the listed grounds, document why and tell the data subject |
| germany-federal-data-protection-act-bdsg::s35 | s 35 Restrict instead of erasing only in the listed cases, and tell the data subject |
| germany-federal-data-protection-act-bdsg::s36 | s 36 Public bodies: honour objections unless a compelling public interest or a legal duty prevails |
| germany-federal-data-protection-act-bdsg::s37 | s 37 Insurance: automated decisions only where the request is met or with human review rights |
| germany-federal-data-protection-act-bdsg::s38 | s 38 Private bodies designate a data protection officer at 20 persons, or regardless of size for high-risk processing |
| germany-federal-data-protection-act-bdsg::s40-4-5 | s 40(4), (5) Give the Land supervisory authority information and tolerate on-site inspections |
Part 3: processing by competent authorities for law enforcement (Directive (EU) 2016/680) – Germany Federal Data Protection Act (BDSG)
| Code | Title |
|---|---|
| germany-federal-data-protection-act-bdsg::s47 | s 47 Apply the six principles to law enforcement processing |
| germany-federal-data-protection-act-bdsg::s48 | s 48 Process special categories only where strictly necessary and with safeguards |
| germany-federal-data-protection-act-bdsg::s49 | s 49 Further process for another purpose only within s 45 purposes or where a law allows |
| germany-federal-data-protection-act-bdsg::s50 | s 50 Use archival, scientific or statistical forms only in the public interest and with safeguards |
| germany-federal-data-protection-act-bdsg::s51 | s 51 Where the law allows consent, obtain valid consent and be able to prove it |
| germany-federal-data-protection-act-bdsg::s52 | s 52 Staff and processors act only on the controller's instructions |
| germany-federal-data-protection-act-bdsg::s53 | s 53 Bind staff to data confidentiality on taking up duties |
| germany-federal-data-protection-act-bdsg::s54 | s 54 Automated individual decisions only when authorised by law, never discriminatory |
| germany-federal-data-protection-act-bdsg::s55 | s 55 Publish general information about the processing |
| germany-federal-data-protection-act-bdsg::s56 | s 56 Where a law requires notification, include the minimum content, and defer only on listed grounds |
| germany-federal-data-protection-act-bdsg::s57 | s 57 Answer access requests with the listed information, and handle refusals through the Federal Commissioner |
| germany-federal-data-protection-act-bdsg::s58 | s 58 Rectify, erase or restrict on request, inform recipients and give written reasons for refusals |
| germany-federal-data-protection-act-bdsg::s59 | s 59 Communicate clearly, free of charge, in the form of the request |
| germany-federal-data-protection-act-bdsg::s62 | s 62 Use processors only with sufficient guarantees and a binding written or electronic contract |
| germany-federal-data-protection-act-bdsg::s63 | s 63 Joint controllers set out their responsibilities in an agreement |
| germany-federal-data-protection-act-bdsg::s64 | s 64 Implement risk-based security measures, including the fourteen control objectives for automated processing |
| germany-federal-data-protection-act-bdsg::s65 | s 65 Notify the Federal Commissioner of breaches within 72 hours and document all breaches |
| germany-federal-data-protection-act-bdsg::s66 | s 66 Tell data subjects of breaches likely to pose a substantial risk |
| germany-federal-data-protection-act-bdsg::s67 | s 67 Assess the impact before high-risk processing and involve the Federal Commissioner |
| germany-federal-data-protection-act-bdsg::s68 | s 68 Cooperate with the Federal Commissioner |
| germany-federal-data-protection-act-bdsg::s69 | s 69 Consult the Federal Commissioner before high-risk processing in a new filing system |
| germany-federal-data-protection-act-bdsg::s70 | s 70 Keep records of processing activities |
| germany-federal-data-protection-act-bdsg::s71 | s 71 Build in data protection by design and by default |
| germany-federal-data-protection-act-bdsg::s72 | s 72 Distinguish between categories of data subjects |
| germany-federal-data-protection-act-bdsg::s73 | s 73 Distinguish facts from personal assessments |
| germany-federal-data-protection-act-bdsg::s74 | s 74 Check quality before transmitting data and pass on processing conditions |
| germany-federal-data-protection-act-bdsg::s75 | s 75 Rectify and erase, and set time limits for erasure or review |
| germany-federal-data-protection-act-bdsg::s76 | s 76 Log collection, alteration, consultation, disclosure, combination and erasure |
| germany-federal-data-protection-act-bdsg::s77 | s 77 Be able to receive confidential reports of data protection violations |
| germany-federal-data-protection-act-bdsg::s78 | s 78 Transfer to third countries only to competent bodies with adequacy, and control onward transfers |
| germany-federal-data-protection-act-bdsg::s79 | s 79 Without adequacy, transfer on appropriate safeguards, document it and report annually |
| germany-federal-data-protection-act-bdsg::s80 | s 80 Transfer without safeguards only on the listed necessity grounds and document it |
| germany-federal-data-protection-act-bdsg::s81 | s 81 Transfer directly to other third-country recipients only exceptionally and with purpose instructions |
Part 4: processing outside the scope of the GDPR and the Directive – Germany Federal Data Protection Act (BDSG)
| Code | Title |
|---|---|
| germany-federal-data-protection-act-bdsg::s85 | s 85 Outside EU law, transfer for defence and crisis tasks only with purpose instructions, and apply the information exemptions narrowly |
| germany-federal-data-protection-act-bdsg::s86 | s 86 State awards and honours: process only what is needed and safeguard special categories |
Maps to 2 other frameworks
Coverage is not the same as your position
This page shows what Germany Federal Data Protection Act (BDSG) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is Germany Federal Data Protection Act (BDSG) and who does it apply to?
Germany Federal Data Protection Act (BDSG) is a compliance framework from Germany with 4 domains and 68 controls. Germany's Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG) of 2017, the national law that implements and supplements the GDPR and transposes the Law Enforcement Directive. It sets the German rules on employee data (s 26, read after the Court of Justice's C-34/21 ruling as a necessity test on top of a GDPR legal basis), video surveillance of publicly accessible spaces (s 4), the 20-person data protection officer threshold (s 38), special categories, scoring and the limits on data subject rights, and the full regime for police and prosecution authorities. Built from the current German consolidation (to 3 July 2026) read with the official English translation. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Germany Federal Data Protection Act (BDSG) actually require?
Germany Federal Data Protection Act (BDSG) has 68 controls organised across 4 domains. The largest domains are Part 3: processing by competent authorities for law enforcement (Directive (EU) 2016/680) – Germany Federal Data Protection Act (BDSG) (33 controls), Part 2: implementing provisions for processing under the GDPR (employment, special categories, rights, private-sector DPOs) – Germany Federal Data Protection Act (BDSG) (23 controls), Part 1: common provisions (public bodies, video surveillance, data protection officers) – Germany Federal Data Protection Act (BDSG) (10 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Germany Federal Data Protection Act (BDSG) do I already cover?
Germany Federal Data Protection Act (BDSG) maps to 2 other compliance frameworks. The top mapping partners are GDPR (85% coverage), ISO 27002:2022 (7% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement Germany Federal Data Protection Act (BDSG)?
Start your Germany Federal Data Protection Act (BDSG) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Germany Federal Data Protection Act (BDSG) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 68 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 844 frameworks.
Get Started Free →Free forever — no credit card required