Back to Frameworks

Germany Federal Data Protection Act (BDSG)

Germany
vConsolidated text as last amended by Art. 3 of the Act of 3 July 2026 (BGBl. 2026 I Nr. 199), retrieved 2026-09-30; official English translation as at Art. 10 of the Act of 23 June 2021
4 domains
68 controls

Germany's Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG) of 2017, the national law that implements and supplements the GDPR and transposes the Law Enforcement Directive. It sets the German rules on employee data (s 26, read after the Court of Justice's C-34/21 ruling as a necessity test on top of a GDPR legal basis), video surveillance of publicly accessible spaces (s 4), the 20-person data protection officer threshold (s 38), special categories, scoring and the limits on data subject rights, and the full regime for police and prosecution authorities. Built from the current German consolidation (to 3 July 2026) read with the official English translation.

Verified

Germany Federal Data Protection Act (BDSG) is a compliance framework from Germany with 4 domains and 68 controls that map to 2 other frameworks. The largest domains are Part 3: processing by competent authorities for law enforcement (Directive (EU) 2016/680) – Germany Federal Data Protection Act (BDSG) (33 controls), Part 2: implementing provisions for processing under the GDPR (employment, special categories, rights, private-sector DPOs) – Germany Federal Data Protection Act (BDSG) (23 controls), Part 1: common provisions (public bodies, video surveillance, data protection officers) – Germany Federal Data Protection Act (BDSG) (10 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (4)

Part 1: common provisions (public bodies, video surveillance, data protection officers) – Germany Federal Data Protection Act (BDSG)

10 controls
Controls in the Part 1: common provisions (public bodies, video surveillance, data protection officers) – Germany Federal Data Protection Act (BDSG) domain of Germany Federal Data Protection Act (BDSG) — 10 controls
CodeTitle
germany-federal-data-protection-act-bdsg::s16-4s 16(4) Give the Federal Commissioner access to premises, equipment, data and information
germany-federal-data-protection-act-bdsg::s3s 3 Public bodies process personal data only where needed for their task or official authority
germany-federal-data-protection-act-bdsg::s4-1s 4(1) Video surveillance of publicly accessible spaces only where necessary for a listed purpose
germany-federal-data-protection-act-bdsg::s4-2s 4(2) Make video surveillance and the controller identifiable at the earliest possible point
germany-federal-data-protection-act-bdsg::s4-3s 4(3) Store and use video data only for the stated purpose, with narrow onward uses
germany-federal-data-protection-act-bdsg::s4-4s 4(4) Inform a person when video data are attributed to them
germany-federal-data-protection-act-bdsg::s4-5s 4(5) Delete video data without delay once no longer needed
germany-federal-data-protection-act-bdsg::s5s 5 Public bodies designate a qualified data protection officer and publish the contact details
germany-federal-data-protection-act-bdsg::s6s 6 Involve, resource and protect the data protection officer
germany-federal-data-protection-act-bdsg::s7s 7 Give the data protection officer at least the statutory tasks and avoid conflicts

Part 2: implementing provisions for processing under the GDPR (employment, special categories, rights, private-sector DPOs) – Germany Federal Data Protection Act (BDSG)

23 controls
Controls in the Part 2: implementing provisions for processing under the GDPR (employment, special categories, rights, private-sector DPOs) – Germany Federal Data Protection Act (BDSG) domain of Germany Federal Data Protection Act (BDSG) — 23 controls
CodeTitle
germany-federal-data-protection-act-bdsg::s22s 22 Process special categories only on a listed national ground and with specific safeguards
germany-federal-data-protection-act-bdsg::s23s 23 Public bodies further process data for another purpose only on a listed ground
germany-federal-data-protection-act-bdsg::s24s 24 Private bodies reuse data for another purpose only for security, prosecution or legal claims
germany-federal-data-protection-act-bdsg::s25s 25 Public bodies transfer data to other bodies only on the listed conditions and with purpose binding
germany-federal-data-protection-act-bdsg::s26-1s 26(1) sentence 1 Process employee data only where necessary for the employment relationship, on a GDPR legal basis
germany-federal-data-protection-act-bdsg::s26-1-s2s 26(1) sentence 2 Investigate suspected crimes by employees only on documented suspicion and proportionately
germany-federal-data-protection-act-bdsg::s26-2s 26(2) Rely on employee consent only where it is genuinely voluntary, in the required form and with text-form notice
germany-federal-data-protection-act-bdsg::s26-3s 26(3) Process employees' special category data only for labour and social law duties, or on explicit consent
germany-federal-data-protection-act-bdsg::s26-4s 26(4) Where a collective or works agreement governs employee data, meet GDPR Art. 88(2)
germany-federal-data-protection-act-bdsg::s26-5s 26(5) Take measures to ensure the GDPR principles are met in employee data processing
germany-federal-data-protection-act-bdsg::s27s 27 Research and statistics: balance interests, safeguard, anonymise early and separate identifiers
germany-federal-data-protection-act-bdsg::s28s 28 Archiving in the public interest: safeguard special categories and record counter-statements
germany-federal-data-protection-act-bdsg::s29s 29 Apply the secrecy exceptions to information, access and breach notice narrowly
germany-federal-data-protection-act-bdsg::s30s 30 Treat EU lenders' credit enquiries like domestic ones, and tell consumers promptly when credit is refused
germany-federal-data-protection-act-bdsg::s31s 31 Use scores for contract decisions only on the statutory conditions
germany-federal-data-protection-act-bdsg::s32s 32 Withhold collection-time information on further use only in the listed cases, with compensating steps
germany-federal-data-protection-act-bdsg::s33s 33 Withhold information on data obtained from others only in the listed cases, with compensating steps
germany-federal-data-protection-act-bdsg::s34s 34 Refuse access only on the listed grounds, document why and tell the data subject
germany-federal-data-protection-act-bdsg::s35s 35 Restrict instead of erasing only in the listed cases, and tell the data subject
germany-federal-data-protection-act-bdsg::s36s 36 Public bodies: honour objections unless a compelling public interest or a legal duty prevails
germany-federal-data-protection-act-bdsg::s37s 37 Insurance: automated decisions only where the request is met or with human review rights
germany-federal-data-protection-act-bdsg::s38s 38 Private bodies designate a data protection officer at 20 persons, or regardless of size for high-risk processing
germany-federal-data-protection-act-bdsg::s40-4-5s 40(4), (5) Give the Land supervisory authority information and tolerate on-site inspections

Part 3: processing by competent authorities for law enforcement (Directive (EU) 2016/680) – Germany Federal Data Protection Act (BDSG)

33 controls
Controls in the Part 3: processing by competent authorities for law enforcement (Directive (EU) 2016/680) – Germany Federal Data Protection Act (BDSG) domain of Germany Federal Data Protection Act (BDSG) — 33 controls
CodeTitle
germany-federal-data-protection-act-bdsg::s47s 47 Apply the six principles to law enforcement processing
germany-federal-data-protection-act-bdsg::s48s 48 Process special categories only where strictly necessary and with safeguards
germany-federal-data-protection-act-bdsg::s49s 49 Further process for another purpose only within s 45 purposes or where a law allows
germany-federal-data-protection-act-bdsg::s50s 50 Use archival, scientific or statistical forms only in the public interest and with safeguards
germany-federal-data-protection-act-bdsg::s51s 51 Where the law allows consent, obtain valid consent and be able to prove it
germany-federal-data-protection-act-bdsg::s52s 52 Staff and processors act only on the controller's instructions
germany-federal-data-protection-act-bdsg::s53s 53 Bind staff to data confidentiality on taking up duties
germany-federal-data-protection-act-bdsg::s54s 54 Automated individual decisions only when authorised by law, never discriminatory
germany-federal-data-protection-act-bdsg::s55s 55 Publish general information about the processing
germany-federal-data-protection-act-bdsg::s56s 56 Where a law requires notification, include the minimum content, and defer only on listed grounds
germany-federal-data-protection-act-bdsg::s57s 57 Answer access requests with the listed information, and handle refusals through the Federal Commissioner
germany-federal-data-protection-act-bdsg::s58s 58 Rectify, erase or restrict on request, inform recipients and give written reasons for refusals
germany-federal-data-protection-act-bdsg::s59s 59 Communicate clearly, free of charge, in the form of the request
germany-federal-data-protection-act-bdsg::s62s 62 Use processors only with sufficient guarantees and a binding written or electronic contract
germany-federal-data-protection-act-bdsg::s63s 63 Joint controllers set out their responsibilities in an agreement
germany-federal-data-protection-act-bdsg::s64s 64 Implement risk-based security measures, including the fourteen control objectives for automated processing
germany-federal-data-protection-act-bdsg::s65s 65 Notify the Federal Commissioner of breaches within 72 hours and document all breaches
germany-federal-data-protection-act-bdsg::s66s 66 Tell data subjects of breaches likely to pose a substantial risk
germany-federal-data-protection-act-bdsg::s67s 67 Assess the impact before high-risk processing and involve the Federal Commissioner
germany-federal-data-protection-act-bdsg::s68s 68 Cooperate with the Federal Commissioner
germany-federal-data-protection-act-bdsg::s69s 69 Consult the Federal Commissioner before high-risk processing in a new filing system
germany-federal-data-protection-act-bdsg::s70s 70 Keep records of processing activities
germany-federal-data-protection-act-bdsg::s71s 71 Build in data protection by design and by default
germany-federal-data-protection-act-bdsg::s72s 72 Distinguish between categories of data subjects
germany-federal-data-protection-act-bdsg::s73s 73 Distinguish facts from personal assessments
germany-federal-data-protection-act-bdsg::s74s 74 Check quality before transmitting data and pass on processing conditions
germany-federal-data-protection-act-bdsg::s75s 75 Rectify and erase, and set time limits for erasure or review
germany-federal-data-protection-act-bdsg::s76s 76 Log collection, alteration, consultation, disclosure, combination and erasure
germany-federal-data-protection-act-bdsg::s77s 77 Be able to receive confidential reports of data protection violations
germany-federal-data-protection-act-bdsg::s78s 78 Transfer to third countries only to competent bodies with adequacy, and control onward transfers
germany-federal-data-protection-act-bdsg::s79s 79 Without adequacy, transfer on appropriate safeguards, document it and report annually
germany-federal-data-protection-act-bdsg::s80s 80 Transfer without safeguards only on the listed necessity grounds and document it
germany-federal-data-protection-act-bdsg::s81s 81 Transfer directly to other third-country recipients only exceptionally and with purpose instructions

Part 4: processing outside the scope of the GDPR and the Directive – Germany Federal Data Protection Act (BDSG)

2 controls
Controls in the Part 4: processing outside the scope of the GDPR and the Directive – Germany Federal Data Protection Act (BDSG) domain of Germany Federal Data Protection Act (BDSG) — 2 controls
CodeTitle
germany-federal-data-protection-act-bdsg::s85s 85 Outside EU law, transfer for defence and crisis tasks only with purpose instructions, and apply the information exemptions narrowly
germany-federal-data-protection-act-bdsg::s86s 86 State awards and honours: process only what is needed and safeguard special categories

Maps to 2 other frameworks

68 total controls
GDPR
58 source controls mapped|32 target controls covered
85%
ISO 27002:2022
5 source controls mapped|5 target controls covered
7%

Coverage is not the same as your position

This page shows what Germany Federal Data Protection Act (BDSG) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is Germany Federal Data Protection Act (BDSG) and who does it apply to?

Germany Federal Data Protection Act (BDSG) is a compliance framework from Germany with 4 domains and 68 controls. Germany's Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG) of 2017, the national law that implements and supplements the GDPR and transposes the Law Enforcement Directive. It sets the German rules on employee data (s 26, read after the Court of Justice's C-34/21 ruling as a necessity test on top of a GDPR legal basis), video surveillance of publicly accessible spaces (s 4), the 20-person data protection officer threshold (s 38), special categories, scoring and the limits on data subject rights, and the full regime for police and prosecution authorities. Built from the current German consolidation (to 3 July 2026) read with the official English translation. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Germany Federal Data Protection Act (BDSG) actually require?

Germany Federal Data Protection Act (BDSG) has 68 controls organised across 4 domains. The largest domains are Part 3: processing by competent authorities for law enforcement (Directive (EU) 2016/680) – Germany Federal Data Protection Act (BDSG) (33 controls), Part 2: implementing provisions for processing under the GDPR (employment, special categories, rights, private-sector DPOs) – Germany Federal Data Protection Act (BDSG) (23 controls), Part 1: common provisions (public bodies, video surveillance, data protection officers) – Germany Federal Data Protection Act (BDSG) (10 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Germany Federal Data Protection Act (BDSG) do I already cover?

Germany Federal Data Protection Act (BDSG) maps to 2 other compliance frameworks. The top mapping partners are GDPR (85% coverage), ISO 27002:2022 (7% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Germany Federal Data Protection Act (BDSG)?

Start your Germany Federal Data Protection Act (BDSG) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Germany Federal Data Protection Act (BDSG) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 68 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 844 frameworks.

Get Started Free →

Free forever — no credit card required