Checked on September 27, 2026
GDPR in Germany
How the GDPR works in Germany: the supervisory authority, the national law that supplements the regulation, and where to notify a breach.
- Supervisory authority
- Federal Commissioner for Data Protection and Freedom of Information (BfDI) (Die Bundesbeauftragte für den Datenschutz und die Informationsfreiheit)
- National law supplementing the GDPR
- Federal Data Protection Act · Bundesdatenschutzgesetz (BDSG) · BDSG of 30 June 2017 (BGBl. I S. 2097)
- Age of digital consent
- 16
- Breach notification
- www.bfdi.bund.de/DE/Service/Kontakt/Meldung-Datenschutzversto%C3%9F/Info_MeldungDSVerstoss.html
- National specifics
- Most private companies are supervised by the data protection authority of their federal state (Land); BfDI covers federal bodies, telecoms and postal services.
- Breaches must be notified to the competent authority (federal or state) under Art. 33 GDPR; BfDI offers an online form for its own remit.
- BDSG requires a DPO where at least 20 persons are regularly engaged in automated processing of personal data (s. 38 BDSG).
Where does your company stand?
The free assessment applies these national rules to your answers and scores every area of the law.
Sources
National laws and portals change. This page is general information, not legal advice; confirm with the authority before relying on it.