What Is BDSG? GDPR + Bundesdatenschutzgesetz (German Federal Data Protection Act)
Germany applies the EU GDPR together with the Bundesdatenschutzgesetz (BDSG), which uses the GDPR's opening clauses to add national rules on employee data, video surveillance, credit scoring, and data-protection-officer appointments. Enforcement is decentralised. The federal BfDI oversees federal bodies and specified sectors such as telecoms and postal services; Länder authorities generally handle private-sector controllers outside the BfDI's special remit and other matters according to their competence. The correct regulator depends on the controller and processing. Germany also has public-record and suppression mechanics: the residents' registration system (Melderegister) lets third parties request certain address data, but residents can seek disclosure blocks (Übermittlungssperre) or, where the statutory risk test is met, a full information block (Auskunftssperre, §51 Bundesmeldegesetz).
At a glance
- Full name
- GDPR + Bundesdatenschutzgesetz (German Federal Data Protection Act)
- Short code
- BDSG
- Jurisdiction
- Germany
- Enacted
- 2018
- Last major update
- BDSG (new) in force 25 May 2018 alongside the EU GDPR; current German text controls this analysis
- Regulator
- BfDI (federal) + 17 state data-protection authorities (Landesdatenschutzbehörden)
- Private right of action
- Yes
- Statutory citation
- BDSG (2018) + Regulation (EU) 2016/679
Scope, who BDSG covers
Protected data
Data subject rights
Right of access (Article 15), including requests for a SCHUFA data copy subject to the GDPR access rules
Right to rectification (Article 16)
Right to erasure / right to be forgotten (Article 17)
Right to restriction of processing (Article 18)
Right to data portability (Article 20)
Right to object, incl. absolute right for direct marketing (Article 21)
Can request an Übermittlungssperre for specified disclosures under §50(5) BMG; an Auskunftssperre under §51 BMG requires the statutory risk assessment
Right to lodge a complaint with the competent state DPA or the BfDI (Article 77)
Notable features
Germany's defining features are its decentralised enforcement (the federal BfDI plus 17 state data-protection authorities) and its registration-office suppression tools. Under §51 Bundesmeldegesetz, a person facing the statutory threat conditions can apply for an Auskunftssperre; the authority assesses and reviews the block under the current law. Residents can also file targeted Übermittlungssperren for specified disclosures. The land register (Grundbuch) is not generally open to anyone: access requires a legitimate interest.
Enforcement & penalties
Regulator: BfDI (federal) + 17 state data-protection authorities (Landesdatenschutzbehörden)
Penalties: GDPR two-tier fines: up to €10M or 2% of global turnover (lower tier) and up to €20M or 4% of global turnover (higher tier), whichever is greater. German DPAs publish enforcement decisions and guidance; a historical fine or court decision should be checked against the current authority record before being used as a current benchmark.
Private right of action: GDPR Article 82 grants a right to compensation for material or non-material damage, enforceable in the German civil courts. Germany also provides representative-action routes for qualified entities under applicable law; the standing, procedure, and remedy depend on the claim.
Relevance to data brokers
Address traders ('Adresshändler'), credit bureaus such as SCHUFA, and directory or people-search services may be controllers under GDPR + BDSG, depending on their role and processing. The marketing-objection right (Article 21) and Melderegister disclosure blocks can help with different exposure layers. Credit scoring is additionally subject to §31 BDSG, GDPR rules, and relevant court decisions.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Who regulates data privacy in Germany?+
A decentralised system: the BfDI handles federal public bodies and specified sectors such as telecoms and postal services, while state data-protection authorities generally handle private-sector controllers outside the BfDI's special remit and other state matters. The right regulator to complain to depends on the controller, sector, processing, and authority's remit; there is no general hierarchy that makes the BfDI an appeal body for state DPA decisions.
How do I hide my address from Germany's residents' register?+
Ask your local Bürgeramt about an Übermittlungssperre for specific disclosures. If the statutory threat conditions are met, you can apply for an Auskunftssperre under §51 Bundesmeldegesetz; the authority decides the request and the current law controls its review and duration.
How do I get and correct my SCHUFA credit data?+
You can make an Article 15 GDPR access request for a SCHUFA data copy; SCHUFA currently describes that copy as free and says it is a snapshot of the data held at the time of preparation. Subject to the access rules and any lawful limits on repeated or excessive requests, you can dispute inaccurate information. A company must have an applicable lawful basis and comply with credit-reporting rules when obtaining or using a score, so do not assume consent is always the required basis.
How do German GDPR and registry rules interact?+
Germany adds BDSG rules on areas such as employment and scoring, operates a decentralised supervisory structure, and has specific registration-office rules. The obligations and responsible authority depend on the controller, sector, and processing; this is not a general ranking of German enforcement against other EU states.
Official sources & citations
- BDSG current German text (gesetze-im-internet)
- BfDI: authority, tasks, and supervisory competence
- BfDI: FAQ on credit agencies and data-subject rights
- §31 BDSG: protection of commercial transactions in scoring
- §50 Bundesmeldegesetz: Übermittlungssperren
- §51 Bundesmeldegesetz: Auskunftssperren
- Bundesmeldegesetz: current full text
- Register an Auskunftssperre (example: Berlin)
- SCHUFA: free Article 15 data copy
Other international privacy regimes
BDSG sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
