Germany supplements GDPR with the BDSG and has 16 state-level DPAs. BfDI handles federal matters while each Bundesland has its own authority.
Enforcement authority
Maximum sanctions
German DPAs have issued significant fines. H&M received EUR 35 million from Hamburg DPA.
Obligations
What GDPR requires from organizations operating in Germany.
Local context
Germany's decentralized system means enforcement can vary by state. Bavaria and Hamburg are particularly active.
Germany supplements GDPR with the BDSG and has 16 state-level DPAs. BfDI handles federal matters while each Bundesland has its own authority.
BfDI (federal) + 16 state-level DPAs (Landesdatenschutzbeauftragte)
German DPAs have issued significant fines. H&M received EUR 35 million from Hamburg DPA.
Start free scan to see your risk score and applicable obligations.