Cleo
CompanyLegal Data
Request a demo
Anaelle GuezNaomie Halioua
Request a demo
Cleo

AI-powered regulatory intelligence.

contact@cleolabs.co

Solutions

  • Product Compliance

Company

  • About
  • Research
  • Blog
  • Compliance Guides

Jurisdictions

  • 🇪🇺 European Union
  • 🇫🇷 France
  • 🇩🇪 Germany
  • 🇬🇧 United Kingdom
  • 🇺🇸 United States

Legal

  • Privacy
  • Terms
  • Security

Events

  • VivaTech ParisJun 11–14, 2026

© 2026 Cleo Labs. All rights reserved.

GDPREU DataSOC 2 Type IIISO 27001
🇩🇪GermanyActive

GDPR compliance in Germany

Germany supplements GDPR with the BDSG and has 16 state-level DPAs. BfDI handles federal matters while each Bundesland has its own authority.

Start free scan
Anaelle GuezNaomie Halioua
or book a call

Enforcement authority

BfDI (federal) + 16 state-level DPAs (Landesdatenschutzbeauftragte)

Maximum sanctions

German DPAs have issued significant fines. H&M received EUR 35 million from Hamburg DPA.

Obligations

Key obligations

What GDPR requires from organizations operating in Germany.

Comply with BDSG employee data protection provisions
Appoint a DPO (mandatory for 20+ employees processing personal data)
Follow state-level DPA guidance in addition to federal rules
Implement works council consultation for employee monitoring

Local context

Local context in Germany

Germany's decentralized system means enforcement can vary by state. Bavaria and Hamburg are particularly active.

Connects to

GDPR by industry in Germany

Retail & Consumer GoodsCosmetics & Personal CareElectronics & Connected DevicesFood & BeveragePet Care & Pet FoodSporting GoodsMedical DevicesDrugs & PharmaceuticalsInsuranceEnergy & Utilities

Frequently asked questions

How does GDPR apply in Germany?

Germany supplements GDPR with the BDSG and has 16 state-level DPAs. BfDI handles federal matters while each Bundesland has its own authority.

Who enforces GDPR in Germany?

BfDI (federal) + 16 state-level DPAs (Landesdatenschutzbeauftragte)

What are the penalties for GDPR non-compliance?

German DPAs have issued significant fines. H&M received EUR 35 million from Hamburg DPA.

Read our complete GDPR compliance guide

GDPR in other jurisdictions

🇪🇺European Union🇫🇷France🇬🇧United Kingdom🇺🇸United States🇧🇷Brazil🇦🇺Australia🇮🇳India

Check your GDPR compliance now

Start free scan to see your risk score and applicable obligations.

Start with 1 product
Start free scan
Anaelle GuezNaomie Halioua
or book a call