#
Comprehensive, mature, directly-applicable EU omnibus regime with a stable national implementing act; only amber-adjacent risk is the ongoing BfDI leadership transition and EU Digital Omnibus reform uncertainty.
Sub-modules (5)
Regulator And AuthorityGreen
BfDI supervises federal public bodies and federally-regulated private-sector entities (post, telecoms); 17 Land DPAs supervise private-sector and Land-level public bodies.
Claims (2):
- BfDI supervises federal public bodies and federally-regulated private-sector entities (post and telecoms sectors). Core supervisory-competence allocation.
- 17 Land data protection authorities supervise private-sector processing and Land-level public bodies (Bavaria splits public/private-sector oversight). Federated supervisory structure.
Act And InstrumentsGreen
BDSG-neu is the national GDPR implementing act; TTDSG is lex specialis for telecom/telemedia and cookies.
Claims (2):
- Bundesdatenschutzgesetz (BDSG-neu) supplements the GDPR as a subsidiary national implementing act, applying only where the GDPR permits derogation or leaves gaps.
- TTDSG (now TDDDG) functions as lex specialis for telecom/telemedia and cookie/tracking consent matters. TTDSG renamed TDDDG following Digital Services Act adaptation.
Material ScopeGreen
GDPR Art 2 material scope covers wholly/partly automated processing and structured manual filing systems, directly applicable in Germany.
Claims (1):
- GDPR Article 2 defines material scope covering wholly/partly automated processing and structured manual filing systems, directly applicable in Germany.
Territorial ScopeGreen
GDPR Art 3(2) extends to non-EU controllers targeting or monitoring individuals in Germany/the EU.
Claims (1):
- GDPR Article 3(2) extends territorial scope to non-EU controllers targeting or monitoring individuals in Germany/the EU.
Regulator Registration And FilingGreen
DPO contact details for federally-supervised entities must be filed with BfDI via a dedicated notification form/portal.
Claims (1):
- Federally-supervised entities must file DPO contact details with BfDI via a dedicated notification form/portal.
Key findings (3)
- — source on file
- — source on file
- — source on file
Regulator & Framework
Germany's data-protection enforcement remains divided across 17 independent supervisory authorities: the federal BfDI and 16 Land-level data protection authorities, coordinated by the non-binding Datenschutzkonferenz (DSK). This structural feature of the German system is unchanged this cycle, but it now sits alongside a newly-created cross-cutting supervisory allocation under the German Data Act Implementation Act (DADG), which entered into force on 30 May 2026. Under the DADG, the Federal Network Agency (Bundesnetzagentur) becomes the central supervisory and enforcement authority for the EU Data Act, while the BfDI retains its existing responsibility for personal-data processing by non-public bodies under the GDPR.
The practical significance of the DADG's entry into force is that it introduces a second federal-level regulator into Germany's data-governance landscape without altering the existing 17-body GDPR structure: the Bundesnetzagentur's Data Act mandate and the BfDI's GDPR mandate are understood to be distinct in scope, with the Bundesnetzagentur handling Data Act matters and the BfDI continuing its narrower personal-data role. Where the boundary between these two mandates will fall in practice, particularly for data-sharing arrangements that touch both personal data and the broader data-access provisions the Data Act addresses, has not yet been tested and remains to be seen as the DADG's practical application develops.
Outlook
The practical division of labour between the Bundesnetzagentur and the BfDI under the newly-in-force DADG is the primary item to watch, since the boundary between Data Act supervision and GDPR personal-data supervision has not yet been tested in a live case. Any early guidance or joint statement from the two authorities clarifying their respective jurisdictions would be the next material development in this area.
1 earlier distinct update(s)
Regulator & Framework
Germany's federal data-protection authority undergoes a confirmed leadership transition this cycle. Prof. Dr. Louisa Specht-Riemenschneider announced her resignation as BfDI for health reasons, remaining in office through 30 September 2026, and the Bundestag has elected Prof. Dr. Moritz Hennemann as her successor. This transition coincides with a material expansion of the BfDI's remit: under the DADG, the BfDI has supervised the Data Act's personal-data aspects for businesses and federal public bodies since the law entered into force on 30 May 2026, with the Bundesnetzagentur serving as the Data Act's general central supervisory and enforcement authority. This is a confirmed, Tier-1-sourced, binding, in-force competence grant rather than a proposal.
The combination of a change in leadership and a substantively new area of statutory competence makes this a material-change cycle for the regulator-and-framework module specifically. The dual-regulator model — BfDI for personal-data aspects, Bundesnetzagentur for the Data Act generally — is a structural feature that will define how German Data Act enforcement operates going forward, distinct from Germany's prior single-authority approach to data-protection matters generally.
Outlook
Watch the formal handover date and Hennemann's early priorities once he assumes office around 30 September 2026, and whether the new BfDI/Bundesnetzagentur dual-regulator model for the Data Act produces early jurisdictional friction or, conversely, the intended consistency and speed benefits the DADG was designed to deliver.
Sources and claims (7)
- ProbableBundesbeauftragte für den Datenschutz und die Informationsfreiheit — BfDI supervises federal public bodies and federally-regulated private-sector entities (post and telecoms sectors). Core supervisory-competence allocation.observed
- ProbableBundesbeauftragte für den Datenschutz und die Informationsfreiheit — 17 Land data protection authorities supervise private-sector processing and Land-level public bodies (Bavaria splits public/private-sector oversight). Federated supervisory structure.observed
- ProbableBfDI — Bundesdatenschutzgesetz (BDSG-neu) supplements the GDPR as a subsidiary national implementing act, applying only where the GDPR permits derogation or leaves gaps.observed
- ProbableOneTrust DataGuidance — TTDSG (now TDDDG) functions as lex specialis for telecom/telemedia and cookie/tracking consent matters. TTDSG renamed TDDDG following Digital Services Act adaptation.observed
- ProbableBfDI — GDPR Article 2 defines material scope covering wholly/partly automated processing and structured manual filing systems, directly applicable in Germany.observed
- ProbableBfDI — GDPR Article 3(2) extends territorial scope to non-EU controllers targeting or monitoring individuals in Germany/the EU.observed
- ProbableBfDI — Federally-supervised entities must file DPO contact details with BfDI via a dedicated notification form/portal.observed