Federal Data Protection Act (BDSG)

The Federal Data Protection Act (BDSG) is the German federal statute that supplements the GDPR (Regulation (EU) 2016/679) and fills its opening clauses. For companies it mainly governs employee data (§ 26), the data protection officer (§ 38) and restrictions of data subject rights (§§ 32 to 37). The current act of June 30, 2017 has been in force since May 25, 2018.

DSGVOLast reviewed:

The BDSG does not replace the GDPR; it sits next to it. Under § 1(5) BDSG, its provisions do not apply where the General Data Protection Regulation (Regulation (EU) 2016/679) applies directly. The duties under the regulation itself are set out in the GDPR guide for mid-sized companies.

Key takeaways

  • The BDSG of June 30, 2017 (BGBl. I p. 2097) has applied since May 25, 2018 and replaced the BDSG of 1990.
  • For companies, Part 2 (§§ 22 to 44) matters most: special categories, change of purpose, employee data, data subject rights, the data protection officer, supervision and sanctions.
  • Under § 38(1) BDSG, a data protection officer must be designated where, as a rule, at least 20 persons are constantly engaged in the automated processing of personal data.
  • After the CJEU judgment of March 30, 2023 (C-34/21), the Baden-Württemberg data protection commissioner considers § 26(1) sentence 1 BDSG probably inapplicable and points to Article 6(1) GDPR.
  • From November 20, 2026, the new § 37a BDSG replaces the previous scoring rule in § 31 (Act of May 12, 2026, BGBl. 2026 I No. 139).

What is the BDSG?

The BDSG (Bundesdatenschutzgesetz, Federal Data Protection Act) is Germany's general federal data protection statute. It applies to federal public bodies and to private bodies such as companies; for these, § 1(1) sentence 2 covers fully or partly automated processing of personal data and data stored, or intended to be stored, in a filing system. Public bodies of the federal states are generally subject to state data protection acts. More specific federal data protection rules take precedence over the BDSG under § 1(2).

How the BDSG is structured in four parts

The act is divided into four parts (as of October 2026):

PartSectionsContentRelevance for companies
Part 1§§ 1 to 21Scope, data protection officers of public bodies, Federal Commissioner (BfDI), cooperation of supervisory authoritiesMedium: scope
Part 2§§ 22 to 44Implementing provisions for the GDPRHigh: the day-to-day rules sit here
Part 3§§ 45 to 84Transposition of Directive (EU) 2016/680 for police and justiceLow
Part 4§§ 85 and 86Activities outside the scope of EU lawNone

BDSG and GDPR: the regulation prevails, the act fills the gaps

The GDPR takes precedence, and the BDSG supplements it where the regulation leaves room for member states through so-called opening clauses. Three examples: Article 88 GDPR allows more specific rules for the employment context, Article 37(4) allows national duties to designate a data protection officer, and Article 23 allows statutory restrictions of data subject rights.

A national rule that goes beyond this framework must be disregarded. Fines for data protection infringements generally follow Article 83 GDPR; § 43 BDSG adds only narrow offenses in consumer credit.

Eight BDSG provisions that matter in day-to-day business

For companies, eight provisions from Parts 1 and 2 are of practical relevance:

ProvisionRuleWhat it means in practice
§ 1Scope, precedence of the GDPRThe BDSG applies only where the GDPR leaves room
§ 22Processing of special categories under Article 9 GDPR, for example to assess an employee's working capacity or under social security lawEmployee health data requires safeguards under § 22(2)
§ 24Change of purpose by private bodiesFurther processing, for example to prosecute criminal offenses or to establish civil law claims
§ 26Employee dataConsent, collective agreements, definition of employee; subsection 1 sentence 1 disputed after C-34/21
§§ 32 to 37Restrictions of the rights to information, access, erasure and objection, automated individual decisionsUse exceptions only with a documented justification
§ 38Data protection officer of private bodiesMandatory from, as a rule, 20 persons or where a DPIA is required
§ 40Supervision by the state authoritiesWith several establishments in Germany, Article 4(16) GDPR (main establishment) applies accordingly
§§ 42 and 43Criminal and administrative offensesUp to three years' imprisonment or a fine for commercially passing on non-public data of a large number of persons without authorization; fines up to EUR 50,000 for consumer credit infringements

What does § 26 BDSG say about employee data?

§ 26 BDSG governs when employers may process personal data of employees. Subsection 1 sentence 1 allows processing where it is necessary to establish, perform or terminate the employment relationship. Under subsection 2, consent must as a rule be given in writing or electronically, with information in text form on the purpose and the right to withdraw. Under subsection 8, applicants and former employees also count as employees.

CJEU judgment C-34/21: what it means for § 26 BDSG

On March 30, 2023, the Court of Justice of the European Union ruled in Case C-34/21 on § 23 of the Hessian Data Protection and Freedom of Information Act (HDSIG), which largely mirrors § 26 BDSG. A national rule qualifies as a more specific rule under Article 88 GDPR only if it meets the requirements of Article 88(2). Otherwise it must be disregarded, unless it constitutes a legal basis under Article 6(3) GDPR. The Court did not rule on § 26 BDSG itself.

The Baden-Württemberg Commissioner for Data Protection and Freedom of Information therefore considers § 26(1) sentence 1 BDSG probably inapplicable. In his view, companies base processing needed to perform the employment contract on Article 6(1)(b) GDPR, legal obligations on point (c), and other employer interests, after a balancing test, on point (f). He considers the rest of § 26 unaffected.

The wording of § 26 BDSG is unchanged after the 2026 amendments (as of October 2026). If your records of processing activities cite § 26(1) sentence 1 BDSG as the sole legal basis for employee data, add Article 6(1) GDPR to that entry; the commissioner recommends the same.

Data protection officer under § 38 BDSG: the 20-person threshold

A company must designate a data protection officer under § 38(1) BDSG where, as a rule, at least 20 persons are constantly engaged in the automated processing of personal data. The test is not total headcount but who regularly works with personal data in automated form.

Regardless of headcount, the duty applies where processing is subject to a data protection impact assessment under Article 35 GDPR, or where personal data is processed commercially for transfer, for anonymized transfer or for market and opinion research. The special protection against removal and dismissal under § 6(4) applies under § 38(2) only where the designation is mandatory.

BDSG amendments in 2026: scoring in § 37a, new duties in § 30

The BDSG was not amended in 2025; the preceding amendment is dated May 6, 2024 (BGBl. 2024 I No. 149). Two amending acts followed in 2026.

Act of May 12, 2026: § 37a replaces § 31 from November 20, 2026

Article 3 of the Act of May 12, 2026 (BGBl. 2026 I No. 139) enters into force on November 20, 2026. It deletes § 31 and inserts § 37a “Scoring”. Probability values may then not be based on, among other things, special categories under Article 9(1) GDPR, age, gender, name, social network data, incoming and outgoing bank account payments or address data, and they may not concern minors.

Data subjects will be able to learn which data and criteria were used and how the criteria are weighted. § 30 gains new duties for credit agencies and lenders in consumer credit.

Act of July 3, 2026: changes for police and justice

Article 3 of the Act of July 3, 2026 (BGBl. 2026 I No. 199) amends § 62(6) and § 70(1) in Part 3 (police and justice) and has no direct relevance for companies. The consolidated German text on gesetze-im-internet.de shows the May 12, 2026 amendment as its status and marks the July amendment as already incorporated in the text.

Employee data in Rizzqo's asset model

Data protection in Rizzqo is a taxonomy on the asset model. A process such as HR administration is a primary asset that can be flagged as containing personal data and assigned to a responsible person. The systems and service providers that support it take over its personal-data flag and its confidentiality rating. This shows which systems hold employee data, and purpose and legal basis can be recorded per link.

Security requirements, for example from ISO/IEC 27002, attach to the same systems and are answered and evidenced there. A risk such as unauthorized access to personnel files is rated with likelihood in percent and impact in euros, and the related tasks can be synced with Jira.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework