The BDSG does not replace the GDPR; it sits next to it. Under § 1(5) BDSG, its provisions do not apply where the General Data Protection Regulation (Regulation (EU) 2016/679) applies directly. The duties under the regulation itself are set out in the GDPR guide for mid-sized companies.
Key takeaways
- The BDSG of June 30, 2017 (BGBl. I p. 2097) has applied since May 25, 2018 and replaced the BDSG of 1990.
- For companies, Part 2 (§§ 22 to 44) matters most: special categories, change of purpose, employee data, data subject rights, the data protection officer, supervision and sanctions.
- Under § 38(1) BDSG, a data protection officer must be designated where, as a rule, at least 20 persons are constantly engaged in the automated processing of personal data.
- After the CJEU judgment of March 30, 2023 (C-34/21), the Baden-Württemberg data protection commissioner considers § 26(1) sentence 1 BDSG probably inapplicable and points to Article 6(1) GDPR.
- From November 20, 2026, the new § 37a BDSG replaces the previous scoring rule in § 31 (Act of May 12, 2026, BGBl. 2026 I No. 139).
What is the BDSG?
The BDSG (Bundesdatenschutzgesetz, Federal Data Protection Act) is Germany's general federal data protection statute. It applies to federal public bodies and to private bodies such as companies; for these, § 1(1) sentence 2 covers fully or partly automated processing of personal data and data stored, or intended to be stored, in a filing system. Public bodies of the federal states are generally subject to state data protection acts. More specific federal data protection rules take precedence over the BDSG under § 1(2).
How the BDSG is structured in four parts
The act is divided into four parts (as of October 2026):
| Part | Sections | Content | Relevance for companies |
|---|---|---|---|
| Part 1 | §§ 1 to 21 | Scope, data protection officers of public bodies, Federal Commissioner (BfDI), cooperation of supervisory authorities | Medium: scope |
| Part 2 | §§ 22 to 44 | Implementing provisions for the GDPR | High: the day-to-day rules sit here |
| Part 3 | §§ 45 to 84 | Transposition of Directive (EU) 2016/680 for police and justice | Low |
| Part 4 | §§ 85 and 86 | Activities outside the scope of EU law | None |
BDSG and GDPR: the regulation prevails, the act fills the gaps
The GDPR takes precedence, and the BDSG supplements it where the regulation leaves room for member states through so-called opening clauses. Three examples: Article 88 GDPR allows more specific rules for the employment context, Article 37(4) allows national duties to designate a data protection officer, and Article 23 allows statutory restrictions of data subject rights.
A national rule that goes beyond this framework must be disregarded. Fines for data protection infringements generally follow Article 83 GDPR; § 43 BDSG adds only narrow offenses in consumer credit.
Eight BDSG provisions that matter in day-to-day business
For companies, eight provisions from Parts 1 and 2 are of practical relevance:
| Provision | Rule | What it means in practice |
|---|---|---|
| § 1 | Scope, precedence of the GDPR | The BDSG applies only where the GDPR leaves room |
| § 22 | Processing of special categories under Article 9 GDPR, for example to assess an employee's working capacity or under social security law | Employee health data requires safeguards under § 22(2) |
| § 24 | Change of purpose by private bodies | Further processing, for example to prosecute criminal offenses or to establish civil law claims |
| § 26 | Employee data | Consent, collective agreements, definition of employee; subsection 1 sentence 1 disputed after C-34/21 |
| §§ 32 to 37 | Restrictions of the rights to information, access, erasure and objection, automated individual decisions | Use exceptions only with a documented justification |
| § 38 | Data protection officer of private bodies | Mandatory from, as a rule, 20 persons or where a DPIA is required |
| § 40 | Supervision by the state authorities | With several establishments in Germany, Article 4(16) GDPR (main establishment) applies accordingly |
| §§ 42 and 43 | Criminal and administrative offenses | Up to three years' imprisonment or a fine for commercially passing on non-public data of a large number of persons without authorization; fines up to EUR 50,000 for consumer credit infringements |
What does § 26 BDSG say about employee data?
§ 26 BDSG governs when employers may process personal data of employees. Subsection 1 sentence 1 allows processing where it is necessary to establish, perform or terminate the employment relationship. Under subsection 2, consent must as a rule be given in writing or electronically, with information in text form on the purpose and the right to withdraw. Under subsection 8, applicants and former employees also count as employees.
CJEU judgment C-34/21: what it means for § 26 BDSG
On March 30, 2023, the Court of Justice of the European Union ruled in Case C-34/21 on § 23 of the Hessian Data Protection and Freedom of Information Act (HDSIG), which largely mirrors § 26 BDSG. A national rule qualifies as a more specific rule under Article 88 GDPR only if it meets the requirements of Article 88(2). Otherwise it must be disregarded, unless it constitutes a legal basis under Article 6(3) GDPR. The Court did not rule on § 26 BDSG itself.
The Baden-Württemberg Commissioner for Data Protection and Freedom of Information therefore considers § 26(1) sentence 1 BDSG probably inapplicable. In his view, companies base processing needed to perform the employment contract on Article 6(1)(b) GDPR, legal obligations on point (c), and other employer interests, after a balancing test, on point (f). He considers the rest of § 26 unaffected.
The wording of § 26 BDSG is unchanged after the 2026 amendments (as of October 2026). If your records of processing activities cite § 26(1) sentence 1 BDSG as the sole legal basis for employee data, add Article 6(1) GDPR to that entry; the commissioner recommends the same.
Data protection officer under § 38 BDSG: the 20-person threshold
A company must designate a data protection officer under § 38(1) BDSG where, as a rule, at least 20 persons are constantly engaged in the automated processing of personal data. The test is not total headcount but who regularly works with personal data in automated form.
Regardless of headcount, the duty applies where processing is subject to a data protection impact assessment under Article 35 GDPR, or where personal data is processed commercially for transfer, for anonymized transfer or for market and opinion research. The special protection against removal and dismissal under § 6(4) applies under § 38(2) only where the designation is mandatory.
BDSG amendments in 2026: scoring in § 37a, new duties in § 30
The BDSG was not amended in 2025; the preceding amendment is dated May 6, 2024 (BGBl. 2024 I No. 149). Two amending acts followed in 2026.
Act of May 12, 2026: § 37a replaces § 31 from November 20, 2026
Article 3 of the Act of May 12, 2026 (BGBl. 2026 I No. 139) enters into force on November 20, 2026. It deletes § 31 and inserts § 37a “Scoring”. Probability values may then not be based on, among other things, special categories under Article 9(1) GDPR, age, gender, name, social network data, incoming and outgoing bank account payments or address data, and they may not concern minors.
Data subjects will be able to learn which data and criteria were used and how the criteria are weighted. § 30 gains new duties for credit agencies and lenders in consumer credit.
Act of July 3, 2026: changes for police and justice
Article 3 of the Act of July 3, 2026 (BGBl. 2026 I No. 199) amends § 62(6) and § 70(1) in Part 3 (police and justice) and has no direct relevance for companies. The consolidated German text on gesetze-im-internet.de shows the May 12, 2026 amendment as its status and marks the July amendment as already incorporated in the text.
Employee data in Rizzqo's asset model
Data protection in Rizzqo is a taxonomy on the asset model. A process such as HR administration is a primary asset that can be flagged as containing personal data and assigned to a responsible person. The systems and service providers that support it take over its personal-data flag and its confidentiality rating. This shows which systems hold employee data, and purpose and legal basis can be recorded per link.
Security requirements, for example from ISO/IEC 27002, attach to the same systems and are answered and evidenced there. A risk such as unauthorized access to personnel files is rated with likelihood in percent and impact in euros, and the related tasks can be synced with Jira.