Berlin Commissioner for Data Protection and Freedom of Information: What companies need to know in 2026
The Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) is the supervisory authority for around 200,000 responsible persons in Berlin. This guide explains responsibility, reporting paths according to Art. 33 GDPR, current audit priorities and how you can keep evidence in an audit-proof manner.
The Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) is the responsible supervisory authority for every non-public body with headquarters in Berlin as well as for all state authorities in accordance with Section 18 of the Berlin Data Protection Act (BlnDSG). The house has been managed by Meike Kamp since January 2022. According to evaluations by the DSK 2025, the BlnBDI is one of the most active German supervisory authorities, measured in terms of fines per 100,000 inhabitants.
Anyone who processes personal data in Berlin should know exactly who is responsible, the reporting channels and the current areas of focus of the inspection. This guide classifies the authority legally, describes the 72-hour reporting path according to Art. 33 GDPR, summarizes the key points for 2026 and shows how an appointed data protection officer controls correspondence with the BlnBDI in a documented manner. Licence the workspace for your internal representatives or have our representatives order it.
Key Takeaways
- The BlnBDI is responsible for all those responsible with its headquarters in Berlin and will focus on tracking technologies, employee data protection and AI systems in 2026.
- Data breaches must be reported within 72 hours of becoming aware of them in accordance with Art. 33 GDPR, ideally via the BlnBDI online form with documented proof of receipt.
- An appointed data protection officer coordinates communication with authorities, maintains a list of procedures, TOMs and reporting documents and reduces the escalation time in an audit case.
Legal status and legal mandate of the BlnBDI
The BlnBDI is a supreme state authority in accordance with Section 17 BlnDSG and performs the tasks of a supervisory authority within the meaning of Art. 51 GDPR. It is not subject to instructions, is accountable to the Berlin House of Representatives and has around 90 full-time positions as well as its own budget in 2026.
The legal mandate includes two pillars: data protection in accordance with the GDPR and BlnDSG and freedom of information in accordance with the Berlin Freedom of Information Act (IFG Bln). The second pillar means that citizens have a right to access to files from public bodies, which the authority enforces.
In the area of data protection, the BlnBDI exercises all of the investigative, remedial and approval powers mentioned in Art. 58 GDPR. It can request information, issue processing bans and impose fines of up to 20 million euros or 4 percent of global group sales.
For cross-border processing, the BlnBDI participates in the one-stop shop procedure in accordance with Art. 56 GDPR. It is in charge if the main branch is in Berlin, or the affected authority if Berlin citizens are affected. This dual role is relevant for corporations with a German holding in Berlin.
In practical terms, this means: Anyone who does not document the processing directory, technical and organisational measures as well as the appointment certificate package from the data protection officer in an audit-proof manner risks considerable follow-up costs in the event of a hearing. CIVAC operates a compliance platform and officer-as-a-service that stores versioned evidence.
Responsibility: When is the BlnBDI your authority?
The local jurisdiction depends on the location of the main branch within the meaning of Art. 4 No. 16 GDPR. If this is located in Berlin, the BlnBDI is responsible even if the company operates nationwide or internationally. It is not the mailbox that is relevant, but rather the location of the central administrative and processing decisions.
The BlnBDI is responsible for companies without a branch in the EU if the representative named in accordance with Art. 27 GDPR is based in Berlin. This constellation affects many US and UK providers who commission Berlin law firms as Article 27 representatives.
Public bodies in the state of Berlin are exclusively subject to the BlnBDI, even if they carry out processing outside of Berlin. This applies to senate administrations, district offices, state-owned companies such as BVG or Vivantes and to universities such as HU, FU and TU Berlin.
For group structures with several German locations, the lead authority is determined in accordance with Art. 56 GDPR. A joint controller with the Berlin headquarters is typically looked after by the BlnBDI as lead supervisory authority, while the other state authorities are called in as affected supervisory authorities.
Unsure about responsibility? An external data protection officer clarifies the main branch status based on the group guidelines, commercial register entries and actual decision-making processes. The appointment certificate, signed, filed, verifiable, is the first question every supervisory authority asks.
72-hour reporting path: Report data breaches correctly to the BlnBDI
According to Art. 33 Para. 1 GDPR, data protection violations must be reported to the responsible supervisory authority immediately, if possible within 72 hours of becoming aware of them. The deadline begins when we become aware of it, not when the incident occurs. The BlnBDI offers a structured online form for this purpose as well as an encrypted email channel via mailbox@datenschutz-berlin.de.
The report must contain at least four pieces of information: type of violation, categories and approximate number of people and data sets affected, expected consequences and remedial measures taken or proposed. If information is missing, a step-by-step report in tranches is permitted in accordance with Art. 33 Para. 4 GDPR.
The BlnBDI automatically confirms receipt with a process number. This number is part of the proof and belongs in the data breach register of the person responsible. Anyone who only submits the report by telephone will lose the documented receipt.
If there is likely to be a high risk to the rights and freedoms of those affected, a parallel notification to those affected in accordance with Art. 34 GDPR is required. The BlnBDI regularly checks whether the risk classification has been comprehensibly justified.
CIVAC stores 490 ready-to-use audit templates in the workspace, including reporting forms, escalation matrix and notification templates in accordance with Art. 34 GDPR. The auditor calls, the evidence is ready. Missed 72-hour deadlines are aggravating according to the DSK's fine assessment guidelines and regularly result in proceedings under Art. 83 GDPR.
Test focus areas for 2026: What do you expect?
The BlnBDI publishes annual activity reports and key topics. For 2026, the focus is on three areas: tracking technologies on websites and in apps, employee data protection in hybrid working models and the use of generative AI systems after the first stages of application of the EU AI Act come into force.
In the case of tracking technologies, the authority checks in particular the effectiveness of consent in accordance with Section 25 TDDDG and the existence of a rejection option on the first level of the cookie banner. In 2025, the BlnBDI wrote to several Berlin media companies and SaaS providers about dark patterns.
Employee data protection focuses on monitoring employees working from home, the use of Microsoft 365 with US data flows and the handling of applicant data. § 26 BDSG and the DSK resolution on Microsoft 365 from November 2022 form the test standard.
When using AI, the BlnBDI asks for data protection impact assessments, documented legal bases and contractual regulations with US LLM providers according to Art. 35 GDPR. Group-wide tools such as ChatGPT Enterprise or Microsoft Copilot will be increasingly examined on an ad-hoc basis in 2026.
Those who act proactively here will have the processing directory, the DPIA library and the order processing contracts mirrored by the external data protection officers. This means there are no gaps between marketing tools, IT inventory and data protection documentation.
Freedom of information: When citizens request files
The Berlin Freedom of Information Act (IFG Bln) grants everyone the right to inspect files from public bodies in the state of Berlin. Applications can be submitted informally. The authority must decide within two weeks; in complex cases the deadline is extended to one month.
The BlnBDI is a complaints office according to Section 18 IFG Bln. Citizens can contact the authority if an application has been rejected or a decision has not been made in a timely manner. The BlnBDI then requests statements and can make recommendations to the rejecting body.
For those responsible for the public, this means: file management must be organised in such a way that requests for information and access can be answered within the statutory deadline. Confidential components, such as personal data of third parties or company and business secrets, must be blacked out in accordance with Section 6 IFG Bln.
Private companies are not directly affected by the IFG Bln. However, public contracting authorities can oblige them to disclose procurement documents after the contract has been concluded. Conflicts with trade secrets are resolved via the hearing procedure in accordance with Section 14 IFG Bln.
Anyone who acts as a state-owned company or public institution should bundle IFG procedures and data protection inquiries in a uniform application register. CIVAC offers combined request management with deadline tracking and redaction workflow in the workspace.
BlnBDI's fine practice: numbers and standards
The BlnBDI has imposed several fines in the double-digit million range since the GDPR came into force in May 2018. What is known is the 14.5 million euro decision against Deutsche Wohnen SE from 2019, which was essentially confirmed in 2023 after several years of proceedings.
According to an evaluation of publicly known proceedings, the average fine for medium-sized companies is between 50,000 and 250,000 euros. The type, severity, duration and intent of the violation as well as the willingness to cooperate in the procedure are decisive for the assessment.
According to the DSK fine guidelines from October 2022, a basic amount is initially determined based on the group turnover. Factors such as severity of the violation and degree of fault multiply this base amount. Delayed reports, missing DPIAs and incomplete procedural directories make things more difficult.
To mitigate the situation, the BlnBDI takes demonstrably implemented training courses, an appointed and registered data protection officer, a functioning ISMS and timely participation in the process into account. These factors measurably reduce the multiplier and can halve the final amount.
In concrete terms, this means: Anyone who presents complete audit templates, proof of training and reporting documentation will significantly reduce the amount of the fine. Others run compliance like a filing cabinet. We run it like software. CIVAC secures exactly the evidence in the reporting line that is crucial in the hearing process.
Correspondence with the BlnBDI: process and pitfalls
The correspondence typically begins with a confirmation of receipt and an initial request for a statement in accordance with Section 28 VwVfG. The BlnBDI regularly sets deadlines of four weeks, and in complex cases six weeks. Extensions of deadlines are usually granted upon a justified request.
In terms of content, the authority expects document-based answers: processing list, affected contracts, technical and organisational measures, if necessary DPIA and proof of training. Blanket assurances without evidence will be rejected in follow-up letters and will prolong the procedure.
Lawyer representation is not mandatory, but recommended in fine proceedings. The appointed data protection officer coordinates the technical processing, and the law firm carries out the procedural defence. In our experience, this division of labour shortens the duration of the procedure by 30 to 50 percent.
Silence is not an option at any stage of the procedure. According to Section 30 OWiG, the BlnBDI can impose penalty payments if there is no cooperation and can regard silence as aggravating the fine procedure. Non-objective or polemical written submissions also damage the position.
Anyone who licences the workspace or appoints our representatives receives a structured library of templates for each phase of the procedure. The following applies to supervisory communication: audit-proof, documented, Section 33-proof. Every statement sent is available in version form with proof of delivery in the CIVAC workspace.
Collaboration with the BlnBDI as part of a consultation
The BlnBDI offers advice in accordance with Article 57 Paragraph 1 Letter d GDPR. Before introducing new processing operations, those responsible can obtain opinions on legal bases, data flows or third-country transfers. Such upfront consultations are free of charge and are usually answered within eight to twelve weeks.
Preliminary consultations in accordance with Art. 36 GDPR are mandatory if there is a high residual risk after a DPIA. The BlnBDI then checks the planned processing and can impose requirements or bans. A preliminary consultation usually lasts ten to sixteen weeks.
For rules of conduct according to Art. 40 GDPR and certifications according to Art. 42 GDPR, the BlnBDI is the approval or accreditation body. This is a way for Berlin associations and industry associations to anchor industry-specific standards in a legally secure manner.
The BlnBDI activity report is required reading every year. It contains case numbers, procedural types and interpretations that are used as a benchmark in hearings. CIVAC evaluates the report and makes the relevant passages available to the clients as a briefing.
In practical terms, this means: Anyone who communicates with the BlnBDI early avoids late escalations. The compliance platform and officer-as-a-service complement each other ideally here, because the external data protection officer manages the content of correspondence with authorities, while the workspace stores the documents in a structured manner.
CIVAC supports the dialogue with the Berlin data protection authority
CIVAC works as a compliance platform and officer-as-a-service. Licence the workspace for your internal representatives or have our representatives order it. Both models use the same data standard, the same 490 audit templates and the same EU data residency. The appointment certificate, signed, filed, verifiable, is created within 2 working days.
Modules relevant for correspondence with the BlnBDI: processing directory according to Art. 30 GDPR, DPIA library according to Art. 35 GDPR, data breach register with 72h escalation, order processing contracts according to Art. 28 GDPR, training module with participant protocol and audit-proof Audit trail.
Our appointed data protection officers currently look after around 200 clients in Berlin, Brandenburg and nationwide. You know the BlnBDI's escalation routines, the typical statement patterns and the clerk structures. The average duration of the procedure is measurably reduced.
All letters, confirmations of receipt and evidence are stored in version form in the workspace. The reporting line to management is maintained automatically. Every process can be exported as a PDF file at the push of a button, for example for internal auditing or the supervisory board.
Turn reading into a mandate. If you would like to put your official correspondence with the BlnBDI on an audit-proof basis, write to info@civac.de or use the contact form on civac.de. We will respond within 2 working days with an initial analysis and a suggestion for the model.
FAQ
Is the BlnBDI also responsible for branches outside of Berlin?
The BlnBDI is responsible if the main branch is in Berlin according to Art. 4 No. 16 GDPR, even if the company operates nationwide. The location of the central processing decisions is decisive, not the mailbox or the headquarters of a subsidiary.
What is the deadline for reporting a data breach to the BlnBDI?
According to Art. 33 Para. 1 GDPR, a 72-hour deadline applies from the date of knowledge of the data protection violation. The clock starts on awareness. The report is made via the BlnBDI online form with automatic confirmation of receipt.
How high are typical BlnBDI fines for medium-sized companies?
According to publicly known procedures, fines for medium-sized companies are usually between 50,000 and 250,000 euros. The amount depends on group sales, severity and degree of culpability as well as the cooperation and presence of an appointed data protection officer.
What testing priorities does the BlnBDI pursue in 2026?
For 2026, the focus will be on tracking technologies in accordance with Section 25 TDDDG, employee data protection including Microsoft 365 and home office as well as the use of generative AI. The benchmark is the GDPR, the BlnDSG and the EU AI Act in their respective levels of validity.
Do I have to report a data protection officer to the BlnBDI?
Yes. According to Art. 37 Para. 7 GDPR, the contact details of the appointed data protection officer must be communicated to the responsible supervisory authority. The BlnBDI offers its own online form with a confirmation PDF, which is part of the appointment certificate package.
Does BlnBDI offer advice before introducing new processing methods?
Yes, according to Article 57 Paragraph 1 Letter d GDPR, advice is part of the legal mandate. Those responsible can obtain statements in advance; advance consultations in accordance with Art. 36 GDPR are mandatory after a DPIA if there is a high residual risk and last ten to sixteen weeks.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.