77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Data protection law in Germany: GDPR, BDSG and obligations 2026
Data Protection & Privacy

Data protection law in Germany: GDPR, BDSG and obligations 2026

8 September 202613 min readBy Lena Vogt
CIVAC

The German data protection law consists of the GDPR and BDSG. This article explains the ordering requirement, 72-hour reporting according to Art. 33 GDPR, the risk of fines and how you can properly document the obligations in 2026.

German data protection law has rested on two pillars since May 25, 2018: the General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and the new Federal Data Protection Act (BDSG, in force since May 25, 2018, last changed in 2023). The GDPR applies directly, the BDSG fills opening clauses, such as Section 38 BDSG on the obligation to appoint a company data protection officer for 20 or more people who constantly handle personal data automatically.

This article brings together the operational obligations that a company must master in 2026: appointment and reporting line of a data protection officer, list of processing activities in accordance with Art. 30 GDPR, data breach notification within 72 hours in accordance with Art. 33 GDPR and a fine limit of up to 20 million euros or 4% of global annual turnover in accordance with Art. 83 GDPR. CIVAC assigns each obligation to a template, a workflow and an audit-proof proof.

Key Takeaways

  • The German data protection law is the combination of GDPR and BDSG; Section 38 BDSG stipulates the obligation to appoint the DSB for 20 or more employees.
  • According to Art. 33 GDPR, data breaches must be reported to the responsible supervisory authority within 72 hours; the deadline begins as soon as they become known.
  • According to Art. 83 GDPR, violations can be punished with up to 20 million euros or 4% of global group sales.

What is the German data protection law? GDPR plus BDSG

When we talk about “the” data protection law, in Germany we mean two legal acts that work together. The GDPR as a European regulation has been directly applicable in every member state since May 25, 2018. The BDSG supplements them nationally, for example in video surveillance, employee data protection in accordance with Section 26 BDSG and the ordering threshold for the DPO in accordance with Section 38 BDSG.

There are also area-specific laws, such as the Telecommunications Digital Services Data Protection Act (TTDSG, since December 1st, 2021) for cookies and tracking and the Social Security Code for social data. Sectors such as banks, insurers and healthcare facilities are subject to additional regimes. Anyone looking for the term "data protection law" usually needs a consolidated view of all three levels.

At the state level, the state data protection laws (LDSG) apply to authorities, such as the DSG NRW or the BayDSG. They are only relevant for private companies if they perform public tasks or act on a sovereign basis. For most SMEs, the combination of GDPR + BDSG + TTDSG is the operational framework.

According to Art. 4 No. 7 GDPR, the person responsible is who decides on the purpose and means of processing, i.e. typically the management. She is personally liable if there is organisational negligence, such as a lack of training or a lack of a record of processing activities.

CIVAC reflects this multi-layered nature in the DSB role as a compliance platform and officer-as-a-service. Each obligation receives a template, a person responsible and proof in the workspace. Filing cabinet compliance becomes software compliance.

If you understand the framework, you will quickly realize that it is not about a single law, but about an operational specification. This is exactly where every audit starts, and this is exactly where fines arise if proof is missing.

Obligation to appoint: Who needs a data protection officer?

The obligation to order results from Art. 37 GDPR and § 38 BDSG. Private companies must appoint a DPO as soon as at least 20 people are constantly involved in the automated processing of personal data. Temporary workers, interns and external employees are counted as soon as they have access to systems with personal data.

Regardless of the number of employees, there is an obligation to order if the core activity includes extensive, regular and systematic monitoring of those affected (Art. 37 Para. 1 lit. b GDPR) or special categories of data are processed in accordance with Art. 9 GDPR, such as health data in practices, pharmacies or personnel service providers.

The order must be in writing The tasks according to Art. 39 GDPR must be explicitly defined, and the contact details of the DPO must be reported to the supervisory authority and made publicly available, typically in the legal notice or in the data protection declaration. A missing or incomplete order is subject to a fine of up to 10 million euros or 2% of global group sales according to Art. 83 Para. 4 GDPR.

The question of whether the order is placed internally or externally is a question of risk and costs. Internal DPOs are subject to protection against dismissal in accordance with Section 38 Paragraph 2 in conjunction with Section 6 Paragraph 4 BDSG, external DPOs can be replaced more quickly and have industry experience. Both models are permissible as long as independence, freedom from instructions and reporting line to top management are guaranteed.

CIVAC offers both models. Licence the workspace for your internal representatives, or have our representatives order it. The appointment certificate is created in the platform, signed and linked to the reporting line and escalation path in the task calendar. The appointment certificate, signed, filed, verifiable.

The decision should be documented, even if there is no obligation. A short written threshold check protects against later questions from the supervisory authority and excludes the argument that the order was "forgotten".

Art. 30 GDPR: List of processing activities

The register of processing activities (VVT) is the central evidence according to Art. 30 GDPR. Those responsible with at least 250 employees must use it, as must smaller companies as soon as risk processing, regular processing or special data categories in accordance with Art. 9 GDPR are involved. In practice, this affects almost every company with a human resources department, customer communication and IT systems.

In terms of content, Art. 30 Para. 1 GDPR requires at least the responsible person, purpose, data categories, recipient groups, third-country transfers, deletion periods and a general description of the technical and organisational measures. Every tool, every processor and every data flow needs to be mapped. Excel lists are legally sufficient, but in practice they fail due to versioning, searchability and auditability.

The VVT ​​must be presented to the supervisory authority immediately upon request (Art. 30 Para. 4 GDPR). In practice, “immediately” is interpreted as a few working days. Anyone who answers here with an outdated status signals organisational failure and risks an in-depth review with further requirements.

Typical errors: Shadow IT (marketing tools without IT approval), missing order processing agreements (AVV) according to Art. 28 GDPR, unchecked third country transfers to the USA since the EU-US Data Privacy Framework of July 10, 2023 and missing deletion concepts. Each of these points appears in supervisory procedures and leads to complaints.

CIVAC maintains the VVT ​​as a living table in the workspace. Each entry is linked to the AVV template, TOM description and deletion SLA. For audits, the platform delivers the export in a format suitable for authorities. The auditor calls, the evidence is ready.

The VVT ​​is not a one-off project, but a maintenance process. New tools, new providers, new data flows, every change needs to be implemented within a week. Otherwise, the document loses its evidentiary value and the person responsible has no line of defence in the supervisory proceedings.

Data breaches: 72 hours according to Art. 33 GDPR

If the person responsible becomes aware of a violation of the protection of personal data, he must report it to the responsible supervisory authority within 72 hours in accordance with Article 33 (1) GDPR. The clock starts on awareness. "Knowledge" means plausible information from an employee who can assess the scope, i.e. typically IT, DPO or management.

The report must contain the type and scope of the violation, categories and approximate number of people affected, expected consequences and measures taken. If information is missing, it may be submitted gradually in accordance with Art. 33 Para. 4 GDPR, but the reporting window remains 72 hours for the initial report. Anyone who reports later must justify the delay.

If there is a high risk to the rights and freedoms of those affected, a separate notification to those affected is required in accordance with Art. 34 GDPR, in clear and simple language. Risk exists when there is a threat of identity theft, financial damage or discrimination. Phishing incidents with contact data exfiltration almost always fall into this category.

Operationally, companies usually fail in three ways: firstly, there is no initial reporting workflow, secondly, there is no triage template, and thirdly, there is no reporting line to management with a time stamp. A data breach that is noticed on Mondays at 10 a.m. must be reported on Wednesdays at 10 a.m., including weekends.

CIVAC has the data breach reporting path available as a template in the workspace. Collection, triage, risk assessment and notification design run along a predefined path with a time stamp and a matrix of responsible persons. The connection to the NIS-2 reporting chain for affected facilities takes place via the same incident data set.

Anyone who has not trained on the 72-hour path loses time, evidence and trust in the crisis. One tabletop exercise per quarter with a documented protocol keeps the process sharp and at the same time fulfils the accountability requirement according to Art. 5 Para. 2 GDPR.

Fine range: Up to 20 million euros or 4% turnover

Art. 83 GDPR distinguishes between two levels of sanctions. Violations of formal obligations, such as orders, VVT, AVV or notification, are punishable by up to 10 million euros or 2% of the global annual consolidated turnover in accordance with Article 83 (4) GDPR. Material violations of principles, legal bases or rights of those affected fall under Art. 83 Para. 5 GDPR with up to 20 million euros or 4% of group sales.

The higher amount applies. For large corporations, the sales criterion pushes the scope well beyond the nominal euro limit. The German supervisory authorities publish fine statistics every year, individual notices are in the seven to eight-digit range, for example H&M (2020, 35.3 million euros) or notebooksbilliger.de (2021, 10.4 million euros, later reduced).

The amount of fines is based on the DSK fine concept and the guidelines document 04/2022 of the European Data Protection Board. Severity, intent, cooperation, repetition and turnover all come into play. A documented compliance structure, for example via a platform with an auditable workspace, has a reducing effect.

In addition to fines, there is a risk of claims for damages in accordance with Art. 82 GDPR. Since the ECJ case law (C-300/21 of May 4, 2023), the claim is not tied to a materiality threshold; non-material damage is generally compensable. Class action lawsuits under Section 8 UWG and the consumer lawsuit register increase the pressure even further.

Personal liability of the management applies according to Section 130 OWiG in the event of supervisory negligence. Anyone who fails to appoint a DPO, does not keep a register and cannot provide evidence of training not only risks a company fine, but also personal liability. Audit-proof, documented, § 130 OWiG-proof.

CIVAC documents every action, every template version and every training participation. In the fine proceedings, the evidence decides. Anyone who delivers a compliance file within 48 hours moves the hearing from the sentencing to the proportionality test.

Third country transfers: USA, Schrems II and the DPF

Transfers of personal data to third countries are only permitted under the conditions of Art. 44 ff. GDPR. The EU-US Data Privacy Framework (adequacy decision C(2023) 4745) has been in effect for the USA since July 10, 2023. Companies that are certified in the USA and are on the DPF list can receive data without additional guarantees.

For non-certified US recipients and all other unsafe third countries, the EU Standard Contractual Clauses (SCC) remain mandatory according to Implementing Decision (EU) 2021/914, supplemented by a Transfer Impact Assessment (TIA) according to Schrems II (ECJ C-311/18 dated July 16, 2020). The TIA checks whether there is a threat of access from security authorities in the recipient country and what additional technical measures (such as encryption, pseudonymization) are required.

In practice, this affects almost every company that uses US cloud services: Microsoft 365, Google Workspace, AWS, Salesforce, HubSpot. The provider's DPF certification must be actively checked; a simple click on the provider's data protection declaration is not enough. The supervisory authorities require documented proof per recipient.

EU data residency is an alternative, not a replacement. Processing workloads in EU regions reduces third country risk, but does not completely eliminate it as long as a US parent company has access (CLOUD Act, FISA 702). CIVAC itself hosts exclusively in the EU and documents the data flows with a list of subservice providers.

For the DSB this means: third country transfers belong in the VVT, each recipient must be provided with a legal basis and TIA, and updates to the DPF status must be checked quarterly. CIVAC provides the TIA template and an update tracker for the DPF list.

Anyone who carries out transfers without a valid legal basis risks a ban according to Art. 58 GDPR and a fine according to Art. 83 Para. 5 GDPR. The “Meta Platforms Ireland” case shows that billion-dollar corporations can also fail here; the DPC fine from May 22, 2023 amounted to 1.2 billion euros.

Rights of those affected: information, deletion, objection

The GDPR grants data subjects six core rights: information (Art. 15), rectification (Art. 16), deletion (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). Applications must generally be answered within one month, which can be extended by two months if they are complex (Art. 12 Para. 3 GDPR).

The right to information according to Art. 15 GDPR is the most common in practice. The controller must provide a copy of all data processed, including purposes, categories, recipients, storage period and origin. The ECJ has interpreted the claim broadly in C-487/21 (05/04/2023): Pseudonymized data and internal notes fall under this if they relate to the person.

Requests for deletion in accordance with Art. 17 GDPR must be weighed against legal retention obligations. Commercial letters, accounting records and personnel files are subject to Section 257 of the German Commercial Code (HGB), Section 147 of the AO and Section 14b of the UStG with periods of six to ten years. A blanket deletion is not permitted, blocking with a specific purpose is the right way.

Objections to direct advertising in accordance with Art. 21 Para. 2 GDPR are absolute, the person responsible must stop processing immediately. In the case of other objections, such as against profiling, a balancing of interests is required and must be documented. Silence is considered a violation and is subject to a fine.

Processing applications is a classic bottleneck. Anyone who receives several dozen applications per quarter will fail without a workflow. CIVAC manages each application as a process with SLA, person responsible and full-text export from the source systems. The answer to the person concerned is stored in the workspace with version protection.

A missing or late answer is subject to a fine according to Art. 83 Para. 5 GDPR and is a frequent trigger for supervisory complaints. Wer die Frist im Blick behält, vermeidet drei Folgen: Bußgeld, Beschwerde, Reputationsschaden.

BDSG specifics: employee data protection and video surveillance

The BDSG fills the opening clauses of the GDPR. Section 26 BDSG regulates employee data protection: Processing of employee data is permitted to the extent that it is necessary for the establishment, implementation or termination of the employment relationship. Consent is only effective under strict conditions, as the voluntary nature of the employment relationship is questionable.

Applicant data may typically be stored for six months after rejection in order to be able to respond to AGG lawsuits (Section 15 Para. 4 AGG, filing deadline two months plus evidence buffer). Longer storage requires the applicant's express consent, for example for a talent pool.

Video surveillance in accordance with Section 4 BDSG is only permitted if there is a legitimate interest and taking proportionality into account. Publicly accessible areas must be marked with information signs; the recording period should not exceed 48 to 72 hours unless there is a specific reason. The DSK orientation aid for video surveillance (as of 2020) provides the framework.

Cookies and tracking have been subject to the TTDSG (§ 25 TTDSG) since December 1st, 2021. Informed, voluntary and revocable consent must be obtained before each non-essential cookie. Pre-ticked boxes and dark patterns are not permitted (ECJ C-673/17 "Planet49" dated October 1, 2019). The supervisory authorities have been increasingly checking consent banners since 2024.

For the DSB this means: personnel files, application processes, video systems and consent management belong in the VVT; every measure needs a legal basis and a deletion plan. CIVAC offers templates for employee data protection concepts, video surveillance directories and consent audits.

Anyone who underestimates the BDSG specifics will be exposed to complaints more often than with GDPR fundamental questions. Employees, applicants and visitors are increasingly aware of their rights, and a lawyer can formulate a complaint in 30 minutes.

Turn reading into an assignment

The Data Protection Act is not a document, but a set of requirements. Ordering, directory, reporting, third country transfers, rights of those affected, BDSG specifics, every obligation creates templates, workflows and evidence. Anyone who does this with Word and Excel loses time, version status and evidence.

CIVAC is the compliance platform and officer-as-a-service that translates exactly these obligations into software. 490 ready-to-use audit templates, 25 agent roles, EU data residency, ISO 27001:2022-ISMS in the background. Others run compliance like a filing cabinet. We run it like software.

You have the choice between two models. Licence the workspace for your internal representatives, or have our representatives order it. Both variants provide the appointment certificate, the reporting line to the management and the documented evidence for each supervisory request.

The onboarding path starts with the threshold check according to Section 38 BDSG, the VVT ​​recording and the reporting path definition according to Art. 33 GDPR. The SLA for external orders is two working days, instead of two to six weeks in the classic model. The FAQ area answers the most common onboarding questions.

If you are unsure whether your organisation is required to order, whether your VVT is audit-proof or whether your reporting path meets the 72-hour window, write to info@civac.de or use the contact form on civac.de. A short inventory takes 30 minutes and the results are available on the same day.

Turn reading into an assignment. Anyone who knows the obligations has taken the first step. Anyone who documents it in an audit-proof manner has reduced the risk. CIVAC accompanies both steps and, if desired, takes on the role itself.

FAQ

For how many employees do you have to appoint a data protection officer?

According to Section 38 BDSG, there is an obligation to order from 20 people who constantly handle personal data automatically. Regardless of this, Art. 37 GDPR applies to extensive monitoring or processing of special categories of data. Temporary workers and external workers count.

How long do you have to report a data breach?

According to Art. 33 GDPR, a deadline of 72 hours applies from the date of knowledge. The report is sent to the responsible supervisory authority and, if the risk is high, also to those affected in accordance with Art. 34 GDPR. Weekends and public holidays do not extend the deadline.

What fines are there for violations of the Data Protection Act?

Art. 83 GDPR provides for two stages. Formal violations are punished with up to 10 million euros or 2% of global group sales, material violations with up to 20 million euros or 4%. The higher amount applies.

Do you need to keep a record of processing activities?

Yes, as soon as there is regular processing, risk processing or special data categories in accordance with Art. 9 GDPR. In practice, this affects almost every company with a human resources department and customer contacts. Exceptions according to Art. 30 Para. 5 GDPR rarely apply.

Are data transfers to the USA permitted again?

The EU-US Data Privacy Framework has been in effect since July 10, 2023. Transfers to DPF certified recipients are permitted without additional guarantees. For non-certified recipients, standard contractual clauses plus transfer impact assessment according to Schrems II remain mandatory.

What distinguishes an internal from an external data protection officer?

Internal DPOs enjoy protection against dismissal according to Section 38 BDSG, external DPOs bring industry experience and interchangeability. CIVAC offers both models: Workspace licence for internal orders or Officer-as-a-Service with two business days SLA for external orders.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles