German Data Protection Law
Constitutional Foundation and the GDPR
German data protection law is built on a strong constitutional foundation. The Federal Constitutional Court (Bundesverfassungsgericht) recognised the right to informational self-determination (Recht auf informationelle Selbstbestimmung) in its landmark Volkszahlungsurteil (Census Act decision) of 15 December 1983. The court derived this right from Articles 2(1) and 1(1) GG, holding that individuals have the right to determine the disclosure and use of their personal data. This constitutional right imposes affirmative obligations on the state to establish data protection frameworks and limits both public and private sector data processing.
The General Data Protection Regulation (GDPR, Regulation 2016/679) has been directly applicable in Germany since 25 May 2018, supplemented by the Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG) as amended. The BDSG contains opening clauses permitted by the GDPR, including provisions on employee data protection, video surveillance, data protection officers, and processing of special categories of data. The interaction between the GDPR and the BDSG follows the principle that national law may specify but not contradict the GDPR, within the scope of opening clauses.
The BDSG and National Implementation
The BDSG (BDSG-neu, effective 2018) replaced the former BDSG 2003 and implements the GDPR’s opening clauses. Key provisions include:
- Section 4 BDSG: video surveillance of publicly accessible spaces, subject to strict necessity and transparency requirements
- Sections 6-7 BDSG: data protection officer requirements; both public and private sector controllers must appoint a data protection officer if they employ at least 20 persons who regularly process personal data (Section 38 BDSG)
- Sections 8-21 BDSG: special provisions for processing of personal data by public bodies, including the principle of data processing for the public interest
- Section 22 BDSG: processing of special categories of data (Article 9 GDPR) for public interest purposes, including scientific research, public health, and social security
- Section 26 BDSG: employee data protection, specifying the conditions under which employee data may be processed (see below)
- Sections 40-44 BDSG: provisions on the independent supervisory authorities
The Schufa Decisions
The Schufa (Schutzgemeinschaft fur allgemeine Kreditsicherung) is Germany’s largest credit reporting agency, maintaining credit scores (Bonitatsauskunfte) on virtually all German consumers. The BVerfG and the Court of Justice of the European Union have rendered pivotal decisions on the Schufa’s scoring methodology.
In its decision of 8 November 2018 (1 BvR 16/13), the BVerfG held that Schufa’s probability-based scoring constitutes an automated decision under Section 31 BDSG (now Article 22 GDPR), requiring transparency and the right to obtain meaningful information about the logic involved. The court emphasised that decisions having legal effects or significantly affecting individuals may not be based solely on automated processing without human involvement.
The CJEU in the Schufa decision (C-634/21, 7 December 2023) clarified that Schufa’s credit scores constitute “automated individual decision-making” within Article 22 GDPR, and that where a bank uses such a score to decide on credit, the bank cannot rely solely on the automated decision. The CJEU also held that controllers must provide meaningful information about the logic and significance of the credit scoring process. These decisions have significantly increased transparency requirements for the German credit reporting industry.
Employee Data Protection
Employee data protection is governed by Section 26 BDSG, which provides the legal basis for processing employee data necessary for employment-related purposes. Section 26(1) BDSG permits processing for decisions on establishing, implementing, or terminating an employment relationship or for fulfilling legal obligations under employment law. Processing for internal planning and organisational purposes is also permitted.
Section 26(4) BDSG provides special rules for employee monitoring: processing that involves covert surveillance or analysis of employee behaviour is subject to strict conditions. The employer must demonstrate a legitimate interest that overrides the employee’s privacy rights, and the means employed must be proportionate. The Betriebsrat (works council) has co-determination rights over the introduction of technical monitoring devices under Section 87(1)(6) of the Works Constitution Act.
The BVerfG’s decision of 20 December 2022 on the constitutional limits of employee monitoring in the insurance sector established that even GDPR-compliant processing may violate the constitutional right to informational self-determination where the processing is extensive and affects the employee’s core private sphere. The decision has prompted legislative proposals for a dedicated Employee Data Protection Act (Beschaftigtendatenschutzgesetz), which has been debated since 2010 but has not yet been enacted.
Video Surveillance
Video surveillance in Germany is regulated by Section 4 BDSG and Article 6 GDPR. Section 4 BDSG permits video surveillance of publicly accessible spaces only where necessary: (1) to fulfil public authority tasks; (2) to exercise the right of determination over access; or (3) to pursue legitimate interests for specifically defined purposes. The surveillance must be proportionate, and the purpose must be documented. Visible signage indicating the surveillance is required, and recordings must be deleted within 48 hours unless an incident requiring retention has occurred.
Video surveillance in the workplace is governed by Section 26 BDSG and the co-determination rights of the works council. Covert video surveillance is permitted only in exceptional circumstances and subject to strict conditions: there must be a specific suspicion of criminal conduct, the surveillance must be the least intrusive means available, and it must be limited in time and scope. The BVerfG has repeatedly held that covert surveillance violates the right to informational self-determination unless justified by overriding interests.
Data Protection Authorities
Data protection enforcement in Germany is carried out by the Federal Commissioner for Data Protection and Freedom of Information (Bundesbeauftragter fur den Datenschutz und die Informationsfreiheit, BfDI) for federal public bodies and telecommunications, and by the independent data protection supervisory authorities of the Lander (Landesdatenschutzbeauftragte) for non-public controllers and Land public bodies.
The supervisory authorities have extensive enforcement powers under Articles 57-58 GDPR, including: the power to investigate, issue warnings, order compliance, impose limitations or bans on processing, impose administrative fines of up to EUR 20 million or 4 per cent of annual worldwide turnover (Article 83 GDPR), and order suspension of data flows to third countries. The one-stop-shop mechanism under Article 56 GDPR designates the lead supervisory authority for cross-border processing; in Germany, the lead authority is typically the authority of the Land where the controller has its main establishment.
The German supervisory authorities operate under the coordinating framework of the Data Protection Conference (Datenschutzkonferenz, DSK), which issues guidelines and decisions to harmonise enforcement across the Lander. The DSK’s orientations, while not legally binding, carry significant persuasive authority and guide supervisory practice nationwide.