DIGITAL PRIVACY REGULATIONSThe Worldwide Register of Data Privacy Law
Tracking 197 jurisdictions
Language: English
Europe · In force · Opt-in

🇩🇪 Germany Data Privacy Laws

Germany runs data protection through seventeen authorities: the federal BfDI plus one per state, each with its own enforcement temperament. The TDDDG (renamed from TTDSG in 2024) puts the cookie consent rule in statute, and German courts produced Planet49, the CJEU case that killed pre-ticked boxes across Europe.

Updated September 28, 2026 · digitalprivacyregs.com
Status
In force
Consent model
Opt-in
Primary law
GDPR + BDSG + TDDDG (cookies and terminal equipment)
Year
2018
Authority
BfDI plus 16 state DPAs
Marketing consent
GDPR legal basis; TDDDG requires opt-in consent for cookies and device access.
Transfers
GDPR Chapter V.
Penalties
Up to EUR 20M or 4% of global turnover.

The GDPR baseline

As an EU member state, this jurisdiction applies the General Data Protection Regulation directly: every use of personal data needs one of six legal bases, individuals hold rights to access, correct, delete and port their data, breaches are reportable within 72 hours, and fines reach EUR 20M or 4% of global turnover. Layered on top, the ePrivacy Directive's national implementation requires prior consent for cookies and similar tracking, with electronic marketing on an opt-in basis softened only by the existing-customer exception.

For advertisers that means the EU standard playbook applies here in full: consent before tracking and behavioral targeting, a compliant consent platform, documented transfer mechanics for any non-EU stack, and one eye on the Digital Omnibus negotiations, which could amend the cookie rules once a final text is adopted. The national details below are what this member state adds or emphasizes.

The national layer

The national implementing act is the BDSG + TDDDG (cookies and terminal equipment), and day-to-day supervision belongs to the BfDI plus 16 state DPAs. Germany runs data protection through seventeen authorities: the federal BfDI plus one per state, each with its own enforcement temperament. The TDDDG (renamed from TTDSG in 2024) puts the cookie consent rule in statute, and German courts produced Planet49, the CJEU case that killed pre-ticked boxes across Europe.

Key instruments

Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG)

2021, renamed 2024 · In force

Germany's ePrivacy implementation. Section 25 requires consent before storing or reading anything on a user's device unless strictly necessary. It also created the legal basis for recognized consent management services (PIMS), a concept the EU later borrowed for its own reform debate.

Official source →

Marketing and advertising

GDPR legal basis; TDDDG requires opt-in consent for cookies and device access. Most channel decisions here follow from that consent rule.

Buyers should know that German DPAs coordinate through the DSK conference and publish joint positions, including a strict line on Google Analytics-era transfers and on the telemetry of major platforms. Consent rates and banner design get audited here more than almost anywhere else in the EU.

Cross-border transfers

GDPR Chapter V applies in full, so personal data leaves the EEA only under an adequacy decision, standard contractual clauses, binding corporate rules or a narrow derogation, with a transfer impact assessment expected where the destination has surveillance-law exposure. The mechanics are identical across the bloc, so a transfer stack built for one member state travels to all of them.

Enforcement and penalties

The GDPR's ceiling applies, with fines up to EUR 20M or 4% of global annual turnover, whichever is higher, levied by the national supervisory authority, and the EDPB can force a harder line through the dispute mechanism. Member states share the ceiling and differ in enforcement appetite.

Primary sources

Cite this page: "Germany Data Privacy Laws." Digital Privacy Regulations, September 28, 2026, https://digitalprivacyregs.com/germany.html. Accessed [date].