Law / Germany

GDPR Articles 12-21 and BDSG Sections 34 and 35, Data Subject Rights in Germany

Regulation (EU) 2016/679, Arts. 12-21; Bundesdatenschutzgesetz (BDSG) §§ 34, 35

In force since .

A data subject rights rule binding public and private bodies.

As of .

What it requires

  • Honor a person's request to access, rectify, erase, restrict, port, or object to processing of their personal data in Germany within one month of receipt.
  • You need not give a person in Germany access under General Data Protection Regulation (GDPR) Article 15 to personal data you keep only because a statutory or regulatory retention duty forbids deleting them, or that serve only data backup or data-protection audit, where giving access would take disproportionate effort and you have technically and organisationally excluded any other use of the data, under BDSG Section 34(1) No. 2.
  • Where non-automated storage makes erasing a person's data in Germany impossible or disproportionately costly and their interest in erasure is minor, restrict processing of the data instead of erasing it, unless the data were processed unlawfully, under BDSG Section 35(1).

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Under General Data Protection Regulation (GDPR) Articles 12 to 21, a person in Germany can ask a controller for access to their personal data and for its rectification, erasure, restriction or portability, or object to its processing, and the controller must answer within one month, a period it may extend by two further months for complex or numerous requests. The BDSG narrows two of these rights for any controller.

Section 34 removes the access right for data kept only because a retention duty forbids deleting them, or kept only for data backup or data-protection audit, where access would take disproportionate effort and any other use is technically and organisationally excluded. Section 35 replaces erasure with restriction where non-automated storage makes erasure impossible or disproportionately costly and the person's interest in erasure is minor, unless the data were processed unlawfully.

When LexLint raises it

When your app profile says your app crawls the web, trains models, generates content with AI, deploys a chatbot or sends automated outreach.

Back to the example  ·  Lint your app