Law / Germany

GDPR Article 82, BDSG Sections 41-43, and BfDI and Landesdatenschutzbehörden Enforcement in Germany

Regulation (EU) 2016/679, Arts. 82-83; Bundesdatenschutzgesetz (BDSG) §§41-43

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018.

An enforcement supervision rule binding public and private bodies.

As of 2 September 2026.

What it requires

  • Expect a German data protection authority to have jurisdiction and fining power, up to the higher of EUR 20,000,000 or 4 percent of global annual turnover, over your processing of personal data of a person in Germany.
  • Expect any person who suffered material or non-material damage from an infringement to have a direct right to claim compensation from you as controller or processor, under General Data Protection Regulation (GDPR) Article 82, and expect a qualifying consumer-protection association to be able to bring a representative claim on behalf of a group of affected consumers under the VDuG.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

BDSG Section 42 creates two federal criminal offences layered on top of the GDPR's purely administrative fines. Section 42(1): knowingly and without authorisation transmitting to a third party, or otherwise making accessible, not-generally-accessible personal data of a large number of people, done commercially, carries imprisonment of up to three years or a fine. Section 42(2): processing not-generally-accessible personal data without authorisation, or obtaining it by false pretences, done for payment or with intent to enrich oneself or another or to harm another, carries imprisonment of up to two years or a fine. Both offences are prosecuted only on complaint (Section 42(3)), and only the data subject, the controller, the Federal Commissioner for Data Protection and Freedom of Information (BfDI), or the competent supervisory authority may bring one.

Penalty structure

GDPR Article 83(5) sets the higher administrative-fine tier a German Land data protection authority applies, up to EUR 20,000,000 or 4 percent of total worldwide annual turnover of the preceding financial year, whichever is higher, for the gravest infringement categories. The narrower Article 83(4) tier, up to EUR 10,000,000 or 2 percent, applies instead to the controller and processor obligations in Articles 25 to 39. BDSG Section 43 layers a separate, much narrower national administrative fine on top of this EU-wide ceiling: mishandling a credit-information request under BDSG Section 30(1), or failing to properly or timely inform a consumer under Section 30(2) sentence 1, is a Germany-specific administrative offence (Ordnungswidrigkeit) carrying a fine of up to EUR 50,000, and Section 43(3) exempts public authorities and other public bodies from this fine entirely. Section 41 applies the Ordnungswidrigkeitengesetz's general administrative-offence procedure to GDPR Article 83(4) to (6) violations, with two of its provisions (Sections 17, 35 and 36 OWiG) disapplied.

Rule
Higher of
As of
2 September 2026
Currency
EUR
Fixed cap
20,000,000
Turnover percentage cap
4

Who enforces it

Enforcement body

Germany has a split structure. Under BDSG Section 40(1), the data protection authority of each of the 16 Laender supervises GDPR compliance by private-sector bodies (nichtoeffentliche Stellen) established or operating in that Land; there is no single national private-sector regulator. The Federal Commissioner for Data Protection and Freedom of Information (BfDI) instead supervises federal public bodies and specific federally regulated sectors (telecommunications and postal services) under separate BDSG provisions. The Laender authorities and the BfDI coordinate through the Datenschutzkonferenz (DSK), a non-statutory conference, rather than a single hierarchical regulator.

What it reaches

Obligation class

Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Germany's enforcement structure is 17 separate authorities: the federal BfDI and 16 state Landesdatenschutzbehorden, coordinated on fine calculation by the Datenschutzkonferenz's shared fining model.

BDSG Sections 41 to 43 add domestic criminal offenses on top of General Data Protection Regulation (GDPR) Article 83's administrative fine regime; total BfDI and state fines reached roughly EUR 160 million from 2018 to 2024, with the largest single BfDI action to date, against Vodafone GmbH, totaling EUR 45 million across two March 2025 decisions. Article 82 arms an individual directly, on the same no-seriousness-threshold terms established EU-wide by CJEU C-300/21.

Germany also has a functioning collective-redress channel: the CJEU (Case C-319/20, Verbraucherzentrale Bundesverband v Meta Platforms Ireland) held that Article 80(2) does not preclude a national provision letting consumer-protection associations sue for a GDPR violation without an individual data subject's mandate, and Germany's Verbraucherrechtedurchsetzungsgesetz (VDuG) lets the Verbraucherzentralen bring representative actions on behalf of an unlimited group of consumers for an infringement affecting at least 50 consumers.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

Read the law

Official Journal text, EUR-Lex, Regulation (EU) 2016/679
BDSG §§41-43; CJEU C-319/20; VDuG

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app