{
 "jurisdiction_id": "DE",
 "jurisdiction": "Germany",
 "url": "https://dataprotection.gi/jurisdictions/germany/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 0,
  "sub_modules": 57,
  "source_register": 36
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/germany/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive, mature, directly-applicable EU omnibus regime with a stable national implementing act; only amber-adjacent risk is the ongoing BfDI leadership transition and EU Digital Omnibus reform uncertainty.",
   "claims": []
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/germany/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Core GDPR bases are firmly in force (green), but §26 BDSG's acknowledged normative imprecision on special-category employee data and the absence of a dedicated Employee Data Protection Act create interpretive uncertainty, justifying an amber rating for this module overall.",
   "claims": []
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/germany/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Directly-applicable EU rights regime with detailed, current BfDI operational guidance; only narrow, well-defined statutory exceptions exist.",
   "claims": []
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/germany/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Robust, CJEU-tested accountability framework with clear national thresholds and multiple layered breach-notification regimes; no material gaps identified.",
   "claims": []
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/germany/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Fully harmonised EU transfer regime with no national derogation gaps identified; rated green reflecting legal certainty, though DE-specific granularity is inherently limited because the mechanism operates at EU level.",
   "claims": []
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/germany/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Telecom/eprivacy and health overlays are well-developed and green; credit-scoring/Art 22 interface remains actively contested at CJEU level, and education/insurance sub-modules lack identified DE-specific overlays, justifying an overall amber rating.",
   "claims": []
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/germany/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Cookie/tracker consent regime is mature and green, but clean-room and cross-context-advertising sub-modules have no identified DE-specific statutory basis, and dark-pattern guidance rests on DSK soft-law rather than binding statute.",
   "claims": []
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/germany/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Art 22 GDPR framework is in force and actively enforced/litigated (green core), but AI-specific risk-assessment rules, biometric-specific statute, and genetic-data-specific statute are all absent or still in guidance/proposal stage, and state-surveillance oversight architecture is itself subject to unresolved reform proposals.",
   "claims": []
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/germany/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "The core Art 8 consent-age rule is settled and green, but minor-profiling-specific bans, education-settings-specific rules, and dependent-adult-specific protections were not identified as distinct DE statutory sub-regimes, and BfDI itself flags the EU reform track as currently under-addressing children's data protection.",
   "claims": []
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/germany/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Well-resourced, actively enforcing regulator network with recent multi-million-euro fines and detailed activity reporting; rated green notwithstanding the leadership transition and open EU-level reform debate, since core enforcement capacity remains fully operative.",
   "claims": []
  }
 ]
}