🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
DE · run data-protection-2026-07-29 v13-gdpri-1.0.0
content: ai_generated 36 sources retrieved model claude-sonnet-5 ·

Germany

DE schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 0 claims · 36 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
0Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

Lead Signal

Germany's federal data protection authority closed out a high-intensity enforcement stretch while confirming a leadership succession that will steer the regulator through the remainder of 2026. The BfDI fined Vodafone GmbH €15 million and €30 million, plus a formal reprimand, for violations of GDPR Articles 28 and 32. Hamburg's state authority, the HmbBfDI, is reported to have imposed its own six-to-seven-figure sanctions — €775,000, €492,000, and €900,000 — across 2024 and 2025. The BfDI's 34th Activity Report is further reported to record 80 on-site inspections, 40 written inspections, and 129 supervisory measures conducted in 2025, a caseload the authority says its roughly 380 staff across Bonn and Berlin are absorbing. Separately, Prof. Dr. Moritz Hennemann has been elected as incoming BfDI, succeeding Prof. Dr. Louisa Specht-Riemenschneider, who remains in office in a transitional capacity until 30 September 2026 for health reasons.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive, mature, directly-applicable EU omnibus regime with a stable national implementing act; only amber-adjacent risk is the ongoing BfDI leadership transition and EU Digital Omnibus reform uncertainty.

Primary frameworkRegulation (EU) 2016/679 (GDPR) as implemented and supplemented by the Bundesdatenschutzgesetz (BDSG-neu)
Traffic-light rationale — GreenComprehensive, mature, directly-applicable EU omnibus regime with a stable national implementing act; only amber-adjacent risk is the ongoing BfDI leadership transition and EU Digital Omnibus reform uncertainty.

Sub-modules (5)

Regulator And AuthorityGreen

BfDI supervises federal public bodies and federally-regulated private-sector entities (post, telecoms); 17 Land DPAs supervise private-sector and Land-level public bodies.

Claims: CLM-DE-a1b2c3d4, CLM-DE-b2c3d4e5

Act And InstrumentsGreen

BDSG-neu is the national GDPR implementing act; TTDSG is lex specialis for telecom/telemedia and cookies.

Claims: CLM-DE-c3d4e5f6, CLM-DE-d4e5f6a7

Material ScopeGreen

GDPR Art 2 material scope covers wholly/partly automated processing and structured manual filing systems, directly applicable in Germany.

Claims: CLM-DE-e5f6a7b8

Territorial ScopeGreen

GDPR Art 3(2) extends to non-EU controllers targeting or monitoring individuals in Germany/the EU.

Claims: CLM-DE-f6a7b8c9

Regulator Registration And FilingGreen

DPO contact details for federally-supervised entities must be filed with BfDI via a dedicated notification form/portal.

Claims: CLM-DE-a7b8c9d0

Category narrative104 words

Germany applies the GDPR directly, supplemented by the federal Bundesdatenschutzgesetz (BDSG-neu) which is subsidiary and applies only where the GDPR permits national derogation or leaves gaps. Supervision is federated: the Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) supervises federal public bodies and certain federally-regulated private sectors (post, telecoms), while 17 Land-level authorities (16 Länder, with Bavaria splitting public/private-sector oversight) supervise private-sector and Land public-sector processing. A leadership transition is underway: Prof. Dr. Moritz Hennemann has been elected by the Bundestag as incoming BfDI, succeeding Prof. Dr. Louisa Specht-Riemenschneider, who remains in office in a transitional capacity until 30 September 2026 for health reasons.

No periodic updates recorded against this sub-brief.

#

Core GDPR bases are firmly in force (green), but §26 BDSG's acknowledged normative imprecision on special-category employee data and the absence of a dedicated Employee Data Protection Act create interpretive uncertainty, justifying an amber rating for this module overall.

Primary frameworkGDPR Articles 6-9, as supplemented by BDSG §§22, 26
Supervisory authorityBfDI
Traffic-light rationale — AmberCore GDPR bases are firmly in force (green), but §26 BDSG's acknowledged normative imprecision on special-category employee data and the absence of a dedicated Employee Data Protection Act create interpretive uncertainty, justifying an amber rating for this module overall.

Sub-modules (4)

Lawful BasesAmber

Six Art 6(1) GDPR bases apply; §26 BDSG (Art 88 opening clause) governs employment-context processing but is considered too imprecise by BfDI/DSK.

Claims: CLM-DE-b8c9d0e1, CLM-DE-c9d0e1f2

Special CategoriesAmber

Art 9(2)(a) explicit consent required for sensitive data; §26(3) BDSG imposes additional employment-context conditions.

Claims: CLM-DE-f2a3b4c5, CLM-DE-a3b4c5d6

Pseudonymisation And AnonymisationGreen

TTDSG §19(2) requires telemedia providers to enable anonymous/pseudonymous use where technically feasible and reasonable.

Claims: CLM-DE-b4c5d6e7

Category narrative70 words

Lawful processing follows the six GDPR Art 6(1) bases, with Germany exercising the Art 8 opening clause to set the digital-consent age at 16 and the Art 88 opening clause to enact §26 BDSG for employment-context processing (criticized by BfDI/DSK as too imprecise, prompting calls for a standalone Employee Data Protection Act). Special-category processing requires explicit consent or a statutory exception; TTDSG imposes an ancillary pseudonymisation/anonymous-use obligation on telemedia providers.

No periodic updates recorded against this sub-brief.

#

Directly-applicable EU rights regime with detailed, current BfDI operational guidance; only narrow, well-defined statutory exceptions exist.

Primary frameworkGDPR Articles 12-22, as narrowed by BDSG §§35-36
Supervisory authorityBfDI
Traffic-light rationale — GreenDirectly-applicable EU rights regime with detailed, current BfDI operational guidance; only narrow, well-defined statutory exceptions exist.

Sub-modules (5)

Access RightGreen

Art 15 GDPR access right is free of charge save for manifestly unfounded/excessive requests.

Claims: CLM-DE-c5d6e7f8

Rectification And ErasureGreen

Erasure right applies subject to §35 BDSG statutory exceptions.

Claims: CLM-DE-d6e7f8a9

Restriction And ObjectionGreen

Restriction (Art 18) and objection (Art 21, narrowed by §36 BDSG) rights are operative.

Claims: CLM-DE-e7f8a9b0, CLM-DE-f8a9b0c1

Data PortabilityGreen

Portability right (Art 20) does not apply to processing necessary for a public-interest task.

Claims: CLM-DE-a9b0c1d2

Deadlines And Response WindowsGreen

One-month response window, extendable by up to two further months for complex/numerous requests, with reasons communicated within the first month.

Claims: CLM-DE-b0c1d2e3

Category narrative44 words

The full GDPR rights catalogue (access, rectification, erasure, restriction, objection, portability) applies directly, with BfDI publishing detailed procedural guidance (e.g., on Art 15 access-request handling, one-month response deadlines, and identity-verification practice). BDSG carves out narrow national exceptions to erasure (§35) and objection (§36) rights.

No periodic updates recorded against this sub-brief.

#

Robust, CJEU-tested accountability framework with clear national thresholds and multiple layered breach-notification regimes; no material gaps identified.

Primary frameworkGDPR Articles 24-39, supplemented by BDSG §§6, 38, 65, 70 and TKG §169
Supervisory authorityBfDI
Traffic-light rationale — GreenRobust, CJEU-tested accountability framework with clear national thresholds and multiple layered breach-notification regimes; no material gaps identified.

Sub-modules (7)

Accountability And DpiaGreen

Art 35 GDPR DPIA duties apply generally; §67(1) BDSG imposes an analogous risk-screening threshold analysis for federal bodies in JI-Directive scope.

Claims: CLM-DE-c1d2e3f4

Dpo RequirementsGreen

National 20-person threshold (§38 BDSG) plus GDPR Art 37 material triggers; enhanced DPO dismissal protection upheld by CJEU.

Claims: CLM-DE-d2e3f4a5, CLM-DE-e3f4a5b6, CLM-DE-f4a5b6c7

Ropa RequirementsGreen

Art 30 GDPR ROPA duty generally applies; §70 BDSG imposes a stricter ROPA duty with no de-minimis exemption for JI-Directive-scope federal processing.

Claims: CLM-DE-a5b6c7d8

Joint Controller ArrangementsAmber

No DE-specific derogation from Art 26/28 GDPR joint-controller/processor rules was identified in this research pass.

Absence provenance: not recorded. Searched: BDSG joint controller Art 26 derogation, BfDI Auftragsverarbeitung Muster.

Security MeasuresGreen

Art 32 GDPR technical/organisational measures apply, including breach-detection capability as a core element.

Claims: CLM-DE-b6c7d8e9

Breach NotificationGreen

72-hour Art 33 GDPR notification rule plus Art 34 high-risk subject notification; stricter 24-hour sectoral rule for telecom breaches under §169 TKG.

Claims: CLM-DE-c7d8e9f0, CLM-DE-d8e9f0a1, CLM-DE-e9f0a1b2

Retention And DisposalAmber

General GDPR storage-limitation principle applies; telecom breach records must be logged for five years under §169(3) TKG. No further DE-specific general retention statute was identified.

Absence provenance: not recorded. Searched: BDSG allgemeine Löschfristen, Aufbewahrungspflicht personenbezogene Daten Deutschland.

Category narrative90 words

Germany layers national specifics onto the GDPR accountability regime: BDSG §38 sets a national DPO-appointment headcount threshold (20 persons regularly engaged in automated processing) in addition to the GDPR Art 37 material triggers, and grants DPOs enhanced dismissal protection (upheld as compatible with EU law by the CJEU in Leistritz, C-534/20). Breach notification follows the general 72-hour Art 33 GDPR rule, with a stricter 24-hour sectoral rule for telecom-sector breaches under §169 TKG. Federal-public-body ROPA duties under §70 BDSG (JI-Directive scope) are stricter than the Art 30 GDPR de-minimis threshold.

No periodic updates recorded against this sub-brief.

#

Fully harmonised EU transfer regime with no national derogation gaps identified; rated green reflecting legal certainty, though DE-specific granularity is inherently limited because the mechanism operates at EU level.

Primary frameworkGDPR Chapter V (Articles 44-49), as applied uniformly across EU Member States
Traffic-light rationale — GreenFully harmonised EU transfer regime with no national derogation gaps identified; rated green reflecting legal certainty, though DE-specific granularity is inherently limited because the mechanism operates at EU level.

Sub-modules (6)

Transfer MechanismsGreen

Germany relies on the EU Chapter V toolkit (adequacy, SCCs, BCRs, Art 49 derogations); no national bilateral mechanism exists.

Claims: CLM-DE-f0a1b2c3

Adequacy ReceivedGreen

Adequacy decisions are adopted by the European Commission and apply uniformly to Germany as an EU Member State; Germany does not receive separate national adequacy determinations.

Claims: CLM-DE-a1b2c3e4

Adequacy GrantedGreen

Germany does not grant national adequacy; this competence sits exclusively with the European Commission under Art 45 GDPR.

Claims: CLM-DE-a1b2c3e4

Sccs And BcrsAmber

SCCs and BCRs are used under the EU-harmonised forms; no DE-specific supplementary form was identified in this pass.

Absence provenance: not recorded. Searched: BfDI SCC BCR Muster Deutschland 2026.

Transfer Impact AssessmentGreen

TIA practice for SCC-based transfers derives from CJEU Schrems case law rather than German-specific statute.

Claims: CLM-DE-b2c3e4f5

Data LocalisationGreen

No general personal-data localisation mandate exists; narrow sectoral retention/logging duties apply (e.g., five-year telecom breach-incident log under §169(3) TKG).

Claims: CLM-DE-c3e4f5a6

Category narrative85 words

As an EU Member State, Germany has no independent national adequacy or bilateral-transfer mechanism: adequacy decisions are adopted centrally by the European Commission under GDPR Art 45 and bind Germany uniformly with all other Member States. Transfer tooling (SCCs, BCRs, Art 49 derogations) is likewise governed at EU level; Transfer Impact Assessment practice traces to the CJEU's Schrems line of case law rather than German statute. No general data-localisation mandate for personal data was identified; only narrow sectoral retention/logging duties exist (e.g., telecom breach records).

No periodic updates recorded against this sub-brief.

#

Telecom/eprivacy and health overlays are well-developed and green; credit-scoring/Art 22 interface remains actively contested at CJEU level, and education/insurance sub-modules lack identified DE-specific overlays, justifying an overall amber rating.

Primary frameworkTTDSG/TDDDG (telecoms/telemedia); §31 BDSG (credit scoring); §26 BDSG (employment); sector health statutes
Traffic-light rationale — AmberTelecom/eprivacy and health overlays are well-developed and green; credit-scoring/Art 22 interface remains actively contested at CJEU level, and education/insurance sub-modules lack identified DE-specific overlays, justifying an overall amber rating.

Sub-modules (7)

Financial Sector OverlayAmber

No dedicated DE financial-sector DP overlay beyond GDPR/BDSG and credit-scoring rules (§31 BDSG) was identified separately from credit_and_scoring.

Absence provenance: not recorded. Searched: BaFin Datenschutz Überschneidung BDSG.

Health Sector OverlayGreen

Mandatory electronic patient record (ePA) obligation for statutory health insurers since 15 Jan 2025, with active BfDI guidance/regulatory sandbox activity (ReguLab, §25b SGB V).

Claims: CLM-DE-d4f5a6b7

Telecoms And EprivacyGreen

TTDSG/TDDDG cookie-consent regime plus Consent Management Ordinance (April 2025).

Claims: CLM-DE-e5a6b7c8, CLM-DE-f6b7c8d9

Employment DataAmber

§26 BDSG plus ancillary labour statutes govern employment-context processing.

Claims: CLM-DE-a7c8d9e0

Credit And ScoringAmber

§31 BDSG credit-scoring practice intersects with Art 22 GDPR automated-decision prohibition; actively before the CJEU (SCHUFA line of cases).

Claims: CLM-DE-b8d9e0f1

EducationRed

No DE-specific education-sector DP overlay distinct from general GDPR/BDSG was identified.

Absence provenance: not recorded. Searched: Schuldatenschutz Deutschland Landesrecht, education sector Germany data protection overlay.

InsuranceRed

No DE-specific insurance-sector DP overlay distinct from general GDPR/BDSG was identified beyond credit/scoring intersections.

Absence provenance: not recorded. Searched: Versicherungsaufsicht Datenschutz Deutschland BDSG.

Category narrative109 words

Telecoms/telemedia is the most developed sectoral overlay: TTDSG (as amended into the TDDDG) supplies a lex specialis cookie/tracking consent regime and a Consent Management Ordinance (effective 1 April 2025) for centralized consent-service recognition. Health-sector data protection is intensifying around the mandatory electronic patient record (ePA) rollout for statutory health-insurance members since 15 January 2025. Employment data processing is governed by §26 BDSG plus a patchwork of labour statutes. Credit-scoring (SCHUFA-style) automated decision-making sits at the direct intersection of §31 BDSG and Art 22 GDPR, actively litigated at CJEU level. Education and insurance-sector-specific DP overlays were not identified as materially distinct from the general GDPR/BDSG regime in this research pass.

No periodic updates recorded against this sub-brief.

#

Cookie/tracker consent regime is mature and green, but clean-room and cross-context-advertising sub-modules have no identified DE-specific statutory basis, and dark-pattern guidance rests on DSK soft-law rather than binding statute.

Primary frameworkTTDSG/TDDDG §25 (cookies/trackers); GDPR Art 21 (direct marketing objection)
Traffic-light rationale — AmberCookie/tracker consent regime is mature and green, but clean-room and cross-context-advertising sub-modules have no identified DE-specific statutory basis, and dark-pattern guidance rests on DSK soft-law rather than binding statute.

Sub-modules (6)

Cookies And TrackersGreen

TTDSG §25(1) consent requirement for terminal-equipment storage/access, narrow §25(2) strict-necessity exception.

Claims: CLM-DE-c9e0f1a2, CLM-DE-d0f1a2b3

Dark PatternsAmber

DSK guidance treats cookie walls as non-compliant, though this rests on soft-law/regulatory guidance rather than a codified statutory prohibition.

Claims: CLM-DE-e1a2b3c4

Opt Out SignalsRed

No DE-specific statutory recognition of Global Privacy Control or equivalent opt-out signals was identified.

Absence provenance: not recorded. Searched: Global Privacy Control Deutschland TTDSG Anerkennung.

Clean Rooms And DcrRed

No DE-specific clean-room/data-collaboration-room statutory regime was identified.

Absence provenance: not recorded. Searched: Clean Room Datenschutz Deutschland Regelung.

Cross Context AdvertisingAmber

No CPRA-style statutory 'sale'/'share' concept exists in German law; cross-context advertising is governed by general GDPR consent/legitimate-interest rules.

Absence provenance: not recorded. Searched: cross-context advertising Germany equivalent CPRA sale share.

Direct MarketingGreen

Art 21(2) GDPR absolute objection right to direct-marketing processing, operationalised via BfDI model objection letters.

Claims: CLM-DE-f2b3c4d5

Category narrative70 words

TTDSG §25 supplies Germany's core cookie/tracker consent rule, requiring consent for any storage of or access to information on end-user terminal equipment regardless of whether personal data processing occurs, with a narrow strict-necessity exception. Cookie walls are treated by German DPAs as non-compliant. Direct-marketing objection rights under Art 21(2) GDPR are operationalised via BfDI model correspondence. Dedicated clean-room/data-collaboration-room and cross-context-advertising (CPRA-style) rules were not identified as part of German law.

No periodic updates recorded against this sub-brief.

#

Art 22 GDPR framework is in force and actively enforced/litigated (green core), but AI-specific risk-assessment rules, biometric-specific statute, and genetic-data-specific statute are all absent or still in guidance/proposal stage, and state-surveillance oversight architecture is itself subject to unresolved reform proposals.

Primary frameworkGDPR Article 22, interfacing with the EU AI Act; no DE-specific biometric/genetic statute identified
Supervisory authorityBfDI
Traffic-light rationale — AmberArt 22 GDPR framework is in force and actively enforced/litigated (green core), but AI-specific risk-assessment rules, biometric-specific statute, and genetic-data-specific statute are all absent or still in guidance/proposal stage, and state-surveillance oversight architecture is itself subject to unresolved reform proposals.

Sub-modules (6)

Profiling RestrictionsGreen

Art 22 GDPR restricts solely-automated, significant-effect decisions including profiling.

Claims: CLM-DE-a3c4d5e6

Automated Decision Making TransparencyAmber

CJEU litigation (SCHUFA line) tests whether a scoring controller's process itself constitutes an Art 22 'decision' even where a third party formally decides.

Claims: CLM-DE-a3c4d5e6

Ai Risk AssessmentsAmber

BfDI issues non-binding AI guidance and co-runs an AI Reallabor sandbox; no binding DE AI-specific risk-assessment statute exists yet.

Claims: CLM-DE-b4d5e6f7

Biometric RegimeAmber

No dedicated biometric-specific German statute identified beyond GDPR Art 9; enforcement gaps alleged (noyb v. HmbBfDI re PimEyes).

Claims: CLM-DE-c5e6f7a8

Genetic DataRed

No DE-specific genetic-data statute beyond GDPR Art 9 special-category rules was identified in this pass.

Absence provenance: not recorded. Searched: Gendatenschutzgesetz Deutschland 2026, genetic data specific statute Germany.

State Surveillance CarveoutsAmber

BfDI retains oversight of federal intelligence-service processing; opposes a proposed UKRat transfer of this supervision as duplicative and likely to weaken oversight.

Claims: CLM-DE-d6f7a8b9

Category narrative129 words

Germany applies the GDPR Art 22 restriction on solely-automated decisions with legal/significant effect, actively tested via CJEU litigation on SCHUFA-style credit scoring where a controller's own scoring process may itself constitute a prohibited automated decision even where a third party makes the final lending decision. BfDI has issued non-binding AI guidance for federal administration and co-runs an AI Reallabor sandbox with the Bundesnetzagentur and Hesse's digital ministry, but no AI-specific statutory risk-assessment regime beyond EU AI Act interfaces exists yet. BfDI currently retains oversight of federal intelligence-service data processing and opposes a proposed transfer of this supervision to a new Unabhängiger Kontrollrat (UKRat). No dedicated German biometric-specific or genetic-data-specific statute beyond GDPR Art 9 was identified; noyb has litigated alleged under-enforcement by Hamburg's HmbBfDI against unlawful facial-recognition (PimEyes) processing.

No periodic updates recorded against this sub-brief.

#

The core Art 8 consent-age rule is settled and green, but minor-profiling-specific bans, education-settings-specific rules, and dependent-adult-specific protections were not identified as distinct DE statutory sub-regimes, and BfDI itself flags the EU reform track as currently under-addressing children's data protection.

Primary frameworkGDPR Article 8 (digital consent age fixed at 16 in Germany)
Supervisory authorityBfDI
Traffic-light rationale — AmberThe core Art 8 consent-age rule is settled and green, but minor-profiling-specific bans, education-settings-specific rules, and dependent-adult-specific protections were not identified as distinct DE statutory sub-regimes, and BfDI itself flags the EU reform track as currently under-addressing children's data protection.

Sub-modules (5)

Age VerificationAmber

Digital-consent age of 16 diverges from the age-7 threshold for general contractual capacity under German civil law, complicating age-verification design.

Claims: CLM-DE-e7a8b9c0

Minor Profiling BansAmber

No standalone statutory ban on profiling of minors beyond general Art 22 GDPR exists; BfDI criticizes the EU Digital Omnibus for insufficient children's-data safeguards.

Claims: CLM-DE-a9c0d1e2

Education SettingsRed

No DE-specific federal education-settings DP statute was identified; school data protection is generally a Land-law matter outside this federal-focused pass.

Absence provenance: not recorded. Searched: Schuldatenschutz Bund Deutschland, education settings DP Germany federal.

Dependent AdultsRed

No DE-specific dependent-adult DP statute distinct from general GDPR/BDSG was identified.

Absence provenance: not recorded. Searched: Betreuungsrecht Datenschutz Deutschland, dependent adults data protection Germany.

Category narrative71 words

Germany fixes the GDPR Art 8 digital-consent age at 16; below that age, parental consent is required for information-society-service processing. This diverges from general German civil-law contractual capacity, under which minors may conclude 'everyday' contracts from age 7, creating friction in age-verification design. No standalone minor-specific profiling ban or dedicated education/dependent-adult DP statute was identified; BfDI has publicly criticized the EU Digital Omnibus reform proposal for not adequately strengthening children's-data protection.

No periodic updates recorded against this sub-brief.

#

Well-resourced, actively enforcing regulator network with recent multi-million-euro fines and detailed activity reporting; rated green notwithstanding the leadership transition and open EU-level reform debate, since core enforcement capacity remains fully operative.

Primary frameworkGDPR Articles 58, 77-84, as applied by BfDI and the 17 Land DPAs
Supervisory authorityBfDI
Traffic-light rationale — GreenWell-resourced, actively enforcing regulator network with recent multi-million-euro fines and detailed activity reporting; rated green notwithstanding the leadership transition and open EU-level reform debate, since core enforcement capacity remains fully operative.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Art 58 GDPR investigative/corrective powers and Art 83 fining maxima apply, exercised via formal Anhörung (hearing) procedure before any supervisory measure.

Claims: CLM-DE-b0d1e2f3

Enforcement Activity IndexGreen

2025: 80 on-site + 40 written inspections, 129 supervisory measures (BfDI); €15m/€30m Vodafone fines (BfDI); €775k/€492k/€900k Hamburg fines (HmbBfDI).

Claims: CLM-DE-c1e2f3a4, CLM-DE-d2f3a4b5, CLM-DE-e3a4b5c6

Regulator Funding And CapacityGreen

BfDI is supported by approximately 380 staff across Bonn and Berlin.

Claims: CLM-DE-f4b5c6d7

Collective Redress And Class ActionsAmber

No dedicated statutory GDPR class-action mechanism identified beyond general German collective-action law; third-party advocacy (noyb) supplements individual redress via complaints and litigation against DPAs.

Claims: CLM-DE-a5c6d7e8

Private Right Of ActionGreen

Art 82 GDPR gives data subjects a harmonised, directly enforceable right to compensation for material/non-material damage.

Claims: CLM-DE-b6d7e8f9

Recent Developments 180DGreen

BfDI leadership transition to Prof. Dr. Moritz Hennemann (2026) and BfDI's public critique of the EU Digital Omnibus reform package on data-broker, children's-data, and AI-specific gaps.

Claims: CLM-DE-c7e8f9a0, CLM-DE-d8f9a0b1

Category narrative133 words

BfDI and the 17 Land DPAs hold full Art 58 GDPR investigative and corrective powers, including administrative fines up to the Art 83 GDPR maxima. Enforcement activity is materially active: BfDI's 34th Activity Report records 80 on-site and 40 written inspections and 129 supervisory measures in 2025, and BfDI fined Vodafone GmbH €15m and €30m plus a reprimand in 2025 for Art 28/32 violations; Hamburg's HmbBfDI separately imposed multiple six-to-seven-figure fines (€775,000; €492,000; €900,000) across 2024-2025. Data subjects benefit from the harmonised Art 82 GDPR compensation right, directly enforceable in German courts; collective advocacy (e.g., noyb litigation against HmbBfDI) supplements individual redress absent a dedicated statutory GDPR class-action mechanism. Recent 180-day developments include the BfDI leadership transition to Prof. Dr. Moritz Hennemann and BfDI's public critique of the EU Digital Omnibus reform package.

No periodic updates recorded against this sub-brief.

No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Germany
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 0 claim(s), 36 source(s) in the cumulative register.