Lead Signal
Germany's federal data protection authority closed out a high-intensity enforcement stretch while confirming a leadership succession that will steer the regulator through the remainder of 2026. The BfDI fined Vodafone GmbH €15 million and €30 million, plus a formal reprimand, for violations of GDPR Articles 28 and 32. Hamburg's state authority, the HmbBfDI, is reported to have imposed its own six-to-seven-figure sanctions — €775,000, €492,000, and €900,000 — across 2024 and 2025. The BfDI's 34th Activity Report is further reported to record 80 on-site inspections, 40 written inspections, and 129 supervisory measures conducted in 2025, a caseload the authority says its roughly 380 staff across Bonn and Berlin are absorbing. Separately, Prof. Dr. Moritz Hennemann has been elected as incoming BfDI, succeeding Prof. Dr. Louisa Specht-Riemenschneider, who remains in office in a transitional capacity until 30 September 2026 for health reasons.
Other Developments
Germany's data-protection architecture continues to rest on a directly applicable GDPR overlaid by the Bundesdatenschutzgesetz (BDSG-neu), which is understood to supplement the Regulation only where it permits derogation or leaves gaps, and by the TTDSG — renamed TDDDG — which is understood to function as lex specialis for telecoms, telemedia, and cookie or tracking consent matters. Supervisory competence remains split federally: the BfDI is understood to supervise federal public bodies and federally regulated private-sector entities such as post and telecoms operators, while 17 Land data protection authorities are understood to supervise private-sector processing and Land-level public bodies, with Bavaria alone dividing public- and private-sector oversight between two separate bodies.
§26 BDSG — which is understood to govern employment-context data processing under the Article 88 GDPR opening clause — continues to draw criticism from the BfDI and the DSK as too imprecise, and calls for a standalone Employee Data Protection Act have not yet produced legislation. Germany's Article 8 digital-consent age is understood to remain fixed at 16, a threshold that diverges from the age-7 general contractual-capacity floor under German civil law, complicating age-verification design for information-society services aimed at minors; parental consent is understood to remain required for such processing below age 16.
§38 BDSG is understood to set a national DPO-appointment headcount threshold of 20 persons regularly engaged in automated processing — raised from 10 by a 2019 BDSG amendment — and German DPOs are understood to benefit from enhanced statutory dismissal protection beyond the GDPR Article 38(3) baseline, a position the CJEU is reported to have upheld as EU-law-compatible in Case C-534/20 (Leistritz). Breach-notification obligations remain layered: GDPR Article 33 sets a 72-hour regulator-notification standard, GDPR Article 34 requires notice to affected data subjects where a breach is likely to result in high risk, and §169 TKG is understood to impose a stricter 24-hour rule for telecommunications-sector breaches.
Reports suggest that statutory health-insurance members have become subject to mandatory electronic patient record (ePA) processing since 15 January 2025, and a Consent Management Ordinance is understood to have become effective on 1 April 2025, establishing centralized consent-service recognition procedures under the TTDSG/TDDDG cookie and tracker regime. TTDSG/TDDDG §25(1) continues to require consent for storage of or access to information on end-user terminal equipment, and §25(2) is understood to provide only a narrow strict-necessity exception. Reports suggest the DSK treats cookie walls as non-compliant, per soft-law guidance rather than a codified statutory prohibition, though this has not been independently confirmed this cycle.
The CJEU's SCHUFA line of litigation — including the continuing Case C-484/24 — is understood to be testing whether a credit-scoring controller's own process itself constitutes a decision with legal or similarly significant effect under GDPR Article 22, even where a third party formally decides, with direct implications for §31 BDSG credit-scoring practice. Separately, the BfDI is reported to oppose a 2026 reform proposal that would expand the remit of the already-operating Unabhängiger Kontrollrat (UKRat) — an oversight body established via the 2021 BNDG amendment — at the apparent expense of BfDI's own oversight of federal intelligence-service data processing. On children's data, the BfDI is understood to have publicly criticized the EU's Digital Omnibus reform proposal for not adequately strengthening children's-data protection.
Cross-Monitor Connections
The SCHUFA-line automated-decision-making litigation under §31 BDSG and GDPR Article 22 intersects with financial-sector credit-risk assessment; financial-crime and credit-risk-specific analysis of this litigation is routed to financial-integrity. Telecom-sector eprivacy and breach-notification rules under the TTDSG/TDDDG and TKG regimes may intersect with payment-service-provider data flows, and payments-specific analysis is routed to world-payments. The BfDI's AI guidance for federal administration, together with an AI regulatory sandbox reports suggest it co-runs with the Bundesnetzagentur and Hesse's digital ministry, and the interface between the EU AI Act and GDPR Article 22, warrant AI-Act-first treatment and are routed to artificial-intelligence, with only the data-protection angle retained here.
Outlook
The near-term marker to watch is the completion of the BfDI leadership transition on 30 September 2026, when Prof. Dr. Moritz Hennemann is expected to take up the office in full following Prof. Dr. Louisa Specht-Riemenschneider's transitional tenure. Enforcement intensity at both federal and Land level shows no sign of easing, and the CJEU's continuing SCHUFA-line docket, together with the unresolved BfDI/UKRat oversight-remit dispute, are likely to remain the principal sources of change in Germany's data-protection operating environment over the coming cycles.