🇩🇪 Germany · Privacy & Data Protection
Data-protection regime (GDPR/CCPA/PIPL and local laws), registration duties, and the official supervisory authority.
Germany applies the EU GDPR together with the Federal Data Protection Act (BDSG); supervision is largely by the state (Land) data-protection authorities, with the Federal Commissioner (BfDI) covering federal bodies and telecoms/postal sectors. Organisations need a lawful basis, must honour data-subject rights, often must appoint a data protection officer, and report breaches within 72 hours.
- The EU GDPR plus the BDSG apply; many organisations must appoint a data protection officer.
- Supervision is mainly by the state (Land) data-protection authorities; the BfDI covers federal bodies and telecoms.
- Uphold data-subject rights and report personal-data breaches within 72 hours.
Official authorities
- Federal Commissioner for Data Protection (BfDI)
Federal data-protection authority (state DPAs supervise most businesses).
Official-information aggregation, not legal advice. Always verify on the authority's own site.
Government portals
- Federal Government of Germany — Germany's Federal Cabinet official website — policy, legislation, news, and government programs
- Federal Office for Migration (BAMF) — German visas, EU Blue Card, asylum, integration courses, and permanent residency
- Federal Central Tax Office (BZSt) — Tax ID (IdNr) registration, tax identification lookup, withholding tax refunds — the key authority for foreign taxpayers in Germany