BDSG
In short: “Bundesdatenschutzgesetz” (Federal Data Protection Act) — the German law that supplements and specifies the GDPR at national level, where the GDPR leaves member states room for their own rules.
In more detail: As an EU regulation, the GDPR applies directly in all member states, but in some places contains so-called opening clauses that national legislators may fill (e.g. for employee data protection or the obligation to appoint a data protection officer). The BDSG regulates these nationally specific points for Germany and contains, for example, concrete thresholds for how many employees make a data protection officer mandatory.
In Depth
Historical context
Germany already had a Federal Data Protection Act from 1977 — long before there was an EU-wide regulation, making Germany one of the first countries in the world with a comprehensive data protection law. When the GDPR came into force on 25 May 2018, the old BDSG was completely revised and re-enacted as the “new BDSG” (or BDSG 2018) — it had to be adapted in many places to the directly applicable GDPR to avoid duplicate rules and contradictions.
The three parts of the law
The BDSG is divided into three parts: part 1 applies to all areas, part 2 specifically to processing that falls within the scope of the GDPR, part 3 to areas outside it (e.g. police and justice, which follow their own EU directives instead of the GDPR). For companies in day-to-day business, part 2 is mainly relevant.
Employee data protection (§ 26 BDSG)
A practical example of a BDSG specification is § 26 BDSG on employee data protection: it regulates more precisely than the GDPR itself under which conditions an employer may process the data of applicants and employees — for example to establish, carry out or end an employment relationship, or to uncover criminal offences. Important here: an employee’s consent as a legal basis is viewed particularly critically in the employment context, because the structural relationship of dependence raises doubts about whether the consent is “voluntary” — employers therefore usually rely on other legal bases such as the performance of the contract.
Data protection officers (§ 38 BDSG)
Another important example is § 38 BDSG: it lowers the threshold at which appointing a company data protection officer becomes mandatory to companies that as a rule permanently employ at least 20 people in the automated processing of personal data — the GDPR itself doesn’t specify a concrete number for this, but leaves exactly that to the member states. Other EU countries have in some cases very different thresholds or don’t require a mandatory data protection officer at all below certain risk thresholds — the German 20-person limit is considered comparatively strict across Europe.
Fines and responsibilities
The BDSG also regulates the responsibilities of the German data protection supervisory authorities (a separate authority for each federal state, plus the Federal Commissioner for Data Protection for federal authorities) and supplements the GDPR’s fine provisions with criminal and administrative offence provisions for certain intentional violations that go beyond the pure GDPR fines.
How it differs from the state data protection laws
Besides the BDSG (which applies to federal authorities and the private sector), all 16 federal states additionally have their own state data protection laws, which apply to state and municipal authorities — a health insurance fund or a company follows the BDSG, a city administration or a state ministry follows the respective state law. This federal fragmentation has grown historically (data protection is traditionally a matter for the states in Germany) and in practice means that, instead of one central authority, Germany still has 17 different data protection supervisory authorities today (one per federal state plus the federal commissioner), which coordinate closely (among other things via the data protection conference, DSK) but formally decide independently of each other.
See also: GDPR