Country:德国 · Data Privacy
High confidenceUpdated 2026-07-15Handbook

Germany · Data Privacy

As an EU member, Germany's personal-data protection centers on the EU General Data Protection Regulation (GDPR, 2018), supplemented by the German Federal Data Protection Act (BDSG). It applies both within and outside the EU; processing requires a lawful basis (consent/contract/legitimate interest, etc.), notice, data-subject rights, DPIA and breach notification within 72 hours. Supervision is by the state data protection authorities and the federal commissioner.

Key points

Procedure

  1. Personal-data inventory and RoPA (record of processing)
  2. Publish privacy policy and manage consent
  3. DPIA for high-risk processing; appoint DPO (if applicable)
  4. Cross-border transfer: sign SCC or assess adequacy
  5. Establish 72-hour breach-notification mechanism

Hard requirements

Costs

Compliance-system build; DPO; audit⏱ ⏱ Timeline:GDPR in force since 2018; continuous compliance required

⚠ Common risks

  • China has no adequacy finding; cross-border requires SCC
  • Defective consent penalized; up to 4% of global turnover or €20 million
  • Breach not reported carries heavy penalty
  • Extraterritorial: may be subject to jurisdiction even without an entity in Germany
Handbook

📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)

Applies to:Chinese companies processing personal data of EU residents in Germany (EU), or providing goods/services to or monitoring the behavior of German users without an entity in Germany and transferring the data back to China (GDPR + BDSG).

Prerequisites

  • Clarify GDPR extraterritorial-application trigger
  • Assess whether DPO appointment is triggered (specific cases)
  • Reserve budget for cross-border SCC and audit
StepActionOwnerTimelineCostOfficial form / systemNotes & penalties
1Personal-data inventory and ROPA
Map processing purposes, basis, categories and recipients; establish the Record of Processing Activities (ROPA).
Legal/Compliance2–3 weeksInternal costROPA, data inventoryGDPR Article 30
Penalty:Up to 4% of global turnover or €20 million
2Determine lawful basis and publish privacy policy
Determine the lawful basis under GDPR (consent/contract/legitimate interest, etc.) and publish a German/English bilingual privacy policy.
Legal1–2 weeksInternal costPrivacy policyBDSG supplementary clauses
Penalty:Same cap as step 1
3Sign SCC for cross-border transfer
Transfer back to China requires Standard Contractual Clauses (SCC) and a Transfer Impact Assessment (TIA); China has no adequacy finding, so PIPL export mechanisms also apply.
Legal3–6 weeksInternal/lawyer feeSCC, TIA, PIPL export documentsNo adequacy requires SCC
Penalty:Transfer without a lawful mechanism carries heavy penalty
4Appoint DPO (if applicable)
Large-scale sensitive processing or specific scenarios require a DPO, who performs duties to the state data protection authority/federal commissioner.
ManagementOngoingDPO staffingDPO appointmentMust be independent
Penalty:Penalty for required-but-not-appointed DPO
5DPIA for high-risk processing
Conduct a Data Protection Impact Assessment (DPIA) for monitoring or large-scale sensitive processing.
Compliance/IT2–4 weeksInternal costDPIA reportGDPR Article 35
Penalty:Penalty for no DPIA
672-hour breach notification
Report a breach to the supervisory authority within 72 hours; high-risk breaches must notify data subjects.
DPO/ITWithin 72 hoursInternal costSupervisory-authority breach reportSet automatic trigger
Penalty:Late/concealed reporting carries heavy penalty
7Ongoing compliance and audit
Periodically review, update policies, train and audit.
ComplianceAnnualInternal costAnnual auditActive regulators
Penalty:Cumulative continuous violations

✅ Self-check list

⚠ Common pitfalls

Transfer back to China without SCC影响:Heavy GDPR penalty规避:Sign SCC + conduct TIA
Required DPO not appointed影响:Penalty规避:Appoint per circumstances
Ignoring PIPL export when transferring back to China影响:Dual violation规避:Process the China-side mechanism in parallel
High-risk processing without DPIA影响:Penalty规避:Front-load DPIA
Breach reported after 72 hours影响:Heavy penalty规避:Set automatic reporting trigger
No record of processing影响:Aggravates inspection规避:Maintain ROPA continuously

📅 Ongoing post-incorporation obligations

  • DPO duties (if applicable)
  • 72-hour breach notification to supervisory authority
  • SCC/TIA and China PIPL export mechanism remain effective
  • Ongoing DSAR response
  • Annual audit, DPIA update and training

🔗 Official portals

📎 Source:欧盟GDPR(2018);德国《联邦数据保护法》(BDSG);各州数据保护局 ; https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?

CompliGo · Outbound Compliance Automation

You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.

CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.