Country:德国 · Data Privacy
Germany · Data Privacy
As an EU member, Germany's personal-data protection centers on the EU General Data Protection Regulation (GDPR, 2018), supplemented by the German Federal Data Protection Act (BDSG). It applies both within and outside the EU; processing requires a lawful basis (consent/contract/legitimate interest, etc.), notice, data-subject rights, DPIA and breach notification within 72 hours. Supervision is by the state data protection authorities and the federal commissioner.
Key points
- GDPR + BDSG dual track; extraterritorial application (subject to jurisdiction if serving EU data subjects)
- Lawful basis: consent, contract necessity, legitimate interest, legal obligation, etc.
- Data-subject rights: access/rectification/erasure/portability/objection
- Breach must be reported to the supervisory authority within 72 hours
- Cross-border transfer: requires adequacy decision or SCC; China has no adequacy finding
- Chinese data-export obligations (pkulaw verification 2026-07): transferring data to or back into China requires one of three routes — security assessment (CAC Order No. 11), standard contract (Order No. 13) or certification (CAC + SAMR Order No. 20, 2025-10-14); the 2024–2025 caliber was relaxed — the Provisions on Promoting and Regulating Cross-Border Data Flows (Order No. 16) and the Cyber Data Security Administration Regulation (State Council Order No. 790) took effect, exempting some scenarios from filing.
Procedure
- Personal-data inventory and RoPA (record of processing)
- Publish privacy policy and manage consent
- DPIA for high-risk processing; appoint DPO (if applicable)
- Cross-border transfer: sign SCC or assess adequacy
- Establish 72-hour breach-notification mechanism
Hard requirements
- Lawful basis; notice; RoPA; DPO (specific cases); cross-border SCC
Costs
Compliance-system build; DPO; audit⏱ ⏱ Timeline:GDPR in force since 2018; continuous compliance required⚠ Common risks
- China has no adequacy finding; cross-border requires SCC
- Defective consent penalized; up to 4% of global turnover or €20 million
- Breach not reported carries heavy penalty
- Extraterritorial: may be subject to jurisdiction even without an entity in Germany
Handbook
📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)
Applies to:Chinese companies processing personal data of EU residents in Germany (EU), or providing goods/services to or monitoring the behavior of German users without an entity in Germany and transferring the data back to China (GDPR + BDSG).
Prerequisites
- Clarify GDPR extraterritorial-application trigger
- Assess whether DPO appointment is triggered (specific cases)
- Reserve budget for cross-border SCC and audit
| Step | Action | Owner | Timeline | Cost | Official form / system | Notes & penalties |
|---|---|---|---|---|---|---|
| 1 | Personal-data inventory and ROPA Map processing purposes, basis, categories and recipients; establish the Record of Processing Activities (ROPA). | Legal/Compliance | 2–3 weeks | Internal cost | ROPA, data inventory | GDPR Article 30 Penalty:Up to 4% of global turnover or €20 million |
| 2 | Determine lawful basis and publish privacy policy Determine the lawful basis under GDPR (consent/contract/legitimate interest, etc.) and publish a German/English bilingual privacy policy. | Legal | 1–2 weeks | Internal cost | Privacy policy | BDSG supplementary clauses Penalty:Same cap as step 1 |
| 3 | Sign SCC for cross-border transfer Transfer back to China requires Standard Contractual Clauses (SCC) and a Transfer Impact Assessment (TIA); China has no adequacy finding, so PIPL export mechanisms also apply. | Legal | 3–6 weeks | Internal/lawyer fee | SCC, TIA, PIPL export documents | No adequacy requires SCC Penalty:Transfer without a lawful mechanism carries heavy penalty |
| 4 | Appoint DPO (if applicable) Large-scale sensitive processing or specific scenarios require a DPO, who performs duties to the state data protection authority/federal commissioner. | Management | Ongoing | DPO staffing | DPO appointment | Must be independent Penalty:Penalty for required-but-not-appointed DPO |
| 5 | DPIA for high-risk processing Conduct a Data Protection Impact Assessment (DPIA) for monitoring or large-scale sensitive processing. | Compliance/IT | 2–4 weeks | Internal cost | DPIA report | GDPR Article 35 Penalty:Penalty for no DPIA |
| 6 | 72-hour breach notification Report a breach to the supervisory authority within 72 hours; high-risk breaches must notify data subjects. | DPO/IT | Within 72 hours | Internal cost | Supervisory-authority breach report | Set automatic trigger Penalty:Late/concealed reporting carries heavy penalty |
| 7 | Ongoing compliance and audit Periodically review, update policies, train and audit. | Compliance | Annual | Internal cost | Annual audit | Active regulators Penalty:Cumulative continuous violations |
✅ Self-check list
⚠ Common pitfalls
Transfer back to China without SCC影响:Heavy GDPR penalty规避:Sign SCC + conduct TIA
Required DPO not appointed影响:Penalty规避:Appoint per circumstances
Ignoring PIPL export when transferring back to China影响:Dual violation规避:Process the China-side mechanism in parallel
High-risk processing without DPIA影响:Penalty规避:Front-load DPIA
Breach reported after 72 hours影响:Heavy penalty规避:Set automatic reporting trigger
No record of processing影响:Aggravates inspection规避:Maintain ROPA continuously
📅 Ongoing post-incorporation obligations
- DPO duties (if applicable)
- 72-hour breach notification to supervisory authority
- SCC/TIA and China PIPL export mechanism remain effective
- Ongoing DSAR response
- Annual audit, DPIA update and training
🔗 Official portals
📎 Source:欧盟GDPR(2018);德国《联邦数据保护法》(BDSG);各州数据保护局 ; https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?
CompliGo · Outbound Compliance Automation
You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.
CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.