DSGVO / BDSG
GDPR (DSGVO) and the Federal Data Protection Act (BDSG)
- Regulator
- The data protection authority of each federal state, and the Federal Commissioner (BfDI)
- Who it applies to
- Every organisation in Germany that processes personal data.
- If you fall short
- Up to €20 million or 4% of annual worldwide turnover, whichever is higher.
- What it asks of you
- A record of processing activities (Verzeichnis von Verarbeitungstätigkeiten) and a lawful basis for each
- A Data Protection Officer (Datenschutzbeauftragter) once at least 20 people regularly process personal data automatically — or whatever the size, where a DPIA is required
- Technical and organisational measures (TOMs) and DPIAs for high-risk processing
- Report a data breach to the authority within 72 hours