Germany

DE · DEU · Europe · Last verified 22 Sep 2026

5 regulators · 6 instruments · 6 obligations · 1 upcoming deadline

Germany — hero image

Regulation 2016

GDPR (Regulation (EU) 2016/679)

Datenschutz-Grundverordnung (DSGVO)

Issued by Federal Commissioner for Data Protection and Freedom of Information

Effective: 27 Apr 2016

Last amended: 25 May 2018

Plain-English summary

The General Data Protection Regulation (GDPR) is the most robust privacy law globally since it provides individuals with total control of their personal information while ensuring there is a uniform digital privacy rulebook for modern companies. The regulation came into force in 2016 and began its implementation in 2018, replacing the outmoded 1995 Data Protection Directive and changing the global privacy landscape through the inclusion of extraterritoriality. This implies that the regulation is applicable strictly to any entity worldwide, processing, storing, or handling the personal information of EU citizens without considering the company’s physical location. The GDPR is enforced at the national level by independent data protection authorities, including the BfDI and state data protection bodies in Germany or CNIL in France. It ensures that data privacy is a basic human right with hefty administrative fines of up to €20 million or 4% of a company's global annual turnover being applied to entities failing to comply with the regulation.

Who it applies to

Banking · Insurance · Telecom & Tech · Healthcare & Pharma

Topics

Data Protection & Privacy

Obligations arising from this instrument

Obligation Timing Regulator Source Detail
Lawful basis, notice and data subject rights Ongoing BfDI source
Personal data breach notification Deadline 72 hours BfDI source

Official source

Latest news

No related news yet. We publish updates as regulators act.

Browse all newsSubscribe for updates