Data Protection Hub

Data Protection Hub

A collection of knowledge on data protection law in Germany, in particular the GDPR and the German Federal Data Protection Act (BDSG).

Contains a collection of knowledge on data protection law in Germany, in particular the GDPR and the BDSG.

1.1 Statutory text

The complete text of the GDPR and of the BDSG, subdivided into chapters, sections and individual provisions.

→ To the statutory text

1.2 Concepts and definitions

Central concepts of data protection law that are referred to again and again. The legal definitions of Article 4 GDPR, each as a separate reference entry.

→ To the concepts

  • 1.2.1 Personal Data: Article 4(1) GDPR: the threshold that triggers data protection law; identifiability, data relating to objects, synthetic data, and the distinction from anonymous data.
  • 1.2.2 Processing: Article 4(2) GDPR: a comprehensive catch-all concept for any handling of data.
  • 1.2.3 Restriction of Processing: Article 4(3) GDPR: the marking of data to limit their future processing (formerly "blocking").
  • 1.2.4 Profiling: Article 4(4) GDPR: the automated evaluation of personal aspects; the relationship with scoring.
  • 1.2.5 Pseudonymization: Article 4(5) GDPR: separating data from identity; the distinction from anonymization.
  • 1.2.6 Filing System: Article 4(6) GDPR: a structured set that also covers manual files.
  • 1.2.7 Controller: Article 4(7) GDPR: whoever determines the purposes and means; the addressee of the GDPR's obligations.
  • 1.2.8 Processor: Article 4(8) GDPR: processing on behalf of a controller, with its own obligations and liability.
  • 1.2.9 Recipient: Article 4(9) GDPR: any body to which data are disclosed.
  • 1.2.10 Third Party: Article 4(10) GDPR: a body outside the controller's organization; there is no group privilege.
  • 1.2.11 Consent: Article 4(11) GDPR: a freely given, informed indication of wishes serving as a legal basis.
  • 1.2.12 Personal Data Breach: Article 4(12) GDPR: a breach of security that triggers the notification obligations.
  • 1.2.13 Genetic Data: Article 4(13) GDPR: data resulting from the analysis of a biological sample.
  • 1.2.14 Biometric Data: Article 4(14) GDPR: data obtained through technical processing for unique identification.
  • 1.2.15 Data Concerning Health: Article 4(15) GDPR: data on a person's physical or mental state of health.

1.3 Individual topics

Individual topics of the GDPR.

→ To the individual topics overview

1.3.1 Scope of application of the GDPR

Material and territorial scope of the GDPR, the existence of personal data, processing, Articles 2 and 3 GDPR.

→ To the scope of application overview

  • 1.3.1.1 Material Scope (Article 2 GDPR): The forms of processing covered (automated and filing-system-based), exclusions from the material scope (national security, criminal law enforcement and the Law Enforcement Directive, the household exemption), the public and the non-public sector, and the media and employment privileges.
  • 1.3.1.2 Territorial Scope (Article 3 GDPR): The establishment criterion, the targeting criterion and the monitoring of behavior, flag and diplomatic mission scenarios; Union citizenship is not a connecting factor.

The structure and system of Article 6 GDPR: the general prohibition subject to permission, the exhaustive catalog of grounds for lawful processing, the necessity requirement, and the relationship with the opening clauses and with the purpose limitation principle.

  • 1.3.2.1 Consent: Consent under Article 6(1)(a) GDPR: significance, conditions for validity, and the relationship with the statutory grounds for lawful processing and with contractual declarations of assent.
  • 1.3.2.2 Contract and Pre-Contractual Steps: Lawfulness under Article 6(1)(b) GDPR: performance of a contract and pre-contractual steps, the EU law concept of necessity, the distinction from consent and terms of use, and typical categories of cases in the online context.
  • 1.3.2.3 Legal Obligation: Lawfulness under Article 6(1)(c) GDPR: a legal obligation to which the controller is subject, and the requirements for the Union or Member State legal basis under Article 6(3) GDPR.
  • 1.3.2.4 Vital Interests: Lawfulness under Article 6(1)(d) GDPR: protection of vital interests, subsidiarity, and the relationship with the right to self-determination.
  • 1.3.2.5 Public Interest and Official Authority: Lawfulness under Article 6(1)(e) GDPR: performance of a task carried out in the public interest or in the exercise of official authority.
  • 1.3.2.6 Legitimate Interests: Lawfulness under Article 6(1)(f) GDPR: the three-stage test (interest, necessity, balancing), the exclusion of public authorities, and categories of cases.
  • 1.3.2.7 Change of Purpose: Change of purpose under Article 6(4) GDPR: function and legal nature, the compatibility test, and the special case of archiving, research and statistical purposes.
  • 1.3.2.8 Opening Clauses and National Law: The opening clauses in Article 6(2) and (3) GDPR and how they are filled out by national law: the BDSG, the data protection acts of the German federal states, and the German Telecommunications Digital Services Data Protection Act (TDDDG).

1.3.3 Principles relating to processing

Principles relating to the processing of personal data under Article 5 GDPR. Classification, legal nature, relationship with Article 6 GDPR, addressees, exceptions under Articles 23 and 85 GDPR, and liability to administrative fines.

  • 1.3.3.1 Lawfulness: The principle of lawful processing under Article 5(1)(a) GDPR as a reference to the requirement of a legal basis under Article 6 GDPR.
  • 1.3.3.2 Fairness: The fairness principle under Article 5(1)(a) GDPR: the duty of consideration, the prohibition of manipulation (including dark patterns), and protection against unclear and covert processing.
  • 1.3.3.3 Transparency: The transparency principle under Article 5(1)(a) GDPR: retrospective and prospective comprehensibility, and the substantive requirements for informing data subjects.
  • 1.3.3.4 Purpose Limitation: Purpose limitation under Article 5(1)(b) GDPR: the obligation to specify the purpose and the prohibition of further processing for incompatible purposes.
  • 1.3.3.5 Data Minimization: Data minimization under Article 5(1)(c) GDPR: relevance, necessity and adequacy of the data processed.
  • 1.3.3.6 Accuracy: Accuracy under Article 5(1)(d) GDPR: the obligation to ensure accuracy and to keep data up to date, including profiling, value judgments and automated decisions.
  • 1.3.3.7 Storage Limitation: Storage limitation under Article 5(1)(e) GDPR: the time limits on storage and the obligations to erase and to review.
  • 1.3.3.8 Integrity and Confidentiality: Integrity and confidentiality under Article 5(1)(f) GDPR: protection against unauthorized processing, loss, destruction and damage by means of technical and organizational measures.
  • 1.3.3.9 Accountability: Accountability under Article 5(2) GDPR: the obligation to comply with the principles set out in paragraph 1 and to demonstrate compliance with them.

1.3.4 Rights of the data subject

Rights of data subjects under Articles 12 and 15 to 23 GDPR (including access, rectification, erasure, restriction, data portability and objection).

1.3.5 Transparency obligations

Information and transparency obligations of the controller under Articles 12 to 14 GDPR: content and design of the privacy policy.

→ To the transparency obligations overview

1.3.6 Controllers and processors

The data protection roles under the GDPR, how they are distinguished according to purposes and means, and the allocation of obligations and liability.

→ To the controllers and processors overview

  • 1.3.6.2 Controller: The concept and its broad interpretation under Article 4(7) GDPR, the obligations under Article 24 GDPR, and persons acting under the authority of the controller under Article 29 GDPR.
  • 1.3.6.3 Joint Controllers: The existence of joint controllership, criteria and categories of cases, and the arrangement on the allocation of obligations under Article 26 GDPR.
  • 1.3.6.4 Processor: The existence of processing on behalf of a controller (categories of cases and assessment framework) and the data processing agreement under Article 28 GDPR.

1.3.7 Records of processing activities

The obligation to maintain records of processing activities under Article 30 GDPR.

  • 1.3.7 Records of Processing Activities: Mandatory content for controllers and processors, form, the obligation to make the records available, the SME exemption under paragraph 5, and reform proposal COM(2025) 501.

1.3.8 Data protection officer

Designation, position and tasks of the data protection officer, Articles 37 to 39 GDPR, § 38 BDSG.

  • 1.3.8 Data Protection Officer (Overview): Function as an instrument of self-monitoring, classification of the areas regulated.
  • 1.3.8.1 Designation: The obligation under Article 37(1) GDPR and § 38 BDSG, voluntary designation, qualifications, formalities, the licensing requirement for external data protection officers under the German Legal Services Act (RDG), termination, and the contract with an external data protection officer.
  • 1.3.8.2 Position: Involvement, resources, freedom from instructions, the prohibition on penalization and removal from office, the reporting line, the right of data subjects to contact the officer, and conflicts of interest under Article 38 GDPR.
  • 1.3.8.3 Tasks: Informing and advising, monitoring compliance, advice on the data protection impact assessment, cooperation with the supervisory authority, and the risk-based approach under Article 39 GDPR.
  • 1.3.8.4 Liability: No compensation under Article 82 GDPR, tort liability towards data subjects, internal liability of the internal and the external data protection officer, and responsibility under criminal and administrative fine law.

1.3.9 Data security

Technical and organizational measures to protect personal data, Article 32 GDPR.

1.3.10 Data protection impact assessment

Requirements, performance and documentation of the data protection impact assessment, Articles 35 and 36 GDPR.

→ To the data protection impact assessment overview

  • 1.3.10.1 Necessity: Threshold analysis under Article 35 GDPR, the statutory examples in paragraph 3, the positive and negative lists of the supervisory authorities, the nine criteria of the risk forecast, the mandatory list and case examples, and the exceptions under paragraphs 5 and 10.
  • 1.3.10.2 Carrying It Out: The six steps under Article 35(7) GDPR, risk assessment with severity, likelihood and risk matrices, the report and templates, review under paragraph 11, and consultation of the supervisory authority under Article 36 GDPR.
  • 1.3.10.3 Internal Organization: Roles and responsibilities of the business unit, the data protection officer, the units involved, data subjects and processors, as well as a proposal for an internal procedure.

1.3.11 Administrative fines

Administrative fines and penalties under the GDPR, Articles 83 and 84 GDPR.

1.3.12 Special categories of personal data (Article 9 GDPR)

Processing of special ("sensitive") categories of personal data under Article 9 GDPR: the general prohibition of processing, the grounds for lawful processing, the relationship with Article 6 GDPR, and opening clauses for Member State law.

1.3.13 Transfers to third countries (data export)

Transfer of personal data to unsafe third countries under Chapter V of the GDPR (Articles 44 to 49 GDPR): when a data export exists, the assessment framework and the instruments for establishing an adequate level of protection.

→ To the transfers to third countries overview

  • 1.3.13.1 Derogations under Article 49 GDPR: When data may be transferred without appropriate safeguards (consent, performance of a contract, legal claims, public interest); narrow interpretation, occasional transfers only, documentation obligation.
  • 1.3.13.2 EU Standard Contractual Clauses and Transfer Impact Assessment: The four modules, the constellations, the delegation model and the conclusion of the standard contractual clauses, as well as the three-stage transfer impact assessment with risk-based considerations and the treatment of the processing chain.
  • 1.3.13.3 EU-US Data Privacy Framework: Adequacy decision for certified US recipients; checking the certification and its scope, no transfer impact assessment, contractual safeguards.
  • 1.3.13.4 Binding Corporate Rules: Binding internal data protection rules for intra-group transfers (controller BCR and processor BCR); scope and limits.
  • 1.3.13.5 Intra-Group Transfers: A framework agreement (Data Transfer Agreement) with an allocation clause and a Data Transfer Directory that bundles processing on behalf of a controller, joint controllership, separate controllers and transfers to third countries for a group of undertakings.

1.3.14 Automated individual decision-making (Article 22 GDPR)

General prohibition of decisions based solely on automated processing under Article 22 GDPR: the statutory criteria, profiling and scoring, the exceptions, the safeguards, sensitive data, and the relationship with the AI Act.

  • 1.3.14 Automated Individual Decision-Making (Article 22 GDPR): The statutory criteria (decision, exclusively automated processing, legal or significant effect, being subject to the decision), profiling and scoring, the exceptions under paragraph 2 (contract, legal provision, consent), the safeguards under paragraph 3, the counter-exception for sensitive data under paragraph 4, information and access rights, and the relationship with the AI Act.

1.3.15 Personal data breach (data breach)

Handling a personal data breach under Articles 4(12), 33 and 34 GDPR: the concept, the internal process, the three-stage risk assessment, notification to the supervisory authority and communication to the data subjects.

→ To the personal data breach overview

  • 1.3.15.1 First Steps and Internal Procedure: Detection and containment, internal reporting, preliminary assessment, from when the breach is deemed known and the 72-hour period begins, attribution of awareness within the organization, and the obligations of processors and joint controllers.
  • 1.3.15.2 Risk Assessment: The three-stage risk model and its legal consequences, obtaining the basis for the assessment, risk analysis based on severity and likelihood of occurrence, the risk matrix, case examples, and special cases such as encryption and a trusted recipient.
  • 1.3.15.3 Notification to the Supervisory Authority (Article 33 GDPR): When notification is required, the deadline (without undue delay, where feasible within 72 hours of becoming aware) and how it is calculated, the competent and the lead supervisory authority, the minimum content under Article 33(3) GDPR, phased and bundled notification, and the documentation obligation under paragraph 5.
  • 1.3.15.4 Communication to Data Subjects (Article 34 GDPR): When communication is required in the case of a high risk, content and form in clear and plain language, the deadline, the exceptions under Article 34(3) GDPR, and the supervisory authority's power to issue an order.

1.4 Case law

Judgments on data protection law, for example of the CJEU, the General Court, the German Federal Court of Justice (BGH) and other German courts.

→ To the case law overview

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn