# Opening Clauses and National Law (Article 6(2), (3) GDPR)

Scope for Member State regulation under Article 6(1)(c) and (e) GDPR: the structure of the opening clauses, the limits on the national legislature, the German Federal Data Protection Act (BDSG), the data protection acts of the Länder and the TDDDG.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.8-oeffnungsklauseln-und-nationales-recht
> Sprache: en



As a regulation, the GDPR is directly applicable. For the grounds for lawful processing in Article 6(1)(c) and (e) GDPR, it nevertheless gives the Member States scope for regulation by means of the opening clauses in paragraphs 2 and 3. These clauses form the basis for extensive national legislation, in Germany in particular in the German Federal Data Protection Act (BDSG), in the data protection acts of the Länder and in numerous sector-specific laws.

<Callout type="info">
  **Key takeaways**

  * The opening clauses in Article 6(2) and (3) GDPR give the Member States scope for regulation, but **only** in respect of the grounds for lawful processing in points (c) and (e).
  * **Paragraph 2** largely serves a clarifying function; **paragraph 3** is the actual basis of competence and sets out the requirements for the national legal basis.
  * Paragraphs 1 and 4 contain no opening clause: the catalog of grounds in paragraph 1 is **exhaustive**.
  * National rules must be clear, precise and proportionate and must always be capable of being traced back to one of the grounds in paragraph 1; otherwise they are contrary to Union law.
  * In Germany, the opening clauses are given effect above all by the BDSG, the data protection acts of the Länder, the German Telecommunications Digital Services Data Protection Act (TDDDG) and numerous sector-specific laws.
</Callout>

## 1 Overview [#1-overview]

### 1.1 Function of the opening clauses [#11-function-of-the-opening-clauses]

The opening clauses serve to accommodate national particularities in the public sector and in areas with statutorily regulated processing obligations. They are to be interpreted narrowly and may not be used to circumvent the GDPR.

### 1.2 No opening clause in paragraphs 1 and 4 [#12-no-opening-clause-in-paragraphs-1-and-4]

Paragraph 1 is exhaustive: the six grounds for lawful processing can neither be supplemented by further grounds nor have their scope altered by national law. On the better view, paragraph 4 is not an opening clause but a compatibility test; the German Federal Court of Justice has, however, taken a different view ([BGH, order of 24 September 2019, VI ZB 39/18](https://juris.bundesgerichtshof.de/cgi-bin/rechtsprechung/document.py?Gericht=bgh\&Art=en\&nr=100737)).

### 1.3 Structure of the two paragraphs [#13-structure-of-the-two-paragraphs]

* Paragraph 2: empowers the Member States to "maintain or introduce" "more specific provisions" within the scope of points (c) and (e). The provision largely serves a clarifying function; it does not create a regulatory competence of its own but refers to paragraph 3.
* Paragraph 3: constitutes the actual basis of competence. It provides that the legal basis for processing under points (c) and (e) is to be laid down by Union law or Member State law, and it sets out substantive requirements for that legal basis.

## 2 Paragraph 2: opening clause with a clarifying function [#2-paragraph-2-opening-clause-with-a-clarifying-function]

### 2.1 More specific provisions [#21-more-specific-provisions]

Paragraph 2 refers to "more specific provisions". What is meant are rules giving concrete form to individual processing situations, for example in employment, health or social law. General catch-all clauses that merely repeat the level of protection afforded by the GDPR do not fall within paragraph 2.

### 2.2 Maintenance of existing provisions [#22-maintenance-of-existing-provisions]

The opening clause also allows the Member States to maintain provisions that already exist. This is of practical importance: the special legislation that has developed over many years in the BDSG and in the data protection acts of the Länder may be continued under the GDPR in so far as it fits within the framework of the opening clauses.

### 2.3 Limits of the opening clause [#23-limits-of-the-opening-clause]

The opening clause does not alter the scope of the grounds for lawful processing in paragraph 1. In particular, national rules may not result in new legal bases being created or in the scope of existing ones being altered ([CJEU, judgment of 30 March 2023, C-34/21, Hauptpersonalrat der Lehrerinnen und Lehrer, para. 70](https://curia.europa.eu/juris/liste.jsf?num=C-34/21\&language=de)).

## 3 Paragraph 3: requirements for the legal basis [#3-paragraph-3-requirements-for-the-legal-basis]

### 3.1 Sources of the legal basis [#31-sources-of-the-legal-basis]

Paragraph 3 permits two sources of law: Union law (paragraph 3(a)) and Member State law (paragraph 3(b)). Union law covers regulations, directives and decisions of the EU institutions. Member State law covers formal statutes, statutory instruments, by-laws and subordinate legislation.

### 3.2 Determination of the purpose [#32-determination-of-the-purpose]

The purpose of the processing must be determined in the legal basis or must be necessary for the performance of the task carried out in the public interest. These are two alternatives: either the purpose is expressly identified, or it follows from the underlying public task.

### 3.3 Substantive framework of the legal basis [#33-substantive-framework-of-the-legal-basis]

Under paragraph 3, third sentence, the legal basis may contain further provisions, for example on:

* the types of data which are processed,
* the categories of data subjects,
* the recipients and the purposes of a disclosure,
* purpose limitation,
* the storage period,
* the processing operations and processing procedures.

### 3.4 Objective in the public interest and proportionality [#34-objective-in-the-public-interest-and-proportionality]

Paragraph 3, fourth sentence, requires the legal basis to meet an objective in the public interest and to be proportionate to the legitimate aim pursued. This transposes the principle of proportionality laid down in Article 52(1), second sentence, of the Charter of Fundamental Rights of the European Union into ordinary law.

## 4 Limits of the Member States' scope for regulation [#4-limits-of-the-member-states-scope-for-regulation]

When giving effect to the opening clauses, the national legislature is bound by four limits:

| Limit                               | Core content                                                                                                                    |
| ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------- |
| No new ground for lawful processing | The catalog in Article 6(1) GDPR is exhaustive; national rules must be capable of being traced back to point (c) or point (e).  |
| No alteration of scope              | National law may neither extend nor restrict the grounds for lawful processing in paragraph 1.                                  |
| Requirement of specificity          | Legal bases must be clear and precise; blanket task-assignment provisions or catch-all clauses are not sufficient.              |
| Proportionality                     | The processing must be limited to what is strictly necessary and must strike an appropriate balance between fundamental rights. |

### 4.1 No new ground for lawful processing [#41-no-new-ground-for-lawful-processing]

The catalog in paragraph 1 is exhaustive; Member States cannot create further grounds for lawful processing. National rules must always be capable of being traced back to one of the grounds in paragraph 1, regularly to point (c) or point (e).

### 4.2 No alteration of the scope of paragraph 1 [#42-no-alteration-of-the-scope-of-paragraph-1]

National rules may neither extend nor restrict the scope of the grounds for lawful processing in paragraph 1. The German Federal Administrative Court (BVerwG) has insisted on this limit on several occasions and has, in particular, objected to balancing-of-interests clauses in general public-law grounds for lawful processing ([BVerwG, judgment of 27 September 2018, 7 C 5/17](https://www.bverwg.de/270918u7c5.17.0); [BVerwG, judgment of 27 March 2019, 6 C 2/18](https://www.bverwg.de/270319u6c2.18.0)).

### 4.3 Requirement of specificity [#43-requirement-of-specificity]

National legal bases must be clear and precise. Blanket provisions merely assigning tasks, or general catch-all clauses, are as a rule not sufficient. The more sensitive the data and the more intrusive the processing, the higher the requirements as to specificity.

### 4.4 Proportionality [#44-proportionality]

The national rule must also be proportionate. The CJEU applies a strict standard here: processing must be limited to what is strictly necessary, and the rule must strike an appropriate balance between the objective pursued and the protection of the data subject's fundamental rights ([CJEU, judgment of 1 August 2022, C-184/20, Vyriausioji tarnybinės etikos komisija, paras. 91 et seq.](https://curia.europa.eu/juris/liste.jsf?num=C-184/20\&language=de)).

## 5 National legislation in Germany [#5-national-legislation-in-germany]

### 5.1 BDSG [#51-bdsg]

The BDSG is the central adaptation statute at federal level. It contains general rules for federal public bodies and for non-public bodies as well as a number of special provisions:

* § 3 BDSG: processing for the purposes of exercising public authority tasks,
* § 4 BDSG: video surveillance of publicly accessible spaces by public bodies (for the private sector, the case law of the BVerwG has in the meantime referred controllers to point (f)),
* §§ 22 et seq. BDSG: special categories of personal data,
* § 26 BDSG: processing of employee data (in part incompatible with Article 88 GDPR according to CJEU, judgment of 30 March 2023, C-34/21),
* § 31 BDSG: scoring.

### 5.2 Data protection acts of the Länder [#52-data-protection-acts-of-the-länder]

The processing of personal data by public bodies of the Länder is governed by the data protection acts of the Länder. They give concrete form to point (e) for the sphere of the respective Land and contain the general provisions on processing by Land and municipal authorities. Alongside these there are sector-specific Land statutes, for example on the police, the protection of the constitution, residence registration law and school law.

### 5.3 TDDDG (formerly TTDSG) [#53-tdddg-formerly-ttdsg]

The German Act on Data Protection and the Protection of Privacy in Telecommunications and Digital Services (TDDDG, formerly TTDSG) transposes the ePrivacy Directive 2002/58/EC and contains special data protection rules for the digital services and telecommunications sector:

* § 25 TDDDG: storage of, and access to, information in terminal equipment (cookies and comparable technologies). The provision requires consent in principle and allows only narrowly defined exceptions (strictly necessary for technical reasons, expressly requested).
* §§ 3 et seq. TDDDG: secrecy of telecommunications and protection of privacy in telecommunications traffic.
* §§ 9 et seq. TDDDG: processing of traffic data and location data.

The TDDDG applies alongside the GDPR; its provisions take precedence over Article 6(1) GDPR in so far as they extend.

### 5.4 Sector-specific laws [#54-sector-specific-laws]

Countless sector-specific laws give concrete form to data processing within their respective scope. Examples: the German Social Codes, the Fiscal Code, the Commercial Code, health legislation, residence registration law, statistics legislation, the Trade Regulation Act, professional laws (German Federal Lawyers' Act, BRAO; Tax Advisers Act, StBerG; Public Accountants Act, WPO).

## 6 Relationship between the GDPR and national law [#6-relationship-between-the-gdpr-and-national-law]

### 6.1 Primacy of application of the GDPR [#61-primacy-of-application-of-the-gdpr]

National law may not conflict with the GDPR. In so far as national rules exceed the framework of the opening clauses, they are contrary to Union law and cannot support any processing. This applies in particular to rules that undermine the exhaustive character of the catalog of grounds for lawful processing.

### 6.2 Interpretation in conformity with the GDPR [#62-interpretation-in-conformity-with-the-gdpr]

National rules are, as far as possible, to be interpreted in such a way that they are compatible with the GDPR. Where a conforming interpretation is not sufficient, the only remaining option is to disapply the national rule and to have direct recourse to Article 6(1) GDPR.

### 6.3 Preliminary ruling procedure [#63-preliminary-ruling-procedure]

Where there are doubts as to whether national rules conform with Union law, the national court may refer the matter to the CJEU by way of the preliminary ruling procedure (Article 267 TFEU). The CJEU has developed its case law on the national opening clauses in numerous decisions, most recently in particular in the field of employee data protection ([CJEU, judgment of 30 March 2023, C-34/21](https://curia.europa.eu/juris/liste.jsf?num=C-34/21\&language=de)).

<Callout type="info">
  When assessing national legal bases, the guiding question is: which of the grounds for lawful processing in Article 6(1) GDPR does the provision give concrete form to? Only once this question has been clearly answered can it be assessed whether the legal basis meets the requirements of paragraph 3. National rules that cannot be traced back to one of the six grounds are contrary to Union law.
</Callout>

<Cards>
  <Card title="Legal bases (Article 6 GDPR)" href="/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung" description="Structure and overview." />

  <Card title="Legal obligation" href="/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.3-rechtliche-verpflichtung" description="Article 6(1)(c) GDPR." />

  <Card title="Public interest and official authority" href="/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.5-oeffentliches-interesse-und-oeffentliche-gewalt" description="Article 6(1)(e) GDPR." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.