DE — Country Profile

Germany

118TOTAL
118OFFICIAL SOURCES
7TOPIC AREAS
Law / Act26
Executive Order5
Policy / Guidance19
National Strategy4
Standard / Framework17
International Agreement1
Working Paper9
Other37
22 JUL 2026 · Law / Act

German AI Market Surveillance and Innovation Promotion Act (KI-MIG)

Primary legal sourceAccountability ·Standards ·Research & DevelopmentOfficial source · gesetze-im-internet.de ↗
26 MAR 2026 · Law / Act

Act implementing EU Data Governance Act (Regulation 2022/868)

On 26 March 2026, the Act implementing the EU Data Governance Act (Regulation 2022/868) was adopted by the Parliament. The Act applies to data intermediary service providers, data altruism organisations, and public bodies holding protected data for re-use. It designates the Federal Network Agency as the supervisory authority for data intermediary services and data altruism organisations, and the Federal Statistical Office as both the competent support body for public bodies and the single nat...

Primary legal sourceNational StrategyOfficial source · bundestag.de ↗
26 MAR 2026 · Law / Act

Act for implementation of EU Regulation 2023/2854 on fair access to and use of data (No. 21/2998)

On 26 March 2026, the Act implementing Regulation (EU) 2023/2854 (the Data Act) was adopted by the Parliament. The Act designates the Federal Network Agency as the principal enforcement authority and establishes national rules on administrative procedure and sanctions. The Act applies to manufacturers and providers of internet-connected products and related services, as well as public bodies requesting access to privately held data. It grants the Federal Network Agency powers to investigate, ...

Primary legal sourceNational StrategyOfficial source · bundestag.de ↗
20 MAR 2026 · Other

Federal Cartel Office's investigation into Adobe's acquisition of Semrush

On 20 March 2026, the Federal Cartel Office cleared the proposed acquisition of Semrush Holdings, Inc. by Adobe Inc. following a first-phase merger control review. Adobe develops creativity, productivity, and marketing software, including content management tools. Semrush provides online visibility software, including search engine optimisation applications and a tool for optimising brand presence across generative AI platforms such as ChatGPT and Gemini, also referred to as answer engines. T...

Official materialCompetitionOfficial source · bundeskartellamt.de ↗
11 FEB 2026 · Other

Kabinett beschließt schlanke KI-Aufsicht in Deutschland

Official materialNational StrategyOfficial source · bmds.bund.de ↗
06 DEC 2025 · Law / Act

Security requirements in NIS 2 Implementation and Cybersecurity Strengthening Act

On 6 December 2025, the NIS 2 Implementation and Cybersecurity Strengthening Act, including security requirements, entered into one day after its official publication. It introduces a minimum set of risk measures, including incident-handling procedures, business continuity requirements, vulnerability management, authentication, cryptographic protection, and supply chain controls. Companies are required to assess their own risks and implement proportionate safeguards. The Act also replaces the...

Primary legal sourceNational StrategyOfficial source · recht.bund.de ↗
24 NOV 2025 · Other

Federal Cartel Office investigation into Qualcomm-Alphawave proposed merger

On 24 November 2025, the Federal Cartel Office (FCO) approved the Qualcomm-Alphawave merger. Qualcomm (US) develops semiconductors, primarily for use in vehicles, internet of things applications, and mobile devices. Alphawave (UK) develops high-speed wireless connectivity solutions used in semiconductors known as SerDes IP, which is used for semiconductors that develop artificial intelligence systems. Qualcomm intends to become a chip provider for data centres. The FCO approved the merger, re...

Official materialCompetitionOfficial source · bundeskartellamt.de ↗
20 NOV 2025 · Law / Act

Resolution on amendments to General Data Protection Regulation focusing on child protection

On 20 November 2025, the Conference of Independent Data Protection Supervisory Authorities of the Federal and State Governments adopted a resolution calling for amendments to the General Data Protection Regulation to strengthen protections for children. The resolution applies to controllers and processors handling children’s personal data across the digital economy. It proposes new obligations, including compatibility tests for data processing, a ban on children’s consent for profiling and ad...

Primary legal sourceNational StrategyOfficial source · datenschutzkonferenz-online.de ↗
15 NOV 2025 · Other

Report of the Hessian Commissioner for Data Protection and Freedom of Information on the Use of Microsoft 365

On 15 November 2025, the Hessian Commissioner for Data Protection and Freedom of Information released the Report on the Use of Microsoft 365, which examines the use of Microsoft 365 based on seven criticism points identified in 2022 by the Conference of Independent Data Protection Authorities of the Federal and State Governments. The Report includes recommendations for public and private users of Microsoft 365 products in Hessen to help them ensure that their use of such products complies wit...

Official materialNational StrategyOfficial source · datenschutz.hessen.de ↗
04 NOV 2025 · Executive Order

Authorisation of consent management under Consent Management Ordinance

On 4 November 2025, the Federal Commissioner for Data Protection and Freedom of Information approved the first consent management service under Germany’s consent management ordinance, which applies to online service providers and website operators using cookies or tracking technologies. The ordinance establishes a recognition process for consent managers, enabling users to set privacy preferences once and apply them across all websites, aimed at enhancing user control. It was also highlighted...

Primary legal sourceNational StrategyOfficial source · bfdi.bund.de ↗
17 OCT 2025 · Policy / Guidance

Guidance on Artificial Intelligence systems with retrieval augmented generation

Official source record dated 2025-10-17 for DE concerning Guidance on Artificial Intelligence systems with retrieval augmented generation. See the linked datenschutzkonferenz-online.de source for the authoritative text, procedural context, and implementation details.

Official materialNational StrategyOfficial source · datenschutzkonferenz-online.de ↗
08 OCT 2025 · Other

Federal Commissioner for Data Protection and Freedom of Information inquiry on data protection-compliant handling of personal data in large language models

On 10 August 2025, the Federal Commissioner for Data Protection and Freedom of Information (BfDI) closes the consultation on data protection-compliant handling of personal data in large language models (LLMs). The consultation applies to stakeholders in science, industry, and civil society. It seeks insights on issues including anonymisation limits, memorisation of personal data, risks of data extraction, and enforcement of General Data Protection Regulation data subject rights in Artificial ...

Official materialNational StrategyOfficial source · bfdi.bund.de ↗
13 AUG 2025 · Law / Act

Federal Commissioner for Data Protection and Freedom of Information information updated Information Brochure on General Data Protection Regulation and Federal Data Protection Act

On 13 August 2025, the Federal Commissioner for Data Protection and Freedom of Information (BfDI) published an informational brochure on the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG). It was highlighted that the GDPR applies to all controllers and processors of personal data across the European Union, affecting over 449 million citizens, and imposes obligations including transparency, purpose limitation, data minimisation, technical and organisationa...

Primary legal sourceNational StrategyOfficial source · bfdi.bund.de ↗
24 JUL 2025 · Working Paper

Federal Office for Information Security white paper on bias in Artificial Intelligence

On 24 July 2025, the German Federal Office for Information Security (BSI) published a white paper on bias in Artificial Intelligence (AI). The paper applies to developers, providers, and operators of AI systems across all sectors. The paper highlights practices including designating bias-responsible personnel, implementing organisational and technical measures during data collection to reduce bias, and prioritising pre-processing and in-processing mitigation methods over post-processing appro...

Official materialNational StrategyOfficial source · bsi.bund.de ↗
17 JUL 2025 · Policy / Guidance

State Data Protection Commissioner of North Rhine-Westphalia guidance on processing employee health data

On 17 July 2025, the State Data Protection Commissioner of North Rhine-Westphalia published the guidance on processing employee health data. The guidance clarifies that employers may only process employee health data when strictly necessary to verify continued payment of wages during extended illness, in line with the Continued Payment of Wages Act (EFZG) and data protection laws. It was highlighted that processing requires a concrete presumption of a continuing illness, with less intrusive a...

Official materialNational StrategyOfficial source · ldi.nrw.de ↗
16 JUN 2025 · Standard / Framework

Conference of Independent Data Protection Supervisory Authorities of the Federal and State Governments Model Guidelines for procedures on imposing fines by the data protection supervisory authorities under GDPR

On 16 June 2025, the Conference of Independent Data Protection Supervisory Authorities of the Federal and State Governments (DSK) adopted the model guidelines for procedures on imposing fines by the data protection supervisory authorities (MRiDaVG), establishing standardised rules for conducting administrative fine proceedings under the General Data Protection Regulation (GDPR). The Guidelines define procedural principles, including the primacy of EU law, equivalence, and effectiveness, outli...

Official materialNational StrategyOfficial source · datenschutz-berlin.de ↗
16 JUN 2025 · Policy / Guidance

Berlin Data Protection Authority source on artificial intelligence governance

Official source record dated 16 June 2025 for DE concerning Conference of the Independent Data Protection Supervisory Authorities of the Federal and State Governments adopted guidance on recommended technical and organisational measures for the development and operation of artificial intelligence systems. See the linked datenschutz-berlin.de source for the authoritative text, procedural context, and implementation details.

Official materialData Privacy & ProtectionOfficial source · datenschutz-berlin.de ↗
12 JUN 2025 · Law / Act

Expansion of Federal Office for Information Security's powers in NIS 2 Implementation and Cybersecurity Strengthening Act

On 6 December 2025, the NIS 2 Implementation and Cybersecurity Strengthening Act including provisions expanding Federal Office for Information Security powers entered into force one day after its official publication. The Act introduces expansions to the powers of the Federal Office for Information Security (BSI). Pursuant to Section 3 of the Act on the Federal Office for Information Security and on the Security of Information Technology of Entities (BSIG), the BSI is tasked with promoting in...

Primary legal sourceNational StrategyOfficial source · recht.bund.de ↗
01 JUN 2025 · Other

BSI guide on explainable Artificial Intelligence in an adversarial context

On 6 January 2025, the German Federal Office for Information Security (BSI) adopted a white paper serving as a guide addressing the explainability of artificial intelligence (AI) in adversarial contexts. The document focuses on the limitations of Explainable Artificial Intelligence (XAI), particularly post-hoc methods used to interpret black box AI models. The white paper identifies three challenges, namely the disagreement problem, manipulation risks, and fairwashing. Solutions to these prob...

Official materialNational StrategyOfficial source · bsi.bund.de ↗
27 MAY 2025 · Other

Hamburg Commissioner for Data Protection and Freedom of Information investigation into Meta over alleged training of Artificial Intelligence models with user data

On 27 May 2025, the Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI), in agreement with the German data protection supervisory authorities, decided against initiating provisional proceedings to prohibit Meta from training its Artificial Intelligence (AI) models using social network user data. The decision, which considered the final ruling by the Cologne Higher Regional Court issued on 23 May 2025, aims to ensure a consistent European approach among data protectio...

Official materialNational StrategyOfficial source · datenschutz-hamburg.de ↗
12 MAY 2025 · Standard / Framework

Guideline on data protection in medical research

On 5 December 2025, the Hessian Commissioner for Data Protection and Freedom of Information (HBDI) adopted the guideline on data protection in medical research. The guideline sets out the legal bases for processing health data in a medical research context and discusses a number of specific case studies. The HBDI drew the guideline up together with the German Society of Internal Medicine (DGIM).

Official materialNational StrategyOfficial source · datenschutz.hessen.de ↗
17 APR 2025 · Policy / Guidance

Saxon Data Protection and Transparency Commissioner advisory on Meta's data processing for Artificial Intelligence training

On 17 April 2025, the Saxon Commissioner for Data Protection and Transparency issued an advisory on Meta's plans to use the personal data of all adult European Facebook and Instagram users for Artificial Intelligence (AI) training from the end of May 2025. This includes public posts and photos, which will be used to improve services, including the Meta-AI chatbot on WhatsApp and language models, including Llama. The Commissioner highlighted that users have the right to object to this use of t...

Official materialNational StrategyOfficial source · datenschutz.sachsen.de ↗
15 APR 2025 · Policy / Guidance

Hamburg Commissioner for Data Protection and Freedom of Information guidance on Meta's data processing for AI training

On 15 April 2025, the Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) issued guidance on Meta’s planned use of personal data for artificial intelligence (AI) training and informed users of their right to object. Meta’s AI training, originally scheduled for 2024, was postponed following concerns raised by the Irish Data Protection Commission regarding legal basis and transparency. Meta now plans to begin using the publicly accessible Facebook and Instagram data of...

Official materialNational StrategyOfficial source · datenschutz-hamburg.de ↗
11 APR 2025 · Other

State Commissioner for Data Protection and Freedom of Information Mecklenburg-Western Pomerania warning to public bodies against third-country cloud computing providers

On 11 April 2025, the State Commissioner for Data Protection and Freedom of Information Mecklenburg-Western Pomerania (LfDI MV) issued a public notice alerting authorities to the potential data protection risks associated with utilising cloud computing services from providers based in non-European Union countries. As many local municipalities phase out on-premise solutions, the LfDI MV recommends prioritising open-source products and solutions to ensure data sovereignty and mitigate legal unc...

Official materialNational StrategyOfficial source · datenschutz-mv.de ↗
08 APR 2025 · Working Paper

Federal Cartel Office approved acquisition of Informatica by Salesforce

On 4 August 2025, the German Federal Cartel Office (FCO) approved the acquisition of sole control of Informatica by Salesforce, both headquartered in the United States, following a merger control assessment of vertical integration in digital markets. Salesforce is the world’s largest provider of customer relationship management (CRM) software, while Informatica is a leading provider of data integration tools, integration platform as a service (iPaaS), data quality solutions, and data and analyti

Official materialCompetitionOfficial source · bundeskartellamt.de ↗
19 MAR 2025 · Policy / Guidance

Hamburg Commissioner for Data Protection and Freedom of Information guidance on data deletion obligations and revised retention periods

On 19 March 2025, the Hamburg Commissioner for Data Protection and Freedom of Information published guidelines on data deletion obligations and revised retention periods under German law. The guidance reminds companies to review and delete outdated records, particularly those containing personal data, in line with the GDPR and the revised statutory retention periods. The retention periods vary depending on the type of document and legal basis, with standard periods of 6, 8, or 10 years and so...

Official materialNational StrategyOfficial source · datenschutz-hamburg.de ↗
13 MAR 2025 · Law / Act

Independent data protection supervisory authorities of federal states statement on Draft Act for implementation of Regulation (EU) 2023/2854 on fair access to and use of data

On 13 March 2025, the independent data protection supervisory authorities of the federal states issued a statement on the Draft Data Act Implementation Act. The Act applies to businesses and public authorities handling data access and sharing under the Data Act. The Act designates the Federal Network Agency as the central supervisory authority, outlining its enforcement and monitoring responsibilities. The statement criticised the proposed supervisory structure of the Act, which shifts oversi...

Primary legal sourceNational StrategyOfficial source · datenschutz.sachsen.de ↗
21 FEB 2025 · Policy / Guidance

State Commissioner for Data Protection in Lower Saxony (LfD Lower Saxony) adopted guidelines on use of Deepseek

On 21 February 2025, the State Commissioner for Data Protection in Lower Saxony (LfD Lower Saxony) issued a recommendation highlighting the risks of using the AI tool DeepSeek R1 (DeepSeek), a generative AI chatbot developed by the Chinese company DeepSeek. While freely available online and through app stores in the EU, DeepSeek may not comply with the European AI Regulation or the General Data Protection Regulation (GDPR). The tool's privacy policy indicates unrestricted collection and processi

Official materialData Privacy & ProtectionOfficial source · lfd.niedersachsen.de ↗
30 JAN 2025 · Law / Act

Data protection authority guidance on obligations and prohibitions under the EU Artificial Intelligence Act

On 30 January 2025, the Data Protection Authority of Hamburg adopted a guidance on obligations and prohibitions under the European Union's Artificial Intelligence (AI) Act. It was highlighted that certain requirements on AI competence requirements and bans on certain AI practices under the AI Act enter into force on 2 February 2025. The guidance highlighted that organisations deploying AI must ensure employees understand the specific technology they use, aligning competence with the AI system...

Primary legal sourceNational StrategyOfficial source · datenschutz-hamburg.de ↗
29 JAN 2025 · Standard / Framework

Conference of the Independent Data Protection Authorities guidelines on anonymisation and pseudonymisation of personal data

On 29 January 2025, the German Conference of Independent Data Protection Supervisory Authorities of the Federal and State Governments (DSK) announced plans to develop guidance on the effective anonymisation and pseudonymisation of personal data. The plan would aim to assist entities in research, business, and the public sector in selecting appropriate methods for data processing. The guidance will build upon existing European Data Protection Board guidelines and clarify procedures and require...

Official materialNational StrategyOfficial source · datenschutzkonferenz-online.de ↗
21 JAN 2025 · Standard / Framework

Federal Office for Information Security guidelines on generative artificial intelligence models including risk analysis for information security management

On 21 January 2025, the Federal Office for Information Security adopted guidelines on the opportunities and risks of generative artificial intelligence (AI) models. The guidelines are intended for companies and authorities integrating generative AI into their operations. It outlines the risks associated with generative AI, including data leakage and misuse, and provides recommendations for risk analysis and countermeasures. It also includes new considerations for AI models generating images a...

Official materialNational StrategyOfficial source · bsi.bund.de ↗
14 JAN 2025 · Other

State data protection authorities investigation into DeepSeek to assess compliance with representative designation under General Data Protection Regulation

On 14 February 2025, the state data protection supervisory authorities of Rhineland-Palatinate, Baden-Württemberg, Thuringia, Saxony-Anhalt, Hesse, Bremen, and Berlin announced an investigation into DeepSeek to assess compliance with representative designation under General Data Protection Regulation (GDPR). The investigation focuses on whether the two Chinese companies behind DeepSeek have appointed a representative in the European Union (EU) as required under Article 27(1) GDPR. This provis...

Official materialNational StrategyOfficial source · baden-wuerttemberg.datenschutz.de ↗
04 JAN 2025 · Law / Act

Ordinance on Consent Management Services in German Telecommunications-Telemedia Data Protection Act (TTDSG)

On 1 April 2025, the Consent Management Ordinance under the Telecommunications-Digital Services-Data Protection Act (TDDDG) entered into force. The Ordinance establishes the legal basis for the recognition of consent management services that enable end-users to manage, store, and revoke their consent for the use of terminal device data under Section 25 TDDDG. These recognised services are designed to offer a user-friendly and privacy-preserving alternative to individual cookie consent banners...

Primary legal sourceNational StrategyOfficial source · dip.bundestag.de ↗
19 DEC 2024 · National Strategy

Bavarian State Office for Data Protection Supervision investigation into Worldcoin over biometric data processing

On 19 December 2024, the Bavarian State Office for Data Protection Supervision concluded its investigation into the processing of biometric data by Worldcoin, a provider of digital verification services and cryptocurrency based on blockchain technology. The investigation, which began in April 2023, focused on the company's compliance with data protection regulations concerning the processing of iris data for creating a unique "World ID". The State Office for Data Protection Supervision issued...

Official materialNational StrategyOfficial source · lda.bayern.de ↗
06 DEC 2024 · Working Paper

BfDI Working Paper on Large Language Models (LLMs)

On 6 December 2024, Germany's Germany's Federal Commissioner for Data Protection and Freedom of Information (DfBI) adopted a working paper on Large Language Models (LLMs). The paper seeks to enhance the safety, privacy, and ethical considerations in the development and deployment of Machine Learning (ML) and Artificial Intelligence (AI) technologies. The paper provides an analysis of the privacy and data protection challenges associated with LLMs, highlighting their growing use in diverse fie...

Official materialNational StrategyOfficial source · bfdi.bund.de ↗
15 NOV 2024 · Other

DSK Artificial Intelligence Working Group

On 15 November 2024, the Conference of the Independent Data Protection Supervisory Authorities of the Federal and State Governments of Germany (DSK) announced the creation of an Artificial Intelligence (AI) Working Group. The Working Group will adopt requirements and recommendations for the development and use of AI systems in compliance with data protection regulations. The Working Group aims to consolidate technical and legal expertise from DSK’s supervisory authorities to monitor AI techno...

Official materialNational StrategyOfficial source · datenschutz.sachsen.de ↗
13 NOV 2024 · Law / Act

Data Governance Act (DGG)

On 13 November 2024, the Federal Council of Germany proposed several amendments to the draft Data Governance Act (20/13090), aiming to enhance the roles of regional and state authorities in data governance within Germany. The proposals include enabling states to establish competent bodies for supporting public entities in data management and regional information centers to operate in coordination with the central information office. Additionally, the Federal Council suggests ensuring data tra...

Primary legal sourceNational StrategyOfficial source · bundestag.de ↗
09 NOV 2024 · Other

DSK Resolution on personal data protection in asset deals

On 11 September 2024, the Conference of the Independent Data Protection Authorities of Germany (DSK) adopted a resolution on personal data protection in asset deals. The resolution applies to businesses involved in company acquisitions through asset deals, particularly for sectors where personal data, such as customer, employee, or supplier data, is integral to the transaction. The resolution clarifies data protection obligations, differentiating between customer data in contract initiation, ...

Official materialNational StrategyOfficial source · datenschutzkonferenz-online.de ↗
31 OCT 2024 · Other

Polish-German cooperation to strengthen cybersecurity

On 31 October 2024, Poland's Ministry of Digital Affairs and Germany's Federal Office for Information Security (BSI) expressed a commitment to deepening Polish-German cooperation in the area of cybersecurity. During these talks, both parties emphasised the importance of collaboration between BSI and Poland's NASK Institute, the National Research Institute focused on promoting the security of information and communication networks in Poland. Poland reiterated its cooperation to support Ukraine...

Official materialNational StrategyOfficial source · gov.pl ↗
18 OCT 2024 · Law / Act

Motion concerning freedom of expression on social networks (No. 20/13364)

On 15 October 2024, the lower chamber of the federal parliament, the Bundestag, passed the motion named “No restriction of freedom of expression in social networks - Advocate for the abolition of the Digital Services Act - Until then, safeguard fundamental rights during implementation” (20/13364). The motion criticises the suppression of legally permissible user posts on social networks through deletion or reduction of reach, attributing this to the operators' internal policies against “hate ...

Primary legal sourceContent ModerationOfficial source · bundestag.de ↗