New law passed on the adaptation of German data protection law to the GDPR
Following the introduction of the of the Federal Data Protection Act (“BDSG”) in 2017 which was devised to focus on areas in which the GDPR offers the possibility of further regulation by national legislation,ensuring, companies offering goods and services to German customers or who monitor their behaviour had to comply with the already sophisticated framework of the GDPR as well as the complex regulations of the BDSG. On 27 June 2019 the German Bundestag passed a second act to adapt the highly fragmented German data protection law to the requirements of the European General Data Protection Regulation (“GDPR”). The goal is to bring the sector-specific data protection rules in 154 federal laws in line with the requirements of the GDPR, which came into force on 25 May 2018. Also affected are a number of laws that are important for businesses, such as the Fiscal Code, the Banking Act, and the Securities Trading Act. The new provisions primarily focus on special legal bases for data processing, the rights of the data subjects, the obligations for processors, cross-border data transfers to countries outside the EU, and the requirements for technical and organisational measures.
First amendments to the BDSG
One year into the data protection regime created by the GDPR, the law also brings important changes to the BDSG:
- Firstly, it changes the mandatory threshold for controllers and processors to designate a data protection officer. The minimum is now 20 (up from ten previously) employees of a company who are permanently engaged in the processing of personal data. Further requirements to designate a data protection officer pursuant to Art. 37 of the GDPR remain unaffected.
- Secondly, the German Bundestag has simplified the requirements for obtaining consent in the context of employment. As employees can give their consent electronically in accordance with the requirements of the GDPR, the BDSG will be amended correspondingly. It will be sufficient in the future for the employer to save the consent as an e-mail. This change takes place within the framework of the coalition agreement one of the aims of which is to examine all laws for their digital suitability.
No changes to the Telecommunications Act
Despite this large-scale initiative, no changes to the data protection provisions set out in the Telecommunications Act (“TKG”) have been made at this point. Although several members of parliament requested some modifications, they were ultimately rejected. The future aim is to implement the requirements of the ePrivacy Directive into the TKG while removing the parts of the TKG that overlap or conflict with the GDPR.
When?
For the most part, the amendments will enter into force on the day following publication in the Federal Law Gazette (Bundesgesetzblatt), the date of which has not yet been determined. Nevertheless, experience shows that this may take place quickly, so organisations should be aware of the changes and to be proactive.
Why?
The NEW BDSG had been subject to some criticism, as the law appeared to contradict some of the standards set by the GDPR including one of the main objectives of the GDPR—to provide for a coherent data protection framework throughout the EU.
Provisions of the BDSG that went beyond the scope of the GDPR proved to be of limited practical relevance, as German courts and authorities may not apply provisions of the BDSG if they deemed them to be contrary to European law. Some voices in German legal literature even argued that these regulations could lead to EU law infringement procedures against Germany.
Where the BDSG limits the rights of data subjects, companies had been advised to rely on the stricter rules under the GDPR, as the application of the less restrictive BDSG regime brings only little benefit and are not being upheld by German courts and authorities. The amendments made to the BDSG is an important step in bringing the two laws together and clearing the landscape of confusion and mixed messages.








