Legal-Updates
2026-07-09 00:00 Legal-Updates

Data Protection Update in Germany: Q4 2025

Germany data protection 2025 saw a notably active fourth quarter, with the German data protection supervisory authorities intensifying enforcement, new guidance emerging on artificial intelligence and cross-border data transfers, and several significant court and regulatory decisions reshaping compliance obligations for businesses operating in Germany. This guide covers the key legislative and regulatory developments, enforcement trends, practical implications for international companies, and the compliance steps that matter most heading into the new year.

Key regulatory and legislative developments in Germany

The Federal Commissioner for Data Protection and Freedom of Information (BfDI) and the sixteen state-level data protection authorities (Landesdatenschutzbehörden) continued to coordinate through the German Data Protection Conference (Datenschutzkonferenz, DSK) to issue harmonised guidance. Several notable positions emerged from the DSK during the quarter.

The DSK published updated orientation on the use of generative AI tools in the workplace. The guidance addresses the lawful basis for processing employee data when AI-assisted productivity tools are deployed, the obligation to conduct a Data Protection Impact Assessment (DPIA) under Article 35 of the General Data Protection Regulation (GDPR), and the requirement to inform employees through works council procedures where applicable. The guidance makes clear that relying on legitimate interests under Article 6(1)(f) GDPR for AI-driven employee monitoring is unlikely to be sufficient without robust balancing tests and documented safeguards.

A further DSK position clarified the application of the GDPR to so-called "shadow profiles" - data sets compiled about individuals who have not directly interacted with a service. Supervisory authorities signalled that collecting and processing such data without a valid legal basis constitutes a serious infringement, and that the accountability principle under Article 5(2) GDPR requires controllers to document how such data is handled from the point of collection.

At the federal legislative level, the German government advanced work on the implementation of the EU AI Act into national administrative structures. While the AI Act is an EU regulation and directly applicable, Germany moved to designate the BfDI as the national supervisory authority for AI systems that process personal data in high-risk categories. This designation has direct implications for companies deploying AI in HR, credit scoring, or access control, as a single point of regulatory contact is now clearer.

Enforcement actions and fines: what changed in Q4

Enforcement activity in Germany remained among the most active in the EU. The Bavarian State Office for Data Protection Supervision (BayLDA) and the Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) both concluded significant investigations during the quarter.

The BayLDA closed an investigation into a mid-sized e-commerce operator concerning unlawful cookie consent practices. The authority found that the company';s consent management platform was configured to pre-tick marketing consent boxes and to make refusal significantly harder than acceptance - a pattern the authority characterised as a violation of Article 7 GDPR and the requirement for freely given consent. The resulting order required the operator to redesign its consent interface within a defined remediation period and to delete all data collected under the non-compliant consent mechanism.

The HmbBfDI issued a reprimand to a financial services firm for failing to honour data subject access requests within the one-month deadline prescribed by Article 12(3) GDPR. The authority noted a systemic backlog caused by inadequate internal processes and required the firm to implement a dedicated data subject rights management system. While the authority stopped short of a monetary fine in this instance, it made clear that repeat failures would attract penalties under Article 83 GDPR.

A common mistake among foreign-headquartered companies is to treat Germany as a single regulatory jurisdiction. In practice, the competent supervisory authority depends on where the company';s EU establishment is located. A company with its German operations in Munich faces BayLDA oversight; one headquartered in Hamburg faces the HmbBfDI. Misidentifying the lead authority delays responses to investigations and can aggravate regulatory relationships.

Cross-border data transfers and the EU-US Data Privacy Framework

Cross-border data transfer compliance remained a live issue throughout the quarter. Following the adoption of the EU-US Data Privacy Framework (DPF) adequacy decision, German supervisory authorities clarified their position on transfers to US-based processors.

The DSK confirmed that transfers to US entities certified under the DPF are permissible without additional Standard Contractual Clauses (SCCs), provided the certification is current and the processing falls within the scope of the certification. However, the DSK issued a practical warning: companies must verify DPF certification status at the time of each new contract and at regular intervals thereafter, because certification lapses if a company fails to renew annually with the US Department of Commerce. A non-obvious requirement is that the DPF certification must specifically cover the categories of data and processing purposes relevant to the transfer - a general certification does not automatically cover all use cases.

For transfers to other third countries, the SCCs adopted under Commission Implementing Decision (EU) 2021/914 remain the primary mechanism. German authorities continued to scrutinise Transfer Impact Assessments (TIAs) accompanying SCCs, particularly for transfers to countries with broad government access laws. The BfDI reiterated that a TIA must be genuinely substantive - a boilerplate document that does not engage with the specific legal framework of the destination country will not satisfy the accountability requirement.

In practice, founders and compliance officers should consider maintaining a living transfer mapping document that records each third-country transfer, the mechanism relied upon, the date of last verification, and the outcome of the TIA. This document is frequently the first item requested during a supervisory investigation.

If your organisation transfers data to multiple jurisdictions and is uncertain whether your current mechanisms remain adequate, contact info@vlolawfirm.com. We can assist with transfer mapping, TIA preparation, and SCC implementation.

AI, automated decision-making, and new compliance obligations

The intersection of AI and data protection law generated significant compliance activity in Germany during the quarter. Article 22 GDPR, which restricts solely automated decision-making with legal or similarly significant effects, came under renewed scrutiny as more companies deployed AI-driven decision tools in hiring, lending, and insurance.

The BfDI published a position paper on automated profiling in the insurance sector. The paper concluded that using AI models to set premiums based on inferred behavioural characteristics - without human review - constitutes a solely automated decision within the meaning of Article 22(1) GDPR. Controllers relying on the contractual necessity exception under Article 22(2)(a) must demonstrate that the automated decision is genuinely necessary for the contract, not merely convenient. The paper also noted that the right to explanation under Article 22(3) requires a meaningful account of the logic involved, not a generic description of the model type.

For HR technology, the DSK';s earlier guidance on AI in the workplace was supplemented by a position from the North Rhine-Westphalia data protection authority (LDI NRW) addressing AI-assisted candidate screening. The LDI NRW found that screening tools that rank candidates using inferred characteristics derived from social media or online behaviour require an explicit legal basis, a DPIA, and - where a works council exists - a works agreement (Betriebsvereinbarung) before deployment. Many underestimate the role of works councils in German data protection compliance: a works council can effectively veto the introduction of monitoring or profiling technology that affects employees, making early engagement essential.

The practical scenario for a foreign company entering the German market is instructive. A US-based HR software provider deploying its platform for a German client must ensure that the platform';s data processing agreement complies with Article 28 GDPR, that any sub-processors are listed and approved, and that the platform';s AI features have been assessed for Article 22 compliance before go-live. Failure to complete these steps before deployment - rather than after - is the most common source of regulatory exposure for international technology vendors.

Data subject rights enforcement and internal compliance priorities

Enforcement of data subject rights - access, erasure, rectification, portability, and objection - remained a priority for German supervisory authorities. The volume of complaints received by state authorities continued to rise, and authorities increasingly used complaint-triggered investigations as a mechanism to examine broader systemic compliance failures within an organisation.

The right of access under Article 15 GDPR generated the most complaints. German courts, including the Federal Court of Justice (Bundesgerichtshof, BGH), have issued a series of rulings clarifying the scope of the access right. The BGH confirmed that the access right extends to copies of documents containing personal data, not merely to a summary of the data processed. This interpretation significantly expands the practical burden of responding to access requests, particularly for companies that process large volumes of correspondence or contractual documents containing personal data.

The right to erasure under Article 17 GDPR also generated notable case law. A regional appellate court found that a company';s retention of data beyond the statutory retention period under the German Commercial Code (Handelsgesetzbuch, HGB) - which requires retention of business correspondence for six years and accounting records for ten years - did not justify indefinite retention of all personal data in those records. The court held that data not required for the specific statutory purpose must be erased even if the document as a whole is retained. Controllers should therefore consider pseudonymisation or selective deletion within retained documents rather than treating statutory retention as a blanket exemption from erasure obligations.

A practical scenario that arises frequently involves a former employee submitting an access request combined with an erasure request. The company must provide a copy of all personal data processed, identify which data is subject to statutory retention, erase the remainder, and respond within one month. In practice, many companies lack the internal tooling to execute this process reliably, leading to late responses and regulatory complaints.

Internally, compliance priorities for the quarter included updating Records of Processing Activities (RoPA) under Article 30 GDPR to reflect new AI tools and data flows, reviewing DPA agreements with cloud and SaaS providers following provider terms updates, and conducting refresher training for staff handling data subject requests.

For organisations that need to audit their data subject rights processes or update their RoPA to reflect current processing activities, contact info@vlolawfirm.com. We can structure the review and assist with documentation.

Frequently asked questions

What is the most significant practical risk for international companies operating in Germany under current data protection rules?

The most significant practical risk is the combination of active supervisory enforcement and the complexity of Germany';s multi-authority structure. International companies often assume that a single data protection officer and a standard set of GDPR policies are sufficient. In Germany, the applicable supervisory authority depends on the location of the establishment, and each authority has its own enforcement priorities and procedural expectations. Companies that fail to identify their competent authority, maintain a current RoPA, and implement functioning data subject rights processes face the highest exposure. Fines under Article 83 GDPR can reach up to four percent of global annual turnover for serious infringements, and German authorities have demonstrated willingness to impose significant penalties on both large and mid-sized organisations.

How long does it typically take to respond to a data subject access request in Germany, and what are the consequences of missing the deadline?

The GDPR requires a response within one calendar month of receipt, extendable by a further two months for complex or numerous requests, provided the data subject is notified of the extension within the first month. Missing the one-month deadline without notification is a direct infringement of Article 12(3) GDPR. German supervisory authorities treat systematic delays as evidence of inadequate internal processes rather than isolated errors, and investigations triggered by a single complaint frequently reveal broader compliance gaps. The practical consequence is not only a potential fine but also a remediation order requiring investment in new processes and systems. Companies should build internal workflows that log receipt dates, assign ownership, and escalate requests approaching the deadline.

Should a company deploying AI tools in Germany conduct a DPIA, and when is one mandatory?

A DPIA is mandatory under Article 35 GDPR when processing is likely to result in a high risk to individuals, and the DSK';s list of processing operations requiring a DPIA in Germany explicitly includes systematic and extensive profiling, large-scale processing of special category data, and automated decision-making with significant effects. AI tools that analyse employee behaviour, screen job candidates, assess creditworthiness, or personalise content based on inferred characteristics will typically trigger the DPIA requirement. The DPIA must be completed before processing begins - not retrospectively. Where the DPIA identifies a high residual risk that cannot be mitigated, the controller must consult the competent supervisory authority under Article 36 GDPR before proceeding. In practice, many companies deploy AI tools without completing a DPIA, treating it as a formality rather than a substantive risk assessment. German authorities have made clear that a DPIA must engage with the specific risks of the tool in question, not simply restate generic GDPR principles.

Conclusion

Germany';s data protection landscape in the fourth quarter was defined by intensified enforcement, clearer regulatory guidance on AI and automated decision-making, and continued scrutiny of cross-border data transfers. Companies operating in Germany face a demanding compliance environment that rewards proactive documentation, functioning internal processes, and early engagement with supervisory authorities. The developments of this quarter signal that enforcement will remain active, and that organisations relying on outdated consent mechanisms, incomplete transfer documentation, or untested data subject rights processes face material regulatory risk.

VLO Law Firms advises international clients on data protection matters in Germany. We can assist with DPIA preparation, Records of Processing Activities, data subject rights process design, cross-border transfer compliance, and supervisory authority engagement. To request a consultation, contact: info@vlolawfirm.com