DE — Country Profile

Germany

196TOTAL
57OFFICIAL SOURCES
11TOPIC AREAS
Law / Act44
Executive Order9
Policy / Guidance20
National Strategy6
Standard / Framework21
International Agreement3
Working Paper11
Court Case31
Other51
26 MAR 2026 · Law / Act

Act implementing EU Data Governance Act (Regulation 2022/868)

On 26 March 2026, the Act implementing the EU Data Governance Act (Regulation 2022/868) was adopted by the Parliament. The Act applies to data intermediary service providers, data altruism organisations, and public bodies holding protected data for re-use. It designates the Federal Network Agency as the supervisory authority for data intermediary services and data altruism organisations, and the Federal Statistical Office as both the competent support body for public bodies and the single nat...

Primary legal sourceNational StrategyOfficial source · bundestag.de ↗
26 MAR 2026 · Law / Act

Act for implementation of EU Regulation 2023/2854 on fair access to and use of data (No. 21/2998)

On 26 March 2026, the Act implementing Regulation (EU) 2023/2854 (the Data Act) was adopted by the Parliament. The Act designates the Federal Network Agency as the principal enforcement authority and establishes national rules on administrative procedure and sanctions. The Act applies to manufacturers and providers of internet-connected products and related services, as well as public bodies requesting access to privately held data. It grants the Federal Network Agency powers to investigate, ...

Primary legal sourceNational StrategyOfficial source · bundestag.de ↗
20 MAR 2026 · Other

Federal Cartel Office's investigation into Adobe's acquisition of Semrush

On 20 March 2026, the Federal Cartel Office cleared the proposed acquisition of Semrush Holdings, Inc. by Adobe Inc. following a first-phase merger control review. Adobe develops creativity, productivity, and marketing software, including content management tools. Semrush provides online visibility software, including search engine optimisation applications and a tool for optimising brand presence across generative AI platforms such as ChatGPT and Gemini, also referred to as answer engines. T...

Secondary evidenceCompetitionIssuing institution: Issuing authority not identified
02 MAR 2026 · Court Case

Lawsuit against Meta Group over data protection violations (Case No. 3 U 31/25)

On 2 March 2026, the 3rd Civil Senate of the Higher Regional Court of Jena issued a judgment ordering the Meta Group to pay damages for data protection violations. Business tools distributed by the Meta Group to website and app operators enable tracking of the internet usage of its social network members, including the collection of sensitive personal data such as health-related information, when a user researches mental health disorders, seeks therapeutic help via doctor portals, or orders m...

Secondary evidenceNational StrategyIssuing institution: Issuing authority not identified
23 FEB 2026 · Court Case

Lawsuit concerning 2016 update to WhatsApp terms of service and privacy policy (Federation of German Consumer Organisations v WhatsApp Inc. / 52 O 22/17)

On 23 February 2026, the 52nd Civil Chamber of the Berlin II Regional Court issued a judgment in Federation of German Consumer Organisations (vzbv) v WhatsApp Inc. (52 O 22/17) regarding claims for injunctive relief related to the 2016 update of the WhatsApp terms of service and privacy policy. The court ordered WhatsApp to refrain, in business transactions with consumers habitually resident in Germany, from disclosing personal data of WhatsApp users and data of third parties who do not use W...

Secondary evidenceNational StrategyIssuing institution: Issuing authority not identified
12 FEB 2026 · Law / Act

Germany Approves Draft Legislation (KI-MIG) to Implement EU AI Act

Germany approved draft legislation (KI-MIG - Kunstliche Intelligenz Management-Gesetz) to implement the EU AI Act, designating the Federal Network Agency (Bundesnetzagentur) as the central AI supervisor and coordinator, with oversight shared among relevant sector regulators.

Secondary evidenceNational Implementation ·Supervisory AuthorityIssuing institution: Issuing authority not identified
10 DEC 2025 · Court Case

Lawsuit concerning text and data mining as a potential violation of copyright (Kneschke v LAION/Case 310 O.22723)

On 10 December 2025, the 5th Civil Senate of the Hanseatic Higher Regional Court dismissed an appeal against a Hamburg Regional Court judgment, holding that the use of a photograph in an Artificial Intelligence (AI) training dataset by an association was lawful. The case concerned the creation of a publicly available image–text dataset, used to train generative AI models, which involved temporarily downloading the photograph from a photo agency website to compare it with descriptive data. The...

Secondary evidenceIntellectual PropertyIssuing institution: Issuing authority not identified
06 DEC 2025 · Law / Act

Security requirements in NIS 2 Implementation and Cybersecurity Strengthening Act

On 6 December 2025, the NIS 2 Implementation and Cybersecurity Strengthening Act, including security requirements, entered into one day after its official publication. It introduces a minimum set of risk measures, including incident-handling procedures, business continuity requirements, vulnerability management, authentication, cryptographic protection, and supply chain controls. Companies are required to assess their own risks and implement proportionate safeguards. The Act also replaces the...

Primary legal sourceNational StrategyOfficial source · recht.bund.de ↗
24 NOV 2025 · Other

Federal Cartel Office investigation into Qualcomm-Alphawave proposed merger

On 24 November 2025, the Federal Cartel Office (FCO) approved the Qualcomm-Alphawave merger. Qualcomm (US) develops semiconductors, primarily for use in vehicles, internet of things applications, and mobile devices. Alphawave (UK) develops high-speed wireless connectivity solutions used in semiconductors known as SerDes IP, which is used for semiconductors that develop artificial intelligence systems. Qualcomm intends to become a chip provider for data centres. The FCO approved the merger, re...

Secondary evidenceCompetitionIssuing institution: Issuing authority not identified
20 NOV 2025 · Law / Act

Resolution on amendments to General Data Protection Regulation focusing on child protection

On 20 November 2025, the Conference of Independent Data Protection Supervisory Authorities of the Federal and State Governments adopted a resolution calling for amendments to the General Data Protection Regulation to strengthen protections for children. The resolution applies to controllers and processors handling children’s personal data across the digital economy. It proposes new obligations, including compatibility tests for data processing, a ban on children’s consent for profiling and ad...

Secondary evidenceNational StrategyIssuing institution: Issuing authority not identified
15 NOV 2025 · Other

Report of the Hessian Commissioner for Data Protection and Freedom of Information on the Use of Microsoft 365

On 15 November 2025, the Hessian Commissioner for Data Protection and Freedom of Information released the Report on the Use of Microsoft 365, which examines the use of Microsoft 365 based on seven criticism points identified in 2022 by the Conference of Independent Data Protection Authorities of the Federal and State Governments. The Report includes recommendations for public and private users of Microsoft 365 products in Hessen to help them ensure that their use of such products complies wit...

Secondary evidenceNational StrategyIssuing institution: Issuing authority not identified
14 NOV 2025 · Court Case

Beschluss 4 L 3030/25

Pro Se Litigant appeared before the Köln. Misrepresented: Case Law | Antragsteller führt vermeintlich ergangene Entscheidungen des OVG NRW an, zitiert diese aber fehlerhaft; Gericht hält dies für ein Zeichen ungeprüfter KI‑Ergebnisse.

Court: KölnParty: Pro Se Litigant
Secondary evidenceJudicial & Law Enforcement ·Generative AI ·Liability & AccountabilityIssuing institution: Köln
11 NOV 2025 · Court Case

Lawsuit concerning alleged copyright infringement of song lyrics by AI systems (GEMA v Open AI) (Case No. 42 O 14139/24)

On 11 November 2025, the 42nd Civil Chamber of the Munich Regional Court largely upheld GEMA’s claims for injunctive relief and damages against two OpenAI group companies. GEMA, a collecting society, argued that lyrics by nine German songwriters had been memorised by OpenAI’s language models and reproduced in chatbot outputs, thereby infringing copyright exploitation rights. OpenAI maintained that its models consist of learned parameters rather than stored data, that users are responsible for...

Secondary evidenceIntellectual PropertyIssuing institution: Issuing authority not identified
04 NOV 2025 · Executive Order

Authorisation of consent management under Consent Management Ordinance

On 4 November 2025, the Federal Commissioner for Data Protection and Freedom of Information approved the first consent management service under Germany’s consent management ordinance, which applies to online service providers and website operators using cookies or tracking technologies. The ordinance establishes a recognition process for consent managers, enabling users to set privacy preferences once and apply them across all websites, aimed at enhancing user control. It was also highlighted...

Primary legal sourceNational StrategyOfficial source · bfdi.bund.de ↗
17 OCT 2025 · Policy / Guidance

Guidance on Artificial Intelligence systems with retrieval augmented generation

Official source record dated 2025-10-17 for DE concerning Guidance on Artificial Intelligence systems with retrieval augmented generation. See the linked datenschutzkonferenz-online.de source for the authoritative text, procedural context, and implementation details.

Secondary evidenceNational StrategyIssuing institution: Issuing authority not identified
11 OCT 2025 · Court Case

Case 19 O 527/16

Expert appeared before the LG Darmstadt. Fabricated: Exhibits & Submissions Outcome: Expert fees reduced to naught.

Court: LG DarmstadtParty: Expert
Secondary evidenceJudicial & Law Enforcement ·Generative AI ·Liability & AccountabilityIssuing institution: LG Darmstadt
08 OCT 2025 · Other

Federal Commissioner for Data Protection and Freedom of Information inquiry on data protection-compliant handling of personal data in large language models

On 10 August 2025, the Federal Commissioner for Data Protection and Freedom of Information (BfDI) closes the consultation on data protection-compliant handling of personal data in large language models (LLMs). The consultation applies to stakeholders in science, industry, and civil society. It seeks insights on issues including anonymisation limits, memorisation of personal data, risks of data extraction, and enforcement of General Data Protection Regulation data subject rights in Artificial ...

Official materialNational StrategyOfficial source · bfdi.bund.de ↗
25 SEP 2025 · Court Case

Beschluss 2-13 S 56/24

Lawyer used Unidentified in proceedings before the LG Frankfurt a. M.. False Quotes: Case Law | verbatim quotations from the Federal Court of Justice (BGH) that did not even exist

Court: LG Frankfurt a. M.Party: Lawyer
Secondary evidenceJudicial & Law Enforcement ·Generative AI ·Liability & AccountabilityIssuing institution: LG Frankfurt a. M.
25 AUG 2025 · Court Case

3 ORbs 164/25

Lawyer appeared before the KG Berlin. Fabricated: Exhibits & Submissions | Factually incorrect submissions

Court: KG BerlinParty: Lawyer
Secondary evidenceJudicial & Law Enforcement ·Generative AI ·Liability & AccountabilityIssuing institution: KG Berlin
13 AUG 2025 · Law / Act

Federal Commissioner for Data Protection and Freedom of Information information updated Information Brochure on General Data Protection Regulation and Federal Data Protection Act

On 13 August 2025, the Federal Commissioner for Data Protection and Freedom of Information (BfDI) published an informational brochure on the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG). It was highlighted that the GDPR applies to all controllers and processors of personal data across the European Union, affecting over 449 million citizens, and imposes obligations including transparency, purpose limitation, data minimisation, technical and organisationa...

Primary legal sourceNational StrategyOfficial source · bfdi.bund.de ↗
12 AUG 2025 · Court Case

Lawsuit against Meta to prohibit use of certain customer data for AI training purposes (Case No. 6 UKI 3/25)

On 12 August 2025, the Schleswig-Holstein Higher Regional Court rejected an application filed by Stichting Onderzoek Marktinformatie (SOMI) against Meta to prohibit the use of certain customer data from Facebook and Instagram services for artificial intelligence (AI) training purposes, on the grounds of lack of urgency, in case number 6 UKI 3/25. The court found that Meta had publicly announced in 2024, and by direct email to users, including SOMI in April 2025, its intention to use certain p...

Secondary evidenceNational StrategyIssuing institution: Issuing authority not identified
24 JUL 2025 · Working Paper

Federal Office for Information Security white paper on bias in Artificial Intelligence

On 24 July 2025, the German Federal Office for Information Security (BSI) published a white paper on bias in Artificial Intelligence (AI). The paper applies to developers, providers, and operators of AI systems across all sectors. The paper highlights practices including designating bias-responsible personnel, implementing organisational and technical measures during data collection to reduce bias, and prioritising pre-processing and in-processing mitigation methods over post-processing appro...

Official materialNational StrategyOfficial source · bsi.bund.de ↗
17 JUL 2025 · Policy / Guidance

State Data Protection Commissioner of North Rhine-Westphalia guidance on processing employee health data

On 17 July 2025, the State Data Protection Commissioner of North Rhine-Westphalia published the guidance on processing employee health data. The guidance clarifies that employers may only process employee health data when strictly necessary to verify continued payment of wages during extended illness, in line with the Continued Payment of Wages Act (EFZG) and data protection laws. It was highlighted that processing requires a concrete presumption of a continuing illness, with less intrusive a...

Secondary evidenceNational StrategyIssuing institution: Issuing authority not identified
17 JUL 2025 · Court Case

Lawsuit relating to joint controllership and cookie consent obligations for social media fan pages (Federal Press and Information Office and Meta Platforms v The Federal Commissioner for Data Protection and Freedom of Information)

On 17 July 2025, the Administrative Court of Cologne annulled a data protection prohibition order issued by the Federal Commissioner for Data Protection and Freedom of Information against the German Federal Press Office regarding its Facebook fan page operation. The ruling affects social media operators and public sector entities, establishing that joint data protection responsibility under Article 26(1) of General Data Protection Regulation requires joint determination of both purposes and m...

Secondary evidenceNational StrategyIssuing institution: Issuing authority not identified
08 JUL 2025 · Court Case

VGH 3 S 1012/25; VG 2 K 1899/25

Fabricated: Case Law | Applicants cited a multitude of non-findable decisions and claimed higher-court jurisprudence that, as far as the court could see, does not exist; the court noted this and treated the complaint as lacking substantive engagement.

Court: VGH Baden-WürttembergParty: Lawyer
Secondary evidenceHarms: Hallucination in legal filingsIssuing institution: VGH Baden-Württemberg
02 JUL 2025 · Court Case

Cologne District Court, 312 F 130/25

Fabricated: Doctrinal Work | Court found citation to 'Viefhues' in a Munich commentary and marginal nos. (9th ed. 2021, marginal no. 65 ff.) to be incorrect and fictitious; actual commentary and edition details differ. || Fabricated: Doctrinal Work | Court could not locate the cited book 'Brons, Kindeswohl und Elternverantwortung, 2013, pp. 175 ff.' and determined the reference to be fictitious. || Fabricated: Doctrinal Work | Reference to 'Völkl, FamRB 2015, p. 74' was found to be incorrect/misleading; the actual FamRB 2015 pages cited contain a different essay (pp. 70-77) and the asserted citation is fictitious. || Fabricated: Doctrinal Work | Citation 'Meyer-Götz, in: Hauß/Gernhuber, Familienrecht, 6th ed. 2022, § 1671, marginal no. 33' was not found; court concluded the reference does not exist and appears conflated. || Fabricated: Case Law | Citation to an 'OLG Frankfurt' decision reported at 'FamRZ 2021, p. 70' was incorrect; the court determined the cited decision/reference was fictitious or mislocated.

Court: Cologne District Court (Family Court)Party: Lawyer
Secondary evidenceHarms: Hallucination in legal filingsIssuing institution: Cologne District Court (Family Court)
27 JUN 2025 · Law / Act

Data Protection Commissioner's assessment of Apple and Google's compliance with Digital Services Act concerning removal of DeepSeek AI following its classification as illegal

On 27 June 2025, the Berlin Commissioner for Data Protection and Freedom of Information, together with the Data Protection Commissioners of Baden-Württemberg, Rhineland-Palatinate, and the Free Hanseatic City of Bremen, formally notified Apple and Google in Germany that the artificial intelligence (AI) application DeepSeek constitutes illegal content. The authorities emphasised that the application unlawfully transfers large volumes of personal data from German users to servers in China witho...

Secondary evidenceContent ModerationIssuing institution: Issuing authority not identified
16 JUN 2025 · Standard / Framework

Conference of Independent Data Protection Supervisory Authorities of the Federal and State Governments Model Guidelines for procedures on imposing fines by the data protection supervisory authorities under GDPR

On 16 June 2025, the Conference of Independent Data Protection Supervisory Authorities of the Federal and State Governments (DSK) adopted the model guidelines for procedures on imposing fines by the data protection supervisory authorities (MRiDaVG), establishing standardised rules for conducting administrative fine proceedings under the General Data Protection Regulation (GDPR). The Guidelines define procedural principles, including the primacy of EU law, equivalence, and effectiveness, outli...

Secondary evidenceNational StrategyIssuing institution: Issuing authority not identified
16 JUN 2025 · Other

Conference of the Independent Data Protection Supervisory Authorities of the Federal and State Governments resolution addressing the interplay between data protection and security in the context of proposed reforms to German security laws

On 16 June 2025, the Conference of the Independent Data Protection Authorities of the Federal and State Governments (DSK) adopted a resolution addressing the interplay between data protection and security in the context of proposed reforms to German security laws. The resolution applies to public authorities involved in policing and data processing, emphasising that data protection is a fundamental element of democratic governance and not a barrier to effective law enforcement. It calls for p...

Secondary evidenceNational StrategyIssuing institution: Issuing authority not identified
16 JUN 2025 · Other

Conference of the Independent Data Protection Supervisory Authorities of the Federal and State Governments Resolution on confidential cloud computing

On 16 June 2025, the Conference of the Independent Data Protection Supervisory Authorities of the Federal and State Governments (DSK) adopted a Resolution on confidential cloud computing, addressing its technical and security implications. The resolution applies to cloud service providers and organisations processing sensitive or personal data using cloud infrastructure. It highlights that marketing claims about data being confidential often overlook the technical complexities involved. It hi...

Secondary evidenceNational StrategyIssuing institution: Issuing authority not identified
16 JUN 2025 · Other

Conference of the Independent Data Protection Supervisory Authorities of the Federal and State Governments resolution on data protection requirements for outsourcing appointment management in healthcare

On 16 June 2025, the Conference of the Independent Data Protection Authorities of the Federal and State Governments (DSK) adopted a resolution setting out data protection requirements for healthcare practices using external service providers for online appointment booking and management. It clarifies that outsourcing appointment management to external service providers is permissible as commissioned data processing under Article 28 of General Data Protection Regulation. It does not require p...

Secondary evidenceNational StrategyIssuing institution: Issuing authority not identified
16 JUN 2025 · Policy / Guidance

Berlin Data Protection Authority source on artificial intelligence governance

Official source record dated 16 June 2025 for DE concerning Conference of the Independent Data Protection Supervisory Authorities of the Federal and State Governments adopted guidance on recommended technical and organisational measures for the development and operation of artificial intelligence systems. See the linked datenschutz-berlin.de source for the authoritative text, procedural context, and implementation details.

Secondary evidenceData Privacy & ProtectionIssuing institution: Issuing authority not identified
12 JUN 2025 · Law / Act

Expansion of Federal Office for Information Security's powers in NIS 2 Implementation and Cybersecurity Strengthening Act

On 6 December 2025, the NIS 2 Implementation and Cybersecurity Strengthening Act including provisions expanding Federal Office for Information Security powers entered into force one day after its official publication. The Act introduces expansions to the powers of the Federal Office for Information Security (BSI). Pursuant to Section 3 of the Act on the Federal Office for Information Security and on the Security of Information Technology of Entities (BSIG), the BSI is tasked with promoting in...

Primary legal sourceNational StrategyOfficial source · recht.bund.de ↗
05 JUN 2025 · Other

Berlin Commissioner for Data Protection and Freedom of Information investigation into DeepSeek over alleged unlawful data transfers to China

On 6 May 2025, the Berlin Commissioner for Data Protection and Freedom of Information requested Hangzhou DeepSeek Artificial Intelligence to remove its DeepSeek AI chatbot apps from German app stores, cease illegal transfers of personal data to China, or meet the legal requirements for lawful third-country transfers. The Commissioner stated that the transfer of user data by DeepSeek to China is unlawful as the company failed to demonstrate that German user data is protected in China at a leve...

Secondary evidenceNational StrategyIssuing institution: Issuing authority not identified
01 JUN 2025 · Other

BSI guide on explainable Artificial Intelligence in an adversarial context

On 6 January 2025, the German Federal Office for Information Security (BSI) adopted a white paper serving as a guide addressing the explainability of artificial intelligence (AI) in adversarial contexts. The document focuses on the limitations of Explainable Artificial Intelligence (XAI), particularly post-hoc methods used to interpret black box AI models. The white paper identifies three challenges, namely the disagreement problem, manipulation risks, and fairwashing. Solutions to these prob...

Official materialNational StrategyOfficial source · bsi.bund.de ↗
27 MAY 2025 · Other

Hamburg Commissioner for Data Protection and Freedom of Information investigation into Meta over alleged training of Artificial Intelligence models with user data

On 27 May 2025, the Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI), in agreement with the German data protection supervisory authorities, decided against initiating provisional proceedings to prohibit Meta from training its Artificial Intelligence (AI) models using social network user data. The decision, which considered the final ruling by the Cologne Higher Regional Court issued on 23 May 2025, aims to ensure a consistent European approach among data protectio...

Secondary evidenceNational StrategyIssuing institution: Issuing authority not identified
23 MAY 2025 · Court Case

Lawsuit concerning use of data from publicly available user profiles for AI training (Consumer Advice Center NRW v Meta)

On 23 May 2025, the 15th Civil Senate of the Cologne Higher Regional Court rejected an application by the Consumer Advice Center NRW against Meta Platforms Ireland Limited in an expedited proceeding. The application sought to prevent Meta from using publicly made user data for artificial intelligence (AI) training, which was scheduled to begin on 27 May 2025. Following a preliminary review, the Court determined that Meta had not violated provisions of the General Data Protection Regulation (G...

Secondary evidenceNational StrategyIssuing institution: Issuing authority not identified
23 MAY 2025 · Court Case

Cologne Higher Regional Court issued a decision finding Meta’s use of public user data for AI training compliant with GDPR and DMA

On 23 May 2025, the 15th Civil Senate of the Cologne Higher Regional Court rejected an application by the Consumer Advice Center NRW against Meta Platforms Ireland Limited in an expedited proceeding. The application sought to prevent Meta from using publicly made user data for artificial intelligence (AI) training, which was scheduled to begin on 27 May 2025. Following a preliminary review, the Court determined that Meta had not violated provisions of the General Data Protection Regulation (GDPR

Secondary evidenceData Privacy & ProtectionIssuing institution: Issuing authority not identified
12 MAY 2025 · Standard / Framework

Guideline on data protection in medical research

On 5 December 2025, the Hessian Commissioner for Data Protection and Freedom of Information (HBDI) adopted the guideline on data protection in medical research. The guideline sets out the legal bases for processing health data in a medical research context and discusses a number of specific case studies. The HBDI drew the guideline up together with the German Society of Internal Medicine (DGIM).

Secondary evidenceNational StrategyIssuing institution: Issuing authority not identified
29 APR 2025 · Standard / Framework

Hamburg Commissioner for Data Protection guidelines on European Data Act

On 29 April 2025, the Hamburg Commissioner for Data Protection (HmbBfDI) published guidelines clarifying the provisions and obligations under the European Data Act. The guidelines outline the regulatory framework for data access and use across various sectors in Germany, with a focus on the management of non-personal data. It sets out the responsibilities of entities handling such data and explains the mechanisms for facilitating access rights and ensuring compliance. The guidelines also note...

Secondary evidenceNational StrategyIssuing institution: Issuing authority not identified