Bundesdatenschutzgesetz (BDSG)
Germany's federal data-protection act (BDSG of 30 June 2017, BGBl. I 2017, 2097), applying alongside the GDPR since 25 May 2018. Germany's data-protection landscape is split: the BDSG governs federal public bodies and private ("nichtöffentliche") bodies; schools are public bodies of the Länder, governed by each Land's Landesdatenschutzgesetz and Schulgesetz (§ 1(1), § 2). For an EdTech vendor this means: the vendor's own processing sits under GDPR + BDSG; the school customer's processing sits under GDPR + Land law — both sides of one contract answer to different German statutes.
Fact documents in this folder are in German (the authentic text); this README is curation.
Applicability to EdTech
- The vendor is a "nichtöffentliche Stelle" (§ 2(4)); the BDSG applies to its wholly or partly automated processing (§ 1(1) sentence 2), with the extraterritorial reach in § 1(4).
- Supervision of private bodies is by the Land data-protection authorities (§ 40(1)) — the competent authority follows the establishment, so a German subsidiary's Land determines the regulator (the LfDI/LDA of that Land).
- Special-category data (health, biometrics — headset eye/interaction data can qualify) is governed by the § 22 opening clause to GDPR Art. 9, with mandatory "angemessene und spezifische Maßnahmen" under § 22(2).
- Employee data (teacher accounts processed as HR-adjacent data in B2B contexts) falls under § 26.
- Children's consent age: the BDSG contains no derogation from GDPR Art. 8(1), so the EU default of 16 applies in Germany for information-society services offered directly to a child — a key operational difference from the UK's 13. (Assertion of absence: checked against the full consolidated act, XML build 2026-07-13; the GDPR default is at Art. 8.)
- School-side rules (what a Schulleitung may lawfully hand to a vendor) live in the Länder instruments, tracked in the TODO Germany entry with the subscriber split: NI 28 · BY 26 · NW 23 · BW 13 · SH 12 · SN 11 · HE 10 · …
Contents
| Document | Covers |
|---|---|
| SCOPE-AND-DEFINITIONS.md | §§ 1–2 — Anwendungsbereich, Begriffsbestimmungen |
| PROCESSING-PROVISIONS.md | §§ 22, 26 — besondere Kategorien, Beschäftigtendaten |
| SUPERVISION.md | § 40 — Aufsichtsbehörden der Länder |
Scope note: the accreditation/certification, DPO (§§ 5–7, 38), video surveillance (§ 4), scoring (§ 31), penal (§§ 41–43) and Teil 3 (JI-Richtlinie) provisions can be added with the same tooling when needed.
Key obligations at a glance
- Special-category processing only within the § 22(1) grounds and with the § 22(2) safeguards catalogue (encryption, pseudonymisation, access restrictions, DPO involvement, …).
- Employee-context processing per § 26, including the consent-voluntariness factors in § 26(2).
Enforcement
Land data-protection authorities for private bodies (§ 40); GDPR Art. 83 fines apply directly (the BDSG's own §§ 41–43 add procedure and criminal provisions, not extracted). The BfDI supervises federal public bodies and telecoms — not the typical EdTech vendor.
Related
- EU GDPR — the BDSG concretises and supplements it; Art. 8's 16-year default applies unmodified in Germany
- Länder school/data-protection instruments — pending per the TODO Germany plan (NI → BY → NW → …)
Sources
- gesetze-im-internet.de — BDSG, consolidated text
- BfDI — Bundesbeauftragter für den Datenschutz und die Informationsfreiheit
- DSK — Datenschutzkonferenz (joint position papers of the German DPAs)
Meta
Statute text in the content documents is reproduced verbatim in German from the gesetze-im-internet.de norm XML (build 2026-07-13) and built/re-verified mechanically by tools/gesetze-im-internet/build_de_bdsg.py (verify mode; do not hand-edit statute text). gesetze-im-internet.de provides no per-provision fragment ids, so anchors are derived from the printed labels ({#p22-1-1-a} = § 22 Abs. 1 Nr. 1 Buchst. a). The children's-age statement is an assertion of statutory absence, checked against the full act at the stated build — re-check on each rebuild.