The Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) is Germany’s federal data protection commissioner. Established in 1978, the BfDI supervises the federal public sector, telecommunications, and postal services. Private-sector processing, including all commercial email marketing, is enforced by sixteen state data protection authorities (Landesdatenschutzbehörden), one per Bundesland. The result is the most fragmented but also one of the strictest enforcement regimes in the EU, with Germany’s strict opt-in doctrine and combined GDPR + UWG + TDDDG stack raising the compliance bar significantly higher than the base EU standard.
Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) · Established 1978 under the original Bundesdatenschutzgesetz · Currently held by Louisa Specht-Riemenschneider since September 2024 · Based at Graurheindorfer Straße 153, 53117 Bonn · Federal independent authority, supervised by the Bundestag · Enforces GDPR at federal level, plus BDSG (Federal Data Protection Act 2018), UWG (Act Against Unfair Competition), and TDDDG (Telecommunications-Telemedia-Data-Protection Act, 2021) for telecom-adjacent processing · Private-sector processing enforced by 16 state DPAs. Max fine: €20M or 4% of global annual turnover.
The federal + state structure
Germany’s data protection enforcement is genuinely federal. The BfDI’s jurisdiction is limited to the federal public sector, telecommunications carriers, and postal service providers. Every private-sector commercial email is enforced by the state DPA of the sender’s registered office (or, for foreign senders, the state where the recipient sits). The 16 state DPAs coordinate through the Datenschutzkonferenz (DSK), which issues joint positions and coordinated enforcement actions, but each retains full independent sanctions power up to the GDPR ceiling.
- Baden-Württemberg (LfDI Baden-Württemberg), based in Stuttgart, known for early GDPR enforcement including the €1.24M against a police union.
- Bayern (BayLDA), based in Ansbach, active on cookie consent and adtech.
- Berlin (BlnBDI), based in Berlin, home to the Deutsche Wohnen €14.5M sanction.
- Hamburg (HmbBfDI), based in Hamburg, lead for many multinational tech companies with German HQ in the city.
- Nordrhein-Westfalen (LDI NRW), based in Düsseldorf, oversees Germany’s largest state and many major corporate headquarters.
- Plus eleven more: Brandenburg, Bremen, Hessen, Mecklenburg-Vorpommern, Niedersachsen, Rheinland-Pfalz, Saarland, Sachsen, Sachsen-Anhalt, Schleswig-Holstein, Thüringen.
The strict opt-in doctrine
Germany’s approach to email marketing consent is materially stricter than the EU baseline. Two features distinguish it:
- Double opt-in (DOI) is the practical standard. While not strictly required by statute, German case law and DSK guidance treat DOI as the default. A single-opt-in signup without email confirmation carries a significant burden of proof if consent is later challenged, and courts routinely disregard single-opt-in evidence as insufficient.
- UWG § 7(2) treats unsolicited commercial email as an unfair commercial practice. This adds a private right of action alongside the GDPR administrative enforcement. Competitors, consumer associations, and industry groups can bring cease-and-desist actions with statutory damages, creating a parallel enforcement track outside the state DPAs.
Recent enforcement highlights
2026 enforcement priorities
Cross-DPA coordination through DSK. The Datenschutzkonferenz’s 2026 priority topics include AI training data lawfulness (with BfDI leading on generative AI regulation in coordination with EU AI Act), employee monitoring (following notebooksbilliger.de and Amazon warehouse cases), and TDDDG-based cookie enforcement now that the transitional regime has ended. State DPAs are expected to follow the CNIL and Garante recommendations on email tracking pixels, though no unified German deadline has been announced. UWG-based private enforcement continues to dominate B2B email risk: German courts issued over 2,500 cease-and-desist orders in 2024 for unsolicited B2B email.
How to file a complaint
- Identify the responsible DPA. For federal public sector and telecommunications carriers, file with the BfDI at bfdi.bund.de. For private-sector commercial email, file with the state DPA of the sender’s registered office.
- The BfDI accepts complaints in German, English, French, and several other languages via a web form or by post. State DPAs vary; most accept English but process in German.
- For B2B email violations, consider the parallel UWG track through a specialised law firm or consumer association. UWG cease-and-desist letters typically resolve within 2 to 4 weeks and produce statutory damages plus legal cost recovery.
- Cross-border cases involving non-German controllers are routed to the lead supervisory authority through the GDPR one-stop-shop.
- Decisions from the BfDI and state DPAs are published (bfdi.bund.de and each state DPA website), typically in German only with occasional English summaries for high-profile cases.
Common misconceptions
“The BfDI is the only German DPA that matters.” No. The BfDI’s jurisdiction is limited to federal public sector, telecom carriers, and postal services. For every private-sector marketing campaign, the state DPA is the enforcer. Getting the state right is essential, complaints filed with the wrong DPA cause administrative delay, not automatic transfer.
“Single opt-in is fine because GDPR does not require double opt-in.” Technically correct on GDPR text; practically wrong in Germany. German case law places the burden of proving valid consent on the sender, and single-opt-in evidence is regularly dismissed by courts. DOI is the practical standard.
“UWG only applies to sellers in the same market.” No. Any competitor, industry association, or consumer protection body can bring a UWG cease-and-desist action. Practical experience shows that unsolicited B2B email in Germany often triggers a UWG letter within days from a competitor’s lawyer, independent of any state DPA action.
“Consent from one German subsidiary covers the whole EU.” No. Consent must be granular and cover each purpose, each controller, and each recipient. Corporate group sharing without granular consent has been repeatedly penalised, particularly by the Berlin, Hamburg, and Baden-Württemberg state DPAs.
Frequently asked questions
Which German DPA has jurisdiction over my company?
For private-sector processing, the DPA of the state (Bundesland) where the controller has its registered office. For controllers established outside Germany with no German office, the DPA of the state where the affected data subjects reside. For public federal bodies, telecom carriers, and postal service providers, the BfDI.
What is a UWG cease-and-desist letter and how does it work?
Under UWG (Gesetz gegen den unlauteren Wettbewerb) Section 7(2), unsolicited commercial email is an “unreasonable harassment” per se. Any competitor or qualified association can file an Unterlassungsklage (cease-and-desist action) seeking an injunction, statutory damages, and reimbursement of legal costs. Typical outcome: a signed Unterlassungserklärung (cease-and-desist declaration) with a contractual penalty of €5,000 to €10,000 per further violation.
Does Germany’s TDDDG add anything beyond GDPR?
Yes. TDDDG (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, in force since December 2021) transposes the ePrivacy Directive Article 5(3) into German law. It requires prior consent for cookies, pixels, and equivalent storage-access technologies, regardless of whether personal data is involved. TDDDG applies to any digital service accessed from Germany.
How does Germany interpret the soft opt-in exception?
Narrowly. UWG § 7(3) permits marketing to existing customers for the same or very similar products, provided the address was collected during a purchase, the customer was informed of the marketing use, and every subsequent message includes an opt-out. German courts interpret “very similar products” strictly, cross-selling to a different product line typically falls outside the exception and requires fresh consent.
Where can I find German DPA guidance in English?
The BfDI publishes English-language annual reports and selected guidance at bfdi.bund.de/EN. State DPAs vary: Baden-Württemberg, Berlin, and Hamburg maintain partial English translations. For unified DSK positions, the datenschutzkonferenz-online.de site publishes German-only material; third-party translations are available through gdprhub.eu and law firm alerts.
Where to go next
- GDPR compliance guide, the underlying regulation the BfDI and state DPAs enforce
- CNIL (France), centralised peer with comparable strict-consent doctrine
- DSB (Austria), German-speaking peer with similar UWG-style private enforcement
- AEPD (Spain), centralised peer with the highest EU decision volume
Sending marketing email into Germany? Pre-validating recipient addresses with SMTPing before you press send catches disposables, catch-alls, and dead mailboxes that generate DPA complaints and UWG cease-and-desist letters. Thirteen validation types, twenty-five free checks daily, no card required. Try SMTPing free.
About the Author

Alaa · LinkedIn
Email infrastructure specialist with 8+ years of hands-on experience in SMTP, deliverability, and email verification. I’ve configured and troubleshot mail systems across Postfix, Exchange, and cloud relays, managed IP reputation and warmup campaigns, and built verification pipelines processing millions of addresses. My work spans DNS authentication (SPF, DKIM, DMARC, BIMI), bounce handling, blocklist monitoring, and compliance frameworks including CAN-SPAM and GDPR. I write every article on SMTPedia to give email professionals, developers, and marketers the accurate, RFC-grounded reference they need.
About SMTPedia
SMTPedia is an independent email industry reference covering SMTP, IMAP, POP3, email deliverability, marketing platforms, DNS authentication, and email verification. Every article is researched from official provider documentation, IETF RFCs, and industry best practices. Settings and configurations are verified quarterly.
We are cited as a source by ChatGPT, Microsoft Copilot, and thousands of email professionals worldwide. Learn more about our editorial process.

