Anyone who processes personal data must contact the relevant data protection authority in case of doubt. For companies with multiple locations, this is not always easy, as interpretations of the GDPR can vary from state to state. A planned reform aims to consolidate responsibilities under the Federal Commissioner for Data Protection and Freedom of Information (BfDI) and thereby create more uniform rules.
Who oversees companies today?
Data protection oversight in Germany is organized on a federal basis. For most private companies, the data protection authorities of the federal states generally have jurisdiction. The determining factor is usually where the company or its principal place of business is located.
If a company operates multiple branches, a single lead authority is typically responsible. However, other state authorities may be involved, for example, if data processing affects employees or customers in multiple federal states.
The BfDI currently oversees primarily federal government agencies. In addition, the federal authority is specifically responsible for certain telecommunications and postal service providers. For ordinary commercial, industrial, or service companies, however, oversight has so far generally been the responsibility of the states.
What role does the Data Protection Conference play?
The Data Protection Conference (DSK) brings together the federal and state data protection authorities. Among other things, it publishes resolutions, guidelines, and joint statements.
These documents help companies comply with the GDPR. However, the DSK is not yet a unified federal authority. Its decisions do not replace laws or binding court rulings. Therefore, state authorities may continue to hold differing views or follow different enforcement practices on specific issues.
What should be bundled in the future?
The plan is to concentrate data protection oversight of the private sector more heavily within the BfDI. The goals are more consistent decisions, industry-specific guidance, and leaner oversight structures. The BfDI has stated that it is available to carry out such a consolidation.
In addition, the DSK is to be enshrined in law. This would provide a clearer legal basis for its responsibilities, procedures, and common standards. However, it remains to be seen exactly how responsibilities will be divided between the federal government and the states, and which areas will remain under the jurisdiction of state authorities.
Centralization is, in principle, possible under Article 51 of the GDPR. The Regulation expressly permits Member States to establish one or more independent supervisory authorities. According to a study by the Scientific Services of the Bundestag, consolidating oversight of the private sector at the federal level is, in principle, legally feasible.
What improvements would this bring for companies?
Companies with locations in multiple federal states could benefit particularly. A central authority could establish a single point of contact, more comparable review procedures, and clearer guidelines. Data breach notifications could also potentially be submitted through a single channel.
To date, it has been the case that supervisory authorities may interpret individual GDPR issues differently. This applies, for example, to tracking technologies, employee data, retention periods, or the requirements for certain types of consent. A more standardized supervisory approach could provide greater planning and legal certainty in this area.
What risks should be considered?
A centralized supervisory authority is not automatically faster or more practical. The BfDI would need to have sufficient staff, expertise, and regional reach. Otherwise, this could result in longer proceedings or an excessive distance from smaller companies. Furthermore, the existing industry knowledge and advisory structures of the state authorities should not be lost.
More Consistent Oversight Creates Opportunities
The planned consolidation could bring significant benefits, particularly for companies that operate across multiple locations. Consistent interpretations and clear reporting channels would simplify data protection management. However, until any legislative changes take effect, the current division of responsibilities will remain in place.
Does the BfDI already have jurisdiction over all companies?
No. Most private companies are currently under the jurisdiction of the state data protection authorities.
Will there be only one data protection authority in the future?
That is not mandatory. The main plan is to consolidate certain responsibilities within the BfDI. The exact division of responsibilities has not yet been determined.
Are DSK decisions binding on companies?
They serve as important guidelines, but they are not laws. Binding decisions are made primarily by the competent authorities and courts.
Do companies need to make changes now?
No. Until legislative reform takes place, the current responsibilities and reporting procedures will continue to apply.
Kostenloser Newsletter
Aktuelle Urteile, Praxistipps und neue Folgen aus Marken-, Urheber-, Medien- und Wettbewerbsrecht. Kompakt per E-Mail.
Double-Opt-in. Abmeldung jederzeit über den Link in jeder E-Mail.

