Germany does not have one data-protection regulator — it has seventeen. The BfDI is the federal one, and it is smaller in reach than its prominence suggests: it polices the federal government and the telecom and postal sector, while the everyday business of supervising companies falls to 16 state authorities. If you assumed “the German DPA” was a single body that fines Meta or your local shop, this profile explains why that is not how Germany works. Every fact is sourced.
Quick facts
- Full name: Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) — Federal Commissioner for Data Protection and Freedom of Information
- What it supervises: German federal public bodies (federal ministries and agencies, the federal police, the BKA, the intelligence services) plus telecommunications and postal service providers — not the general private sector
- Two mandates: data protection and freedom of information (access to federal documents) — a dual role, like Estonia’s AKI
- Governing law: the GDPR plus Germany’s federal data-protection act, the Bundesdatenschutzgesetz (BDSG) (gesetze-im-internet.de)
- Commissioner: Prof. Dr. Louisa Specht-Riemenschneider — in office since 3 September 2024, succeeding Ulrich Kelber; on 17 March 2026 she announced she will step down for health reasons once a successor is appointed, remaining in office until then (BfDI)
- Term: five years, renewable once
- Headquarters: Bonn
- Website: bfdi.bund.de
What the BfDI is — and Germany’s two-tier system
This is the single most misunderstood thing about German data protection. There is no one “German DPA”. Responsibility is split:
- The BfDI — the federal commissioner — supervises federal public bodies and the telecom and postal sector.
- 16 Länder (state) authorities — one per federal state (Bavaria, North Rhine-Westphalia, Hamburg, etc.) — supervise the private sector (companies) and state-level public bodies in their territory.
So when a company is fined under GDPR in Germany, it is almost always a state authority acting, not the BfDI. The big cross-border tech cases against US firms generally run through Ireland’s DPC under the one-stop-shop, not through any German regulator. The BfDI’s domain is the federal state apparatus and the communications sector.
The federal and state authorities coordinate through the Datenschutzkonferenz (DSK) — the conference of all German data-protection authorities — which issues common positions so that the seventeen do not contradict each other.
What the BfDI actually does
Within its federal and telecom remit, the BfDI:
- supervises and investigates federal bodies — including security-sensitive ones such as the BKA (Federal Criminal Police Office) and the intelligence services — and can issue complaints and corrective measures under the BDSG
- handles complaints from individuals against federal bodies and telecom/postal providers
- oversees freedom of information — the right of access to federal documents, the transparency half of its dual mandate
- represents Germany in the EDPB and the DSK, shaping common German and EU positions
Leadership
The Commissioner is elected by the Bundestag (the federal parliament) and appointed for a five-year term, renewable once, with independence guaranteed.
- Current Commissioner: Prof. Dr. Louisa Specht-Riemenschneider. A professor of civil and data law (University of Bonn), she was elected by the Bundestag in May 2024 and took office on 3 September 2024, succeeding Ulrich Kelber. On 17 March 2026 she announced she would step down for health reasons — but stressed the office “must not remain vacant”, so she stays in post until a successor is appointed (BfDI). As of June 2026 the succession is in transition — verify the current office-holder against the BfDI site before citing.
A note on the AI Act
When Germany set up its AI Act supervision, the BfDI was deliberately excluded from the lead role. Under the German implementation draft (KI-MIG), the Federal Network Agency (BNetzA) is the main market-surveillance authority and EU single point of contact — not the BfDI. The data-protection commissioner keeps its GDPR remit; AI market surveillance sits elsewhere. See our news on Germany’s KI-MIG and the AI Act pillar.
What this means for you
- If you run a company processing data in Germany: your supervisory authority is almost certainly the state DPA where you are established — not the BfDI. Identify your Land’s authority.
- If you deal with a federal body or a telecom/postal provider: complaints about how they handle your data go to the BfDI.
- If you track EU enforcement: German GDPR fines on companies come from the state authorities; the BfDI’s enforcement targets the federal administration and the communications sector. Don’t expect Big-Tech fines from this office.
TL;DR
The BfDI is Germany’s federal data-protection commissioner — it supervises federal public bodies and the telecom/postal sector, with a second mandate over freedom of information, under the GDPR and the BDSG. It is not Germany’s all-purpose DPA: companies and state bodies are supervised by 16 state authorities, coordinated with the BfDI through the DSK. Seat in Bonn, led by Prof. Dr. Louisa Specht-Riemenschneider (in office since 3 September 2024), who announced on 17 March 2026 that she will step down for health reasons once a successor is appointed. For AI Act market surveillance, Germany chose the Federal Network Agency (BNetzA), not the BfDI.
Sources
- BfDI — Commissioner announces withdrawal (17 March 2026) — health reasons, stays until successor appointed
- BfDI 34th Activity Report 2025 — federal supervision, BDSG application
- Bundesdatenschutzgesetz (BDSG) — gesetze-im-internet.de — Germany’s federal data-protection act
- bfdi.bund.de — official site
- Related: GDPR pillar · EDPB profile · Germany’s KI-MIG (news)