← Regulators
GDPR EU 2016/679 Germany

Who is the BfDI: Germany's federal data protection commissioner

The BfDI is Germany's federal data-protection regulator — but it supervises only federal bodies and the telecom and postal sector. The rest is handled by 16 state authorities. What the BfDI does, how Germany's two-tier system works, and who runs it. Every fact sourced.

Germany does not have one data-protection regulator — it has seventeen. The BfDI is the federal one, and it is smaller in reach than its prominence suggests: it polices the federal government and the telecom and postal sector, while the everyday business of supervising companies falls to 16 state authorities. If you assumed “the German DPA” was a single body that fines Meta or your local shop, this profile explains why that is not how Germany works. Every fact is sourced.

Quick facts

  • Full name: Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) — Federal Commissioner for Data Protection and Freedom of Information
  • What it supervises: German federal public bodies (federal ministries and agencies, the federal police, the BKA, the intelligence services) plus telecommunications and postal service providers — not the general private sector
  • Two mandates: data protection and freedom of information (access to federal documents) — a dual role, like Estonia’s AKI
  • Governing law: the GDPR plus Germany’s federal data-protection act, the Bundesdatenschutzgesetz (BDSG) (gesetze-im-internet.de)
  • Commissioner: Prof. Dr. Louisa Specht-Riemenschneider — in office since 3 September 2024, succeeding Ulrich Kelber; on 17 March 2026 she announced she will step down for health reasons once a successor is appointed, remaining in office until then (BfDI)
  • Term: five years, renewable once
  • Headquarters: Bonn
  • Website: bfdi.bund.de

What the BfDI is — and Germany’s two-tier system

This is the single most misunderstood thing about German data protection. There is no one “German DPA”. Responsibility is split:

  • The BfDI — the federal commissioner — supervises federal public bodies and the telecom and postal sector.
  • 16 Länder (state) authorities — one per federal state (Bavaria, North Rhine-Westphalia, Hamburg, etc.) — supervise the private sector (companies) and state-level public bodies in their territory.

So when a company is fined under GDPR in Germany, it is almost always a state authority acting, not the BfDI. The big cross-border tech cases against US firms generally run through Ireland’s DPC under the one-stop-shop, not through any German regulator. The BfDI’s domain is the federal state apparatus and the communications sector.

The federal and state authorities coordinate through the Datenschutzkonferenz (DSK) — the conference of all German data-protection authorities — which issues common positions so that the seventeen do not contradict each other.

What the BfDI actually does

Within its federal and telecom remit, the BfDI:

  • supervises and investigates federal bodies — including security-sensitive ones such as the BKA (Federal Criminal Police Office) and the intelligence services — and can issue complaints and corrective measures under the BDSG
  • handles complaints from individuals against federal bodies and telecom/postal providers
  • oversees freedom of information — the right of access to federal documents, the transparency half of its dual mandate
  • represents Germany in the EDPB and the DSK, shaping common German and EU positions

Leadership

The Commissioner is elected by the Bundestag (the federal parliament) and appointed for a five-year term, renewable once, with independence guaranteed.

  • Current Commissioner: Prof. Dr. Louisa Specht-Riemenschneider. A professor of civil and data law (University of Bonn), she was elected by the Bundestag in May 2024 and took office on 3 September 2024, succeeding Ulrich Kelber. On 17 March 2026 she announced she would step down for health reasons — but stressed the office “must not remain vacant”, so she stays in post until a successor is appointed (BfDI). As of June 2026 the succession is in transition — verify the current office-holder against the BfDI site before citing.

A note on the AI Act

When Germany set up its AI Act supervision, the BfDI was deliberately excluded from the lead role. Under the German implementation draft (KI-MIG), the Federal Network Agency (BNetzA) is the main market-surveillance authority and EU single point of contact — not the BfDI. The data-protection commissioner keeps its GDPR remit; AI market surveillance sits elsewhere. See our news on Germany’s KI-MIG and the AI Act pillar.

What this means for you

  • If you run a company processing data in Germany: your supervisory authority is almost certainly the state DPA where you are established — not the BfDI. Identify your Land’s authority.
  • If you deal with a federal body or a telecom/postal provider: complaints about how they handle your data go to the BfDI.
  • If you track EU enforcement: German GDPR fines on companies come from the state authorities; the BfDI’s enforcement targets the federal administration and the communications sector. Don’t expect Big-Tech fines from this office.

TL;DR

The BfDI is Germany’s federal data-protection commissioner — it supervises federal public bodies and the telecom/postal sector, with a second mandate over freedom of information, under the GDPR and the BDSG. It is not Germany’s all-purpose DPA: companies and state bodies are supervised by 16 state authorities, coordinated with the BfDI through the DSK. Seat in Bonn, led by Prof. Dr. Louisa Specht-Riemenschneider (in office since 3 September 2024), who announced on 17 March 2026 that she will step down for health reasons once a successor is appointed. For AI Act market surveillance, Germany chose the Federal Network Agency (BNetzA), not the BfDI.

Sources