Search
Contact
04.07.2017 | KPMG Law Insights

There is no turning back. The new GDPR applies. – New data protection law approved by cabinet

New data protection law approved by cabinet

On February 1, 2017, the German Federal Cabinet approved a new draft law for the adaptation and restructuring of German data protection law. The “Data Protection Adaptation and Implementation Act” (DSAnpUG-EU) is necessary to adapt German data protection regulations to the European Data Protection Directive for Police and Justice and to the requirements of the new EU General Data Protection Regulation (EU GDPR). The EU GDPR aims to create a unified data protection law and thus largely the same standards for handling personal data within the EU. Nevertheless, it opens up scope for national regulations in the member states with a large number of opening clauses.

What does the new law regulate?

The DSAnpUG-EU represents a comprehensive reform and restructuring of German data protection law. The focus of the redesign is the comprehensive revision of the current Federal Data Protection Act (BDSG), which is intended to supplement and concretize the EU GDPR that will apply in Germany from May 2018. The 85-paragraph law presented in the draft is much more comprehensive than the previous BDSG. The underlying regulation is directly applicable as a European regulation. However, it is supplemented by the new BDSG. As a result, companies will have to comply with both sets of rules in the future. In addition, there are sector-specific regulations in specialized laws, which must also be within the framework of the EU GDPR regulations that have priority.

Criticism from experts and data protection authorities

The draft of the DSAnpUG-EU adopted by the Federal Cabinet is – like the previous drafts – in part considered to be contrary to European law and misguided. Many opening clauses are repeated in the draft of the new BDSG, which lacks the necessary concretizing regulation. In addition, the room for maneuver granted to the member states is being overstretched in some cases, so that regulations are being created that are not covered by the opening clauses of the EU GDPR. For example, the German supervisory authorities criticize that the rights of data subjects in particular would be unduly restricted. Overall, this would jeopardize the intended harmonization of data protection law in the EU and unlawfully lower the level of data protection provided for by the EU GDPR. Due to the many exceptions and references in the draft of the DSAnpUG-EU, an opaque thicket had been created especially for companies subject to German law. This would make the application of the new data protection law considerably more difficult and thus counteract the EU’s efforts to standardize and simplify data protection law for companies throughout Europe.

Finally, the draft in its current form leaves open the extent to which additional regulations are necessary with regard to the numerous sector-specific data protection provisions in Germany. Accordingly, there is a risk of an inconsistent data protection structure in Germany with partly contradictory regulations. The legal practitioners are simply overwhelmed with this situation and considerable legal uncertainty is created by the draft law.

Outlook

It remains to be seen in what concrete form the draft will actually be promulgated as law after the vote in the Bundestag and Bundesrat and whether the points of criticism raised will be taken into account. In any case, companies are advised to keep a close eye on the legislative process and deal with the largest data protection reform in Europe now, otherwise they will face severe fines of up to EUR 20 million or 4% of the previous year’s global turnover as of May 25, 2018. On March 10, the Federal Council is expected to discuss the new law.

Services of KPMG Law

Our team of highly specialized attorneys advises international and national corporations, small and medium-sized enterprises, public corporations, as well as financial investors and start-ups comprehensively in the area of information management (data protection and IT security), especially in the identification, analysis and evaluation of existing legal documentation and internal processes for handling personal data (“Privacy Impairment Check”) as well as their optimization.

In addition, we provide creative advice on the introduction of information and data management in compliance with data protection requirements, as well as on the development and market launch of products (“Privacy by Design”).

Of course, we also advise you on an ad hoc basis in internal or external investigation proceedings, e.g. following a “data loss incident” in the event of a crisis, and represent you in all official or court proceedings (legal representation). Feel free to contact us at any time about our consulting services!

Explore #more

23.03.2026 | Deal Notifications

KPMG Law, KPMG Law AT as well as KPMG in Germany and KPMG in Austria advise GOLDBECK GmbH on the acquisition of 50 percent of the shares in ZAUNERGROUP Holding GmbH

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) and Buchberger Ettmayer Rechtsanwälte GmbH (KPMG Law AT) as well as KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG in Germany) and KPMG…

19.03.2026 | KPMG Law Insights

Business Judgement Rule in the use of AI: how governing bodies are liable for decisions

If an AI provides the basis for business decisions, the people responsible are liable, not the machine. This makes the use of artificial intelligence risky…

16.03.2026 | KPMG Law Insights

KPIs in the legal department: How legal becomes strategically effective through control, transparency and data analysis

Today, legal departments are facing a strategic turning point: they must reliably hedge risks, but at the same time enable speed, control costs and make…

13.03.2026 | KPMG Law Insights

Commercial courts: when they are worthwhile for companies – and when they are not

Large commercial disputes are given courts specially tailored to their needs: the Commercial Courts. The German legislator introduced it with the Act to Strengthen the

10.03.2026 | Deal Notifications

KPMG Law advises on the sale of Krasemann Hausverwaltung to Buena

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) provided legal advice to the KRASEMANN family on the sale of KRASEMANN Immobilien- & Gebäudeservice GmbH (KIGS) and KRASEMANN…

09.03.2026 | KPMG Law Insights

MiCAR and whitepaper obligations – what the transitional regulations mean

The Markets in Crypto-Assets Regulation (MiCAR) has been in force for just over a year. Among other things, MiCAR obliges issuers and providers of crypto…

09.03.2026 | In the media

Guest article in Private Banking Magazine: What tokenized banknotes mean in day-to-day treasury operations

The future of payment transactions will be shaped not by new currencies, but by new processing models. A practical report by Marc Pussar (KPMG Law),…

06.03.2026 | In the media

Guest article in smartlegalmarket: Trends for legal departments in 2026 & 2027

KPMG Law has been surveying international legal departments on their challenges for more than ten years. The “Right to Progress” report is now regarded as…

06.03.2026 | KPMG Law Insights

Carve-out: The biggest risks and how the legal workstream avoids them

A carve-out does not usually fail due to a lack of ideas. And not due to a lack of buyers. Nor do they usually fail…

04.03.2026 | In the media

KPMG Law expert with statement in dpn magazine on the Location Promotion Act

Shortly after coming into force, the Location Promotion Act is apparently already having a noticeable effect on the investment plans of institutional market participants. In…

© 2026 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll