German RoPA Compliance

German Article 30 records with BDSG and DSK context.

Extend the core RoPA workflow with German-specific fields, deletion concepts, DSK-categorised TOMs, works council tracking, compliance scoring and a Verzeichnis export for supervisory review.

Acompli German RoPA Compliance Brochure — page 1
View brochure

Article 30 in Germany

What are the RoPA requirements in Germany?

Article 30 GDPR applies directly in Germany: controllers and processors must keep a record of processing activities — the Verzeichnis von Verarbeitungstätigkeiten — covering the purposes, data categories, recipients, transfers, retention periods and security measures set out in Article 30(1) and 30(2). Supervision sits with the BfDI (the federal data protection authority) and the 17 Landesdatenschutzbehörden — for most private companies, the state authority of the Land where the company is established is the competent supervisor.

The Bundesdatenschutzgesetz (BDSG) supplements the GDPR rather than replacing it, and section 70 BDSG mirrors the Article 30 record-keeping duty for specific processing contexts outside the GDPR’s direct scope. The obligation, the field lists, and the narrow Article 30(5) derogation are the same GDPR provisions that apply across the EU — read the Ireland & UK version of this guide for how the DPC and ICO apply them, or see the core Article 30 register for the underlying workflow.

Key takeaways

  • Article 30 GDPR applies directly — German entities maintain the Verzeichnis von Verarbeitungstätigkeiten to the same Article 30(1) and 30(2) field requirements as every EU controller and processor, with the BDSG supplementing the GDPR in specific contexts.
  • Supervision is federal and state-level — the BfDI at federal level and the 17 Landesdatenschutzbehörden across the Länder supervise compliance; most private companies answer to their state authority, and the authorities coordinate expectations through the Datenschutzkonferenz (DSK).
  • The Article 30(5) derogation is narrow — the under-250-employee carve-out falls away where processing is more than occasional, likely to risk data subjects’ rights, or includes Article 9 special categories, so most HR, marketing and customer processing carries the full duty.
  • Plan for two languages — German supervisory authorities and works councils generally expect German-language records while group privacy teams work in English; one jurisdiction-aware register with a German Verzeichnis export avoids maintaining parallel registers that drift apart.

Who supervises Article 30 RoPA compliance in Germany — the BfDI or a Landesdatenschutzbehörde?

Both, by remit. The BfDI supervises at federal level, and the 17 Landesdatenschutzbehörden supervise at state level — for most private companies, the data protection authority of the Land where the company is established is the competent supervisor and the body that would request the Verzeichnis von Verarbeitungstätigkeiten in an audit. The authorities coordinate their expectations through the Datenschutzkonferenz (DSK), whose Kurzpapiere set the form German reviewers expect. Acompli records the competent supervisory authority per legal entity, so a group with entities in several Länder, Ireland and the UK exports each register in the format its own authority — Landesdatenschutzbehörde, DPC or ICO — expects.

Can the Verzeichnis stay in German while the wider group works in English?

Yes — this is the dual-language reality for most DACH groups: the German entity's Verzeichnis, Löschkonzept and Betriebsrat documentation are generally expected in German by the competent Landesdatenschutzbehörde and the works council, while the group privacy team runs the register in English. Acompli holds one canonical Article 30 record set in which German entities carry the German-named overlay fields (Löschkonzept, Rechtsgrundlage, Betriebsrat) and export to the seven-sheet German Verzeichnis format, while Irish and UK entities export to DPC and ICO formats — so the German records and the English working view never diverge.

The German overlay

From jurisdiction detection to DPA-ready export

Each stage adds German-specific governance on top of the standard Article 30 register. Acompli's German overlay adapts the UI, AI extraction, validation, and export format — all from a single configuration.

StartDetect

German requirements applied through a jurisdiction overlay

Create an entity with jurisdiction DE or assign a German supervisory authority. The BDSG/DSK overlay activates — field visibility, requirement levels, AI guidance, and export format all update.

Organisations with entities in Germany, Ireland, and the UK see the correct requirements for each. Detection works from supervisory authority codes, ICO registration, or explicit jurisdiction assignment.

Supervisory authorityBfDI or Landesdatenschutzbehörde code activates the German overlay
Jurisdiction codeDE maps to BDSG/DSK, IE to DPC, GB to ICO — automatic per entity
AI extraction adaptsThe AI receives German-specific guidance and populates BDSG fields during extraction
No manual templatesNo template selection or configuration — jurisdiction drives everything
01Extend

Eight additional fields for German entities

Acompli adds eight structured fields on top of the standard Article 30 set. Each has a defined requirement level — mandatory, expected, or recommended — based on BDSG and DSK guidance.

Rechtsgrundlage (legal basis) is promoted to mandatory for German entities — including BDSG § 26 for employment data and § 22 for special categories. All fields are structured forms with defined components, so completeness is measurable.

LöschkonzeptStructured deletion rules — retention periods, legal bases, triggers, methods
TOMs (Art. 32 / DSK)Security controls by DSK category — confidentiality, integrity, availability, resilience
Betriebsrat (§87 BetrVG)Works council consultation status, date, and Betriebsvereinbarung reference
RechtsgrundlageExtended legal basis including BDSG § 26 and § 22 provisions
ZweckbindungPurpose limitation with compatibility assessment per Article 6(4)
Betroffenenrechte & MeldepflichtData subject rights procedures and breach notification path
DSFA-VerknüpfungLinks to associated DPIAs with risk assessment outcomes
Datenherkunft & RichtlinienData sources and linked internal policies with version tracking
02Löschkonzept

Structured deletion concept per processing activity

The Löschkonzept captures per-category deletion rules as a structured form — retention periods, legal bases, deletion triggers, methods, and verification. Each data category gets its own entry.

Teams define retention per category (e.g., 6 years post-employment for payroll per §257 HGB), the deletion method, who is responsible, and how deletion is verified. Incomplete entries are flagged as NICHT DOKUMENTIERT in the dashboard and export.

Löschkonzept — Personalverwaltung
OverviewComplete
Per-category rules4 categories
Retention periodsDefined
Legal basesLinked
Deletion triggersDefined
Deletion methodPartial
VerificationDefined
Last reviewed2026-03-15
Structured →Each component is a defined field — completeness is scored, gaps are flagged
03DSK TOMs

Security measures organised by the DSK framework

Article 32 technical and organisational measures are structured into five DSK categories — each with defined control areas. The platform maps your measures to this structure and flags coverage gaps.

Acompli supports framework references including ISO 27001 and BSI IT-Grundschutz, so teams can cross-reference existing certifications against DSK expectations.

Vertraulichkeit

Confidentiality

Access control, encryption, pseudonymisation, physical security, and data separation

Integrität

Integrity

Input control, transfer control, logging and monitoring

Verfügbarkeit

Availability

Backup, recovery, and business continuity measures

Belastbarkeit

Resilience

Capacity planning, stress testing, and failover procedures

Verfahren

Procedures

Incident response, vendor assessments, staff training, and formal testing

04Betriebsrat

Works council consultation tracking

For processing activities involving employee data, Acompli's register captures whether the Betriebsrat was consulted, the consultation date, and any Betriebsvereinbarung reference — per §87 BetrVG.

Activities that involve employee monitoring or performance evaluation without documented consultation are flagged in the compliance dashboard.

Consultation status

Ja / Nein / Nicht zutreffend — tracked per processing activity with date and contact.

Betriebsvereinbarung reference

Link to the applicable works council agreement (e.g., BV-2026-003).

Gap flagging

Activities requiring consultation without documented status are surfaced in the dashboard.

Consultation status
PendingConsultedApprovedN/A
05Score

Six-area compliance scoring for German entities

Acompli's dedicated German dashboard scores each processing activity across six areas. Completion percentages are visible at entity level and in the Deckblatt (cover sheet) of the export.

Three requirement tiers — mandatory, expected, and recommended — make it clear where to focus effort. The dashboard filters to German-jurisdiction entities with expandable activity rows showing all German-specific fields and status indicators.

Löschkonzept

Deletion concept

Per-category retention rules, deletion methods, and verification

TOMs

Security measures

DSK 5-category coverage with gap identification

Richtlinien

Policies

Internal policies linked, current, and version-controlled

Zweckbindung

Purpose limitation

Purpose-to-legal-basis linkage per processing activity

Betriebsrat

Works council

Consultation documented where required under §87 BetrVG

DSFA

DPIA linkage

Datenschutz-Folgenabschätzungen completed and linked

06Export

7-sheet Verzeichnis export in one click

Acompli's German export generates an enterprise-ready XLSX workbook with seven sheets — structured for supervisory authority review and ready to hand to an auditor without reformatting.

The Herkunftsnachweis sheet documents where each value came from — manually entered, imported, or AI-drafted and confirmed by your team — providing an auditable provenance trail.

Verzeichnis Export — 7 Sheets
1. DeckblattCover
2. VerarbeitungstätigkeitenRegister
3. LöschkonzeptDeletion
4. TOMs (Art. 32)Security
5. RichtlinienPolicies
6. BetriebsratCouncil
7. HerkunftsnachweisProvenance
Export →DPA-ready workbook with compliance summary, gap flags, and AI source provenance

German RoPA questions answered

How Acompli structures the Article 30 register for German (BDSG/DSK) requirements.

How should German firms compare RoPA tools for BDSG and Article 30?

Compare on five axes that BDSG/DSK-aligned reviewers actually test. (1) Article 30(1)/(2) field coverage with BDSG §26 (employment) and §22 (special categories) promoted to mandatory for German entities. (2) Structured Löschkonzept per data category with retention, legal basis, trigger, method and verification — not a free-text field. (3) DSK 5-category TOMs (Vertraulichkeit, Integrität, Verfügbarkeit, Belastbarkeit, Verfahren) with gap flagging against Article 32. (4) Betriebsrat consultation tracking per §87 BetrVG with Betriebsvereinbarung references. (5) A Verzeichnis export the BfDI or a Landesdatenschutzbehörde can read without reformatting. Tools that bolt German labels onto a generic Article 30 form fail the first DSK audit; jurisdiction-aware overlays that share one register across DE/IE/UK do not.

How should a German Löschkonzept be structured inside the Article 30 register?

Per the DSK Kurzpapier on Löschkonzepte, a defensible Löschkonzept is per data category, not per system or per activity. Each category needs: retention period with the source rule (for example payroll records 6 years post-employment per §257 HGB, tax records 10 years per §147 AO), the legal basis the retention rests on, the deletion trigger (event-based or time-based), the deletion method (overwrite, destruction, anonymisation), the responsible role, and how deletion is verified. Acompli captures each as a structured field on the Article 30 record so completeness is measurable and gaps surface in the DSK-aligned dashboard, rather than living in a Word annex the DPC, BfDI or a Landesdatenschutzbehörde cannot inspect.

How should DSK Article 32 TOMs be tracked in the register?

DSK guidance organises Article 32 measures into five categories: Vertraulichkeit (access control, encryption, pseudonymisation), Integrität (input/transfer control, logging), Verfügbarkeit (backup, recovery, continuity), Belastbarkeit (capacity, failover) and Verfahren (incident response, vendor management, training, testing). A register that records TOMs as free text loses gaps; one that requires a measure in each category, cross-references ISO 27001 or BSI IT-Grundschutz controls, and flags empty categories, gives the DSK reviewer what they expect. After the DPC €1.2bn Meta decision (2023) the bar for evidencing TOMs that protect transferred data has risen — record cross-border safeguards (SCCs, supplementary measures) at the TOM level too, not only in the transfer field.

Must Betriebsrat consultation be tracked at the processing-activity level?

Yes for any processing that touches employee behaviour or performance. §87(1) Nr. 6 BetrVG gives the Betriebsrat a co-determination right on technical devices that monitor employees, which extends to most HR analytics, time-tracking, productivity tooling, video surveillance and many cloud HR systems. A Verzeichnis that cannot prove which activities triggered Mitbestimmung, when consultation happened, and which Betriebsvereinbarung governs the activity, is not audit-ready. Acompli captures consultation status (Ja/Nein/Nicht zutreffend), date, contact, and Betriebsvereinbarung reference per processing activity, and flags employee-data activities that lack documented consultation.

Can one register cover German, Irish and UK entities without duplicating data?

Yes — jurisdiction should be an entity attribute, not a tenant. Acompli's jurisdiction overlay activates BDSG/DSK fields and the German export for DE entities, DPA 2018/DPC framing for IE, and UK GDPR/ICO framing for GB — from the same record set. A group with a DE GmbH, an IE Ltd and a UK Ltd holds one canonical Article 30 register; each entity sees only the fields its supervisory authority expects, and exports separately to BfDI/Landesdatenschutzbehörde, DPC and ICO formats. This avoids the common failure mode of three half-maintained Excel files diverging across the group.

More detailed questions
How should the register handle Schrems II international transfers from a German entity?

After Schrems II (CJEU C-311/18) and the DPC €1.2bn Meta decision (2023), every transfer outside the EEA needs more than a country code in the Article 30 record. Capture: the legal mechanism (adequacy, SCCs 2021, BCRs, Article 49 derogation), the supplementary measures applied (encryption at rest/in transit, key residency, access controls), the linked Transfer Impact Assessment, and the receiving party's onward-transfer commitments. Article 30(1)(e) requires identifying recipients in third countries and the safeguards; DSK and EDPB Recommendations 01/2020 set the substance. Acompli links each German processing activity to its TIA so the DSK reviewer can trace the safeguard chain from the Verzeichnis row in one click.

Market-specific questions

Deutsch

Wie vergleicht man RoPA-Tools für das deutsche Verzeichnis von Verarbeitungstätigkeiten?

Prüfen Sie fünf Achsen, die BDSG- und DSK-konform sind. (1) Vollständige Abdeckung der Felder nach Art. 30 Abs. 1 und 2 DSGVO, mit BDSG §26 (Beschäftigtendaten) und §22 (besondere Kategorien) als Pflichtfelder für deutsche Einheiten. (2) Strukturiertes Löschkonzept pro Datenkategorie mit Aufbewahrungsdauer, Rechtsgrundlage, Auslöser, Methode und Verifizierung — kein Freitextfeld. (3) TOMs nach DSK-Kategorien (Vertraulichkeit, Integrität, Verfügbarkeit, Belastbarkeit, Verfahren) mit Lückenkennzeichnung gegen Art. 32 DSGVO. (4) Betriebsratsbeteiligung gemäß §87 Abs. 1 Nr. 6 BetrVG mit Verweis auf die Betriebsvereinbarung. (5) Export im Verzeichnis-Format, das BfDI oder die zuständige Landesdatenschutzbehörde ohne Nacharbeit prüfen kann. Tools, die nur deutsche Labels auf ein generisches Art.-30-Formular setzen, scheitern in der ersten DSK-Prüfung.

Ist ein Verzeichnis von Verarbeitungstätigkeiten in Deutschland, Irland und Großbritannien gesetzlich vorgeschrieben?

Ja — Art. 30 DSGVO gilt in allen drei Jurisdiktionen mit nationalen Erweiterungen. In Deutschland prüfen BfDI und Landesdatenschutzbehörden gegen BDSG und DSK-Kurzpapier Nr. 1. In Irland gilt der Data Protection Act 2018, die DPC ist zuständig. In Großbritannien gelten UK GDPR und Data Protection Act 2018, die ICO ist zuständig. Die Ausnahme nach Art. 30 Abs. 5 DSGVO (unter 250 Beschäftigte) greift faktisch selten: Sie entfällt bei regelmäßiger Verarbeitung, bei Risiken für Betroffene oder bei besonderen Kategorien (Art. 9). HR, Marketing und B2B-Verarbeitungen fallen damit fast immer unter die volle Pflicht. Behandeln Sie die Ausnahme in der Praxis als nicht anwendbar.

Wie sollte ein Löschkonzept im Verzeichnis von Verarbeitungstätigkeiten strukturiert sein?

Nach dem DSK-Kurzpapier zum Löschkonzept wird je Datenkategorie dokumentiert — nicht je System oder Verarbeitungstätigkeit. Jede Kategorie braucht: Aufbewahrungsdauer mit Quelle (z. B. Lohnunterlagen 6 Jahre nach Beendigung nach §257 HGB, Steuerunterlagen 10 Jahre nach §147 AO), Rechtsgrundlage, Löschauslöser (ereignis- oder fristbasiert), Löschmethode (Überschreiben, Vernichtung, Anonymisierung), verantwortliche Rolle und Nachweis der Löschung. Acompli erfasst jeden dieser Punkte als strukturiertes Feld am Art.-30-Datensatz, sodass Vollständigkeit messbar ist und Lücken im DSK-Dashboard erscheinen — statt in einem Word-Anhang zu liegen, den die Aufsicht nicht prüfen kann.

Wie werden TOMs nach Art. 32 DSGVO im DSK-Schema im Verzeichnis erfasst?

Die DSK gliedert Art.-32-Maßnahmen in fünf Kategorien: Vertraulichkeit (Zugangs-, Zugriffs-, Weitergabekontrolle, Verschlüsselung, Pseudonymisierung), Integrität (Eingabe- und Übertragungskontrolle, Protokollierung), Verfügbarkeit (Backup, Wiederherstellung, Notfallmanagement), Belastbarkeit (Kapazität, Failover) und Verfahren (Incident Response, Auftragsverarbeiter-Audit, Schulung, Tests). Ein Verzeichnis, das TOMs als Freitext führt, verliert Lücken; eines, das eine Maßnahme je Kategorie verlangt, ISO 27001 oder BSI IT-Grundschutz referenziert und leere Kategorien meldet, entspricht den DSK-Erwartungen. Nach der DPC-Entscheidung gegen Meta (€1,2 Mrd., 2023) sollten Schutzmaßnahmen für Drittlandtransfers (SCCs, ergänzende Maßnahmen) ebenfalls auf TOM-Ebene dokumentiert werden, nicht nur im Übermittlungsfeld.

Muss die Betriebsratsbeteiligung pro Verarbeitungstätigkeit dokumentiert werden?

Ja, sobald eine Verarbeitung Beschäftigtenverhalten oder -leistung berührt. §87 Abs. 1 Nr. 6 BetrVG gibt dem Betriebsrat ein erzwingbares Mitbestimmungsrecht bei technischen Einrichtungen, die geeignet sind, Verhalten oder Leistung zu überwachen. Das erfasst die meisten HR-Analytics-, Zeiterfassungs-, Videoüberwachungs- und Cloud-HR-Lösungen. Ein Verzeichnis, das nicht nachweisen kann, welche Tätigkeit Mitbestimmung auslöst, wann die Beteiligung stattfand und welche Betriebsvereinbarung greift, ist nicht prüfungsfähig. Acompli erfasst Status (Ja/Nein/Nicht zutreffend), Datum, Ansprechperson und Betriebsvereinbarungs-Referenz pro Tätigkeit und markiert Beschäftigtendaten-Verarbeitungen ohne dokumentierte Beteiligung.

Kann ein einziges Register deutsche, irische und britische Einheiten abdecken?

Ja — Jurisdiktion ist ein Attribut der Einheit, kein eigener Mandant. Das Acompli-Overlay aktiviert BDSG/DSK-Felder und den deutschen Export für DE-Einheiten, DPA-2018/DPC-Logik für IE und UK-GDPR/ICO-Logik für GB — aus demselben Datenbestand. Eine Gruppe mit GmbH (DE), Ltd (IE) und Ltd (UK) führt ein kanonisches Verzeichnis; jede Einheit sieht nur die Felder, die ihre Aufsichtsbehörde erwartet, und exportiert getrennt nach BfDI/Landesdatenschutzbehörde, DPC und ICO. So vermeiden Sie das übliche Scheitern von drei halb gepflegten Excel-Dateien, die im Konzern auseinanderlaufen.

Wie werden internationale Datenübermittlungen nach Schrems II im deutschen Verzeichnis dokumentiert?

Nach Schrems II (EuGH C-311/18) und der DPC-Entscheidung gegen Meta (€1,2 Mrd., 2023) reicht ein Länderkürzel im Art.-30-Datensatz nicht. Erfassen Sie: Rechtsgrundlage der Übermittlung (Angemessenheitsbeschluss, Standardvertragsklauseln 2021, BCR, Ausnahme nach Art. 49), ergänzende Maßnahmen (Verschlüsselung at rest und in transit, Schlüsselverwaltung im EWR, Zugriffskontrollen), verknüpftes Transfer Impact Assessment und die Weitergabezusagen des Empfängers. Art. 30 Abs. 1 lit. e DSGVO verlangt die Identifizierung der Empfänger in Drittländern und der Garantien; EDSA-Empfehlungen 01/2020 und DSK-Hinweise präzisieren das Inhaltliche. Acompli verknüpft jede deutsche Verarbeitungstätigkeit mit ihrem TIA, sodass die Aufsicht den Schutzpfad direkt aus der Verzeichnis-Zeile nachvollziehen kann.

See German RoPA compliance in action

One jurisdiction-aware German register, connected to your assessments and risk register in one platform.