GDPR Criminal Liability in Germany: What US Companies Must Know (EN)

Executive summary

Most US companies think of GDPR enforcement as an administrative fine matter under Article 83. That view is incomplete. In Germany, certain data protection violations are criminal offenses under § 42 of the Federal Data Protection Act (BDSG), punishable by up to three years of imprisonment. These provisions target natural persons – not companies – and apply to individuals who transfer, disclose, or process personal data unlawfully with a commercial motive or with intent to enrich or harm. Meanwhile, the Court of Justice of the EU has confirmed in Deutsche Wohnen (2023) that Article 83 GDPR fines can be imposed directly on legal persons – including US companies subject to the GDPR – without needing to prove misconduct by a specific individual. The combined framework – administrative fines against the company, criminal exposure against executives – creates a two-track risk that many US-headquartered organizations underestimate. This guide explains the criminal side, the extraterritorial reach, and how US companies and their leadership should think about it.

Table of contents

1. The two-track framework: administrative fines vs. criminal offenses

2. § 42 BDSG in detail – the criminal offenses

3. Extraterritorial reach: when § 42 BDSG applies to US individuals

4. Corporate exposure: Article 83 GDPR after Deutsche Wohnen

5. Enforcement patterns and case law 2024–2026

6. The self-incrimination protection under § 42 (4) BDSG

7. Cross-border investigation dynamics

8. Compliance considerations for US executives

9. Frequently asked questions

1. The two-track framework: administrative fines vs. criminal offenses

Germany's data protection enforcement operates on two parallel tracks:

Track 1 – Administrative fines. Article 83 GDPR authorizes fines up to €20 million or 4% of global annual turnover (whichever is higher) for serious violations, and up to €10 million or 2% for lesser violations. These fines are imposed by German data protection authorities (there are 17 – one federal, sixteen state) against companies as legal persons. Following the CJEU's decision in Deutsche Wohnen (C-807/21, December 2023), a fine can be imposed directly on a company without first attributing the infringement to a specific natural person. The old German requirement of individual attribution has been superseded by EU primacy.

Track 2 – Criminal prosecution of individuals. § 42 BDSG creates two criminal offenses that go beyond the GDPR's fine regime. They target natural persons – executives, employees, data protection officers, sometimes former employees – who commit specific data protection violations. Punishment: up to three years of imprisonment or fines. This is real criminal law, prosecuted by the Staatsanwaltschaft (public prosecutor), with entries in the criminal record on conviction.

Why this matters for US organizations. A single incident can trigger both tracks simultaneously. The company faces administrative fines from the data protection authority. Individual executives face potential criminal investigation. And under German law, statements made in one procedure can – within limits – affect the other. The strategic coordination between administrative response and criminal defense is essential from the first day.

2. § 42 BDSG in detail – the criminal offenses

The statutory text (in official English translation):

Section 42 – Penal provisions

(1) The following actions done deliberately and without authorization with regard to the personal data of a large number of people which are not publicly accessible shall be punishable with imprisonment of up to three years or a fine:

– transferring the data to a third party, or

– otherwise making them accessible

for commercial purposes.

(2) The following actions done with regard to personal data which are not publicly accessible shall be punishable with imprisonment of up to two years or a fine:

– processing without authorization, or

– fraudulently acquiring

and doing so in return for payment or with the intention of enriching oneself or someone else or harming someone.

(3) Such offences shall be prosecuted only if a complaint is filed. The data subject, the controller, the Federal Commissioner and the supervisory authority shall be entitled to file complaints.

(4) A notification pursuant to Article 33 of Regulation (EU) 2016/679 or a communication pursuant to Article 34 (1) of Regulation (EU) 2016/679 may be used in criminal proceedings against the person required to provide a notification or a communication or relatives as referred to in Section 52 (1) of the Code of Criminal Procedure only with the consent of the person required to provide a notification or a communication.

2.1 The § 42 (1) offense – commercial data transfer

Five elements must be satisfied cumulatively:

  • Non-publicly-accessible personal data. Anything not freely available to the general public – customer lists, employee records, financial data, internal correspondence.

  • A large number of people. German case law and commentary place the threshold in the range of several hundred data subjects – often 100 to 500 as a working figure.

  • Without authorization. Absence of a lawful basis under Article 6 GDPR, contract, or consent.

  • Transfer to a third party or making accessible. Both active transmission and passive availability (uploading to accessible servers) qualify.

  • Commercial purposes. The perpetrator must act with commercial motivation – often expressed as the intent to establish a recurring income stream. Not limited to formal salespersons; includes competitive advantage in a new role.

Mental element: § 42 (1) requires deliberate ("wissentlich") conduct – a heightened form of intent. Reckless or negligent commercial data transfers are not covered by § 42 (1).

2.2 The § 42 (2) offense – unauthorized processing or fraudulent acquisition

Broader in scope, narrower in penalty (up to two years). Two variants:

  • Unauthorized processing – any GDPR-regulated processing operation performed without a lawful basis, with the required subjective element.

  • Fraudulent acquisition – obtaining personal data through false statements, deception, or misrepresentation. Practically relevant in social engineering and industrial espionage contexts.

Additional subjective element required: one of three alternatives must be present – (i) acting in return for payment, (ii) intent to enrich oneself or a third party, or (iii) intent to harm another person. Ordinary intent is not sufficient; the additional motive is what elevates the conduct to criminal.

2.3 Complaint-based prosecution

Under § 42 (3), § 42 BDSG offenses are prosecuted only upon complaint (Antragsdelikt). Standing to file: the data subject, the controller, the Federal Commissioner for Data Protection, and the competent supervisory authority. The three-month deadline runs from the point at which the complainant learns of the offense and the offender. Miss this deadline, and the criminal path is generally foreclosed.

Strategic implication for US companies: Filing a complaint is a real option when an internal investigation identifies rogue conduct by an employee or ex-employee. Not filing may effectively immunize the individual. Both choices carry consequences – reputational, litigation-related, employment-law-related – that must be weighed.

3. Extraterritorial reach: when § 42 BDSG applies to US individuals

The application of § 42 BDSG to US-based individuals is governed by both the substantive scope of the BDSG and general principles of German criminal jurisdiction:

§ 1 (4) BDSG brings within scope any company – controller or processor – that either processes data in Germany, processes data through the activities of an establishment in Germany, or is subject to the GDPR under Article 3 (2) (offering goods/services to EU residents or monitoring their behavior). Since 2018, a non-EU company subject to the GDPR is automatically subject to the BDSG.

§ 9 StGB (German Criminal Code) – the criminal jurisdiction principle. German criminal law applies to acts committed abroad if either the act itself or the result occurs in Germany. In data protection cases, the "result" – the accessible or transferred data being made available to a German-based recipient, or a data subject in Germany suffering harm – can establish jurisdiction.

Practical scenarios for US executives:

  • A US-based executive who authorizes the unlawful commercial transfer of German customer data to a third party could face German criminal jurisdiction, even if the conduct itself takes place in the US.

  • A former employee of a German subsidiary who takes customer data to a US-based competitor may be prosecutable in Germany.

  • A US-headquartered DPO who instructs commercially motivated data transfers affecting a German operation could be individually exposed.

Enforcement realities: German prosecutors rarely pursue individuals abroad who are not otherwise present in Germany or the EU. But extradition is possible under the US-Germany treaty for offenses carrying more than one year of potential imprisonment – which § 42 BDSG does. More practically, individuals who travel to Germany or the EU can be arrested and prosecuted. And where cross-border criminal cooperation is close – DOJ, FBI, Europol channels – information can flow.

4. Corporate exposure: Article 83 GDPR after Deutsche Wohnen

The other side of the coin. In Deutsche Wohnen (Case C-807/21, December 2023), the CJEU clarified:

  • Article 83 GDPR fines can be imposed directly on a legal person (a company) without prior attribution of the infringement to a specific natural person.

  • Culpability (intent or negligence) is required – no strict liability. But culpability of the entity is sufficient; individual leadership involvement does not need to be proven.

  • The "undertaking" concept for calculating maximum fines refers to the economic unit – meaning fines can be sized against parent company or group turnover, not just the fined entity's own turnover.

  • Conflicting national provisions – such as the prior German requirement under § 30 OWiG for individual attribution – are set aside by EU primacy.

What this means for US groups. A German subsidiary's data protection infringement can result in a fine calculated against the US parent's global turnover. This has already been reflected in several high-profile enforcement actions. The exposure for a group with, say, $10 billion in annual global revenue is €400 million at the Article 83 (5) maximum – for a single serious infringement.

German enforcement data 2024–2025:

  • Vodafone GmbH: €45 million (June 2025), for security failures.

  • H&M Germany: €35.3 million (historic, but still cited), for employee data monitoring.

  • Deutsche Wohnen: €14.5 million (subsequent proceedings after CJEU ruling).

  • Numerous six- and low-seven-figure fines against SaaS providers, financial institutions, and healthcare organizations.

  • Multiple pending investigations against US tech companies with German subsidiaries.

5. Enforcement patterns and case law 2024–2026

Several patterns emerge from the current enforcement environment:

Pattern 1: Cross-border data transfer scrutiny. After Schrems II and the transition to the EU-US Data Privacy Framework, German DPAs remain skeptical of US-bound transfers. The Wiesbaden Administrative Court held in 2021 that even use of a US cloud provider – whose infrastructure sits in the EEA – can constitute an unlawful transfer under Article 44 because the provider is subject to the US CLOUD Act. This doctrine has been influential and continues to drive fine actions against companies relying on US-based sub-processors.

Pattern 2: Employee data cases. Systematic employee monitoring, HR data leaks, or improper handling of employment records are among the most frequent triggers for fines. Individual DPOs and HR leaders are increasingly named in investigations.

Pattern 3: Data breach follow-through. Breach notification often triggers a full compliance review by the DPA. Companies that fail the review face fines even where the underlying breach was contained. The compliance state at the moment of breach – not perfect prevention – is what matters.

Pattern 4: Coordinated US-EU proceedings. The Meta case (Ireland, €1.2 billion, 2023) and the ongoing enforcement against Clearview AI (multiple EU jurisdictions) illustrate the trend toward coordinated action against US-headquartered companies. Investigations against directors personally are being explored in the Netherlands and elsewhere.

Pattern 5: German court validation of directorial personal liability. The Dutch DPA has publicly explored personal liability for Clearview AI directors. Similar theories – rooted in § 130 OWiG (supervisory duties) and § 43 GmbHG / § 93 AktG (directors' duties) – are being tested in Germany. The theoretical basis for going after individual executives when the corporate compliance regime fails is increasingly robust.

6. The self-incrimination protection under § 42 (4) BDSG

A critical provision often overlooked by US counsel. § 42 (4) BDSG creates a specific evidentiary bar:

A GDPR breach notification (Article 33) or communication to data subjects (Article 34) may not be used in criminal proceedings against the notifying party or their close relatives without their consent.

This protection exists because otherwise the 72-hour breach notification obligation would function as a compelled self-incrimination – incompatible with the nemo tenetur principle. In effect, § 42 (4) BDSG is a limited immunity for the fact of notification and its content.

What the protection covers:

  • The notification itself and its factual content, when used as evidence against the notifier.

What the protection does not cover:

  • Independent evidence obtained through other means (documents seized in a subsequent raid, statements by other witnesses).

  • Use of the notification against a different individual than the notifier.

  • Use in administrative fine proceedings (Article 83 GDPR) – which are separate from criminal proceedings.

Strategic implication: The 72-hour breach notification should typically be filed even in situations where individual criminal exposure is a concern. Withholding notification creates additional violations (Article 33 GDPR breach itself becomes a separately punishable event) without gaining criminal law advantage – because the § 42 (4) protection covers notification-based evidence anyway.

For US in-house teams accustomed to weighing US-style Fifth Amendment considerations, this German-specific protection is a valuable and underused tool.

7. Cross-border investigation dynamics

Several practical realities for US-headquartered organizations:

The CLOUD Act problem. Data protection authorities and courts have increasingly held that US-based service providers – and their EU subsidiaries – are subject to US government access under the CLOUD Act. This creates a structural tension: the GDPR (Article 44) prohibits certain data transfers, and the CLOUD Act obliges compliance with US legal process. Companies caught in the middle face German enforcement action even when they follow US legal requirements.

Document production in parallel investigations. A US company producing documents to the DOJ or SEC in response to US enforcement action may inadvertently trigger GDPR issues if the produced data includes information subject to European data protection rules. Cross-jurisdictional privilege review is essential.

Coordinated agency response. German DPAs increasingly coordinate with prosecutors. A DPA investigation may trigger a prosecutor referral for potential § 42 BDSG offenses. Conversely, prosecutors investigating unrelated offenses may find GDPR issues and refer them to the DPA.

Internal investigation risk. US-style internal investigations – with broad Upjohn warnings, structured employee interviews, and formal cooperation frameworks – must be adapted for German legal requirements. Works council rights (§ 87 BetrVG), employee self-incrimination protections, and GDPR compliance in investigation methodology are all in play.

Whistleblower dynamics. The German Hinweisgeberschutzgesetz (HinSchG) creates strong protections for internal and external whistleblowing on GDPR violations. Retaliation against a legitimate whistleblower can create additional civil, administrative, and reputational exposure. US-style "don't rock the boat" cultures often clash with the German whistleblower framework.

8. Compliance considerations for US executives

Practical steps for US-headquartered organizations with German or EU operations:

Governance and documentation

  • Records of processing activities (Article 30 GDPR) must be complete, current, and available. Gaps here are the most common finding in DPA investigations.

  • Data protection impact assessments for high-risk processing activities – required and increasingly scrutinized.

  • Documented risk assessments under Article 32 GDPR, mapped to technical and organizational measures (TOMs).

  • Board-level engagement – the CJEU has emphasized organizational responsibility, and German courts have begun to test directorial liability. Board minutes should reflect data protection governance.

Investigative response readiness

  • Playbook for the 72-hour notification – integrated with US-side breach response, GDPR breach notification, and § 42 (4) BDSG considerations.

  • Preserved legal privilege – for external EU counsel, arrangements to preserve German attorney-client protection under § 97 StPO.

  • Coordinated document management – separate custody for materials that may be responsive to DOJ, SEC, DPA, and § 42 BDSG proceedings.

Individual protection for executives and DPOs

  • Clear delegation structures – documented decision authority for data processing operations. Where an executive did not personally authorize an unlawful transfer, the record should reflect that.

  • Training and role documentation – for DPOs and senior compliance personnel, ensuring their function conforms to Article 39 GDPR (advisory and monitoring, not operational).

  • D&O and legal defense insurance – reviewed for coverage of individual criminal defense costs in EU jurisdictions.

Vendor and cross-border management

  • CLOUD Act mapping – which US-based providers may be subject to US legal process affecting European data?

  • Transfer mechanism due diligence – DPF certification, SCCs, TIAs, all with documentation available for regulator inquiry.

  • Sub-processor visibility – full chain from controller through processor to sub-processor, with transfer mechanisms in place at each link.

9. Frequently asked questions

Can a US company be criminally prosecuted under § 42 BDSG?

No. § 42 BDSG targets natural persons only – individual executives, employees, DPOs. Corporate exposure runs through Article 83 GDPR (administrative fines) and § 30 OWiG (administrative offense for corporate benefit). Germany does not currently have true corporate criminal liability, though a Corporate Sanctions Act has been repeatedly discussed.

Can a US executive be extradited to Germany for a § 42 BDSG offense?

Legally yes, under the US-Germany extradition treaty. Practically, extradition is rarely sought for individual data protection cases. However, an executive who travels to Germany or the EU can be arrested. And information sharing under MLATs and direct agency cooperation means that a German investigation can be built even when the target remains in the US.

What is the "large number of people" threshold under § 42 (1) BDSG?

There is no fixed statutory number. German case law and commentary suggest the range of several hundred data subjects – often 100 to 500 as a working reference. In practice, most enforcement cases involve datasets well above this threshold, so the debate rarely proves decisive.

Does § 42 BDSG apply to a US-based cloud provider processing EU data?

If the US provider is subject to the GDPR (Article 3 (2)) or has an EU establishment, then § 42 BDSG's substantive scope reaches it. Whether an individual at the US provider is criminally liable turns on jurisdictional principles under § 9 StGB and the specific factual scenario. In many configurations, the answer is yes – theoretically.

How does § 42 BDSG interact with US-side FCPA or SEC enforcement?

Different offenses, potentially overlapping conduct. A US bribery investigation with EU data protection dimensions can trigger both US and German criminal exposure. Coordination between US and German defense counsel is essential to avoid inconsistent positions or unintended waivers.

What about the CLOUD Act problem?

Real and unresolved. German courts have taken the view that US providers – even those with EU infrastructure – are potentially subject to US government access, and that this creates a GDPR transfer issue under Article 44. There is no comprehensive fix. Practical mitigation: contract structuring, encryption with customer-held keys, and (where feasible) architectural separation from US legal process.

Are DPOs personally liable under § 42 BDSG?

Only if they personally engage in conduct that satisfies the elements of the offense. DPOs performing their Article 39 GDPR duties – advising, monitoring, cooperating with supervisory authorities – are not liable for the organization's decisions. But a DPO who operationally participates in unauthorized data transfers, or who fails to report while enabling ongoing violations, can become individually exposed.

Should a US company file breach notifications when there's potential § 42 BDSG exposure?

In almost all cases, yes. § 42 (4) BDSG creates a limited but real evidentiary protection for the notification itself. Withholding notification creates a separate GDPR violation and does not provide protection against other evidence. The strategic value of the § 42 (4) protection is best captured by timely, complete notification – coordinated through counsel.

About the author

Niklas Hanitsch is a German criminal defense attorney with a focus on economic crime, IT and cyber criminal law, compliance, and data protection criminal law. He advises companies and executives on the intersection of GDPR enforcement, criminal proceedings, and cross-border regulatory dynamics. Founder and CEO of SECJUR, a venture-backed compliance and cybersecurity automation company selected for the Google for Startups Cybersecurity Accelerator. Member of the Federal Commission on Cybersecurity of the German Economic Council (CDU). Named Capital 40 Under 40 (2023) and winner of the German Startup Cup for Cybersecurity (GFFT, 2022). Previous positions include Legal at Amazon, Taylor Wessing Silicon Valley (advising US companies on European data protection law), Taylor Wessing Germany, and Bird & Bird.

Schedule a confidential consultation →

Related articles

Legal disclaimer

This article is for informational purposes only and does not constitute legal advice. Every case is different. For advice on a specific matter, please schedule a confidential consultation.

Zurück
Zurück

Vermögensarrest im Ermittlungsverfahren: Konten gesperrt – was jetzt?

Weiter
Weiter

German White Collar Crime Defense: A Guide for US Executives (EN)