Bavarian DPA Tests GDPR Implementation of 150 Companies
Time 1 Minute Read

On May 24, 2017, the Bavarian Data Protection Authority (“DPA”) published a questionnaire to help companies assess their level of implementation of the EU General Data Protection Regulation (“GDPR”).  

The DPA announced that it has sent the questionnaire to 150 randomly selected Bavarian companies.

The questionnaire examines the following topics:

  • procedures relating to the GDPR and the Data Protection Officer’s responsibilities;
  • data processing activities, inventories and privacy by design;
  • onboarding of external vendors and data processing agreements;
  • transparency, privacy notices and individuals’ rights;
  • accountability, the risk-based approach and security measures; and
  • data breach notification.

The DPA noted that it will be increasing its investigations after May 2018, and that this questionnaire provides an indication of how the investigations will be conducted.

Read the questionnaire (in German).

Read the press release (in German).

You May Also Be Interested In

Time 2 Minute Read

On February 23, 2026, a Joint Statement on AI-Generated Imagery was published by 61 data protection authorities. The Joint Statement addresses concerns regarding AI systems capable of generating realistic images and videos depicting identifiable individuals without their knowledge or consent.

Time 5 Minute Read

On November 19, 2025, the European Commission unveiled the much-anticipated digital omnibus legislative package (the “Digital Omnibus”), setting the stage for a new era of digital governance and regulatory simplification across the European Union. According to the Commission, this initiative is designed to enable European businesses to devote more energy to innovation and growth, rather than navigating complex compliance landscapes.

Time 2 Minute Read

On November 17, 2025, the Council of the European Union adopted new rules designed to strengthen cooperation among national data protection authorities, enhancing the enforcement of the EU General Data Protection Regulation.

Time 3 Minute Read

On November 4, 2025, the European Data Protection Board adopted its opinion on the European Commission’s draft decision regarding the adequacy of Brazil’s personal data protection framework. Once finalized, this decision will enable the free flow of personal data from the European Union to Brazil.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page