German DPA Publishes English Translation of Standard Data Protection Model
Time 2 Minute Read
Categories: International

On April 13, 2017, the North Rhine-Westphalia State Commissioner for Data Protection and Freedom of Information published an English translation of the draft Standard Data Protection Model (“SDM”). The SDM was adopted in November 2016 at the Conference of the Federal and State Data Protection Commissioners. 

German data protection authorities (“DPAs”) are currently reviewing the SDM, and the final version is expected to be published later this year. The English version of the SDM is a literal translation of the German text. An international version of the SDM currently is being prepared by the German DPAs.

The SDM contains a catalogue of data security measures and creates a methodology with respect to how the EU General Data Protection Regulation’s (“GDPR’s”) general security requirements should be implemented in practice. The SDM aims to harmonize how German DPAs review data security measures. The SDM also aims to assist companies in planning, implementing and reviewing their data security measures. The SDM structures the legal requirements in terms of data protection goals, such as data minimization, availability, integrity, confidentiality, transparency, “unlinkability” and “intervenability.”

In the current version, the SDM takes into account the GDPR wherever it contains references to German legal requirements, and is applicable until the GDPR takes effect in May 2018.

Read the SDM in English and German.

You May Also Be Interested In

Time 2 Minute Read

On February 23, 2026, a Joint Statement on AI-Generated Imagery was published by 61 data protection authorities. The Joint Statement addresses concerns regarding AI systems capable of generating realistic images and videos depicting identifiable individuals without their knowledge or consent.

Time 5 Minute Read

On November 19, 2025, the European Commission unveiled the much-anticipated digital omnibus legislative package (the “Digital Omnibus”), setting the stage for a new era of digital governance and regulatory simplification across the European Union. According to the Commission, this initiative is designed to enable European businesses to devote more energy to innovation and growth, rather than navigating complex compliance landscapes.

Time 2 Minute Read

On November 17, 2025, the Council of the European Union adopted new rules designed to strengthen cooperation among national data protection authorities, enhancing the enforcement of the EU General Data Protection Regulation.

Time 3 Minute Read

On November 4, 2025, the European Data Protection Board adopted its opinion on the European Commission’s draft decision regarding the adequacy of Brazil’s personal data protection framework. Once finalized, this decision will enable the free flow of personal data from the European Union to Brazil.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page