German DPAs Publish App Guidelines and Step Up Enforcement
Time 1 Minute Read

On June 18, 2014, the German state data protection authorities responsible for the private sector (the Düsseldorfer Kreis) issued guidelines concerning the data protection requirements for app developers and app publishers (the “Guidelines”). The Guidelines were prepared by the Bavarian state data protection authority and cover requirements in Germany’s Telemedia Act as well as the Federal Data Protection Act. Topics addressed in the 33-page document include:

  • Applicability of German law;
  • Compliance responsibilities (e.g., legal bases, consent, profiling, pseudonymization and anonymization, and purpose limitation);
  • User information (e.g., data protection notices and their readability on mobile devices, data subject rights);
  • Technological means (e.g., local data storage, logging, location data); and
  • High-risk data processing (e.g., payment processing, apps for children).
According to Thomas Kranig, President of the Bavarian state data protection authority, a 2013 review of apps discovered many shortcomings in how developers and publishers comply with German data protection law. Now that specific guidelines have been published, Kranig emphasized that enforcement action will be stepped up for apps that breach data protection law in a way constitutes an administrative offense.

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 2 Minute Read

On February 23, 2026, a Joint Statement on AI-Generated Imagery was published by 61 data protection authorities. The Joint Statement addresses concerns regarding AI systems capable of generating realistic images and videos depicting identifiable individuals without their knowledge or consent.

Time 2 Minute Read

On November 17, 2025, the Council of the European Union adopted new rules designed to strengthen cooperation among national data protection authorities, enhancing the enforcement of the EU General Data Protection Regulation.

Time 1 Minute Read

On October 14, 2025, the European Data Protection Board announced that its fifth coordinated enforcement action will focus on compliance with the transparency and information requirements under the GDPR.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page