A SaaS vendor signs with a German host assuming "GDPR + BDSG = checkbox done." Legal then asks whether a Datenschutzbeauftragter (DPO) is required on the client side, whether technical and organisational measures are annexed to the contract, and how fines split when IaaS is misconfigured.
Germany remains a major European hosting market — Hetzner, IONOS, Strato, and others. The BDSG is not a conflicting second GDPR: it is the local layer that changes contract reading and expected documentation rigour.
GDPR and BDSG: who does what
Two texts coexist without replacing each other. GDPR sets the European framework: processing, transfers, data subject rights, accountability. BDSG adds German details: mandatory DPO in some cases, sector rules, Länder authority competence. The hosting contract and DPA operationalise these principles day to day.
The TTDSG (cookies and telemetry) is a separate but linked layer if your hosted site tracks visitors. Do not confuse it with pure hosting scope — but include it in your overall register.
| Level | Role for hosting |
|---|---|
| GDPR | EU framework: processing, transfers, rights, accountability |
| BDSG | DE details: mandatory DPO in some cases, sector rules, Länder authority competence |
| Contract / DPA | Operational terms with the host |
| TTDSG (cookies/telemetry) | Separate but linked if the hosted site tracks users |
For a standard hosting contract, BDSG shows up mainly via DPO obligation (Art. 38 GDPR + § 38 BDSG), stronger security-measure documentation, and cooperation with Länder authorities depending on your establishment.
Reading a "made in Germany" DPA
Serious German hosts often offer a detailed AVV (Auftragsverarbeitungsvertrag), sometimes more precise than non-DE providers. Verify six elements before signing.
First, purpose and term of processing — what the host actually does for you. Then technical and organisational measures in the annex: encryption, access control, backups, logging. Next, listed sub-processors (Unterauftragsverarbeiter) with objection rights. Datacenter location (Germany, sometimes Finland). Audit and assistance terms for data subject requests. Finally return or deletion at contract end.
Match the AVV to your processing register and, if applicable, internal DPO requirements. For Hetzner specifically, see our Hetzner DPA review.
German IaaS: non-delegable duties
On cloud or dedicated server, responsibility boundaries stay clear. You: hardening, patching, encryption, backups, logs, breach notification to the competent authority (BfDI or Landesbehörde). Host: platform and datacenter security documented in technical and organisational measures.
BDSG does not lighten your operational load — it documents what German courts expect in dispute. A misconfigured server at Hetzner remains your responsibility as controller or processor as applicable.
The crux: Falkenstein datacenter does not sign your AVV
That is the "100% DSGVO-konform" quote illusion: German compliance is proven, not located.
Decide and move forward without blind spots
Start by checking whether your organisation must appoint a client-side DPO under BDSG thresholds. Then sign the full AVV and archive technical-measure annexes. Map the host's German sub-processors and your own in the register. Test deletion and export procedures before a client or authority forces you to. Finally, compare providers via the directory and compare tool on contractual criteria, not VPS price alone.
Frequently asked questions
Does BDSG replace GDPR?
No. It supplements GDPR in German law with details on DPO, fines, and certain local processing. Hosting remains under the European framework; BDSG adds a layer of reading and documentation expected in Germany.
Is a German host automatically compliant?
No. Compliance depends on the signed DPA, sub-processor chain, your configuration, and sector. A German datacenter eases jurisdictional alignment but does not replace contract analysis.
Which clauses to verify?
Client DPO if required, annexed technical and organisational measures, assistance with data subject rights, breach notification, data location, and sub-processor lists. The German AVV often groups these — read the annex, not only the pricing page.
Does BDSG change transfers outside the EU?
Not fundamentally: GDPR Chapter V applies. However, German documentation culture often produces more detailed annexes, useful for audits and transfer impact assessments.
Before signing in Germany, request the full AVV — not only the DSGVO mention on the pricing page.
