DataAct Ready

EU Data Act guides ·

Germany's Data Act Enforcement Law: What the Fines Actually Are

Germany's Data Act Implementation Act (DADG) is in force since 30 May 2026. Here is who enforces, what the real fine amounts are, and why the 4% figure only applies in one lane.

For two years, most articles about EU Data Act enforcement in Germany, including some of ours, repeated one number: fines of up to 4% of global turnover, floated in early drafts of the German implementation law. The law that actually passed looks different, and if you sell into the EU's largest market it is worth knowing exactly what changed.

The DADG in one paragraph

The Data Act itself is an EU regulation, directly applicable since 12 September 2025, but it leaves enforcement to the member states: each one designates a competent authority and writes its own penalty rules. Germany did this through the Data Act Implementation Act (Datenrecht-Anwendungs- und Durchsetzungsgesetz, DADG), passed by the Bundestag on 26 March 2026 and in force since 30 May 2026. From that date the Bundesnetzagentur, the Federal Network Agency that already regulates telecoms and energy, became Germany's central Data Act authority and single point of contact.

What the Bundesnetzagentur actually does

The agency's Data Act remit covers monitoring compliance with the cloud switching rules, certifying dispute resolution bodies, handling complaints, cooperating with other authorities and the Commission, and promoting data literacy. In practice, for a SaaS or connected-product company, it is the regulator that a frustrated customer, or a competitor, complains to when data access is refused or a switching request is stonewalled.

The real fine amounts

The final DADG sets a tiered system: minor violations up to EUR 50,000, moderate violations up to EUR 100,000, and serious violations up to EUR 500,000. That is dramatically lower than the EUR 10 million ceiling in the draft bill and nowhere near the GDPR-style percent-of-turnover figures discussed earlier. One important catch: a fine may exceed these caps where it needs to skim off the economic benefit a company gained from the violation, so a profitable violation does not stay profitable.

Why the 4% number is not dead

Here is the nuance that most summaries miss. Article 40(4) of the Data Act itself, not German law, gives data protection authorities the power to impose GDPR-scale fines, up to EUR 20 million or 4% of global annual turnover, for infringements of the Data Act's core chapters where personal data is involved. Germany's DADG preserves exactly this split: the Federal Commissioner for Data Protection (BfDI) keeps sole jurisdiction over Data Act supervision insofar as personal data processed by private companies is concerned.

For most connected products and SaaS tools, usage data is rarely purely technical. Telemetry tied to an identifiable user, driver, or account holder is personal data. So the practical picture for a company in scope is a two-lane system: the Bundesnetzagentur with capped six-figure fines for the general obligations, and the data protection lane where the familiar GDPR mathematics still applies.

What this means for your compliance planning

First, enforcement in Germany is no longer theoretical: the authority exists, is staffed, and has been live since May 2026, and the access-by-design obligation it polices has applied to new products since 12 September 2026. Second, the headline risk for most companies is not the fine schedule at all. It is the commercial exposure: unfair contract clauses being void under Article 13, customers invoking switching rights, and enterprise procurement asking for documented compliance. A EUR 500,000 cap does not make a void contract clause any less void.

Third, other member states are at different stages, and their penalty regimes vary. If you sell across the EU, you comply with the regulation once, not with 27 fine schedules, so the sensible planning basis remains the obligations themselves.

If you have not yet mapped which Data Act obligations apply to your product, our free 3-minute readiness assessment gives you an instant score and a gap list mapped to the exact articles, no signup needed, at https://www.dataactready.org.

Where does your product stand on the Data Act?

Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.

Start free assessment

This article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.