Medical data privacy by country

Medical data privacy in Germany.

In Germany, medical secrecy is backed by criminal law as well as data law. What a doctor learns about you stays with the doctor.

General information, checked against the law on 23 September 2026. For your own case, ask a lawyer in Germany.

What the law says

How Germany treats your health data.

The law
GDPR, with the Federal Data Protection Act (BDSG)[S76][S110]
The regulator
Federal Commissioner for Data Protection, with a data protection authority in each state[S110]
Health data
Health data is a special category under Article 9 of the GDPR. It may be processed only on a listed ground, such as your explicit consent or care by health professionals bound by secrecy.[S76]
Sending it abroad
Data moves freely within the European Economic Area. Leaving it needs an adequacy decision for the destination or other safeguards (GDPR Chapter V).[S76]
Medical records
Section 22 of the BDSG allows health data to be processed for diagnosis and treatment by professionals bound by secrecy, and Section 203 of the Criminal Code makes it a crime for a doctor to disclose a patient's secrets.[S110][S111]
EU adequacy
Not needed: as an EU member, the GDPR applies directly.[S76]
If there is a breach
Within 72 hours to the national authority where feasible, and to the people affected without undue delay when the risk to them is high (Articles 33 and 34).[S76]
Fines
Up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher (Article 83).[S76]

Sending your records

The law protects the clinic’s copy. How it gets there is up to you.

Email and messaging apps leave a readable copy on every server they pass through, in Germany and at home. The safest file is the one that stays encrypted on your own phone, shown to the doctor in the room or sent by a link that expires by itself.

Try the free privacy check

Questions

Germany: common questions.

Is it safe to email medical records to a clinic in Germany?

Email is protected between mail servers only when both providers support TLS, and it stays readable on each server afterwards. Once your records reach a clinic in Germany, local law applies: health data is a special category under Article 9 of the GDPR. It may be processed only on a listed ground, such as your explicit consent or care by health professionals bound by secrecy. For a full history, use a channel where you hold the key, such as a link that expires by itself.

How does Germany protect health data?

Health data is a special category under Article 9 of the GDPR. It may be processed only on a listed ground, such as your explicit consent or care by health professionals bound by secrecy. Breaches must be reported within 72 hours to the national authority where feasible, and to the people affected without undue delay when the risk to them is high (Articles 33 and 34). The regulator is the Federal Commissioner for Data Protection, with a data protection authority in each state.

Can a clinic in Germany send my medical records abroad?

Data moves freely within the European Economic Area. Leaving it needs an adequacy decision for the destination or other safeguards (GDPR Chapter V). Section 22 of the BDSG allows health data to be processed for diagnosis and treatment by professionals bound by secrecy, and Section 203 of the Criminal Code makes it a crime for a doctor to disclose a patient's secrets.