The German Telecommunications and Telemedia Data Protection Act (TTDSG/TDDDG)

The German Telecommunications and Telemedia Data Protection Act (TTDSG), or Telekommunikation-Telemedien-Datenschutzgesetz, adopted by the German Federal Cabinet, has been in force since December 1, 2021.

The German Telecommunications and Telemedia Data Protection Act merges the data protection provisions of the Telemedia Act (TMG) and the Telecommunications Act (TKG) into one.

The TTDSG applies not only to providers of number-based telecommunications services (i.e., telephone services) but also to providers of number-independent services (so-called over-the-top services such as webmail or messenger).

The TTDSG also applies to telemedia service providers. Telemedia is electronic information and communication, excluding telecommunications or telecommunications-based services (see above) or broadcasting. This includes websites and other online offers of goods/services, video-on-demand platforms, and simple advertising e-mails.

The TTDSG became the TDDDG on May 13, 2024. The law was renamed the Telecommunications Digital Services Data Protection Act (TDDDG) in order to harmonize German law with the European Digital Services Act (DSA).

The geographical scope of the application corresponds to GDPR.

You may also like:


  • HIPAA-compliant analytics for healthcare systems: How hospital marketing teams can measure what matters

    Patients now research symptoms, compare providers, and book appointments entirely online before ever contacting a hospital. Healthcare marketers need to adapt to digital-first patient journeys, run campaigns for numerous service lines, manage hospital marketing analytics across multiple locations, and prove ROI to administrators. For nonprofit hospitals, the picture is broader still — donation tracking is…

  • Privacy by design in practice: How “just enough” data beats “just in case” collection

    While collecting more data “just in case” feels safer, according to Matt Gershoff, it’s also one of the biggest sources of unnecessary compliance risk, analytical noise, and wasted organizational resources in the analytics industry today. His approach of “just enough” data collection is more intentional, more aligned with privacy regulation, and often more analytically effective.