Germany's data-protection and data-security bar is high and rising — and for a non-EU digital-health company it's usually the hardest, most underestimated hurdle. It's not one rule but a stack, and it gates your DiGA listing regardless of how good the clinical evidence is.
Health data is a special category under the GDPR, tightened further by Germany's BDSG and health-sector rules that push processing onto German / EU soil. On top of that, a DiGA must clear a defined data-security bar — BfArM requirements plus a BSI security certificate (based on the technical guideline BSI TR-03161), typically backed by an information-security management system (ISO/IEC 27001) and, for cloud, the BSI C5 criteria. It's a layered programme, not a checkbox — and it gates the listing.
For most software, security is a quality attribute. For digital health in Germany, it's a pass/fail condition of market access.
A DiGA can have excellent clinical evidence and still fail to list if the data-security programme isn't certified. For any health product — app, device software, platform — data protection is also decisive in hospital and payer procurement. Non-EU teams routinely underestimate this because the bar is higher, more formal, and more German-specific than in their home market.
The clinical study proves it works. The security certificate proves you're allowed to run it here.
You don't pick one of these — you satisfy all of them, bottom to top. The top layer is what actually gates a DiGA listing, but it only holds if the foundation is solid.
Build bottom-up. Teams that start at L5 without L1–L4 in place stall — the certificate can't be issued on shaky foundations.
Health data isn't ordinary personal data. Under the GDPR (Regulation (EU) 2016/679), it's a special category (Art 9) — processing is prohibited unless a specific condition applies, and it demands extra safeguards.
For a DiGA, data security isn't just GDPR compliance — it's a certified, product-specific programme verified before listing.
Alongside BfArM's data-protection and security requirements, a DiGA must hold a security certificate issued on the basis of the technical guideline BSI TR-03161 — a hard prerequisite for listing.
Certification rests on a functioning information-security management system (commonly ISO/IEC 27001) and, where you host in the cloud, alignment with the BSI C5 criteria for cloud providers.
None of this is fast to retrofit. It's the reason we tell digital-health entrants to start the security workstream first: it gates the listing regardless of how strong the clinical evidence is, and it has the longest lead time.
In a focused session we outline the full stack for your product — GDPR, German rules, hosting, the BSI certificate path — sequence it so it doesn't block your listing, and connect you to the right certification partners.