Germany’s federal data protection commissioner used one of her final major public interventions to press for tighter European handling of neurodata, at a BCI-themed academic conference in Bonn on 4 September 2026, four weeks before she steps down. Prof. Dr. Louisa Specht-Riemenschneider, the sitting Federal Commissioner for Data Protection and Freedom of Information (BfDI), spoke at the third annual conference of the University of Bonn’s Zentrum für Medizinische Datennutzbarkeit und Translation (ZMDT), a centre she will herself co-direct after her BfDI term ends on 30 September 2026. The Bundestag-elected successor, Prof. Dr. Moritz Hennemann of the University of Freiburg, takes over on 1 October 2026.
What the commissioner said
Specht-Riemenschneider’s substantive message was that data protection and medical progress are not opposites, that established GDPR standards should not be watered down for commercial neurodata processing, and that “effective instruments” are needed to prevent people from becoming “playthings of large tech corporations” (Spielbälle großer Tech-Konzerne). The commercial-research route does not exempt operators from GDPR obligations, in her reading of the law. She called for personal responsibility in research design (broad consent, protected processing environments, codes of conduct, certifications) rather than a new ban regime, and for the European Data Protection Board (EDPB) to take up neurotechnology as a standalone workstream.
Dr. Ruben Plum-Schneider, Personal Advisor to the BfDI, delivered the technical intervention at the same conference. His framing: data protection law applies once raw neural signals are read, neural data supports “brain fingerprint” biometric traceability comparable to iris scans, and current GDPR has a “blind spot” on bidirectional BCI systems that write into the brain rather than only read from it. His invocation of “Brain Malware” (viruses uploaded to BCI software) is anticipatory-risk vocabulary drawn from a decade of academic work on BCI security (Bonaci et al., University of Washington, 2014; Denning, Matsuoka, Kohno, Neurosurgical Focus, 2009). It is not a documented incident.
The formal BfDI underpinning
The commissioner’s Bonn intervention rests on a formal 16-month-old BfDI-hosted document. On 15 May 2025 the International Working Group on Data Protection in Technology (Berlin Group, chaired through BfDI) published a Working Paper on Emerging Neurotechnologies and data protection. The Working Paper does not name specific companies. It reads existing GDPR against neurodata as follows: raw neural signals qualify as sensitive personal data under Article 9 in most cases (health data under Article 4(15), biometric data where used for unique identification). The Working Paper argues for clearer definitions of neurodata, cognitive freedom, and mental integrity, but does not call for a new EU regulation.
The “Big Tech limits” framing in the German tech press headline is an editorial elevation of Specht-Riemenschneider’s verbal rhetoric. The formal BfDI Berlin Group Working Paper does not use “Big Tech” as a category, and does not name Meta, Apple, Google, Neuralink, OpenAI, Amazon, or any individual company.
The existing legal ground the BfDI is working from
Germany does not have a neurodata-specific statute. The BfDI intervention leverages three existing European frameworks.
GDPR (Regulation (EU) 2016/679). Article 9 covers health data and biometric data as special-category personal data. Neural signals qualify under existing case law in most read-only clinical or consumer scenarios. Article 5 principles (purpose limitation, data minimisation) apply. There is no standalone EDPB neurotechnology guideline in force.
EU AI Act (Regulation (EU) 2024/1689). In force since 1 August 2024, with prohibitions applicable from 2 February 2025 and full application from 2 August 2027. The European Commission’s February 2025 Guidelines on prohibited AI practices explicitly identify brain-computer interfaces as one sample vector for the Article 5(1)(a) ban on “subliminal techniques beyond a person’s consciousness.” Medical BCI operators are separately classified as high-risk AI under Annex III where the device is a regulated medical device (Article 6). This classification is already binding.
EU Medical Device Regulation (MDR, Regulation (EU) 2017/745). Implantable BCIs fall under Rule 8 (implantables) and Rule 22 (active devices interacting directly with the central nervous system). Class III classification is the default. Notified Body conformity assessment and clinical investigation are mandatory before CE Mark.
The Berlin Group Working Paper identifies the concrete regulatory shortfall the BfDI wants closed. Current GDPR analysis is developed for read-only neural data. Bidirectional systems that write electrical stimulation back into the brain (INBRAIN, CorTec Brain Interchange, Subsense’s proposed molecular route, closed-loop neuromodulation platforms generally) sit less cleanly inside the existing framework.
BfDI enforcement reach in practice
A BfDI intervention on neurodata is soft-law. The BfDI has direct fining authority only over federal public bodies and postal and telecommunications providers. Big Tech consumer-facing neurodata processing would fall under the German Länder-level data protection commissioners (or, under the GDPR one-stop-shop, the lead EU data protection authority for that firm’s establishment) and under AI Act market-surveillance authorities. A BfDI statement carries evidentiary weight for future legislation and coordinated Datenschutzkonferenz (DSK) enforcement, and shapes German positions inside the EDPB, but it does not by itself create binding obligations on Meta, Apple, Google, OpenAI, or any Neuralink-adjacent US operator.
The German BCI operator most affected
Germany’s most prominent BCI operator is CorTec GmbH (Freiburg, founded 2010), which holds two FDA Breakthrough Device Designations for its Brain Interchange implant (April 2026 for stroke motor rehabilitation, 31 August 2026 for communication in non-progressive quadriplegia). CorTec’s clinical work runs through University of Washington, Mayo Clinic, and UMC Utrecht (Netherlands). The Brain Interchange is a bidirectional closed-loop platform. It is exactly the device class the Berlin Group Working Paper identifies as sitting less cleanly inside current GDPR analysis. CorTec’s primary regulatory route as of 2026 is US FDA rather than EU, a pattern InsideBCI has flagged across the European BCI operator cohort (INBRAIN, ABILITY, Precision Neuroscience, CorTec).
Where this sits on the four-jurisdiction posture map
Issue 01 of the Dargentic Intelligence Report classified four global regulatory postures on brain-computer interfaces: Rights-First (Chile), Horizontal Regulator (EU with AI Act and GDPR), State-Patchwork (US with Colorado, California, Montana, Connecticut, Vermont), and Industrial Builder (China and South Korea). The BfDI’s Bonn intervention is a Horizontal Regulator move. Germany’s contribution is not a new BCI-specific statute. It is one national data protection authority using its existing GDPR mandate, coordinating through the Berlin Group (an international expert body it chairs), and pointing to the AI Act’s existing subliminal-manipulation and high-risk classifications. That is the Horizontal Regulator posture operating as designed: cross-sectoral rules stretched to cover a new technology class, rather than a technology-specific rule enacted from scratch.
The succession
Specht-Riemenschneider was elected BfDI by the Bundestag on 16 May 2024 and took office in September 2024 for a five-year statutory term. She announced early resignation for health reasons on 17 March 2026. The Bundestag elected Prof. Dr. Moritz Hennemann, a data-law scholar at the University of Freiburg, as her successor on 25 June 2026. Hennemann’s known public writing covers competition law and the digital economy. His position on neurodata governance is not publicly disclosed. He takes office on 1 October 2026.
Not disclosed
The specific German or EU legislative proposals the BfDI is calling for on bidirectional BCI systems have not been detailed as draft language. Any timeline for a standalone EDPB neurotechnology guideline has not been announced. Any coordinated Länder-level enforcement action against a specific Big Tech firm on neurodata has not been announced. Prof. Hennemann’s neurodata position has not been publicly disclosed ahead of his 1 October 2026 start. The German Bundestag has no current draft brain-data legislation on the order paper.
What to watch
Whether Prof. Hennemann publicly addresses neurodata in his first weeks in office. His inaugural statements will indicate whether the BfDI’s neurodata focus continues, deepens, or is replaced by a different tech-policy priority (competition law, AI foundation model governance, or another domain).
Whether the EDPB publishes a standalone neurotechnology guideline in the coming quarters. The Berlin Group Working Paper is the input document, but only a formal EDPB guideline would create Europe-wide binding regulatory expectations for BCI operators.
Whether Germany, individually or with France, pushes for a targeted bidirectional-BCI provision in an EU-level instrument. The GDPR “blind spot” on write-side BCI identified by the BfDI is the concrete shortfall. Whether Berlin lifts that shortfall into a Council-level policy ask is the next signal.
Whether German BCI operators (CorTec) or German BCI research consortiums (Berlin BCI Consortium at TU Berlin and Charité, Fraunhofer IDMT NAFAS mobile-EEG programme) engage publicly with the BfDI position. A response from the operator side would indicate whether the German BCI industry sees the intervention as workable or as an operating constraint.
Whether any Big Tech firm operating a consumer-facing neural or brain-adjacent product line in Germany (Meta Neural Band in market surveillance, Apple neural-signal patents, Google-adjacent hardware) receives a Länder DPA inquiry or an AI Act market-surveillance action. That would be the practical enforcement test of whether BfDI soft-law guidance converts to binding regulatory pressure at the member-state operating level.