What I would like to define in my acl is that the each bind will give
access to everything under his sub entries but no access to the other entries. Unfortunately, I have no idea how to do this.
Is this possible and if yes, how?
Yes, have a look at the FAQ "How do I allow a user write to all entries below theirs?":
http://www.openldap.org/faq/data/cache/653.html
hth, daniel