Skip to the content
Global Data RulesData governance rules, country by country

Germany

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Germany — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Active

You can store German data outside Europe. Neither European nor German law says personal data must stay in Europe. What the law asks for is paperwork before data leaves. Either the country you send to has an official decision saying it is safe enough. Or you sign a standard contract and write down a risk assessment. Germany then adds its own rules on top. One of them is a real ban. Health and social data can only be handled in the cloud inside Europe. The cloud provider must also hold a specific German security certificate.

Data governance in Germany

The eight things that decide how you handle data about people in Germany. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law reaches you even if you have no office in Germany. Europe's privacy law covers any company anywhere that offers goods or services to people in Europe. It also covers anyone who tracks how people in Europe behave. If you have no office in Europe, you must appoint a representative inside Europe.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, if you do the paperwork. European law does not say where data must sit. It says what you must have in place before data leaves Europe. Where you store data is one risk factor in that assessment. It is never a ban on its own. For data that is not about people, Europe goes further. It forbids member states from making rules about where that data is stored.

What to do: Get the paperwork for one of the routes below signed before any data leaves Germany.

Sending data out of the country

You have three routes. Best case, the country you are sending to is on Europe's official approved list. Then you need nothing extra. There are 17 entries on that list today. They include the United Kingdom, Japan, South Korea, Switzerland, Canada for commercial bodies, and Brazil since January 2026. The United States is on it too, but only for companies self-certified under the EU-US Data Privacy Framework. If your country is not on the list, sign Europe's standard contract clauses. Or get group-wide internal rules approved. With either of those, you must also write down an assessment. It has to say whether the destination country's surveillance laws weaken the protection.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

There are eighteen separate authorities. For a private company it is almost never the federal one. Each of the 16 states has its own regulator. You answer to the one where your German office is. The federal regulator handles government bodies plus telecoms and postal operators. Bavaria splits it further, with different bodies for private and public sector. If you operate across Europe, a separate rule helps. You can deal mainly with the regulator where your main European office sits.

How long you must keep it — and when to delete it

Some business records have a minimum. Accounting vouchers must be kept 8 years. That was cut from 10 years starting in 2025, and starting in 2026 for banks and insurers. Annual accounts and trading books must still be kept 10 years. Business correspondence must be kept 6 years. Privacy law pushes the other way. Do not keep personal data longer than you need it. Where the two clash, German law has a neat answer. You lock the data away so nobody can use it, instead of deleting it.

What you have to do here:
Keep data for a minimum period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

You have 72 hours to tell your state regulator about a personal data breach. You must also tell the people affected without undue delay if the risk to them is high. Since December 2025 Germany's cyber security law adds its own clocks. It covers around 29,500 companies. They send a first warning within 24 hours. Then an update at 72 hours. Then a full report within a month. Financial firms follow a separate set of European rules instead.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

There are four traps. First, health and social data really does have to stay in Europe. The cloud provider needs a specific German security certificate. The general answer that data can go anywhere is wrong here. Second, doctors, lawyers, tax advisers and notaries need more than a standard data protection contract. You need explicit secrecy promises passed down to every subcontractor. Breaking this is a crime, not a fine. Third, Germany still makes you appoint a data protection officer once 20 employees work with personal data. That is far stricter than European law. The government promised to scrap it by the end of 2026, but it is still in force. Fourth, people still cite an old German rule about employee data. Europe's top court struck it down in 2023. Nobody ever removed it from the law books. Using it as your legal basis is a mistake.

What you have to do here:
Extra vendor secrecy terms · Appoint a data protection officer · Keep the data in the country · Hold a security certificate

What's changing next

Two firm dates and one live risk. From 12 January 2027 every cloud provider must charge nothing for switching provider or moving your data out. Renegotiate your contracts now. By 31 December 2026 Germany's banking IT rulebook is fully withdrawn. European financial rules replace it. The live risk is the US arrangement. On 31 July 2026 Europe's data protection board asked the European Commission to review whether it is still valid. A separate court appeal is also pending. If it falls, thousands of transfers move to standard contracts overnight.

What you have to do here:
Make switching cloud provider possible

What to do: Diarise 12 January 2027 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries2 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Health and social care

Cloud and outsourcing rules

Official name: § 393 SGB V — Cloud-Einsatz im Gesundheitswesen · Act of parliament

In forceNo — it stays put

This is Germany's real rule about keeping data in the country. It is also the one that matters most commercially. Health and social data can only be handled in the cloud in three places. Germany. The European Union or the wider European Economic Area. Or a country Europe has decided is safe enough. In that last case the provider needs a German office. The provider must hold a current C5 Type 2 certificate from Germany's Federal Office for Information Security. This covers health providers, insurers and the companies that work for them.

In force since 1 January 2022

Enforced by Federal Commissioner for Data Protection and Freedom of Information

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision

Professional secrecy trades

Cloud and outsourcing rules (Professional secrecy trades)

Official name: § 203 StGB — Verletzung von Privatgeheimnissen · Act of parliament

In forceYes, with paperwork

This is not about where data is stored. It is the trap that catches cloud deals with doctors, lawyers, tax advisers, auditors and notaries. Since 2017 you can outsource to IT providers. But only if secrecy promises are passed down the whole chain of suppliers. Getting it wrong is a crime, not a fine.

In force since 9 November 2017

Enforced by Criminal courts

How this country controls where data goes: No restriction

Applies to every company1 rule

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: § 38 BDSG — Datenschutzbeauftragte nicht-öffentlicher Stellen · Act of parliament

In forceYes — store it anywhere

Germany adds this on top of European law. You must appoint a data protection officer once 20 employees work with personal data. Many people assume this was repealed. It was not.

In force since 25 May 2018

Enforced by The 16 state data protection authorities

How this country controls where data goes: No restriction

Applies across the European Union2 rules

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Verordnung (EU) 2016/679 (Datenschutz-Grundverordnung) · Regulation (EU) 2016/679 · Directly binding regulation

In forceYes, with paperwork

This is the European baseline. It sets the conditions for data leaving Europe. It does not say where data must be stored. Fines are the higher of a fixed cap or a percentage of worldwide group turnover. That is a much bigger risk than countries with fixed-cap fines, like India.

In force since 25 May 2018

Enforced by European Data Protection Board

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

Cloud and outsourcing rules (2027)

Official name: Data Act — Regulation (EU) 2023/2854 · Directly binding regulation

In forceYes — store it anywhere

This is not about where data sits. It is about being able to move it. From 12 January 2027 cloud providers must charge nothing for switching provider or moving your data out. That is a firm deadline. It affects every cloud contract directly.

In force since 12 September 2025In force now, but not enforced until 12 January 2027

That is a long gap: the duty is real law today, but no penalty can follow until 12 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.

Enforced by Federal Network Agency

How this country controls where data goes: No restriction

On the books, but not enforceable1 rule

These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.

Telecoms

Telecoms rules

Official name: §§ 175–181 TKG — Vorratsdatenspeicherung · Act of parliament

UnenforceableNo — it stays put

These telecoms data retention rules are still printed in the law. They cannot be enforced and are not enforced. A plain text search would report that Germany requires blanket retention. It does not. This shows why asking whether a rule is on the statute book is the wrong question.

Enforced by Federal Network Agency

How this country controls where data goes: Not allowed

Who you would hear from

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether new standard contract clauses for importers already subject to European law have been adopted very recently

    The European Commission's own page still lists them as work in progress. That is strong evidence but not proof. Check the Commission's site before you rely on this.

  • The court case number for the pending appeal against the EU-US arrangement, and any hearing date

    We could not confirm the case number or a hearing date from an official court source. Check the court's own records if this matters to you.

  • Whether the German data retention bill approved by cabinet in April 2026 has passed parliament

    The bill had only reached government-bill stage. We could not confirm that parliament passed it. Check the German parliament's site before you rely on this.

  • Whether the German reform bill and the Data Act enforcement law have been enacted

    Both bills were still going through parliament as of August 2026. We could not confirm that either became law. Check before you rely on them.

  • Whether any German fine since 2024 exceeds the EUR 35.26m record

    We found no larger fine. Our source is a private tracker, not a regulator's own register. Treat the figure as a guide only.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.