Germany
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Germany — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can store German data outside Europe. Neither European nor German law says personal data must stay in Europe. What the law asks for is paperwork before data leaves. Either the country you send to has an official decision saying it is safe enough. Or you sign a standard contract and write down a risk assessment. Germany then adds its own rules on top. One of them is a real ban. Health and social data can only be handled in the cloud inside Europe. The cloud provider must also hold a specific German security certificate.
Data governance in Germany
The eight things that decide how you handle data about people in Germany. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law reaches you even if you have no office in Germany. Europe's privacy law covers any company anywhere that offers goods or services to people in Europe. It also covers anyone who tracks how people in Europe behave. If you have no office in Europe, you must appoint a representative inside Europe.
- What you have to do here:
- Appoint a representative
Sources
- Official sourcePublications Office of the European UnionGeneral Data Protection Regulation (EU) 2016/679, Articles 3 and 27
eur-lex.europa.eu
Where the data is allowed to live
Yes, if you do the paperwork. European law does not say where data must sit. It says what you must have in place before data leaves Europe. Where you store data is one risk factor in that assessment. It is never a ban on its own. For data that is not about people, Europe goes further. It forbids member states from making rules about where that data is stored.
There is one real exception. German social security law does require this data to stay close to home. You can only handle social and health data in the cloud in three places. Germany. The European Union or the wider European Economic Area. Or a country Europe has officially decided is safe enough. In that last case, the provider must also have a German office. The provider must hold a current C5 cloud security certificate from Germany's Federal Office for Information Security. Since 1 July 2025 it must be the Type 2 version. So a global cloud provider can serve German healthcare only through a European region, through a German company, with that certificate.
Sources
- Official sourcePublications Office of the European UnionGDPR, Chapter V (Articles 44–50) — transfers, not storage location
eur-lex.europa.eu
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 on the free flow of non-personal data — prohibits member-state localisation rules
eur-lex.europa.eu
- Official sourceBundesministerium der Justiz / Bundesamt für Justiz§ 393 SGB V — Cloud-Einsatz im Gesundheitswesen (the real German localisation rule)
gesetze-im-internet.de
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Germany.
Sending data out of the country
You have three routes. Best case, the country you are sending to is on Europe's official approved list. Then you need nothing extra. There are 17 entries on that list today. They include the United Kingdom, Japan, South Korea, Switzerland, Canada for commercial bodies, and Brazil since January 2026. The United States is on it too, but only for companies self-certified under the EU-US Data Privacy Framework. If your country is not on the list, sign Europe's standard contract clauses. Or get group-wide internal rules approved. With either of those, you must also write down an assessment. It has to say whether the destination country's surveillance laws weaken the protection.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules
Two gaps are worth knowing. First, there is still no purpose-built standard contract for sending data to a company already covered directly by European law. The European Commission has promised this set since 2024. It had not appeared as of August 2026. So most companies use the 2021 clauses and switch off the parts that repeat. Second, the US arrangement is under real pressure. On 31 July 2026 Europe's data protection board wrote to the Commission. It asked the Commission to examine a US Supreme Court decision on the independence of the US enforcement agency. The question is whether that decision breaks the arrangement. It remains in force today. Do not build on it as your only route.
Sources
- Official sourceEuropean CommissionAdequacy decisions — current list
commission.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionStandard contractual clauses — including the still-unadopted set for importers subject to GDPR
commission.europa.eu
Link checked 18 August 2026
- Official sourceEuropean Data Protection BoardEDPB Guidelines 02/2024 on Article 48 — a foreign court order is not by itself a lawful basis to disclose
edpb.europa.eu
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
There are eighteen separate authorities. For a private company it is almost never the federal one. Each of the 16 states has its own regulator. You answer to the one where your German office is. The federal regulator handles government bodies plus telecoms and postal operators. Bavaria splits it further, with different bodies for private and public sector. If you operate across Europe, a separate rule helps. You can deal mainly with the regulator where your main European office sits.
Sources
- Official sourceBundesbeauftragter für den Datenschutz und die InformationsfreiheitCompetence of the Federal Commissioner — states plainly it is not competent for most private companies
bfdi.bund.de
How long you must keep it — and when to delete it
Some business records have a minimum. Accounting vouchers must be kept 8 years. That was cut from 10 years starting in 2025, and starting in 2026 for banks and insurers. Annual accounts and trading books must still be kept 10 years. Business correspondence must be kept 6 years. Privacy law pushes the other way. Do not keep personal data longer than you need it. Where the two clash, German law has a neat answer. You lock the data away so nobody can use it, instead of deleting it.
- What you have to do here:
- Keep data for a minimum period
Sources
- Official sourceBundesministerium der Justiz / Bundesamt für Justiz§ 257 HGB — commercial record retention periods
gesetze-im-internet.de
- Official sourceBundesministerium der Justiz / Bundesamt für Justiz§ 147 AO — tax record retention periods
gesetze-im-internet.de
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
You have 72 hours to tell your state regulator about a personal data breach. You must also tell the people affected without undue delay if the risk to them is high. Since December 2025 Germany's cyber security law adds its own clocks. It covers around 29,500 companies. They send a first warning within 24 hours. Then an update at 72 hours. Then a full report within a month. Financial firms follow a separate set of European rules instead.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Sources
- Official sourceBundesamt für Sicherheit in der InformationstechnikNIS2 implementation act in force from 6 December 2025
bsi.bund.de
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
There are four traps. First, health and social data really does have to stay in Europe. The cloud provider needs a specific German security certificate. The general answer that data can go anywhere is wrong here. Second, doctors, lawyers, tax advisers and notaries need more than a standard data protection contract. You need explicit secrecy promises passed down to every subcontractor. Breaking this is a crime, not a fine. Third, Germany still makes you appoint a data protection officer once 20 employees work with personal data. That is far stricter than European law. The government promised to scrap it by the end of 2026, but it is still in force. Fourth, people still cite an old German rule about employee data. Europe's top court struck it down in 2023. Nobody ever removed it from the law books. Using it as your legal basis is a mistake.
- What you have to do here:
- Extra vendor secrecy terms · Appoint a data protection officer · Keep the data in the country · Hold a security certificate
Sources
- Official sourceBundesministerium der Justiz / Bundesamt für Justiz§ 203 StGB — breach of professional secrecy, and the 2017 carve-out for IT service providers
gesetze-im-internet.de
- Official sourceBundesministerium der Justiz / Bundesamt für Justiz§ 38 BDSG — the 20-employee data protection officer threshold
gesetze-im-internet.de
- Official sourceCourt of Justice of the European UnionCJEU C-34/21 — German employee data provision incompatible with GDPR
curia.europa.eu
What's changing next
Two firm dates and one live risk. From 12 January 2027 every cloud provider must charge nothing for switching provider or moving your data out. Renegotiate your contracts now. By 31 December 2026 Germany's banking IT rulebook is fully withdrawn. European financial rules replace it. The live risk is the US arrangement. On 31 July 2026 Europe's data protection board asked the European Commission to review whether it is still valid. A separate court appeal is also pending. If it falls, thousands of transfers move to standard contracts overnight.
- What you have to do here:
- Make switching cloud provider possible
More is moving. Europe proposed a broad simplification package in November 2025. It would loosen the definition of personal data. It would stretch the breach deadline from 72 hours to 96 hours. It would create a single portal for reporting incidents. Europe's own regulators publicly opposed the core change in February 2026. So the outcome is uncertain. Germany's own reform bill passed one chamber in July 2026. A third attempt at a telecoms data retention law was approved by cabinet in April 2026. It is narrowed to IP addresses for three months.
Sources
- Official sourceEuropean CommissionData Act explained — switching charges and egress fees to zero from 12 January 2027
digital-strategy.ec.europa.eu
- Official sourceEuropean Data Protection BoardEDPB — 31 July 2026 letter to the Commission on the Data Privacy Framework
edpb.europa.eu
What to do: Diarise 12 January 2027 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries2 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Cloud and outsourcing rules
Official name: § 393 SGB V — Cloud-Einsatz im Gesundheitswesen · Act of parliament
This is Germany's real rule about keeping data in the country. It is also the one that matters most commercially. Health and social data can only be handled in the cloud in three places. Germany. The European Union or the wider European Economic Area. Or a country Europe has decided is safe enough. In that last case the provider needs a German office. The provider must hold a current C5 Type 2 certificate from Germany's Federal Office for Information Security. This covers health providers, insurers and the companies that work for them.
Enforced by Federal Commissioner for Data Protection and Freedom of Information
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision
What you have to do
- Keep the data in the countryGermany, the European Union or the wider European Economic Area, or a country Europe has decided is safe enough. In that last case only, the provider must have a German office.
- Hold a security certificate — from 1 July 2025You need a C5 Type 2 certificate from Germany's Federal Office for Information Security. Type 1 was enough only until 30 June 2025.
Sources
- Official sourceBundesministerium der Justiz / Bundesamt für Justiz§ 393 SGB V, official consolidated text
gesetze-im-internet.de
Link checked 18 August 2026
Cloud and outsourcing rules (Professional secrecy trades)
Official name: § 203 StGB — Verletzung von Privatgeheimnissen · Act of parliament
This is not about where data is stored. It is the trap that catches cloud deals with doctors, lawyers, tax advisers, auditors and notaries. Since 2017 you can outsource to IT providers. But only if secrecy promises are passed down the whole chain of suppliers. Getting it wrong is a crime, not a fine.
Enforced by Criminal courts
How this country controls where data goes: No restriction
What you have to do
- Extra vendor secrecy termsShare only what is needed. Bind the provider to secrecy in the contract. Make it bind its own subcontractors too. Then supervise it. A standard data protection contract does not satisfy this.
What it costs if you get it wrong
- Criminal liabilityThe professional commits an offence by failing to obligate the provider. The provider and its staff commit an offence by breaching.
Sources
- Official sourceBundesministerium der Justiz / Bundesamt für Justiz§ 203 StGB, official consolidated text
gesetze-im-internet.de
Applies to every company1 rule
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: § 38 BDSG — Datenschutzbeauftragte nicht-öffentlicher Stellen · Act of parliament
Germany adds this on top of European law. You must appoint a data protection officer once 20 employees work with personal data. Many people assume this was repealed. It was not.
Enforced by The 16 state data protection authorities
How this country controls where data goes: No restriction
What you have to do
- Appoint a data protection officer — applies at: 20 or more persons permanently engaged in automated processing of personal dataThis is stricter than European law, which has no employee-count trigger. The government committed in December 2025 to abolish it by 31 December 2026. As of August 2026 no bill had been introduced. It is still law.
Sources
- Official sourceBundesministerium der Justiz / Bundesamt für Justiz§ 38 BDSG, official consolidated text
gesetze-im-internet.de
Applies across the European Union2 rules
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Verordnung (EU) 2016/679 (Datenschutz-Grundverordnung) · Regulation (EU) 2016/679 · Directly binding regulation
This is the European baseline. It sets the conditions for data leaving Europe. It does not say where data must be stored. Fines are the higher of a fixed cap or a percentage of worldwide group turnover. That is a much bigger risk than countries with fixed-cap fines, like India.
Enforced by European Data Protection Board
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What you have to do
- Get consent
- Document a legitimate interest
- Tell people what you do
- Keep records of how you use data
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Assess high-risk projects
- Written vendor contract
- Appoint a representativeRequired if you have no office in the European Union.
- Put a transfer safeguard in placeYou must also write down a risk assessment for the transfer. That comes from the Schrems II court ruling.
- Do not hand data to foreign authorities on demandAn order from a government outside Europe is not on its own a legal reason to hand data over.
- Delete data after a period
- Get a parent's consent for children — applies at: 16 in Germany
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnover or €20,000,000, whichever is higher — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Percentage of global turnover: 2% of worldwide group turnover or €10,000,000, whichever is higher — about $11 millionController and processor obligations
- Order to stopRegulators can ban processing or suspend data flows to a third country — often more damaging than the fine
- Claims by individualsIndividuals can claim compensation, now a live mass-claims risk in Germany
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (GDPR), consolidated text
eur-lex.europa.eu
Cloud and outsourcing rules (2027)
Official name: Data Act — Regulation (EU) 2023/2854 · Directly binding regulation
This is not about where data sits. It is about being able to move it. From 12 January 2027 cloud providers must charge nothing for switching provider or moving your data out. That is a firm deadline. It affects every cloud contract directly.
That is a long gap: the duty is real law today, but no penalty can follow until 12 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.
Enforced by Federal Network Agency
How this country controls where data goes: No restriction
What you have to do
- Make switching cloud provider possible — from 12 January 2027All switching charges and data export fees must be zero from 12 January 2027. Notice is capped at 2 months. There is a 30-day changeover period.
- Do not hand data to foreign authorities on demandCloud providers must stop governments outside Europe reaching non-personal data held in Europe, where that would clash with European law. They must use technical, organisational and legal measures. This is the closest thing Europe has to an anti-surveillance rule for data that is not about people.
Sources
On the books, but not enforceable1 rule
These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.
Telecoms rules
Official name: §§ 175–181 TKG — Vorratsdatenspeicherung · Act of parliament
These telecoms data retention rules are still printed in the law. They cannot be enforced and are not enforced. A plain text search would report that Germany requires blanket retention. It does not. This shows why asking whether a rule is on the statute book is the wrong question.
Enforced by Federal Network Agency
How this country controls where data goes: Not allowed
What you have to do
- Keep logsNOT CURRENTLY ENFORCEABLE. European law overrides it. That follows the Court of Justice of the European Union ruling of 20 September 2022. It also follows the Federal Administrative Court decision of 14 August 2023. The telecoms regulator says on its own site that these rules no longer apply. It has stopped enforcing them.
Sources
- Official sourceBundesnetzagenturBundesnetzagentur — 'Damit sind die §§ 175 bis 181 TKG nicht mehr anwendbar'
bundesnetzagentur.de
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether new standard contract clauses for importers already subject to European law have been adopted very recently
The European Commission's own page still lists them as work in progress. That is strong evidence but not proof. Check the Commission's site before you rely on this.
The court case number for the pending appeal against the EU-US arrangement, and any hearing date
We could not confirm the case number or a hearing date from an official court source. Check the court's own records if this matters to you.
Whether the German data retention bill approved by cabinet in April 2026 has passed parliament
The bill had only reached government-bill stage. We could not confirm that parliament passed it. Check the German parliament's site before you rely on this.
Whether the German reform bill and the Data Act enforcement law have been enacted
Both bills were still going through parliament as of August 2026. We could not confirm that either became law. Check before you rely on them.
Whether any German fine since 2024 exceeds the EUR 35.26m record
We found no larger fine. Our source is a private tracker, not a regulator's own register. Treat the figure as a guide only.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.