Skip to the content
Global Data RulesData governance rules, country by country

Germany

Part of the European Union, so bloc-wide rules apply here too. Checked today.

The answer

Yes, with paperworkWork: HighEnforcement: Active

Contrary to widespread belief, neither Europe nor Germany requires personal data to be stored in Europe. What the law requires is a valid legal instrument before data leaves — an official decision that the destination is safe enough, or a standard contract, plus a documented risk assessment. Germany then adds its own layer on top, and one genuine hard wall: health and social data may only be processed in the cloud within Europe, by a provider holding a specific German security certificate.

Eight questions about Germany

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Germany's rules apply to my company?

Yes, it reaches you with no office in Germany. Europe's privacy law applies to any organisation anywhere that offers goods or services to people in Europe or monitors their behaviour. If you have no European establishment you must also appoint a representative inside Europe.

High confidenceBloc rulesAppoint a local representative

Can I store my users' data outside Germany?

Yes — with paperwork. This is the single most misunderstood point in the field. European law does not say where data must sit; it says what you must have in place before it leaves Europe. Storage location is a risk factor in that assessment, never a prohibition. For non-personal data, Europe goes further and actually forbids member states from imposing storage-location rules.

High confidenceYes, with paperwork

What do I need in place before data leaves Germany?

One of three routes. Best case, the destination is on Europe's official 'adequate' list and you need nothing extra — currently 17 entries including the UK, Japan, South Korea, Switzerland, Canada for commercial bodies, Brazil since January 2026, and the United States but only for companies self-certified under the EU-US Data Privacy Framework. Otherwise you sign Europe's standard contract clauses, or get group-wide internal rules approved. In either of those two cases you must also document an assessment of whether the destination country's surveillance laws undermine the protection.

High confidenceOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesAllowlist

Who enforces the rules in Germany, and what can they do?

Eighteen separate authorities, and for a private company it is almost never the federal one. Each of the 16 states has its own regulator, and you answer to the one where your German office is. The federal regulator handles government bodies plus telecoms and postal operators. Bavaria splits it further, with different bodies for private and public sector. If you operate across Europe, a separate rule lets you deal mainly with the regulator where your main European establishment sits.

High confidenceActive

How long do I have to keep the data?

Business records have a floor: accounting vouchers must be kept 8 years (cut from 10 with effect from 2025, and from 2026 for banks and insurers), the annual accounts and trading books still 10 years, and business correspondence 6 years. Privacy law pushes the other way — don't keep personal data longer than you need it. Where the two collide, German law has an elegant answer: you restrict processing of the data instead of deleting it.

High confidenceKeep data for a minimum periodDelete data after a period

What happens if there is a breach?

72 hours to tell your state regulator about a personal data breach, and without undue delay to tell affected people where the risk to them is high. Separately, since December 2025 Germany's cybersecurity law adds its own clocks for around 29,500 in-scope companies: a first warning within 24 hours, an update at 72 hours, and a full report within a month. Financial firms follow a separate European regime instead.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Germany?

Four. (1) Health and social data really does have to stay in Europe, with a specific German security certificate — the general 'no localisation' answer is wrong here. (2) For doctors, lawyers, tax advisers and notaries, a standard data processing agreement is NOT enough: you need explicit secrecy undertakings flowed down to every subcontractor, and breach is a criminal offence, not a fine. (3) Germany still requires a data protection officer at just 20 employees involved in data processing — far stricter than European law, and still in force despite a government promise to scrap it by the end of 2026. (4) The German rule people cite for employee data was effectively struck down by Europe's top court in 2023 but never removed from the statute book, so citing it as your legal basis is a mistake.

High confidenceExtra vendor secrecy termsAppoint a data protection officerKeep the data in the countryHold a security certificate

What is changing soon in Germany?

Two hard dates and one live risk. From 12 January 2027 every cloud provider must drop switching and data egress fees to zero — renegotiate contracts now. By 31 December 2026 Germany's banking IT rulebook is fully withdrawn in favour of the European financial regime. The live risk is the US arrangement: Europe's data protection board formally asked the Commission on 31 July 2026 to review whether it is still valid, and a separate court appeal is pending. If it falls, thousands of transfers move to standard contracts overnight.

High confidenceMake switching cloud provider possible

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    Bloc rules

    Made by a group of countries together. Applies inside every member country.

    2 rules here

  2. Layer 2

    National rules

    Added by this country on top of any bloc rules.

    1 rule here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    3 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

Bloc rules2 rules

Verordnung (EU) 2016/679 (Datenschutz-Grundverordnung)

Directly binding regulation · Regulation (EU) 2016/679

In forceYes, with paperwork

The European baseline. Regulates the conditions for data leaving Europe, not where it is stored. Fines are the higher of a fixed cap or a percentage of worldwide group turnover — a materially different risk shape from fixed-cap regimes like India's.

In force since 25 May 2018

Enforced by European Data Protection Board

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

High confidence

Data Act — Regulation (EU) 2023/2854

Directly binding regulation

In forceYes — store it anywhere

Not about where data sits, but about being able to move it. From 12 January 2027 cloud providers must charge nothing for switching or data egress — a hard deadline with direct commercial impact on every cloud contract.

In force since 12 September 2025But only enforceable from 12 January 2027

Enforced by Federal Network Agency

Transfer model: No restriction

High confidence

National rules1 rule

§ 38 BDSG — Datenschutzbeauftragte nicht-öffentlicher Stellen

Act of parliament

In forceYes — store it anywhere

Germany's own addition on top of European law: a data protection officer is mandatory at 20 employees involved in data processing. Widely assumed to have been repealed; it has not been.

In force since 25 May 2018

Enforced by The 16 state data protection authorities

Transfer model: No restriction

High confidence

Industry rules3 rules

§ 393 SGB V — Cloud-Einsatz im Gesundheitswesen

Act of parliament · Health and social care

In forceNo — it stays put

The genuine German data localisation rule, and the most commercially important one. Cloud processing of health and social data by providers, insurers and their processors is confined to Germany, the EU/EEA or an adequacy country with a German establishment, and requires a current BSI C5 Type 2 attestation.

In force since 1 January 2022

Enforced by Federal Commissioner for Data Protection and Freedom of Information

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision

High confidence

§ 203 StGB — Verletzung von Privatgeheimnissen

Act of parliament · Professional secrecy trades

In forceYes, with paperwork

Not a localisation rule, but the trap that catches cloud deals with doctors, lawyers, tax advisers, auditors and notaries. Since 2017 outsourcing to IT providers is lawful, but only if secrecy undertakings are flowed down the entire chain. Failure is criminal, not administrative.

In force since 9 November 2017

Enforced by Criminal courts

Transfer model: No restriction

High confidence

§§ 175–181 TKG — Vorratsdatenspeicherung

Act of parliament · Telecoms

UnenforceableNo — it stays put

A textbook example of why 'is it on the statute book?' is the wrong question. These telecoms data retention provisions are still printed in the law but are unenforceable and unenforced. A naive text search would report Germany as having blanket retention. It does not.

Enforced by Federal Network Agency

Transfer model: Not allowed

High confidence

Who you would hear from

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether new standard contract clauses for importers already subject to European law have been adopted very recently

    The Commission's own page still lists them as work in progress, which is strong but not conclusive.

  • The court case number for the pending appeal against the EU-US arrangement, and any hearing date

    Not verifiable from a primary source.

  • Whether the German data retention bill approved by cabinet in April 2026 has passed parliament

    It was at government-bill stage; passage not confirmed.

  • Whether the German reform bill and the Data Act enforcement law have been enacted

    Both were in the parliamentary process as of August 2026.

  • Whether any German fine since 2024 exceeds the EUR 35.26m record

    None found, but this rests on a secondary tracker rather than a regulator's own register.

30-day cadence, the shortest in the dataset. The EU-US transfer arrangement is under active challenge on two fronts and a suspension would invalidate the transfer answer for thousands of organisations within days. Any change there must be reflected fast or the site is actively misleading.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.