Germany
Part of the European Union, so bloc-wide rules apply here too. Checked today.
The answer
Contrary to widespread belief, neither Europe nor Germany requires personal data to be stored in Europe. What the law requires is a valid legal instrument before data leaves — an official decision that the destination is safe enough, or a standard contract, plus a documented risk assessment. Germany then adds its own layer on top, and one genuine hard wall: health and social data may only be processed in the cloud within Europe, by a provider holding a specific German security certificate.
Eight questions about Germany
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Germany's rules apply to my company?
Yes, it reaches you with no office in Germany. Europe's privacy law applies to any organisation anywhere that offers goods or services to people in Europe or monitors their behaviour. If you have no European establishment you must also appoint a representative inside Europe.
Sources
- Official sourcePublications Office of the European UnionGeneral Data Protection Regulation (EU) 2016/679, Articles 3 and 27
eur-lex.europa.eu
Can I store my users' data outside Germany?
Yes — with paperwork. This is the single most misunderstood point in the field. European law does not say where data must sit; it says what you must have in place before it leaves Europe. Storage location is a risk factor in that assessment, never a prohibition. For non-personal data, Europe goes further and actually forbids member states from imposing storage-location rules.
The exception that proves the rule: section 393 of the German Social Code is a real localisation requirement. Cloud processing of social and health data is permitted only in Germany, the EU/EEA, or a country covered by an official adequacy decision — and in that last case only where the provider has a German establishment. The provider must also hold a current BSI C5 attestation, and since 1 July 2025 a Type 2 attestation specifically. In practice this means a global cloud provider can serve German healthcare only through a European region, via a German legal entity, with that certificate.
Sources
- Official sourcePublications Office of the European UnionGDPR, Chapter V (Articles 44–50) — transfers, not storage location
eur-lex.europa.eu
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 on the free flow of non-personal data — prohibits member-state localisation rules
eur-lex.europa.eu
- Official sourceBundesministerium der Justiz / Bundesamt für Justiz§ 393 SGB V — Cloud-Einsatz im Gesundheitswesen (the real German localisation rule)
gesetze-im-internet.de
Link checked 18 August 2026
What do I need in place before data leaves Germany?
One of three routes. Best case, the destination is on Europe's official 'adequate' list and you need nothing extra — currently 17 entries including the UK, Japan, South Korea, Switzerland, Canada for commercial bodies, Brazil since January 2026, and the United States but only for companies self-certified under the EU-US Data Privacy Framework. Otherwise you sign Europe's standard contract clauses, or get group-wide internal rules approved. In either of those two cases you must also document an assessment of whether the destination country's surveillance laws undermine the protection.
Two live gaps worth knowing. First, there is still no purpose-built standard contract for sending data to a recipient who is already directly subject to European law — the Commission has been promising this set since 2024 and it had not appeared as of August 2026, so market practice is to use the 2021 clauses with the duplicative parts disapplied. Second, the US arrangement is under real pressure: on 31 July 2026 Europe's data protection board formally wrote to the Commission asking it to examine whether a US Supreme Court decision on the independence of the US enforcement agency undermines the arrangement's validity. It remains in force today. Do not build on it as your only route.
Sources
- Official sourceEuropean CommissionAdequacy decisions — current list
commission.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionStandard contractual clauses — including the still-unadopted set for importers subject to GDPR
commission.europa.eu
Link checked 18 August 2026
- Official sourceEuropean Data Protection BoardEDPB Guidelines 02/2024 on Article 48 — a foreign court order is not by itself a lawful basis to disclose
edpb.europa.eu
Who enforces the rules in Germany, and what can they do?
Eighteen separate authorities, and for a private company it is almost never the federal one. Each of the 16 states has its own regulator, and you answer to the one where your German office is. The federal regulator handles government bodies plus telecoms and postal operators. Bavaria splits it further, with different bodies for private and public sector. If you operate across Europe, a separate rule lets you deal mainly with the regulator where your main European establishment sits.
Sources
- Official sourceBundesbeauftragter für den Datenschutz und die InformationsfreiheitCompetence of the Federal Commissioner — states plainly it is not competent for most private companies
bfdi.bund.de
How long do I have to keep the data?
Business records have a floor: accounting vouchers must be kept 8 years (cut from 10 with effect from 2025, and from 2026 for banks and insurers), the annual accounts and trading books still 10 years, and business correspondence 6 years. Privacy law pushes the other way — don't keep personal data longer than you need it. Where the two collide, German law has an elegant answer: you restrict processing of the data instead of deleting it.
Sources
- Official sourceBundesministerium der Justiz / Bundesamt für Justiz§ 257 HGB — commercial record retention periods
gesetze-im-internet.de
- Official sourceBundesministerium der Justiz / Bundesamt für Justiz§ 147 AO — tax record retention periods
gesetze-im-internet.de
What happens if there is a breach?
72 hours to tell your state regulator about a personal data breach, and without undue delay to tell affected people where the risk to them is high. Separately, since December 2025 Germany's cybersecurity law adds its own clocks for around 29,500 in-scope companies: a first warning within 24 hours, an update at 72 hours, and a full report within a month. Financial firms follow a separate European regime instead.
Sources
- Official sourceBundesamt für Sicherheit in der InformationstechnikNIS2 implementation act in force from 6 December 2025
bsi.bund.de
What trips people up in Germany?
Four. (1) Health and social data really does have to stay in Europe, with a specific German security certificate — the general 'no localisation' answer is wrong here. (2) For doctors, lawyers, tax advisers and notaries, a standard data processing agreement is NOT enough: you need explicit secrecy undertakings flowed down to every subcontractor, and breach is a criminal offence, not a fine. (3) Germany still requires a data protection officer at just 20 employees involved in data processing — far stricter than European law, and still in force despite a government promise to scrap it by the end of 2026. (4) The German rule people cite for employee data was effectively struck down by Europe's top court in 2023 but never removed from the statute book, so citing it as your legal basis is a mistake.
Sources
- Official sourceBundesministerium der Justiz / Bundesamt für Justiz§ 203 StGB — breach of professional secrecy, and the 2017 carve-out for IT service providers
gesetze-im-internet.de
- Official sourceBundesministerium der Justiz / Bundesamt für Justiz§ 38 BDSG — the 20-employee data protection officer threshold
gesetze-im-internet.de
- Official sourceCourt of Justice of the European UnionCJEU C-34/21 — German employee data provision incompatible with GDPR
curia.europa.eu
What is changing soon in Germany?
Two hard dates and one live risk. From 12 January 2027 every cloud provider must drop switching and data egress fees to zero — renegotiate contracts now. By 31 December 2026 Germany's banking IT rulebook is fully withdrawn in favour of the European financial regime. The live risk is the US arrangement: Europe's data protection board formally asked the Commission on 31 July 2026 to review whether it is still valid, and a separate court appeal is pending. If it falls, thousands of transfers move to standard contracts overnight.
Also moving: a broad European simplification package proposed in November 2025 would loosen the definition of personal data, extend the breach deadline from 72 to 96 hours and create a single incident-reporting portal — but Europe's own regulators publicly opposed the core change in February 2026, so the outcome is genuinely uncertain. Germany's own reform bill passed one chamber in July 2026. A third attempt at a telecoms data retention law, narrowed to IP addresses for three months, was approved by cabinet in April 2026.
Sources
- Official sourceEuropean CommissionData Act explained — switching charges and egress fees to zero from 12 January 2027
digital-strategy.ec.europa.eu
- Official sourceEuropean Data Protection BoardEDPB — 31 July 2026 letter to the Commission on the Data Privacy Framework
edpb.europa.eu
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
Bloc rules
Made by a group of countries together. Applies inside every member country.
2 rules here
Layer 2
National rules
Added by this country on top of any bloc rules.
1 rule here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
3 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
Bloc rules2 rules
Verordnung (EU) 2016/679 (Datenschutz-Grundverordnung)
Directly binding regulation · Regulation (EU) 2016/679
The European baseline. Regulates the conditions for data leaving Europe, not where it is stored. Fines are the higher of a fixed cap or a percentage of worldwide group turnover — a materially different risk shape from fixed-cap regimes like India's.
Enforced by European Data Protection Board
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What it makes you do
- Get consent
- Document a legitimate interest
- Tell people what you do
- Keep records of processing
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Assess high-risk projects
- Written vendor contract
- Appoint a local representativeRequired where there is no EU establishment.
- Put a transfer safeguard in placePlus a documented transfer impact assessment after the Schrems II judgment.
- Do not hand data to foreign authorities on demandA third-country authority's order is not by itself a lawful basis to disclose.
- Delete data after a period
- Get a parent's consent for children — applies at: 16 in Germany
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnover or €20,000,000, whichever is higher — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Percentage of global turnover: 2% of worldwide group turnover or €10,000,000, whichever is higher — about $11 millionController and processor obligations
- Order to stopRegulators can ban processing or suspend data flows to a third country — often more damaging than the fine
- Claims by individualsIndividuals can claim compensation, now a live mass-claims risk in Germany
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (GDPR), consolidated text
eur-lex.europa.eu
Data Act — Regulation (EU) 2023/2854
Directly binding regulation
Not about where data sits, but about being able to move it. From 12 January 2027 cloud providers must charge nothing for switching or data egress — a hard deadline with direct commercial impact on every cloud contract.
Enforced by Federal Network Agency
Transfer model: No restriction
What it makes you do
- Make switching cloud provider possible — from 12 January 2027All switching charges and data egress fees must be zero from 12 January 2027. Maximum 2-month notice, 30-day transitional period.
- Do not hand data to foreign authorities on demandCloud providers must take technical, organisational and legal measures to prevent third-country government access to non-personal data held in Europe where that would conflict with EU law. The closest thing Europe has to an anti-overseas-surveillance provision for non-personal data.
Sources
National rules1 rule
§ 38 BDSG — Datenschutzbeauftragte nicht-öffentlicher Stellen
Act of parliament
Germany's own addition on top of European law: a data protection officer is mandatory at 20 employees involved in data processing. Widely assumed to have been repealed; it has not been.
Enforced by The 16 state data protection authorities
Transfer model: No restriction
What it makes you do
- Appoint a data protection officer — applies at: 20 or more persons permanently engaged in automated processing of personal dataStricter than European law, which has no headcount trigger. The government committed in December 2025 to abolish this by 31 December 2026, but as of August 2026 no bill had been introduced and it remains law.
Sources
- Official sourceBundesministerium der Justiz / Bundesamt für Justiz§ 38 BDSG, official consolidated text
gesetze-im-internet.de
Industry rules3 rules
§ 393 SGB V — Cloud-Einsatz im Gesundheitswesen
Act of parliament · Health and social care
The genuine German data localisation rule, and the most commercially important one. Cloud processing of health and social data by providers, insurers and their processors is confined to Germany, the EU/EEA or an adequacy country with a German establishment, and requires a current BSI C5 Type 2 attestation.
Enforced by Federal Commissioner for Data Protection and Freedom of Information
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision
What it makes you do
- Keep the data in the countryGermany, the EU/EEA, or an adequacy country — and in the adequacy case only where the provider has a German establishment.
- Hold a security certificate — from 1 July 2025BSI C5 Type 2 attestation required; Type 1 sufficed only until 30 June 2025.
Sources
- Official sourceBundesministerium der Justiz / Bundesamt für Justiz§ 393 SGB V, official consolidated text
gesetze-im-internet.de
Link checked 18 August 2026
§ 203 StGB — Verletzung von Privatgeheimnissen
Act of parliament · Professional secrecy trades
Not a localisation rule, but the trap that catches cloud deals with doctors, lawyers, tax advisers, auditors and notaries. Since 2017 outsourcing to IT providers is lawful, but only if secrecy undertakings are flowed down the entire chain. Failure is criminal, not administrative.
Enforced by Criminal courts
Transfer model: No restriction
What it makes you do
- Extra vendor secrecy termsDisclose only what is necessary; contractually bind the provider to secrecy; oblige it to bind its own subcontractors; supervise. A standard data processing agreement does not satisfy this.
What it costs if you get it wrong
- Criminal liabilityThe professional commits an offence by failing to obligate the provider. The provider and its staff commit an offence by breaching.
Sources
- Official sourceBundesministerium der Justiz / Bundesamt für Justiz§ 203 StGB, official consolidated text
gesetze-im-internet.de
§§ 175–181 TKG — Vorratsdatenspeicherung
Act of parliament · Telecoms
A textbook example of why 'is it on the statute book?' is the wrong question. These telecoms data retention provisions are still printed in the law but are unenforceable and unenforced. A naive text search would report Germany as having blanket retention. It does not.
Enforced by Federal Network Agency
Transfer model: Not allowed
What it makes you do
- Keep logsNOT CURRENTLY ENFORCEABLE. Disapplied by primacy of EU law after the CJEU ruling of 20 September 2022 and the Federal Administrative Court decision of 14 August 2023. The telecoms regulator states on its own site that the provisions are no longer applicable and has ceased enforcement.
Sources
- Official sourceBundesnetzagenturBundesnetzagentur — 'Damit sind die §§ 175 bis 181 TKG nicht mehr anwendbar'
bundesnetzagentur.de
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether new standard contract clauses for importers already subject to European law have been adopted very recently
The Commission's own page still lists them as work in progress, which is strong but not conclusive.
The court case number for the pending appeal against the EU-US arrangement, and any hearing date
Not verifiable from a primary source.
Whether the German data retention bill approved by cabinet in April 2026 has passed parliament
It was at government-bill stage; passage not confirmed.
Whether the German reform bill and the Data Act enforcement law have been enacted
Both were in the parliamentary process as of August 2026.
Whether any German fine since 2024 exceeds the EUR 35.26m record
None found, but this rests on a secondary tracker rather than a regulator's own register.
30-day cadence, the shortest in the dataset. The EU-US transfer arrangement is under active challenge on two fronts and a suspension would invalidate the transfer answer for thousands of organisations within days. Any change there must be reflected fast or the site is actively misleading.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.