-
Software – How are proprietary rights in software and associated materials protected?
In Germany, proprietary rights in software and associated materials are protected through several mechanisms:
– First and foremost, Computer programs (including drafts and preparatory design materials) are protected under the German Copyright Act (UrhG) if they constitute individual works in the sense that they are the result of their author’s own intellectual creation. Ideas and principles underlying any element of the program, including its interfaces, are as such not eligible for protection (cf. Section 69a UrhG, which is based on Directive (EU) 2009/24/EC). As soon as new software that is eligible for copyright protection comes into existence, it is automatically (i.e. without any formal process to register the right) protected under the law.
– Computer programs “as such” are not eligible for patent protection, but inventions related to computer programs can potentially qualify for patent protection. Due to this high threshold, patent law in practice typically has rather limited impact on protecting computer programs.
– Software-related technical inventions may also fall within the scope of the German Employee Inventions Act if they are patentable or eligible for utility model protection.
-
Software – In the event that software is developed by a software developer, consultant or other party for a customer, who will own the resulting proprietary rights in the newly created software in the absence of any agreed contractual position?
Under German law, the ownership of proprietary rights in software developed by a third party is not automatically vested in the customer. As software is typically classified as a creative work, the initial ownership of the copyright rests with the author(s). The customer may acquire exclusive rights of use regarding the program – but not the actual copyright itself.
In the absence of any contractual provision, it depends on the context to what extent the customer automatically receives such rights of use. Here are two key rules:
– To allow employers to fully exploit programs created within an employment relationship, Section 69b of the German Copyright Act (UrhG) states that the employer alone is entitled to exercise all economic rights in the computer program that employed programmers have created in the performance of their duties or in accordance with their employer’s instructions. This statutory rule, however, typically does not apply to programmers who work as freelancers.
– Section 31 (5) of the German Copyright Act (UrhG) is a pivotal regulation that interprets the extent of usage rights in the software granted to the customer based on the intended purpose of the contract when there are no clear contractual rules. It safeguards the author’s interests by ensuring they retain as many rights of use as possible without frustrating the underlying goals of the contract.
-
Software – Are there any specific laws that govern the harm / liability caused by Software / computer systems?
In Germany, the legal framework regarding harm/liability caused by software is currently primarily governed by two main laws:
– The German Civil Code (Bürgerliches Gesetzbuch – BGB) contains general rules about contractual and tortious liability, which can be applied if software causes damage.
– Additionally, claims for damages may arise under the German Product Liability Act (Produkthaftungsgesetz) where a defective product causes personal injury or damage to property that is ordinarily intended and used for private purposes. Whether standalone software qualifies as a product is disputed under the current Act. The revised EU Product Liability Directive (Directive (EU) 2024/2853) must be transposed by 9 December 2026 and expressly includes software, including AI systems, irrespective of the mode of provision. The German implementation legislation had passed the Bundestag but had not yet entered into force. Under the revised regime, the circle of potentially liable economic operators will be broadened, the existing aggregate liability cap will be abolished, and disclosure and evidentiary rules will facilitate certain claims. The new rules are intended to apply to products placed on the market or put into service from 9 December 2026.
– The proposed EU AI Liability Directive, which was intended to establish a uniform set of rules for fault-based non-contractual civil liability for damages caused by AI systems, was withdrawn by the European Commission in early 2025. Liability for AI-related harm will therefore, for the time being, continue to be governed by the general rules of the BGB and the (reformed) product liability regime.
-
Software – To the extent not covered by (3) above, are there any specific laws that govern the use (or misuse) of software / computer systems?
Sections 69a-69g of the Copyright Act (UrhG) contain specific rules on restricted acts when using software. This includes for instance restrictions on modifications or the distribution of computer programs, but also certain special rights for the licensee concerning, i.a.,
– back-up copies,
– text and data mining, and
– decompilation.Some of these rights cannot be circumvented by deviating contractual provisions (cf. Section 69g Copyright Act).
Sections 31 et seq. of the Copyright Act contain rules on how rights of use in software are granted by authors. These rules are important, for example, when drafting end-user licence agreements (EULAs), as mandatory statutory provisions may limit the parties’ contractual freedom. The copyright holder may grant simple or exclusive rights of use and may limit them geographically, temporally or by reference to the permitted type or purpose of use.
Furthermore, the new Sections 327 et seq. of the German Civil Code (BGB), which implement the EU Directive 2019/770/EU, regulate the contractual aspects of providing digital content and services. They mainly apply to contracts between businesses and consumers (B2C) but may also allow for B2B recourse in contracts for digital products within the commercial supply chain.
Finally, there are several criminal offenses related to the misuse of software. For example, Section 303b of the Criminal Code (StGB) addresses computer sabotage. The criminal offenses of spying on data (Section 202a of the German Criminal Code), interception of data (Section 202b of the German Criminal Code) and computer fraud (Section 263a of the German Criminal Code) can also be relevant.
-
Software Transactions (Licence and SaaS) – Other than as identified elsewhere in this overview, are there any technology-specific laws that govern the provision of software between a software vendor and customer, including any laws that govern the use of cloud technology?
There are no technology-specific laws that govern the provision of software between a vendor and customer. The civil law classification under German law usually depends on the type of contract. Depending on the use and creation of the software, the provisions of the purchase contract, work contract, services contract or leasing contract may be applicable. Different regulations govern customer warranties in the event of defects. In addition, some laws are applicable depending on the parties involved, such as Sections 327 et seq. BGB in the case of consumer contracts for the provision of digital content and services.
There are however some sector-specific regulations that govern the usage of cloud-based services, especially in the context of outsourcing (see question 9).
-
Software Transactions (License and SaaS) – Is it typical for a software vendor to cap its maximum financial liability to a customer in a software transaction? If ‘yes’, what would be considered a market standard level of cap?
German law permits contractual limitations of liability, but standard terms are subject to the strict fairness and transparency requirements of Sections 307 et seq. BGB, including in B2B transactions. Liability for ordinary negligence is commonly excluded except in cases involving material contractual obligations; for breaches of such obligations, liability is typically limited to the foreseeable loss typical of the contract. Aggregate monetary caps can be enforceable if they are transparent and provide an adequate level of protection in light of the contractual risks. There is no fixed statutory or uniform market-standard cap. In negotiated SaaS transactions, a common commercial starting point is the fees paid or payable during the preceding twelve months, or a multiple of annual fees, with separate caps or exclusions for specific risk categories.
-
Software Transactions (License and SaaS) – Please comment on whether any of the following areas of liability would typically be excluded from any financial cap on the software vendor’s liability to the customer or subject to a separate enhanced cap in a negotiated software transaction (i.e. unlimited liability): (a) confidentiality breaches; (b) data protection breaches; (c) data security breaches (including loss of data); (d) IPR infringement claims; (e) breaches of applicable law; (f) regulatory fines; (g) wilful or deliberate breaches; (h) claims arising out of or in relation to artificial intelligence.
(a): Confidentiality breaches are sometimes subject to a separate enhanced cap or, less frequently, excluded from the general cap. Contractual penalties may also be agreed, particularly for reciprocal confidentiality obligations, but their amount and drafting are subject to the rules on standard terms and they are commonly credited against any damages claim.
(b) and (c): Data protection and data security breaches are frequently subject to a separate enhanced cap rather than unlimited liability. The agreed allocation depends, in particular, on the parties’ respective GDPR roles, the sensitivity and volume of the data, the security obligations assumed and available insurance coverage. Loss of data may also be subject to specific rules on back-ups and recoverability.
(d), (e) and (f): IPR infringement claims are often addressed through a separate indemnity and may be subject to an enhanced cap. General breaches of applicable law are not usually treated as a standalone uncapped category. Regulatory fines require particular care: their allocation is negotiated on a case-by-case basis, and the enforceability of an obligation to reimburse punitive or personal fines may be restricted by mandatory law or public policy.
(g): A debtor cannot exclude or limit in advance its liability for its own wilful misconduct (Section 276 (3) BGB). The position regarding wilful misconduct by legal representatives or other persons used to perform the contract must additionally be assessed under Section 278 sentence 2 BGB and the applicable rules on standard terms.
(h): Liability arising out of or in relation to the use of artificial intelligence is not yet an established, separate category in German cap regimes. In practice, AI-related risks are typically allocated through the existing categories – in particular IPR indemnities (e.g. for infringing AI output), data protection liability and warranties regarding the quality of AI-generated results. In more recent negotiated transactions, customers increasingly request unlimited liability or enhanced caps for breaches of AI-specific obligations (such as compliance with the EU AI Act or restrictions on the use of customer data for training purposes), while vendors seek to keep such claims within the general cap. A clear market standard has not yet emerged.
-
Software Transactions (License and SaaS) – Is it normal practice for software source codes to be held in escrow for the benefit of the software licensee? If so, who are the typical escrow providers used? Is an equivalent service offered for cloud-based software?
In Germany, source-code escrow is the exception rather than standard practice. It is most commonly considered for bespoke or business-critical software, products supplied by smaller vendors, or situations in which the customer’s continued operations depend on access to the source code. The escrow agent may be a specialised commercial provider, a notary or a law firm; there is no single dominant provider in the German market. For cloud-based software, continuity arrangements may extend beyond source code to deployment scripts, configuration data, technical documentation, access credentials and, in some cases, a replicated operating environment. The usefulness of any escrow arrangement depends substantially on appropriate deposit, verification, updating and release procedures.
-
IT Outsourcing – Other than as identified elsewhere in this questionnaire, are there any specific technology laws that govern IT outsourcing transactions?
IT outsourcing is typically governed in sector-specific laws, in particular regarding the financial sector. These regulations are delineated in various provisions such as Section 25b of the Banking Act (KWG), Section 26 of the Payment Services Supervision Act (ZAG), Section 80 (6) of the Securities Trading Act (WpHG) or Section 32 of the Insurance Supervision Act (VAG).
Regulators such as the Federal Financial Supervisory Authority (BaFin) and the Federal Office for Information Security (BSI) have issued detailed guidelines on how they interpret statutory requirements regarding IT outsourcing, IT security and cloud services.
The EU Digital Operational Resilience Act (DORA), which governs ICT risk management, incident reporting and the oversight of ICT third-party providers in the financial sector, has applied since 17 January 2025 and has become a central framework for IT outsourcing in that sector; financial entities must, i.a., ensure that their contracts with ICT service providers contain the mandatory provisions set out in Article 30 DORA. In addition, managed IT service providers and other digital service providers may themselves fall within the scope of the recast BSIG implementing the NIS 2 Directive (see the Cybersecurity section below), which is increasingly relevant in outsourcing due diligence and contract negotiations.
-
IT Outsourcing – Please summarise the principal laws (present or impending), if any, that protect individual staff in the event that the service they perform is transferred to a third party IT outsource provider, including a brief explanation of the general purpose of those laws.
German labour law imposes strict regulations on terminating employment contracts, which might occur in cases of outsourcing. If the Protection Against Dismissal Act (KSchG) applies, the employer may only terminate an employment contract if it is “socially justified”. This means the termination must be based on reasons related to the employee’s conduct, personal circumstances, or compelling operational requirements that prevent the continued employment of the employee in the business. If the termination is due to operational reasons, such as business reorganisation, the employer typically must apply correct “social” criteria to determine which employees to let go. Certain categories of employees, such as pregnant employees or members of the works council, enjoy enhanced protection against dismissal.
Individual staff members may also be protected by rights of a works council under the Works Constitution Act (BetrVG). For instance, the employer may have to inform the works council fully and in good time of proposed operational changes that may entail substantial disadvantages for employees and consult the works council on the proposed changes (Section 111 BetrVG).
Furthermore, an IT outsourcing may constitute a transfer of an undertaking or part of an undertaking within the meaning of Section 613a BGB if an economic entity is transferred while retaining its identity. If the provision applies, the transferee succeeds by operation of law to the existing employment relationships attributable to the transferred entity. A dismissal by the former employer or the transferee solely because of the transfer is ineffective (Section 613a (4) BGB); dismissals for other reasons remain possible subject to the general requirements of employment law.
-
Telecommunications – Please summarise the principal laws (present or impending), if any, that govern telecommunications networks and/or services, including a brief explanation of the general purpose of those laws.
Telecommunications networks and services are mainly regulated in the Telecommunications Act (TKG). The purpose of the TKG is to promote competition in the telecommunications sector and efficient telecommunications infrastructures through technology-neutral regulation and to ensure adequate and sufficient services nationwide (Section 1 (1) TKG). The TKG contains regulations on market regulation, access regulation, fee regulation, abuse prevention, customer protection, information on infrastructure and network expansion, frequency regulation as well as public safety and emergency preparedness.
The Telecommunications Digital Services Data Protection Act (TDDDG) contains, i.a., special provisions on the protection of personal data and privacy when using telecommunications services, in particular regarding confidentiality of telecommunications and the use of traffic or location data.
Supplementary to the aforementioned laws, a multitude of regulations exist that cover distinct elements of telecommunications. The overarching purpose of these regulatory instruments is to facilitate the efficient functioning of telecommunications services, safeguard the rights of consumers and guarantee the security of information technology systems.
-
Telecommunications – Please summarise any licensing or authorisation requirements applicable to the provision or receipt of telecommunications services in your country. Please include a brief overview of the relevant licensing or authorisation regime in your response.
The provision of telecommunications services in Germany is subject to a general authorisation regime under the TKG. Since the liberalisation of the telecommunications sector, the operation of public telecommunications networks and the provision of publicly available telecommunications services does not require an individual licence but instead requires a prior notification to the Federal Network Agency (Bundesnetzagentur) in accordance with Section 5 (1) TKG.
This notification must include, i.a., the name and address of the undertaking, a description of the intended activity, and the planned date of commencement. Upon successful notification, the undertaking is entered into a public register and becomes subject to the general regulatory framework, including transparency obligations, customer protection measures, and network integrity requirements (cf. Section 5 (4) TKG).
Number-independent interpersonal telecommunications services (such as email services or messenger services) are expressly exempted from the notification requirement under Section 5 TKG.
In contrast, the use of scarce public resources, such as radio frequencies and numbering resources, remains subject to individual rights of use. Such rights must be formally granted by the Bundesnetzagentur in accordance with Sections 91 et seq. TKG (frequency usage rights) and Sections 108 et seq. TKG (number allocation). Depending on the spectrum, allocation may take place via administrative procedures or competitive processes, such as public tenders or auctions (cf. Section 100 TKG).
Cross-border provision within the European Economic Area benefits from the harmonised framework of the European Electronic Communications Code, but this does not create a general passport that disapplies national notification requirements. A provider that commercially operates a public telecommunications network or provides a publicly available telecommunications service in Germany must assess whether a notification under Section 5 TKG is required, irrespective of its place of establishment. The TKG does not impose a general requirement on non-EEA telecommunications providers to appoint an EU legal representative; any representative requirement must be derived from the specific legislation applicable to the service.
-
Telecommunications – Please summarise the principal laws (present or impending) that govern access to communications data by law enforcement agencies, government bodies, and related organisations. In your response, please outline the scope of these laws, including the types of data that can typically be requested, how these laws are applied in practice (e.g., whether requests are confidential, subject to challenge, etc.), and any legal or procedural safeguards that apply.
Access to communications data by public authorities in Germany is governed by various national laws, particularly the TKG, the TDDDG, and the German Code of Criminal Procedure (Strafprozessordnung – StPO). These laws distinguish between different categories of data, such as customer data, traffic data, location data and content data, each subject to specific access and safeguard requirements.
Pursuant to Section 3 TDDDG, telecommunications secrecy is protected as a fundamental principle. Access is nevertheless permitted under specific statutory authorisations. Sections 173 and 174 TKG regulate, respectively, automated and manual subscriber-data disclosure procedures on the provider side. In criminal proceedings, the relevant authorising provisions include Section 100j StPO for subscriber data and Section 100g StPO for traffic and location data. Preventive access may be based on the applicable federal or state police and intelligence legislation. The applicable thresholds and procedural safeguards vary according to the type of data and the purpose of the measure.
The interception and recording of communications content are authorised, in criminal proceedings, primarily under Section 100a StPO and are generally subject to a judicial order, a catalogue offence and strict necessity and proportionality requirements. Sections 170 et seq. TKG regulate corresponding technical and organisational obligations of telecommunications providers.The statutory provisions on general traffic-data retention are currently not applied following decisions of the Federal Constitutional Court and the Court of Justice of the European Union. Current Section 100g StPO governs access to traffic data. Proposals concerning targeted preservation orders and the retention of IP address data have been the subject of legislative debate; their status should therefore be checked at the relevant editorial cut-off.
Access requests are typically confidential and not disclosed to the data subjects during ongoing investigations. However, affected individuals must in principle be informed ex post unless an exemption applies. Legal remedies are available, including court proceedings and constitutional complaints. In addition, oversight is ensured through data protection authorities, judicial review and, in the case of intelligence-related access, through dedicated parliamentary control bodies.
-
Telecommunications – Please summarise the principal laws (present or impending) that impose cyber security and/or operational resiliency obligations applicable to the operation of telecommunications infrastructure and/or provision of telecommunications services.
Sector-specific cybersecurity obligations for telecommunications are primarily set out in the TKG. Pursuant to Sections 165 et seq. TKG, providers of telecommunications services and operators of public telecommunications networks must implement appropriate technical and organisational measures – taking into account the state of the art – to protect the confidentiality of telecommunications and personal data and to safeguard their systems against disruptions and unauthorised access. Operators of public telecommunications networks and providers of publicly available telecommunications services must, i.a., appoint a security officer, prepare a security concept and, in the case of operators with increased risk exposure, deploy systems for attack detection. The details are specified in a catalogue of security requirements issued by the Federal Network Agency (Bundesnetzagentur) in agreement with the Federal Office for Information Security (BSI) and the Federal Commissioner for Data Protection. Security incidents with significant impact must be reported to the Bundesnetzagentur and the BSI. For the use of critical components in telecommunications networks (in particular 5G networks), certification requirements apply and the deployment of components of untrustworthy manufacturers may be prohibited on public security grounds.
In addition, the German NIS 2 implementation act (NIS2UmsuCG), which entered into force on 6 December 2025 and comprehensively recast the BSIG, has extended the general cybersecurity regime to the telecommunications sector: operators of public telecommunications networks and providers of publicly available telecommunications services now generally qualify as “particularly important” or “important” entities under the new BSIG, largely irrespective of their size. To avoid duplication, the sector-specific security and reporting requirements of the TKG – which have been aligned with the risk management requirements of the new BSIG – continue to apply as lex specialis, and certain general BSIG obligations are disapplied for such providers.
With regard to operational resilience beyond IT security, the KRITIS umbrella act (KRITIS-Dachgesetz), which entered into force on 17 March 2026 and implements the EU Critical Entities Resilience Directive (CER), imposes obligations concerning the physical resilience of critical infrastructure, including telecommunications: operators of critical facilities must, i.a., carry out risk assessments, implement resilience measures and report significant incidents, with the Federal Office of Civil Protection and Disaster Assistance (BBK) acting as the central competent authority.
-
Mobile communications and connected technologies – What are the principle standard setting organisations (SSOs) governing the development of technical standards in relation to mobile communications and newer connected technologies such as digital health or connected and autonomous vehicles?
The Federal Network Agency (Bundesnetzagentur) is the principal German telecommunications regulator, but it is not itself a standard-setting organisation. Relevant standards are developed at international, European and national level by bodies including the International Telecommunication Union (ITU), the 3rd Generation Partnership Project (3GPP), the European Telecommunications Standards Institute (ETSI), ISO and IEC, CEN and CENELEC, and the German organisations DIN and DKE. Additional sector-specific bodies are relevant depending on the use case, for example oneM2M and IEEE for connected devices, HL7 for digital health interoperability and UNECE working groups for connected and automated vehicles.
– Mobile communications:
The 3rd Generation Partnership Project (3GPP) is a global cooperation between standardisation bodies which includes the ETSI (European Telecommunications Standards Institute, a leading SSO in Europe). In 2019, 3GPP for instance published an initial package of 5G specifications.
Recently, global research activities on 6G have gained significant momentum. In the radio sector of the International Telecommunication Union (ITU-R), initial work on 6G was launched in March 2021, the results of which will be incorporated into 3GPP in the future.
– Connected technologies:
Machine-to-machine (M2M) communication refers to technologies that for instance enable automated exchange of data between devices. It encompasses various application areas such as e-health or automotive technology communication and plays a significant role in the Internet of Things (IoT). The standardisation of M2M is handled by different committees that focus on specific fields of application. OneM2M, a global partnership for standardisation of M2M, includes, i.a., the European SSO ETSI.
Dedicated Short Range Communication (DSRC) is one of the technologies that can be used in vehicles for collision avoidance, congestion reporting or toll collection. Current standardisation activities on this topic are taking place at ETSI and 3GPP, among others.
Intensive standardisation work has been going on at ETSI for several years in the area of Reconfigurable Radio Systems (RRS), which are expected to offer the possibility to support the needs of our networked world – including the Internet of Things (IoT) – e.g. by sharing frequencies between different services.
The applicable standards landscape is use-case specific and evolves rapidly. In addition to information published by the Bundesnetzagentur, the work programmes and standards databases of the relevant international, European and sector-specific standardisation bodies should therefore be consulted.
-
Mobile communications and connected technologies – How do technical standards facilitating interoperability between connected devices impact the development of connected technologies?
Technical standards facilitating interoperability between connected devices are crucial for the development of connected technologies. They play a vital role in ensuring seamless communication, fostering innovation, and driving market growth.
Key legal frameworks in Germany include the Telecommunications Act (TKG), the Act on Electromagnetic Compatibility of Equipment (EMVG), and the Radio Equipment Act (FuAG). These laws transpose EU directives into national legislation and provide the legal basis for technical standards and interoperability requirements.
For a comprehensive overview of relevant technical standards, the Federal Network Agency (Bundesnetzagentur) website serves as a valuable resource, offering information on standards, regulatory requirements, and developments in connected technologies and telecommunications.
-
Data Protection – Please summarise the principal laws (present or impending), if any, that govern data protection, including a brief explanation of the general purpose of those laws.
Data protection in Germany is primarily governed by the EU General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG). The Telecommunications Digital Services Data Protection Act (TDDDG) additionally regulates telecommunications secrecy and data protection for telecommunications and digital services.
The GDPR ensures that personal data is processed lawfully (see Article 6 GDPR), fairly and in a transparent manner for specified purposes and imposes various obligations on companies. They must maintain records of processing activities (Article 30 GDPR), providing a comprehensive overview of their data processing operations. In case of data breaches, controllers are required to notify the supervisory authority and, in certain cases, the affected individuals (Article 33, 34 GDPR). Companies must implement appropriate technical and organisational measures to ensure data security (Article 32 GDPR), which may include encryption, regular testing, and measures to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems. In many cases, organisations are required to appoint a data protection officer (Article 37 GDPR) to oversee compliance and act as a point of contact for data subjects and supervisory authorities. Transfers of personal data to third countries outside the EU/EEA are subject to strict requirements (Chapter V GDPR), often necessitating appropriate safeguards such as standard contractual clauses or binding corporate rules.
The GDPR also grants data subjects extensive rights, including the right to information, access, rectification, erasure, and data portability.
The BDSG complements the GDPR, providing specific local rules for data processing by public bodies and addressing particular processing situations. The TDDDG focuses on the protection of privacy in telecommunications and digital services, such as restrictions on storing information on user devices (Section 25 TDDDG).
-
Data Protection – What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable data protection laws?
The maximum sanctions for data protection breaches are primarily set by the GDPR. For the most serious infringements, fines can reach up to EUR 20 million or 4% of the total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83 (5) GDPR). Less severe breaches may incur fines up to EUR 10 million or 2% of annual turnover (Article 83 (4) GDPR). The German Federal Data Protection Act (BDSG) also provides for criminal penalties in certain cases, including imprisonment up to three years (Section 42 BDSG). Additionally, the TDDDG allows for fines up to EUR 300,000 for specific telecommunications and digital services-related infringements (Section 28 (2) TDDDG).
-
Data Protection – What data protection rules are relevant to technology contracts in your country? Do they typically refer to external data protection regimes, e.g. EU GDPR or CCPA, even where the contract has no clear international element?
Data protection is one of the key regulatory topics in technology contracts. Where a vendor processes personal data on behalf of a customer – which is regularly the case in SaaS, cloud and IT outsourcing arrangements – the parties must conclude a data processing agreement that satisfies the mandatory content requirements of Article 28 GDPR. Depending on the setup, joint controllership arrangements (Article 26 GDPR) or the rules on international data transfers (Chapter V GDPR, e.g. the EU standard contractual clauses) may also need to be addressed. In addition, the TDDDG is relevant for technologies involving the storage of or access to information on end users’ terminal equipment (Section 25 TDDDG).
Technology contracts in Germany usually contain a general obligation to comply with the data protection laws applicable to the relevant processing activities. Whether an individual data protection obligation constitutes a material or ‘cardinal’ contractual obligation depends on the nature and purpose of the specific contract and should not be assumed in the abstract. Purely domestic agreements do not normally need to refer to foreign regimes such as the CCPA. International contract templates, however, often define ‘Applicable Data Protection Law’ broadly and may expressly include the GDPR, the UK GDPR and relevant US state privacy laws where those regimes may apply. Data processing agreements under Article 28 GDPR typically contain more detailed provisions on processing instructions, security, sub-processors, data-subject rights, audits, breach notification and international transfers.
-
Cybersecurity – Please summarise the principal laws (present or impending), if any, that govern cybersecurity (to the extent they differ from those governing data protection), including a brief explanation of the general purpose of those laws.
Cybersecurity regulation in Germany is governed by a distinct legal framework that complements data protection laws such as the GDPR and the Telecommunications Digital Services Data Protection Act (TDDDG). The core legislation is the Act on the Federal Office for Information Security (Gesetz über das Bundesamt für Sicherheit in der Informationstechnik – BSIG), which was comprehensively recast with effect from 6 December 2025 by the NIS 2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG), transposing the EU NIS 2 Directive (Directive (EU) 2022/2555) into German law.
The new BSIG significantly expands the scope of cybersecurity regulation from roughly 4,500 to an estimated 29,500 entities across 18 sectors. In-scope entities are categorised as “particularly important entities” (besonders wichtige Einrichtungen) and “important entities” (wichtige Einrichtungen), primarily based on sector and size thresholds; operators of critical infrastructure (KRITIS) form a subcategory of particularly important entities. In-scope entities are subject to three core sets of obligations: registration with the BSI, reporting of significant security incidents (see below), and the implementation and documentation of appropriate risk management measures covering, i.a., incident handling, business continuity, supply chain security, encryption, access control and security training. The management of in-scope entities is personally responsible for approving and monitoring the implementation of these measures and must attend regular training; this responsibility cannot be delegated.
Complementing the cybersecurity framework, the KRITIS umbrella act (KRITIS-Dachgesetz), which implements the EU Critical Entities Resilience Directive (CER) and entered into force on 17 March 2026, addresses the physical resilience of operators of critical infrastructure. It requires, i.a., risk assessments, resilience plans, minimum physical protection measures and the reporting of significant incidents, and designates the Federal Office of Civil Protection and Disaster Assistance (BBK) as the central competent authority.
At the product level, the EU Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) introduces horizontal cybersecurity requirements for products with digital elements, including mandatory “security by design”, vulnerability handling and update obligations. Manufacturers’ obligations to report actively exploited vulnerabilities and severe incidents will apply from 11 September 2026, and the main obligations from 11 December 2027.
Other relevant cybersecurity provisions can be found in sector-specific regulations. The Telecommunications Act (TKG), for instance, imposes security obligations on telecommunications network and service providers, including requirements on availability, integrity and reporting of disruptions (cf. Section 165 TKG). In the financial sector, the Digital Operational Resilience Act (DORA) has been in effect since 17 January 2025 and imposes detailed ICT risk management and incident reporting obligations on financial institutions and designated ICT third-party providers.
-
Cybersecurity – What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable cybersecurity laws?
Under the recast BSIG, the maximum sanctions depend on the category of the entity and the nature of the infringement (cf. Section 65 BSIG). For particularly important entities, fines can reach up to EUR 10 million or 2% of the total worldwide annual turnover of the preceding financial year, whichever is higher; for important entities, the maximum is EUR 7 million or 1.4% of the total worldwide annual turnover. Fines may be imposed, i.a., for failure to register, failure to report significant security incidents, or failure to implement or document the required risk management measures; an actual security incident is not necessarily required. Management bodies have statutory approval, monitoring and training duties. Breaches may result in supervisory or administrative consequences and, depending on the circumstances, internal liability under corporate law; the precise basis and scope of any personal liability must be assessed separately.
Sector-specific legislation may provide for additional or parallel sanctions. For example, under the Telecommunications Act (TKG), the Federal Network Agency (Bundesnetzagentur) may impose fines for breaches of IT security-related obligations by network and service providers (cf. Section 228 TKG), and breaches of DORA requirements in the financial sector can trigger supervisory measures and fines under the applicable financial supervisory laws. Where a cybersecurity incident also involves a personal data breach, fines under the GDPR (up to EUR 20 million or 4% of worldwide annual turnover) may apply in parallel.
-
Cybersecurity – Are there any cybersecurity regulatory frameworks in your jurisdiction which require registration for certain sectors or services?
Yes. Under the recast BSIG, particularly important entities and important entities must register with the BSI within three months of qualifying as such, providing information on, i.a., their sector, contact details and public IP ranges (Section 33 BSIG). Certain providers of digital infrastructure and digital services – such as DNS service providers, top-level domain name registries, cloud computing service providers, data centre service providers, content delivery networks, managed (security) service providers and providers of online marketplaces, online search engines and social networks – are subject to a special registration regime (Section 34 BSIG). The BSI’s registration portal has been available since 6 January 2026; for entities that were already in scope when the new BSIG entered into force, the registration deadline expired on 6 March 2026. Failure to register constitutes an administrative offence subject to fines.
Separate registration and notification requirements apply under other regimes: operators of critical facilities must register under the KRITIS-Dachgesetz, providers of telecommunications networks and services are subject to the notification requirement under Section 5 TKG (see the Telecommunications section above), and, in the financial sector, DORA requires financial entities to maintain and submit registers of information regarding their contractual arrangements with ICT third-party service providers.
-
Cybersecurity – Please summarise the regulatory framework for the reporting of cybersecurity incidents.
Under the recast BSIG, particularly important and important entities must report significant security incidents to the BSI in a staged procedure: an initial notification must be made without undue delay and at the latest within 24 hours of becoming aware of the incident, followed by an updated notification within 72 hours and a final report within one month. A security incident is significant, in particular, if it has caused or is capable of causing serious operational disruption of services or financial loss for the entity concerned, or if it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage. Reports are submitted via the reporting portal operated by the BSI, which has been available since 6 January 2026. The BSI may also require affected entities to inform the recipients of their services about significant incidents.
Parallel reporting regimes exist under sector-specific and horizontal legislation and may apply cumulatively: personal data breaches must be notified to the competent data protection authority without undue delay and, where feasible, within 72 hours under Article 33 GDPR (and, in certain cases, to the affected individuals under Article 34 GDPR); telecommunications providers must report security incidents to the Bundesnetzagentur and the BSI under the TKG; financial entities must report major ICT-related incidents to the competent supervisory authority under DORA; operators of critical facilities must additionally report incidents affecting their physical resilience under the KRITIS-Dachgesetz; and, from 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents under the EU Cyber Resilience Act. In practice, incident response plans should therefore map the different triggers, deadlines and competent authorities in advance.
-
Artificial Intelligence – Which body(ies), if any, is/are responsible for the regulation of artificial intelligence?
The Act on the Market Surveillance and Innovation Promotion of Artificial Intelligence (KI-Marktüberwachungs- und Innovationsförderungsgesetz – KI-MIG) is intended to designate the Federal Network Agency (Bundesnetzagentur) as the central market-surveillance authority, single point of contact and complaints body for the EU AI Act. A coordination and competence centre for the AI Act (KoKIVO), an AI service desk and a regulatory sandbox are to be established at the Bundesnetzagentur. For particularly fundamental-rights-sensitive high-risk AI systems, including certain systems used for biometrics and law enforcement, an independent AI market-surveillance chamber within the Bundesnetzagentur is envisaged.
Sector-specific oversight remains with existing authorities, in particular BaFin for AI in financial services and the competent product regulators for AI embedded in regulated products; the supervision of AI in the press and broadcasting sector lies with the state media authorities (Landesmedienanstalten). At EU level, the European Commission’s AI Office supervises providers of general-purpose AI models and can enforce their obligations from 2 August 2026. In addition, the data protection authorities remain competent where AI systems involve the processing of personal data.
-
Artificial Intelligence – Please summarise the principal laws (present or impending), if any, that govern the deployment and use of artificial intelligence, including a brief explanation of the general purpose of those laws.
The primary law governing AI in the EU, including Germany, is the EU AI Act. It establishes a risk-based framework that prohibits specified AI practices, imposes extensive requirements on defined categories of high-risk AI systems and creates transparency and governance obligations for other systems and general-purpose AI models. The commonly used labels ‘unacceptable’, ‘high’, ‘limited’ and ‘minimal’ risk are a useful explanatory shorthand, but they are not four exhaustive statutory categories. High-risk AI systems are subject, among other things, to risk-management, data-governance, technical-documentation, record-keeping, transparency, human-oversight, accuracy, robustness and cybersecurity requirements, as well as conformity-assessment obligations where applicable. The framework seeks to protect health, safety and fundamental rights while supporting innovation and the functioning of the internal market.
The AI Act applies in stages: the prohibitions of specified AI practices and the AI-literacy obligation have applied since 2 February 2025, and the governance rules and obligations for general-purpose AI models since 2 August 2025, with the European Commission’s enforcement powers for those models applying from 2 August 2026. The transparency obligations under Article 50, including requirements relevant to chatbots, deepfakes and certain AI-generated content, apply from 2 August 2026. Under the AI simplification amendment approved by the EU legislature in June 2026, the high-risk rules will apply from 2 December 2027 to stand-alone high-risk systems under Article 6 (2) and Annex III and from 2 August 2028 to high-risk systems embedded in regulated products under Article 6 (1) and Annex I. The amendment also introduces a number of substantive and procedural changes and simplifications, which should be assessed in their final published form.
-
Artificial Intelligence – Are there any specific legal provisions (present or impending) in respect of the deployment and use of Large Language Models and/or generative AI (including agentic AI)?
The EU AI Act contains specific provisions for general-purpose AI models, a category that includes many large language models and generative AI models (Articles 51–55). Providers must, among other things, maintain technical documentation, provide information to downstream AI-system providers, put in place a policy to comply with EU copyright law and publish a sufficiently detailed summary of training content (Article 53). Providers of general-purpose AI models with systemic risk are subject to additional model-evaluation, systemic-risk assessment and mitigation, serious-incident reporting and cybersecurity obligations (Article 55). ‘Agentic AI’ is not a separate legal category under the AI Act; the applicable obligations depend on whether the relevant model or system falls within the statutory definitions, its intended purpose, risk classification and the role of the relevant actor.
In addition to the AI Act, the deployment of generative AI solutions must comply with other relevant legal frameworks, such as works council co-determination rights and data protection regulations when processing personal data.
In July 2025, the European Commission published the (voluntary) General-Purpose AI Code of Practice together with accompanying guidelines and a template for the public summary of training content, which providers of general-purpose AI models can use to demonstrate compliance with their obligations under the AI Act. In addition, the transparency obligations under Article 50 AI Act – including the duty to mark AI-generated or manipulated content (e.g. deepfakes) in a machine-readable manner – apply from 2 August 2026 and are particularly relevant for generative AI applications.
-
Artificial Intelligence – Do technology contracts in your jurisdiction typically contain either mandatory (e.g. mandated by statute) or recommended provisions dealing with AI risk? If so, what issues or risks need to be addressed or considered in such provisions?
The European Commission has published standard contractual clauses for public procurement of AI systems, with two versions available: one for high-risk AI and one for non-high-risk AI. These standard contractual clauses are designed for public bodies procuring AI systems developed by external suppliers. The clauses are not mandatory but provide a structured template that may influence future contracting standards, including in the private sector.
For the private sector, there is no established standard for addressing AI risks in B2B contracts, as European and national legal frameworks on AI liability are still under development. However, to adequately address risks in private contracts, parties may consider including provisions that address:
– Data quality and management, including data protection and privacy compliance
– Transparency and explainability of AI decision-making processes
– Performance metrics and quality assurance measures
– Liability and indemnification for AI-related errors or harm
– Ethical AI use and compliance with relevant guidelines or standards
– Intellectual property rights related to AI systems and training data
– Cybersecurity measures and incident response protocols
– Regular auditing and monitoring of AI system performance
– Human oversight and intervention mechanisms
– Provisions for system updates, maintenance, and decommissioning -
Artificial Intelligence – Do software or technology contracts in your jurisdiction typically contain provisions regarding the application or treatment of copyright or other intellectual property rights, or the ownership of outputs in the context of the use of AI systems?
Software and technology contracts involving AI commonly address rights in inputs, provider materials and models, generated outputs, feedback and training or fine-tuning data. Whether an AI-generated output is protected by copyright under German law depends on whether it reflects a sufficient human personal intellectual creation; a purely autonomously generated output will generally not qualify for copyright protection. Contractual provisions may allocate permissions to use outputs and regulate the parties’ relationship, but they cannot create statutory copyright where the legal requirements for protection are not met. Provider terms frequently grant users broad rights to use outputs, subject to the terms of service, third-party rights and restrictions that may differ between free and paid offerings.
When procuring AI solutions, companies should distinguish clearly between pre-existing provider technology, customer inputs, permitted uses of customer data for training or service improvement, fine-tuned models and generated outputs. The agreement should address use rights, confidentiality, data protection, retention and deletion, responsibility for prompts and outputs, third-party infringement claims, provenance and audit information, and the extent to which exclusivity can realistically be promised where similar outputs may be generated for different users.
-
Blockchain – What are the principal laws (present or impending), if any, that govern (i) blockchain specifically (if any) and (ii) digital assets, including a brief explanation of the general purpose of those laws?
The European Union has taken a leading global role in establishing regulations for the application of distributed ledger and blockchain technology in the financial market. Key initiatives include the Regulation on Markets in Crypto-Assets (MiCAR), the Transfer of Funds Regulation (TFR), and the Regulation on the establishment of a DLT Pilot Regime. These legislative measures aim to establish a consistent, standardised legal framework across Europe for the lawful handling and further experimentation with DLT in the financial sector. Through this unified regulatory approach, the EU acknowledges the potential of distributed ledger technology and seeks to address various challenges it presents, including those related to financial stability, market integrity, and consumer protection. Ultimately, these efforts are expected to foster greater trust among market participants.
In Germany, MiCAR has been operationalised through the Financial Market Digitalisation Act (Finanzmarktdigitalisierungsgesetz – FinmadiG) and, at its core, the Crypto Markets Supervision Act (Kryptomärkteaufsichtsgesetz – KMAG), which designates BaFin as the competent authority, sets out the administrative and sanctions framework and replaced the previous national licensing regime for crypto asset services under the German Banking Act (KWG). Since the end of the MiCAR transition period, crypto-asset service providers require an authorisation from BaFin under MiCAR, while the KWG continues to apply to certain activities such as the qualified crypto custody business. The German Electronic Securities Act (Gesetz über elektronische Wertpapiere – eWpG) allows for the issuance of electronic securities, including those based on blockchain. The Fund Jurisdiction Act (Fondsstandortgesetz – FoStoG) regulates investment funds that incorporate crypto-assets. The FATF “travel rule” for crypto-asset transfers now follows directly from the recast EU Transfer of Funds Regulation (Regulation (EU) 2023/1113). These regulations aim to create a stable and trustworthy legal environment for the adoption and use of blockchain technologies and digital assets in Germany.
-
Search Engines and Marketplaces – Please summarise the principal laws (present or impending), if any, that govern search engines and marketplaces, including a brief explanation of the general purpose of those laws.
Search engines and marketplaces are primarily regulated by two key EU legislations: the Digital Services Act (DSA) and the Digital Markets Act (DMA).
The DSA provides a unified set of rules to protect users and combat illegal online content. It regulates obligations and liability of intermediary services, including hosting providers, online platforms, marketplaces, and search engines (Article 2 DSA). Key provisions include:
– Content moderation obligations (Article 16 DSA)
– Internal complaint-handling and dispute-settlement mechanisms (Articles 20, 21 DSA)
– Transparency reporting requirements (Article 24 DSA)
– Ban on deceptive practices like dark patterns (Article 25 DSA)
– Restrictions on ads targeting minors based on profiling (Article 28 DSA)
– Traceability requirements for traders on online marketplaces (Article 30 DSA)Very Large Online Platforms (VLOPs) and Very Large Online Search Engines (VLOSEs) face additional obligations, including at least annual assessments of systemic risks under Article 34 DSA, reasonable, proportionate and effective risk-mitigation measures under Article 35 DSA, and public repositories of advertisements under Article 39 DSA.
The DMA targets “gatekeepers” (Article 3 DMA) – large digital platforms providing “core platform services” in at least three Member States. It aims to ensure fair and open digital markets by:
– Requiring interoperability with third-party services (Article 7 DMA)
– Allowing access to data generated on their platforms (Article 6 (10) DMA)
– Prohibiting self-preferencing in rankings (Article 6 (5) DMA)
– Ensuring users can connect with businesses outside the platform (Article 5 (5) DMA)In addition to these specific regulations, search engines and marketplaces must also comply with general data protection laws, particularly the General Data Protection Regulation (GDPR). Of particular importance in this context is the “right to be forgotten” (Article 17 GDPR), which allows individuals to request the deletion of personal data, including the removal of search results linking to such information.
-
Social Media – Please summarise the principal laws (present or impending), if any, that govern social media and online platforms, including a brief explanation of the general purpose of those laws?
In Germany, social media platforms operate within a complex regulatory framework that combines EU-wide regulations with national laws. The European Digital Services Act (DSA), forms a cornerstone of this framework, introducing comprehensive obligations for online platforms, with particularly stringent rules for very large platforms. It mandates content moderation procedures, transparency measures, and user protection mechanisms.
Complementing this at the national level is the German Digital Services Act (DDG), which contains, i.a., provisions on dealing with violations of the law by users of digital services. The DDG replaced the Telemedia Act (TMG) and large parts of the Network Enforcement Act (NetzDG), which prior to the DSA required social media platforms to implement effective complaint management systems and promptly remove illegal content.
The Interstate Treaty on Media (Medienstaatsvertrag) further regulates media diversity and user protection across various online platforms, including social media. Additionally, child protection regulations such as the Youth Protection Act aim to safeguard minors from harmful content on social media and other online platforms. The regulatory landscape remains dynamic, with ongoing adjustments to address emerging challenges in the digital sphere, requiring social media companies operating in Germany to continuously adapt to ensure compliance while maintaining their services.
-
Social Media – What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable online safety laws?
Under the EU Digital Services Act (DSA), the maximum fine may reach 6% of the provider’s total worldwide annual turnover in the preceding financial year. Article 52 DSA requires Member States to establish effective, proportionate and dissuasive sanctions for infringements within their competence, while the European Commission may impose fines on VLOPs and VLOSEs under Article 74 DSA. Relevant infringements may include failures relating to content-moderation procedures, transparency or systemic-risk management.
In Germany, the Digital Services Act (Digitale-Dienste-Gesetz – DDG) governs national enforcement and empowers authorities to impose fines aligned with the DSA, for example for failure to report illegal content or to appoint a legal representative (cf. Section 33 DDG).
The DSA and its national implementation through the DDG have largely replaced the former Network Enforcement Act (NetzDG), which had provided for fines of up to EUR 50 million for persistent failures to remove illegal content. These core enforcement functions now fall under the harmonised EU regime, where significantly higher penalties may apply.
Additional sanctions may arise under sector-specific laws such as the Youth Protection Act and the Interstate Treaty on Media, particularly in cases involving child protection or audiovisual regulation. Relevant enforcement bodies include the Federal Agency for the Protection of Children and Young Persons in the Media (Bundeszentrale für Kinder- und Jugendmedienschutz – BzKJ) and the State Media Authorities.
-
Spatial Computing – Please summarise the principal laws (present or impending), if any, that govern spatial computing, including a brief explanation of the general purpose of those laws?
Spatial computing technologies such as augmented, virtual, or mixed reality are not yet subject to a dedicated legal framework in Germany. Instead, they are regulated through a range of existing cross-sectoral laws, depending on the specific use case.
Where spatial computing involves the processing of personal data – for example through motion tracking, facial recognition or geolocation – the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG) apply. The Telecommunications Digital Services Data Protection Act (TDDDG) may also be relevant to the storage of or access to information on end-user devices and to telecommunications-specific processing.
For hardware and immersive devices, product safety rules under the Product Safety Act (ProdSG) and the new EU General Product Safety Regulation (2023/988) ensure that AR/VR equipment meets applicable health and safety standards. If used in educational or media contexts, the Youth Protection Act and the Interstate Treaty on Media may also apply, particularly where minors are involved.
In addition, spatial computing increasingly falls within the scope of horizontal digital legislation that has meanwhile become applicable or will apply shortly, including the AI Act (phased application since February 2025), the Data Act (applicable since 12 September 2025, in particular regarding access to data generated by connected devices) and the Cyber Resilience Act (main obligations applying from December 2027), depending on its integration with connected systems and AI functionalities.
-
Quantum Computing – Please summarise the principal laws (present or impending), if any, that govern quantum computing and/or issues around quantum cryptography, including a brief explanation of the general purpose of those laws?
Quantum computing is not yet governed by a dedicated regulatory framework in Germany or at the EU level. However, existing laws in the areas of cybersecurity, export control, and research funding provide a general legal structure relevant to the development and deployment of quantum technologies.
At the EU level, the Chips Act and the Strategic Technologies for Europe Platform (STEP) promote quantum innovation through targeted investment and infrastructure support. The European Quantum Communication Infrastructure (EuroQCI) initiative further aims to establish a secure quantum communication network across the EU, with a focus on quantum key distribution (QKD).
In July 2025, the European Commission presented its Quantum Europe Strategy and announced a proposal for a European Quantum Act intended to consolidate the policy, funding and industrial framework for quantum technologies. A legislative proposal was planned for 2026 but had not been adopted at the editorial cut-off on 21 July 2026.
Quantum cryptography and quantum-resilient systems are also increasingly relevant under cybersecurity legislation. In Germany, the Federal Office for Information Security Act (BSIG) and the EU Cyber Resilience Act (in force since December 2024, with its main obligations applying from December 2027) form the basis for evaluating encryption standards and future-proofing critical infrastructure against potential quantum threats. The BSI has also published recommendations on the migration to post-quantum cryptography, which are increasingly reflected in security requirements for critical infrastructure and public procurement.
In addition, quantum technologies with potential military or surveillance applications may fall within the scope of the EU Dual-Use Regulation (Regulation (EU) 2021/821), which imposes export restrictions on certain high-risk technologies.While the legal framework for quantum computing remains general and fragmented, further regulation is expected as practical applications and security concerns evolve.
-
Datacentres – Does your jurisdiction have any specific regulations that apply to data centres?
Germany does not have a single, dedicated legal framework governing data centres. However, operators and developers must comply with a complex mix of cross-sectoral and project-specific regulations, depending on the function, size, and classification of the facility.
From a real estate and planning perspective, data centres must meet local zoning, construction and environmental permitting requirements. These are governed by federal and state-level building codes and, where applicable, the Federal Immission Control Act (BImSchG). If extensive cooling or backup power infrastructure is involved, energy and environmental permits may be required.
Under the recast BSIG implementing the NIS 2 Directive, providers of data centre services are now expressly regulated as part of the digital infrastructure sector and generally qualify as particularly important or important entities, triggering registration, risk management and incident reporting obligations. Data centres supporting critical infrastructure may additionally fall under the KRITIS regime, including the new KRITIS-Dachgesetz on the physical resilience of critical facilities.
In terms of sustainability, the Energy Efficiency Act (EnEfG) imposes obligations for large data centres, including mandatory efficiency targets, reporting duties and energy re-use requirements. The act aims to align data centre operations with Germany’s broader climate and digitalisation goals.
The reliable energy supply and waste heat utilisation have also become central regulatory concerns, particularly in urban areas with high energy demand and limited grid capacity. Operators increasingly require negotiated solutions on grid access, power purchase agreements (PPAs), and district heating integration, particularly for hyperscale and co-location data centres.
While no central licence is required to operate a data centre, the regulatory burden is high, and successful project delivery typically requires multidisciplinary legal advice across real estate, energy, planning, IT, and regulatory law.
-
General – What are your top 3 predictions for significant developments in technology law in the next 3 years?
– Operational Enforcement of the EU AI Act and Evolution of AI Liability Frameworks
The EU AI Act is rapidly moving into its operational phase, with authorities focusing on implementation, risk classification and market surveillance. In Germany, the KI-MIG had completed the parliamentary process but was awaiting promulgation at the editorial cut-off. We anticipate a sharp increase in regulatory guidance, standard-setting and initial enforcement activity, particularly as the transparency obligations and the European Commission’s enforcement powers vis-à-vis providers of general-purpose AI models apply from August 2026, while the high-risk compliance deadlines have been postponed to December 2027 for Annex III systems and August 2028 for Annex I systems. In parallel, discussion of civil liability for AI-related harm will intensify. Although the proposed AI Liability Directive was withdrawn, questions remain as to how existing frameworks, including the revised Product Liability Directive and national fault-based liability rules, will address harm in high-risk applications such as healthcare, mobility and employment.
– Deepening Convergence of Cybersecurity, Digital Resilience, and Supply Chain Regulation
The integration of cybersecurity and operational resilience frameworks will intensify significantly. This is primarily driven by the entry into force of the German NIS 2 transposition (NIS2UmsuCG) in December 2025 and of the KRITIS-Dachgesetz in March 2026, the Digital Operational Resilience Act (DORA), which has been fully applicable since January 2025, and the phased application of the Cyber Resilience Act (CRA), with manufacturers’ reporting obligations applying from September 2026 and full application by December 2027. With the first registration deadlines under the new BSIG having expired in 2026, we expect supervisory practice and initial enforcement by the BSI to gather pace. Technology service providers – including cloud, software, and hardware vendors – will face increasingly strict reporting, compliance, and third-party risk obligations. Regulatory scrutiny will broaden to cover entire digital service ecosystems and their supply chains, extending beyond traditional critical infrastructures.
– Broadening Reach of Data Governance and Platform Regulation into Traditional Sectors
The practical application of the Data Act (applicable since September 2025), together with the Digital Services Act (DSA) and Digital Markets Act (DMA), will continue to reshape platform regulation, access to non-personal data and B2B/B2G data sharing. These horizontal regimes will increasingly affect sectors such as energy, health, mobility and manufacturing, which historically operated under distinct regulatory frameworks. We anticipate disputes over interoperability, access obligations and the role of gatekeeper platforms in emerging technology contexts, including IoT, edge computing and industrial AI. In addition, implementation of the EU’s Digital Omnibus initiatives – including the AI Act amendment approved in June 2026 and further proposed changes across the digital acquis – will materially shape the compliance landscape over the next three years.
-
General – Do technology contracts in your country commonly include provisions to address sustainability / net-zero obligations or similar environmental commitments?
Sustainability-related provisions are not yet standard in most private-sector technology contracts in Germany, but their inclusion is increasing – particularly in large-scale procurement, public tenders, and long-term outsourcing or cloud service agreements.
In the public sector, contracting authorities often include environmental criteria in award procedures, based on the Federal Climate Protection Act (KSG) and sustainability procurement guidelines. In the private sector, ESG-conscious companies may include contractual clauses addressing data centre energy use, green software practices, waste heat reuse, or renewable power procurement (e.g. PPAs) – especially in IT infrastructure and cloud service deals.
Broader regulatory drivers such as the Corporate Sustainability Reporting Directive (CSRD), the existing European Sustainability Reporting Standards (ESRS), the Supply Chain Due Diligence Act (LkSG) and the ongoing EU sustainability simplification reforms are influencing technology contracts indirectly, as corporate customers increasingly request environmental performance data, energy-consumption information and lifecycle transparency from technology suppliers. The relevance of these drivers depends on the parties’ reporting scope, value-chain obligations and the final form of the applicable simplification measures.
While sustainability clauses are not yet market standard, they are becoming more common in response to compliance needs, reputational risks, and climate-related performance targets – particularly among listed companies and multinationals operating in Germany.
Germany: TMT
This country-specific Q&A provides an overview of TMT laws and regulations applicable in Germany.
-
Software – How are proprietary rights in software and associated materials protected?
-
Software – In the event that software is developed by a software developer, consultant or other party for a customer, who will own the resulting proprietary rights in the newly created software in the absence of any agreed contractual position?
-
Software – Are there any specific laws that govern the harm / liability caused by Software / computer systems?
-
Software – To the extent not covered by (3) above, are there any specific laws that govern the use (or misuse) of software / computer systems?
-
Software Transactions (Licence and SaaS) – Other than as identified elsewhere in this overview, are there any technology-specific laws that govern the provision of software between a software vendor and customer, including any laws that govern the use of cloud technology?
-
Software Transactions (License and SaaS) – Is it typical for a software vendor to cap its maximum financial liability to a customer in a software transaction? If ‘yes’, what would be considered a market standard level of cap?
-
Software Transactions (License and SaaS) – Please comment on whether any of the following areas of liability would typically be excluded from any financial cap on the software vendor’s liability to the customer or subject to a separate enhanced cap in a negotiated software transaction (i.e. unlimited liability): (a) confidentiality breaches; (b) data protection breaches; (c) data security breaches (including loss of data); (d) IPR infringement claims; (e) breaches of applicable law; (f) regulatory fines; (g) wilful or deliberate breaches; (h) claims arising out of or in relation to artificial intelligence.
-
Software Transactions (License and SaaS) – Is it normal practice for software source codes to be held in escrow for the benefit of the software licensee? If so, who are the typical escrow providers used? Is an equivalent service offered for cloud-based software?
-
IT Outsourcing – Other than as identified elsewhere in this questionnaire, are there any specific technology laws that govern IT outsourcing transactions?
-
IT Outsourcing – Please summarise the principal laws (present or impending), if any, that protect individual staff in the event that the service they perform is transferred to a third party IT outsource provider, including a brief explanation of the general purpose of those laws.
-
Telecommunications – Please summarise the principal laws (present or impending), if any, that govern telecommunications networks and/or services, including a brief explanation of the general purpose of those laws.
-
Telecommunications – Please summarise any licensing or authorisation requirements applicable to the provision or receipt of telecommunications services in your country. Please include a brief overview of the relevant licensing or authorisation regime in your response.
-
Telecommunications – Please summarise the principal laws (present or impending) that govern access to communications data by law enforcement agencies, government bodies, and related organisations. In your response, please outline the scope of these laws, including the types of data that can typically be requested, how these laws are applied in practice (e.g., whether requests are confidential, subject to challenge, etc.), and any legal or procedural safeguards that apply.
-
Telecommunications – Please summarise the principal laws (present or impending) that impose cyber security and/or operational resiliency obligations applicable to the operation of telecommunications infrastructure and/or provision of telecommunications services.
-
Mobile communications and connected technologies – What are the principle standard setting organisations (SSOs) governing the development of technical standards in relation to mobile communications and newer connected technologies such as digital health or connected and autonomous vehicles?
-
Mobile communications and connected technologies – How do technical standards facilitating interoperability between connected devices impact the development of connected technologies?
-
Data Protection – Please summarise the principal laws (present or impending), if any, that govern data protection, including a brief explanation of the general purpose of those laws.
-
Data Protection – What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable data protection laws?
-
Data Protection – What data protection rules are relevant to technology contracts in your country? Do they typically refer to external data protection regimes, e.g. EU GDPR or CCPA, even where the contract has no clear international element?
-
Cybersecurity – Please summarise the principal laws (present or impending), if any, that govern cybersecurity (to the extent they differ from those governing data protection), including a brief explanation of the general purpose of those laws.
-
Cybersecurity – What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable cybersecurity laws?
-
Cybersecurity – Are there any cybersecurity regulatory frameworks in your jurisdiction which require registration for certain sectors or services?
-
Cybersecurity – Please summarise the regulatory framework for the reporting of cybersecurity incidents.
-
Artificial Intelligence – Which body(ies), if any, is/are responsible for the regulation of artificial intelligence?
-
Artificial Intelligence – Please summarise the principal laws (present or impending), if any, that govern the deployment and use of artificial intelligence, including a brief explanation of the general purpose of those laws.
-
Artificial Intelligence – Are there any specific legal provisions (present or impending) in respect of the deployment and use of Large Language Models and/or generative AI (including agentic AI)?
-
Artificial Intelligence – Do technology contracts in your jurisdiction typically contain either mandatory (e.g. mandated by statute) or recommended provisions dealing with AI risk? If so, what issues or risks need to be addressed or considered in such provisions?
-
Artificial Intelligence – Do software or technology contracts in your jurisdiction typically contain provisions regarding the application or treatment of copyright or other intellectual property rights, or the ownership of outputs in the context of the use of AI systems?
-
Blockchain – What are the principal laws (present or impending), if any, that govern (i) blockchain specifically (if any) and (ii) digital assets, including a brief explanation of the general purpose of those laws?
-
Search Engines and Marketplaces – Please summarise the principal laws (present or impending), if any, that govern search engines and marketplaces, including a brief explanation of the general purpose of those laws.
-
Social Media – Please summarise the principal laws (present or impending), if any, that govern social media and online platforms, including a brief explanation of the general purpose of those laws?
-
Social Media – What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable online safety laws?
-
Spatial Computing – Please summarise the principal laws (present or impending), if any, that govern spatial computing, including a brief explanation of the general purpose of those laws?
-
Quantum Computing – Please summarise the principal laws (present or impending), if any, that govern quantum computing and/or issues around quantum cryptography, including a brief explanation of the general purpose of those laws?
-
Datacentres – Does your jurisdiction have any specific regulations that apply to data centres?
-
General – What are your top 3 predictions for significant developments in technology law in the next 3 years?
-
General – Do technology contracts in your country commonly include provisions to address sustainability / net-zero obligations or similar environmental commitments?