Law / Germany

Germany

European Union law applies in Germany Germany is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Germany, described on this page below, applies here too.

20 of 21 named instruments researched to a stage, across all six areas of law we track: 18 in force, 1 enacted but not yet in force and 1 repealed, withdrawn or blocked. As of 22 September 2026.

When they take effect12 of 20 carry a date, 8 do not. Earlier is before 2014.
Before 2014: 2 instruments (1 in force, 1 repealed, withdrawn or blocked) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 6 instruments (6 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 1 instrument (1 in force) 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 2 instruments (2 in force) 2026: 1 instrument (1 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 6
  3. Scraping law 5
  4. Cybersecurity law 2
  5. Age gating law 3
  6. News aggregation law 3

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (282 words)

The EU AI Act (Regulation (EU) 2024/1689) applies directly in Germany and is not restated here as German law.

Germany's own addition is the Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), in effect since 29 July 2026, which names the Bundesnetzagentur as the country's central market surveillance authority, single point of contact, and central complaints office for the Regulation, gives the Bundesanstalt für Finanzdienstleistungsaufsicht concurrent market surveillance jurisdiction over an AI system tied to a regulated financial activity it already supervises, and adds a national administrative fine of up to 50,000 euros for specified failures to inform, assess, or explain under Articles 21, 27, 45, and 86 of the Regulation, separate from the fine level the Regulation itself sets for a substantive violation.

No criminal offense specific to artificial intelligence is in force in the Strafgesetzbuch: section 201b, a provision that would criminalize violating personal rights through a digitally faked recording, does not appear in the consolidated federal criminal code published by the Federal Ministry of Justice, so it is not enacted.

The Medienstaatsvertrag, an interstate treaty among the German states rather than a federal statute, governs telemedia platforms and intermediaries and has been in force in its seventh amended version since 1 December 2025. A synthetic media or deepfake labeling duty in the treaty's own text is not addressed here, beyond the treaty's official overview.

Federal guidelines on AI use inside the federal administration (Bundesministerium des Innern und für Heimat, March 2025) bind only government bodies, and a proposition that the Gesetz gegen den unlauteren Wettbewerb's misleading-omission provisions reach an AI chatbot's commercial statements rests on commentary rather than AI-specific statutory text; neither is catalogued as an instrument here.

AI governance

Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), AI Market Surveillance and Innovation Promotion Act

Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-Marktüberwachungs-und-Innovationsförderungs-Gesetz… KI-MIG), §§ 2, 6, 8, 13, 15, 16official consolidated KI-MIG text, gesetze-im-internet.de

In force 56 days, effective 29 July 2026. Binds public and private bodies.

What this law does

KI-MIG names the Bundesnetzagentur as Germany's central market surveillance authority for the EU AI Act. The Bundesnetzagentur is also the Regulation's single point of contact under Article 70. The Bundesnetzagentur is the Regulation's central complaints office under Article 85. The Bundesanstalt für Finanzdienstleistungsaufsicht is instead the market surveillance authority for an AI system that a regulated financial undertaking it already supervises places on the market.

A competent Land authority is the market surveillance authority instead where a Land public body deploys an AI system. A competent Land authority is also the market surveillance authority where a broadcaster or media service provider deploys an AI system for a journalistic or advertising purpose. A person who fails to carry out or update the fundamental rights impact assessment that Article 27 requires commits a national administrative offense.

The operator of a high-risk AI system who fails to give an affected person the explanation Article 86 requires commits the same national administrative offense. That administrative offense is punishable by a fine of up to 50,000 euros. A violation of the Regulation under Article 99(3) to (5) is instead prosecuted in Germany through the OWiG administrative-offense procedure. The Bundesnetzagentur separately operates at least one KI-Reallabor, an AI regulatory sandbox, under Articles 57 and 58.

What it requires

Privacy law6 instruments, 6 in force

Research summary (67 words)

Germany's private-sector regime is the General Data Protection Regulation (GDPR) plus the Bundesdatenschutzgesetz (BDSG), BGBl. I S. 2097 (2017) as amended. The BDSG's most consequential addition on top of GDPR is Section 26, which supplies Germany's employee-data regime and specifically constrains how biometric data may be processed in employment, and a fragmented, 17-authority enforcement structure, the federal BfDI plus 16 state Landesdatenschutzbehorden, that has no equivalent among the other GDPR-family jurisdictions.

Breach notification

GDPR Articles 33-34, Breach Notification in Germany

Regulation (EU) 2016/679, Arts. 33-34Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify the competent Landesdatenschutzbehorde, or the BfDI for the federal public sector and telecommunications and postal providers, without undue delay and within 72 hours where feasible, after becoming aware of a personal data breach, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No BDSG derogation from this timeline was identified.

What it requires

Comprehensive regime

Bundesdatenschutzgesetz (BDSG), Federal Data Protection Act

Bundesdatenschutzgesetz (BDSG), BGBl. I S. 2097 (2017), as amendedGesetze im Internet (official federal law portal), consolidated BDSG text

In force since 25 May 2018. Binds public and private bodies.

What this law does

The General Data Protection Regulation (GDPR) applies directly in Germany, and the Bundesdatenschutzgesetz (BDSG), BGBl. I S. 2097 (2017) as amended, supplies domestic derogations and procedural rules, most significantly Section 26 (employment data) and Sections 31 and 37 (credit-scoring automated decisions). Lawful bases otherwise follow GDPR Article 6 unmodified.

Enforcement is fragmented across 17 separate authorities: the federal BfDI, whose jurisdiction is limited to the federal public sector, telecommunications carriers, and postal providers, and 16 state Landesdatenschutzbehorden, which supervise the private sector and are each independent of the BfDI and of their own state government.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Germany

Regulation (EU) 2016/679, Arts. 44-49Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

Transferring personal data of a person in Germany outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the highest Article 83(5) fine tier. The BfDI publishes its own guidance on international transfers but adds no additional national restriction layer beyond General Data Protection Regulation (GDPR). This is a real, structured condition on outbound transfer, not an absence of restriction.

What it requires

Data subject rights

GDPR Article 22 and BDSG Sections 31 and 37, Automated Decisions and Credit Scoring in Germany

Regulation (EU) 2016/679, Art. 22; Bundesdatenschutzgesetz (BDSG) §§31, 37Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Articles 12 to 23 apply, including Article 22 rights against solely automated decision-making. BDSG Section 31 supplements this for credit-reporting and scoring agencies specifically.

The CJEU's SCHUFA ruling, Case C-634/21 (OQ v Land Hessen, judgment 7 December 2023), held that automated credit-score generation used determinatively by a third party such as a bank constitutes a decision based solely on automated processing within Article 22(1), which cast doubt on BDSG Section 31's compatibility with the narrow exceptions in Article 22(2)(b). No subsequent German court ruling resolving the Wiesbaden Administrative Court's remand from that reference is identified.

What it requires

Enforcement supervision

GDPR Article 82, BDSG Sections 41-43, and BfDI and Landesdatenschutzbehörden Enforcement in Germany

Regulation (EU) 2016/679, Arts. 82-83; Bundesdatenschutzgesetz (BDSG) §§41-43Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

Germany's enforcement structure is 17 separate authorities: the federal BfDI and 16 state Landesdatenschutzbehorden, coordinated on fine calculation by the Datenschutzkonferenz's shared fining model.

BDSG Sections 41 to 43 add domestic criminal offenses on top of General Data Protection Regulation (GDPR) Article 83's administrative fine regime; total BfDI and state fines reached roughly EUR 160 million from 2018 to 2024, with the largest single BfDI action to date, against Vodafone GmbH, totaling EUR 45 million across two March 2025 decisions. Article 82 arms an individual directly, on the same no-seriousness-threshold terms established EU-wide by CJEU C-300/21.

Germany also has a functioning collective-redress channel: the CJEU (Case C-319/20, Verbraucherzentrale Bundesverband v Meta Platforms Ireland) held that Article 80(2) does not preclude a national provision letting consumer-protection associations sue for a GDPR violation without an individual data subject's mandate, and Germany's Verbraucherrechtedurchsetzungsgesetz (VDuG) lets the Verbraucherzentralen bring representative actions on behalf of an unlimited group of consumers for an infringement affecting at least 50 consumers.

What it requires

Sensitive categories

GDPR Article 9 and BDSG Section 26(3), Special Categories and Employment Biometric Data in Germany

Regulation (EU) 2016/679, Art. 9; Bundesdatenschutzgesetz (BDSG) §26(3)Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 9(1) governs biometric data as a special category. BDSG Section 26(3), the provision governing special category data in employment, was upheld as GDPR-compatible and is the controlling provision for a workplace-deployed biometric time clock, access control, or voice-authentication system; Section 26(1), the general employment lawful-basis clause, was found incompatible with GDPR's own conditions and cannot be relied on alone.

Consent is disfavored as the legal basis in an employment relationship because of the power imbalance, so employers typically rely on necessity under Section 26(3) or Article 9(2) rather than Article 9(2)(a) consent. A voiceprint or faceprint captured for identification is covered identically to a fingerprint; GDPR draws no distinction by modality.

Germany's leading biometric enforcement precedent is the Hamburg Commissioner for Data Protection and Freedom of Information's 2021 order against Clearview AI to delete a German complainant's biometric identifier, the first such order against Clearview worldwide.

What it requires

Scraping law5 instruments, 5 in force

Research summary (351 words)

Germany has no scraping-specific statute; general law governs each dimension separately, and several of these dimensions are also EU law directly applicable in Germany (see the eu scraping document, not restated here).

The Strafgesetzbuch's computer-misuse offences at sections 202a to 202d and 303a to 303b turn on overcoming a technical access-security measure or otherwise unlawfully interfering with data, so reading a public, unauthenticated page without defeating any access control falls outside a plain reading of those provisions.

The Urheberrechtsgesetz's section 44b transposes the EU text-and-data-mining exception with a machine-readable opt-out, section 60d extends it to scientific research without that opt-out, and sections 87a to 87e give database makers a sui generis right that the same text-and-data-mining exceptions expressly limit.

The Bundesgerichtshof has held, applying the Gesetz gegen den unlauteren Wettbewerb's targeted-obstruction ground for protecting competitors, that continuing to retrieve data from a website by automated means after its operator has stated, including through its terms, that it does not permit this does not by itself amount to a targeted obstruction of that competitor, so whether persisting after a specific demand to stop is unlawful here remains untested absent circumvention of a technical protective measure.

Personal data scraped from a public German website remains subject to the General Data Protection Regulation (GDPR) and the Bundesdatenschutzgesetz researched under the privacy topic, which recognises no general publicly-available exemption; that finding is not restated here as a separate instrument.

German law recognises no separate tort of trespass to chattels for server strain caused by crawling; a data-processing operation substantially disrupted by such conduct falls instead under the Strafgesetzbuch's computer-sabotage offence already described above.

Regulation (EU) 2024/1689 (the AI Act) is directly applicable in Germany without transposition and specifically governs AI-training data: a provider of a general-purpose AI model must put in place a policy to comply with Union copyright law, including identifying a reservation of rights expressed under the text-and-data-mining opt-out, and must publish a sufficiently detailed summary of the content used for training; the Act implementing the Regulation that took effect in July 2026 (KI-MIG) adds only the designation of the Bundesnetzagentur as market-surveillance authority and enforcement procedure.

Computer misuse

Ausspaehen, Abfangen und Manipulation von Daten (Computer Misuse and Data Interference)

Strafgesetzbuch (StGB), §§ 202a, 202b, 202c, 202d, 303a, 303bofficial consolidated Strafgesetzbuch text, gesetze-im-internet.de

In force. Binds public and private bodies.

What this law does

Section 202a punishes, with imprisonment of up to three years or a fine, unlawfully obtaining access, for oneself or another, to data that is not intended for oneself and is specially secured against unauthorised access, by overcoming that access security.

Section 202b punishes, with imprisonment of up to two years or a fine, unlawfully obtaining such data for oneself or another using technical means from a non-public data transmission or from a data-processing installation's electromagnetic emissions, unless a more severe provision applies.

Section 202c punishes, with imprisonment of up to two years or a fine, preparing such an offence by producing, obtaining, selling, supplying, distributing or otherwise making accessible passwords or other security codes enabling access to such data, or computer programs designed to commit such an offence.

Section 202d punishes, with imprisonment of up to three years or a fine, obtaining, passing on, distributing or otherwise making accessible data that is not generally accessible and that another person obtained through an unlawful act, in order to enrich oneself or a third party or to harm another, with an exemption for acts performed exclusively in fulfilment of lawful official or professional duties.

Section 303a punishes, with imprisonment of up to two years or a fine, unlawfully deleting, suppressing, rendering unusable or altering data, and the attempt is itself punishable.

Section 303b punishes substantially disrupting a data-processing operation of essential significance to another through such conduct, with imprisonment of up to three years or a fine, rising to up to five years where the data processing is of essential significance to an outside business, undertaking or public authority, and, in especially serious cases, to imprisonment of six months to ten years, a category the statute names as including causing a loss of great magnitude, acting commercially or as a member of a gang formed for repeated computer sabotage, or impairing the population's supply of essential goods or services or the Federal Republic's security.

Because section 202a's offence turns on overcoming an access-security measure, a scraper reading a public, unauthenticated page without defeating any technical access control falls outside a plain reading of the provision.

What it requires

Copyright and text and data mining (TDM)

Text und Data Mining (General Text and Data Mining Exception)

Urheberrechtsgesetz (UrhG), § 44bofficial consolidated Urheberrechtsgesetz text, gesetze-im-internet.de

In force. Binds public and private bodies.

What this law does

Text and data mining is defined as the automated analysis of one or more digital or digitised works to derive information, in particular about patterns, trends and correlations. Reproducing lawfully accessible works for text and data mining is permitted, and the reproduction must be deleted once it is no longer needed for that purpose.

This use is permitted only if the rightsholder has not reserved it, and a reservation over a work accessible online is effective only if made in machine-readable form.

This is Germany's transposition of the EU text-and-data-mining exception and its opt-out mechanism, applicable to AI-model training and other automated collection of lawfully accessible text and data, including web-scraped content, and it is expressly extended to the sui generis database right by the database-right provision's own limitations clause.

What it requires

Text und Data Mining fuer Zwecke der wissenschaftlichen Forschung (Text and Data Mining for Scientific Research)

Urheberrechtsgesetz (UrhG), § 60dofficial consolidated Urheberrechtsgesetz text, gesetze-im-internet.de

In force. Binds public and private bodies.

What this law does

Reproductions for text and data mining are permitted for purposes of scientific research, without the machine-readable opt-out that limits the general exception, for research organisations (universities, research institutes or other bodies conducting scientific research that pursue no commercial purpose, reinvest all profits into scientific research, or act under a state-recognised public-interest mandate, but excluding an organisation under a private undertaking's determining influence with preferential access to the research results), for publicly accessible libraries and museums and for archives and film- or sound-heritage institutions, and for individual researchers pursuing no commercial purpose.

Those entitled who pursue no commercial purpose may make such reproductions available to a defined circle of persons for their joint scientific research, and to individual third parties to verify the quality of scientific research, but must end that availability once the joint research or the quality check is complete.

Entitled persons and organisations may retain the reproductions, with reasonable security precautions against unauthorised use, for as long as needed for scientific-research purposes or to verify research findings. Rightsholders may take necessary measures to prevent these reproductions from endangering the security and integrity of their networks and databases.

What it requires

Database right

Schutz des Datenbankherstellers (Sui Generis Database Right)

Urheberrechtsgesetz (UrhG), §§ 87a, 87b, 87c, 87d, 87eofficial consolidated Urheberrechtsgesetz text, gesetze-im-internet.de

In force. Binds public and private bodies.

What this law does

A database is a collection of works, data or other independent elements arranged systematically or methodically and individually accessible, whose obtaining, verification or presentation required a substantial investment by type or extent; the database maker is whoever made that investment.

The maker holds the exclusive right to reproduce, distribute and publicly communicate the database as a whole or a substantial part of it by type or extent, and repeated, systematic reproduction, distribution or communication of insubstantial parts is treated the same way where it conflicts with the database's normal exploitation or unreasonably prejudices the maker's legitimate interests.

The right does not reach reproduction of a substantial part for private use of a database whose elements are not individually electronically accessible, for scientific research, for illustrating teaching, for text and data mining under section 44b, for text and data mining for scientific research under section 60d, or for preservation, and separately permits use in court, arbitral or administrative proceedings and for public-security purposes.

The right lasts fifteen years from the database's publication, or from its making if it was not published within that period.

A contractual term obliging an owner of a lawfully marketed copy of the database, or another person lawfully entitled to use it, to refrain from reproducing, distributing or communicating an insubstantial part of the database is void to the extent that doing so conflicts neither with the database's normal exploitation nor unreasonably prejudices the maker's legitimate interests.

What it requires

Unfair competition

Verbot unlauterer geschaeftlicher Handlungen und Mitbewerberschutz (General Clause and Competitor Protection)

Gesetz gegen den unlauteren Wettbewerb (UWG), §§ 3, 4official consolidated Gesetz gegen den unlauteren Wettbewerb text, gesetze-im-internet.de

In force. Binds private bodies.

What this law does

Unfair commercial acts are prohibited generally, and a commercial act directed at or reaching consumers is unfair where it does not conform to professional diligence and is capable of materially influencing the consumer's economic behaviour, alongside a fixed annex of acts that are always unlawful toward consumers.

Separately, a person acts unfairly toward a competitor by denigrating or disparaging that competitor's identifying marks, goods, services, activities, or personal or business circumstances; by asserting or spreading unproven facts capable of damaging a competitor's business or credit; by offering goods or services that imitate a competitor's, where that causes an avoidable deception of buyers about commercial origin, unfairly exploits or impairs the reputation of the imitated goods or services, or was achieved through dishonestly obtained knowledge or documents; or by targeted obstruction of a competitor.

A person who intentionally or negligently commits an unlawful commercial act under these provisions is liable to a competitor for the resulting damage.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (680 words)

Germany's NIS2 transposition is enacted and in force. The NIS2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (the Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung, NIS2UmsuCG) was enacted 2 December 2025 (BGBl. 2025 I Nr. 301) and, under its own Article 30, entered into force on 6 December 2025 with no transition period.

Its Article 1 wholly replaces the 2009 BSI-Gesetz with a new BSI-Gesetz (BSIG), which is now the operative text.

Sections 28 and 30 bind a besonders wichtige Einrichtung (essential entity) or wichtige Einrichtung (important entity), defined by Anlage 1 and Anlage 2 sector lists that include, alongside critical-facility operators, large telecommunications and digital-infrastructure providers (including cloud computing), and public administration, the digital-service providers Anlage 2 Nummer 6 names expressly: an online marketplace, an online search engine, and a social-networking-platform provider, bound at the wichtige Einrichtung threshold of at least 50 employees or an annual turnover and balance-sheet total each over EUR 10 million.

Section 32 sets a graduated incident-notification clock to a joint reporting office run by the BSI and the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe: an early warning within 24 hours of becoming aware of a significant security incident, a full notification within 72 hours, an intermediate report on the BSI's request, and a final report within one month (or a progress report if the incident is still ongoing at that point), transposing NIS2 Articles 21 and 23.

No German instrument reviewed here imposes a mandatory product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here; Section 55 BSIG establishes a Freiwilliges IT-Sicherheitskennzeichen (voluntary IT security label) under which a manufacturer or service provider may seek the BSI's approval to display a label backed by a manufacturer declaration and a BSI security notice, but the section's own heading and text mark participation as voluntary, so it is named here rather than recorded as an instrument.

The pre-NIS2 BSIG obligations on KRITIS operators do not remain in force as a separate regime: the 2025 Act's own publisher note records that it replaces (ersetzt) the 2009 BSI-Gesetz (BGBl. I S. 2821) outright, and a critical-facility operator (Betreiber kritischer Anlagen) is now bound by the new Act's own Sections 30 and 31 risk-management duties as a besonders wichtige Einrichtung; Section 39's transitional rule only lets an operator already compliant under the old Section 8a evidentiary regime keep its existing proof timetable for a period after commencement, rather than preserving the old duty itself.

Which entity counts as a Betreiber kritischer Anlagen is in turn set by the separate KRITIS-Dachgesetz (the CER Directive's physical-resilience transposition), whose own implementing Rechtsverordnung had not yet entered into force as of this review, so Section 66 keeps a narrower pre-existing definition and a narrower Section 33 registration duty in effect until it does; that dependency concerns which operators are designated, not whether the cyber duties documented here apply once designated.

Germany has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation, and personal-data breach notification under GDPR Articles 33 and 34 and BDSG Sections 41-43 to the BfDI and the Landesdatenschutzbehörden, both of which sit in the privacy topic rather than here.

Only the digital-provider slice of the essential-and-important-entity class (an online marketplace, an online search engine, a social-networking-platform provider, and a cloud-computing-service provider) is flagged on this jurisdiction's rows; the wider sector classes Sections 28 to 31 also reach (critical-facility operators, telecommunications, energy, health, finance, and public administration) are recorded here as law the lint does not yet reach rather than flagged on an unrelated activity.

The Act's official full citation records it as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), and the consolidated text also carries an amendment by Article 4 of the Act of 11 March 2026 (BGBl. 2026 I Nr. 66); the December 2025 date on each instrument is the Act's commencement, not the date it last changed.

Sector security regimes

BSI-Gesetz (BSIG), Risk-Management Measures for Essential and Important Entities

BSI-Gesetz (BSIG) vom 2. Dezember 2025, as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), §§ 28, 30, 38BSI-Gesetz (BSIG), consolidated text, gesetze-im-internet.de, Section 30

In force 10 months, effective 6 December 2025. Binds public and private bodies.

What this law does

Section 30 requires a besonders wichtige Einrichtung or wichtige Einrichtung, as Section 28 defines them against the Anlage 1 and Anlage 2 sector lists, to adopt appropriate, proportionate and effective technical and organisational measures to avoid disruption to the availability, integrity and confidentiality of the network and information systems it uses to provide its services, and to minimise the impact of a security incident, weighing risk exposure, size, implementation cost, and the likelihood and severity of incidents.

The measures must cover at least ten baseline categories: risk analysis and information-security policy, incident handling, business continuity and crisis management, supply-chain security, security in system acquisition and development including vulnerability management and disclosure, evaluation of measures' effectiveness, basic cyber-hygiene training, cryptography, personnel security and access control, and multi-factor or continuous authentication, transposing NIS2 Article 21.

Anlage 2 Nummer 6 names an online marketplace, an online search engine and a social-networking-platform provider among the digital-service providers this duty reaches expressly. Section 38 places implementation and oversight of these measures on the entity's management body, which is liable to the entity for culpable damage under the ordinary rules of company law and must attend regular training on recognising and assessing risk and risk-management practice.

What it requires

Vulnerability and incident reporting

BSI-Gesetz (BSIG), Incident Notification

BSI-Gesetz (BSIG) vom 2. Dezember 2025, as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), § 32BSI-Gesetz (BSIG), consolidated text, gesetze-im-internet.de, Section 32

In force 10 months, effective 6 December 2025. Binds public and private bodies.

What this law does

Section 32 requires a besonders wichtige Einrichtung or wichtige Einrichtung to notify a joint reporting office run by the BSI and the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe of a significant security incident on a graduated clock.

It requires an early warning within 24 hours of becoming aware of the incident, stating whether it may be unlawful or malicious or have cross-border effect, followed by a full notification within 72 hours that confirms or updates that assessment with the incident's severity, impact and any indicators of compromise, and an intermediate report on the BSI's request.

A final report is due within one month of the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report after its resolution, transposing NIS2 Article 23. A Betreiber kritischer Anlagen must additionally report the type of critical facility and critical service affected and the incident's effect on that service.

What it requires

Age gating law3 instruments, 2 in force, 1 enacted but not yet in force

Research summary (216 words)

Germany requires providers of pornographic content in telemedia (internet services) to restrict access to a closed user group of verified adults under Section 4(2) of the Jugendmedienschutz-Staatsvertrag (JMStV, Interstate Treaty on the Protection of Minors in the Media), enforced by the Kommission fuer Jugendmedienschutz (KJM, Commission for the Protection of Minors in the Media).

The 2021 amendment to the Jugendschutzgesetz (JuSchG, Youth Protection Act) created the Bundeszentrale fuer Kinder- und Jugendmedienschutz (BzKJ, Federal Agency for Child and Youth Protection in the Media) and requires, under Section 24a, that platforms accessible to minors adopt structural precautions such as reporting tools, parental controls, and age aware default settings.

The Sechster Medienaenderungsstaatsvertrag (Sixth Interstate Treaty Amending Media Law Treaties), in force since 1 December 2025, added Sections 12 to 12b JMStV, a device level mandate requiring operating systems commonly used by minors to ship a one button youth protection device (Jugendschutzvorrichtung) with an age setting that app distribution platforms and apps must respect; those duties phase in one year after the KJM designates the covered operating systems (designation due by 1 December 2026), so at the latest from 1 December 2027 for current systems.

App and game age labeling through USK.online remains an industry self regulation system operating under JuSchG authority rather than a binding app store verification law.

Adult content age verification (AV)

Jugendmedienschutz-Staatsvertrag (JMStV, Interstate Treaty on the Protection of Minors in the Media), Section 4(2)

JMStV Sec. 4(2), consolidated text in force 2025-12-01official consolidated treaty text published by the German state media authorities (die Medienanstalten)

In force since 1 April 2003. Binds private bodies.

What this law does

Prohibits offering pornographic content in telemedia unless the provider ensures the content is accessible only to adults through a closed user group (geschlossene Benutzergruppe), typically verified by an age verification system (Altersverifikationssystem) assessed against KJM criteria.

Note and primary source

Age-appropriate design code

Jugendschutzgesetz (JuSchG, Youth Protection Act), Section 24a, Vorsorgemassnahmen (provider precautionary measures)

JuSchG Sec. 24aofficial federal law text, gesetze-im-internet.de

In force since 1 May 2021. Binds private bodies.

What this law does

Requires providers of platforms accessible to children and teenagers to implement structural precautions: an accessible reporting and remedy procedure, easily findable references to independent counselling and help services, technical tools for parental control, and default settings that limit usage risk with regard to age.

Enforced by the BzKJ, the federal agency created by the same 2021 amendment that also replaced the former Bundespruefstelle fuer jugendgefaehrdende Medien (BPjM, Federal Review Board for Media Harmful to Young Persons).

Note and primary source

App store age verification (AV)

Jugendmedienschutz-Staatsvertrag (JMStV, Interstate Treaty on the Protection of Minors in the Media), Sections 12-12b, operating system youth protection device (Jugendschutzvorrichtung)

JMStV Secs. 12 12a and 12b, inserted by the Sechster Medienaenderungsstaatsvertrag (Sixth Interstate Treaty Amending Media Law Treaties), treaty in force 2025-12-01; transition rules in JMStV Sec. 25official consolidated treaty text published by the German state media authorities (die Medienanstalten)

Commencement not set. Binds private bodies.

What this law does

Requires providers of operating systems commonly used by children and adolescents, as determined by the KJM, to equip their systems with a youth protection device (Jugendschutzvorrichtung) that can be activated, deactivated and adjusted in a simple, easily accessible and secured way and in which a child's age can be set.

Once an age is set, the operating system must restrict browsing to search engines with a secured search function, allow app installation only from distribution platforms whose apps carry a machine readable age label from a KJM recognized automated rating system, and make only age appropriate apps usable unless individually unlocked by the parent.

Under Section 25 these duties apply one year after the KJM publishes its determination of the covered operating systems, which is itself due within one year of the treaty's 1 December 2025 entry into force, so at the latest from 1 December 2027, extended to at most three years for operating systems in a current or completed production cycle, with non updatable systems on devices already sold exempt.

Note and primary source

News aggregation law3 instruments, 2 in force, 1 repealed, withdrawn or blocked

Research summary (229 words)

Germany transposed the EU Digital Single Market Copyright Directive's press-publisher neighbouring right (Article 15) into the Urheberrechtsgesetz (UrhG) at sections 87f to 87k, replacing the country's earlier 2013 Leistungsschutzrecht, which the Court of Justice of the European Union declared inapplicable in Case C-299/17 for want of technical-standards notification.

That repealed 2013 statute is carried below as its own instrument; the C-299/17 judgment sits in the eu aggregation document, alongside the EU-level right that replaced it. The current right excludes facts, private or non-commercial use, hyperlinks, and single words or very short extracts, lasts two years from a press publication's first appearance, and reserves at least a third of the publisher's revenue from it to the authors and performers whose work the publication carries.

Section 51 UrhG's general quotation exception can permit a snippet's reproduction where the use is justified by a genuine quotation purpose, independent of the press-publisher right.

Germany has no compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code, Canada's Online News Act, or the US JCPA proposals; the neighbouring right's own transferable, licensable structure is the country's only payment mechanism, administered through ordinary negotiation and collecting-society enforcement of the author-participation share rather than a designated bargaining process.

No hot-news or misappropriation doctrine distinct from the general unfair-competition law researched under the scraping topic (Gesetz gegen den unlauteren Wettbewerb) was verified against a primary source.

Press publishers' right

Germany, Leistungsschutzrecht fur Presseverleger (sections 87f-87h Urheberrechtsgesetz)

Achtes Gesetz zur Anderung des Urheberrechtsgesetzes, BGBl. I 2013, Nr. 11, 1. Marz 2013 (effective 1 August 2013)Bundesgesetzblatt

Repealed: no longer in force, effective 1 August 2013. Binds public and private bodies.

What this law does

This German member-state ancillary copyright law (not an EU instrument) gave press publishers the right to prohibit commercial search engines and news aggregators from reproducing parts of 'press products' beyond mere headlines, aiming to require platforms such as Google News to pay licensing fees. In practice it failed: publishers who feared losing traffic granted free licences, and Google displayed only unprotected headlines.

The CJEU declared it inapplicable with retroactive effect in Case C-299/17 (2019) because Germany had not notified the European Commission under the TRIS Directive (98/34/EC); it was subsequently superseded by Germany's transposition of Digital Single Market (DSM) Art. 15.

Note and primary source

Presseverleger-Leistungsschutzrecht (Press Publisher Neighbouring Right)

Urheberrechtsgesetz (UrhG), §§ 87f, 87g, 87h, 87i, 87j, 87kofficial consolidated Urheberrechtsgesetz text, gesetze-im-internet.de

In force. Binds private bodies.

What this law does

A press publisher, meaning whoever produces a press publication (a collection consisting mainly of journalistic writings, published under a single title on a periodic or regularly updated basis, to inform the public about news or other topics, under the publisher's own editorial responsibility, excluding scientific or academic periodicals), holds the exclusive right to make its press publication, in whole or in part, available online and to reproduce it for that purpose.

The right does not reach the use of facts contained in a press publication, private or non-commercial use by individual users, hyperlinking to a press publication, or the use of single words or very short extracts from one.

The right may not be invoked to the detriment of an author or holder of a related right whose work is contained in the publication, nor to stop a third party's use of works validly licensed to the publication under a simple licence or of works that are already in the public domain. It lasts two years from a press publication's first appearance. The currently consolidated text does not apply to publications first published before 6 June 2019.

Authors and holders of related rights are entitled to an appropriate share, at least one third, of the publisher's revenue from exercising this right, an entitlement that can be reduced against their interest only by an agreement resting on a common remuneration rule or a collective bargaining agreement. That entitlement can be asserted only through a collecting society.

The general limitations of German copyright law, including the text-and-data-mining exception and the quotation right, apply correspondingly to the press-publisher right.

Note and primary source

Snippet reproduction

Zitatrecht (Quotation Right)

Urheberrechtsgesetz (UrhG), § 51official consolidated Urheberrechtsgesetz text, gesetze-im-internet.de

In force. Binds public and private bodies.

What this law does

Reproducing, distributing, and publicly communicating a published work for the purpose of quotation is permitted, provided the extent of the use is justified by the specific quotation purpose.

The statute names three illustrative cases: individual works incorporated after publication into an independent scientific work to explain its content, passages of a work cited after publication in an independent work of language, and individual passages of a published musical work cited in an independent musical work.

The quotation privilege covers use of an illustration or other reproduction of the quoted work even where that reproduction is itself separately protected by a copyright or related right. No decision applying this provision specifically to a news aggregator's reproduction of headlines or snippets was verified against a primary source.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.