GERMANY Law and Practice Contributed by: Josefine Spengler and Svetlana Ulrici, Annerton
a follow-up report within 72 hours, and a final report within one month. Authorities – in particular, the BSI – explicitly accept that early warning/initial reports may be incomplete or based on preliminary assessments. The focus at this stage is on enabling co-ordination, risk assessment and, where necessary, technical support. GDPR Under the GDPR, notification obligations arise where an incident qualifies as a personal data breach and is likely to result in a risk to the rights and freedoms of individuals. The threshold is therefore not operational impact but risk to individuals, such as identity theft, fraud or loss of confidentiality. Notification to the state data protection authority is generally required within 72 hours, and notification to affected individuals may be required where the risk is high. Supervisory authori - ties expect prompt breach notifications and may request supplementary information as investigations progress. While post-incident reports are not formally labelled as such under the GDPR, authorities routinely require updates and remedial action plans. In addition to the BSIG and the GDPR, sector-specific German laws may trigger cybersecurity-related inci - dent notification duties. Financial Sector Under DORA, financial entities must classify cyber-, ICT- or payment-related incidents according to a har - monised EU framework distinguishing between major and non-major incidents. Classification criteria include the criticality of affected services, financial and oper - ational impact, data losses, reputational effects and cross-border relevance. Reports must be submitted to BaFin, the supervisory authority for the financial sector. Compared to the BSIG, DORA applies more granular and prescriptive thresholds, reflecting the heightened sensitivity of the financial sector. Only inci - dents classified as “major” trigger full notification obli - gations. Strict deadlines apply: an initial report must be submitted within four hours of classification (at the latest within 24 hours of detection of the incident), interim reports every 72 hours, and a final report within 30 days. Supervisory authorities use these reports pri - marily to assess operational resilience and third-party
risk management, rather than to sanction early report - ing behaviour. Operators of Critical Infrastructure (KRITIS) KRITIS operators are subject to heightened incident- reporting obligations under the German IT security framework. Since 1 April 2025, stricter notification requirements apply, including a 24-hour deadline for initial incident notification. Owing to the systemic rel - evance of critical services, even disruptions with lim - ited immediate impact may trigger reporting duties. Telecommunications Providers Telecommunications providers must report security breaches affecting networks or services pursuant to Section 168 of the Telecommunications Act (TKG). Notifications must be made to both the BSI and the Federal Network Agency ( Bundesnetzagentur ). These obligations operate alongside, and independently from, GDPR breach notification requirements. As a result, cybersecurity incidents in Germany fre - quently trigger parallel notification obligations under multiple legal regimes, each with different classifica - tion criteria and timelines. Organisations operating in regulated or critical sectors must therefore assess incidents against several statutory thresholds simul - taneously and ensure co-ordinated reporting to avoid delays or inconsistencies. 2.4 State Responsibilities and Obligations The German State bears primary responsibility for national cyber-resilience, understood as the ability of public institutions and essential services to prevent, withstand and recover from cyber-incidents. This responsibility is anchored in a co-ordinated federal approach, with cybersecurity treated as a matter of internal security, economic stability and public safety. The State’s role focuses on setting strategic direc - tion, ensuring operational readiness and co-ordinating responses to large-scale or systemic cyber-incidents. Operationally, responsibilities are concentrated at the federal level, while state authorities retain roles in spe - cific sectors and enforcement contexts. The overall objective is to maintain continuity of public services and limit cascading effects across society and the economy.
147 CHAMBERS.COM
Powered by FlippingBook