GERMANY Law and Practice Contributed by: Josefine Spengler and Svetlana Ulrici, Annerton
cial institutions must therefore manage operational resilience primarily under DORA, while ensuring con - sistency with cross-sector governance and reporting duties where applicable. 3.2 ICT Service Provider Contractual Requirements In Germany, mandatory requirements for ICT and third-party service providers arise mainly under DORA and the BSIG (NIS2 implementation). An ICT service provider is defined broadly and functionally, covering any provider supplying digital or data-related services that support critical or regulated functions, such as cloud services, data centres, software, managed IT Criticality depends on the importance of the service for operational continuity and security of the finan - cial entity. Under DORA, certain ICT service providers may also be designated as critical at EU level based on systemic relevance, scale, substitutability and dependency risks. Designated providers are subject to direct oversight, while others are indirectly regu - lated through contractual requirements imposed on supervised entities. Key Contractual Requirements services or network infrastructure. Criticality and Scope of Oversight Regulated entities must ensure that outsourcing and ICT service contracts include specific minimum con - tractual safeguards. These commonly cover: • clearly defined service descriptions and security requirements; • incident notification and co-operation duties; • audit, access and information rights for the regu - lated entity and supervisory authorities; and • termination and exit rights. Contracts must allow regulated entities to demon - strate control over outsourced functions and to com - ply with supervisory expectations throughout the out - sourcing life cycle. Access, Inspection and Audit Rights A core requirement across regimes is that regulated entities retain effective access, inspection and audit rights. This includes the ability to obtain information,
conduct audits or rely on pooled audits, and enable supervisory authorities to exercise their own oversight powers where required. In practice, these rights must be operationally feasi - ble. Authorities increasingly scrutinise whether audit rights are meaningful in cloud and large-scale service environments, rather than purely contractual in nature. Subcontracting and Chain Outsourcing Subcontracting and chain outsourcing are permitted but subject to transparency and control requirements. Regulated entities must be informed of material sub - contracting arrangements and retain the ability to assess associated risks. In critical cases, consent or notification mechanisms are required. The key expec - tation is that risk management extends across the entire outsourcing chain. Regulated entities cannot avoid responsibility by relying on complex subcon - tracting structures. Exit Strategies, Data Portability and Substitutability Exit planning is a central element of third-party risk management. Regulated entities must ensure that contracts provide for orderly termination, including data portability, deletion or return of data, and con - tinued access during transition periods. Organisations are expected to assess substitutability in advance and to avoid excessive dependency on a single provider. For critical services, tested exit strategies and realistic transition plans are increasingly expected. Data Location and Operational Dependencies While data localisation is not generally mandated, reg - ulated entities must maintain transparency over data location and processing. This includes understanding where data and services are hosted and how cross- border dependencies affect risk exposure. In practice, regulators focus on whether data location and ser - vice architecture support effective incident response, supervision and continuity, rather than on strict geo - graphic requirements. However, providers established in the EU or hosting data within the EU are easier to manage, as they operate under a uniform EU data protection and cybersecurity framework, facilitating supervision, audit rights and enforcement.
149 CHAMBERS.COM
Powered by FlippingBook