GERMANY Law and Practice Contributed by: Josefine Spengler and Svetlana Ulrici, Annerton
critical ICT third-party providers on 18 November 2025, which effectively marked the operational “start - ing point” for direct oversight. Supervisory Measures and Investigative Tools For such critical ICT providers, the Lead Overseer has a toolkit designed to overcome classic supervision barriers (lack of access, cross-border service deliv - ery, concentration). In particular, DORA contemplates: • information and documentation requests (including on subcontracting) and follow-up reporting expec - tations; • general investigations and on-site/off-site inspec - tions, backed by formal decisions and procedural safeguards; and • recommendations following investigations/inspec - tions, which are shared with the competent author - ities of the affected financial entities – critical ICT providers must respond within a set period (“follow or explain”). A practical “how we will do this” layer is also provided by the ESAs’ Guide on DORA oversight activities (15 July 2025), which (while not legally binding) signals supervisory expectations and process mechanics. Sanctioning Powers and Typical Penalty Ranges (Critical ICT Providers) The most distinctive sanctioning tool at EU level is periodic penalty payments to compel co-operation and remediation. DORA allows the Lead Overseer to impose daily penalty payments for non-compliance – up to 1% of the provider’s average daily worldwide turnover, for up to six months (until compliance is achieved). Public, provider-specific sanctions against designat - ed critical ICT providers are not yet given (the regime is still early-cycle), but the penalty payment lever is explicitly built for fast escalation where access/co- operation is blocked. What This Means in Practice Even if a critical ICT provider is headquartered outside Germany (or outside the EU), the oversight regime is designed to remain enforceable where the provider is systemic for EU financial services (including via “busi -
ness presence” expectations discussed in the Regula - tion’s recitals). 3.5 International Data Transfers Germany does not operate a general cybersecurity- driven data localisation rule comparable to strict “data must stay in-country” requirements. Instead, cross- border data handling is governed primarily by EU data protection law (GDPR) and, in the financial sector, by DORA’s ICT third-party risk framework. In practice, this means that firms can use global providers but must be able to demonstrate control, auditability and recoverability even when services and data are deliv - ered from outside the EU. DORA does not ban third-country outsourcing, but it treats location and cross-border dependencies as core resilience factors. A practical lever is the regis - ter of information: financial entities must document ICT outsourcing comprehensively, including relevant subcontractors for ICT services supporting critical or important functions. This enables supervisors to identify geographical dependencies and concentra - tion patterns, and it forces firms to understand where their critical ICT services are actually delivered from. EU and sectoral outsourcing guidance (commonly used as a benchmark in practice) repeatedly highlights five areas that become more complex when provid - ers or processing are outside the EU: data and sys - tem security, data location and processing location, access and audit rights, chain outsourcing, and exit strategies/contingency planning. From a resilience perspective, the “third-country” issue is often less about where the servers sit and more about whether foreign legal constraints (eg, restrictions on disclo - sure or audit) could undermine supervision, incident response or recovery planning. A recurring market reality is therefore that EU-hosted/ EU-established providers are operationally easier to manage, because a uniform EU legal baseline typically reduces friction around supervisory access, audit exe - cution and enforcement (particularly when combined with GDPR-aligned contractual set-ups). Where operational resilience outsourcing involves personal data and the data leaves the European Eco -
151 CHAMBERS.COM
Powered by FlippingBook