GERMANY Law and Practice Contributed by: Josefine Spengler and Svetlana Ulrici, Annerton
typically includes access controls, encryption, logging and incident-response capabilities. Data protection law does not establish a separate cybersecurity regime but integrates cybersecurity into compliance wherever personal data is processed. Cyber-incidents involving personal data often trigger parallel obligations under the GDPR and sector-spe - cific cybersecurity frameworks, requiring aligned gov - ernance and escalation processes. A personal data breach includes breaches of confi - dentiality, integrity or availability. Where a breach is likely to result in a risk to individuals, the supervisory authority must be notified within 72 hours of aware - ness. If a high risk exists, affected individuals must also be informed without undue delay, subject to lim - ited exceptions such as effective encryption. Notifications must describe the nature and scope of the breach, its likely consequences and the mitigation measures taken or planned. Where necessary, infor - mation may be provided in stages. German authori - ties actively enforce these obligations and expect demonstrable preparedness, including documented risk assessments and tested incident-response pro - cedures. 6.2 Cybersecurity and AI In Germany, cybersecurity obligations for AI systems primarily arise from the EU AI Act, which introduces horizontal requirements based on risk classification. Although the AI Act is not a cybersecurity law in the strict sense, it embeds security-by-design and resil - ience expectations – particularly for high-risk AI sys - tems – as part of its risk management and governance framework. For high-risk AI, providers must ensure appropriate levels of robustness and cybersecurity throughout the system life cycle, including protection against manipu - lation, data poisoning and similar attacks. Security is treated as an inherent quality requirement rather than a purely operational measure. The AI Act also addresses supply-chain and compo - nent security. Providers remain responsible for risks arising from training data, pre-trained models and
third-party components, and must maintain appropri - ate documentation, traceability and controls propor - tionate to the system’s risk profile. High-risk AI systems are subject to post-market moni - toring and incident-reporting obligations. Serious inci - dents or malfunctions must be reported to competent authorities without undue delay. These duties comple - ment existing notification obligations under cyberse - curity and data protection law, meaning that a single incident may trigger multiple reporting regimes. AI-specific cybersecurity requirements interact closely with general obligations under the GDPR, NIS2/new BSIG and, where applicable, the CRA. Where personal data is processed, GDPR security and breach-notifi - cation rules apply in full. In practice, organisations are expected to integrate AI governance into their exist - ing cybersecurity and data protection frameworks to ensure consistent risk management and incident response across regimes. 6.3 Cybersecurity in the Healthcare Sector In Germany, healthcare providers are subject to height - ened cybersecurity obligations due to the sensitivity of health data and the critical nature of healthcare ser - vices. These obligations arise from a combination of data protection law, sector-specific healthcare regula - tion and general cybersecurity legislation. Many hos - pitals and larger healthcare institutions are classified as critical infrastructure (KRITIS) operators and must implement risk-based technical and organisational measures, including incident-response planning and regular security assessments, under BSI supervision. Cybersecurity requirements for medical devices are primarily shaped by EU product regulation. Under the Medical Device Regulation (Regulation EU 2017/745 – MDR), manufacturers must address cybersecurity risks throughout the product life cycle. Where devices qualify as products with digital elements, additional horizontal EU cybersecurity requirements may apply, reinforcing security-by-design, vulnerability manage - ment and update capabilities. Germany’s electronic health record systems and digi - tal health infrastructure are subject to specific statu - tory security requirements, including access controls,
155 CHAMBERS.COM
Powered by FlippingBook