SOVEREIGNTY LAW ATLAS — DE
Germany
The verdict.
FOUR DOMAINS · CONFIDENCE-LABELLED · AS CAPTURED 2026-08-04selling cloud or AI workloads to German public sector or regulated industry effectively means meeting C5 — plan for it early.
ATLAS RECOMMENDATION — MAXIMUM CLEAN-ORIGIN · C5 culture — restricted component-origin policy, no overflow path. Seeded into the configurator; adjust anything.
The dossier.
SOURCES FOOTNOTED · EVIDENCE STATE LABELLEDDomains
D1 — Data residency & localization
GDPR Chapter V governs transfers.1 The BDSG supplements it nationally, and Germany adds sectoral residency beyond the GDPR baseline — tax-relevant records and parts of the health sector carry hosting expectations. The practical posture: strict interpretation, active data-protection authorities, and procurement that treats transfer risk as a scored criterion.
D2 — AI-specific regulation
The EU AI Act applies directly; phased application runs to August 2026 for most obligations.2 Germany's national enforcement structure (market surveillance allocation) was still being settled at capture. (REPORTED)
D3 — Cloud & procurement sovereignty
The BSI's Cloud Computing Compliance Criteria Catalogue — C5:2020 — is the operative attestation: type 1/2 attestations by auditors against ~120 criteria across 17 domains.3 It is technically a voluntary audit catalogue, but in practice it is the admission ticket for public-sector and regulated-industry cloud in Germany.
D4 — Export & access
Standard EU exposure to US lawful access via US-controlled providers. Germany's response is procurement-side: C5 criteria address provider jurisdiction and disclosure duties, and public tenders routinely prefer EU-controlled providers for sensitive workloads.
Extraterritorial exposure
CLOUD Act reach applies to US-controlled providers operating in Germany. The German market's own mitigation is mature: C5 plus procurement preference means "US-controlled but attested" is an increasingly hard sell for sensitive workloads. US reference record deferred to Phase 2.
Disclaimer
This dossier describes the law as captured on 2026-08-04; it is not legal advice, and no compliance determination is made or implied.
- Regulation (EU) 2016/679 (GDPR), Ch. V — EUR-Lex CELEX 32016R0679 — fetch blocked by EUR-Lex bot-gating (202), cited to official source. (REPORTED) ↑
- Regulation (EU) 2024/1689 (AI Act) — EUR-Lex CELEX 32024R1689 — fetch blocked by EUR-Lex bot-gating (202), cited to official source. (REPORTED) ↑
- Cloud Computing Compliance Criteria Catalogue (C5:2020) — BSI — vault
atlas-vault/de/de-c5/2026-08-04.pdf, sha256e0ad7c23…, captured 2026-08-04. (VERIFIED) ↑
The instruments.
3 ON RECORD · 1 GAPSRegulation (EU) 2016/679 (GDPR), Chapter V — transfers to third countries
REPORTEDCloud Computing Compliance Criteria Catalogue (C5:2020), BSI
VERIFIEDatlas-vault/de/de-c5/2026-08-04.pdf · SHA256 e0ad7c23… · CAPTURED 2026-08-04Regulation (EU) 2024/1689 (AI Act)
REPORTEDUS CLOUD Act / FISA 702 reference record deferred to Phase 2 (PRD §3.2)
This dossier describes the law as captured 2026-08-04; it is not legal advice, and no compliance determination is made or implied.