← SOVEREIGNTY LAW ATLAS

SOVEREIGNTY LAW ATLAS — DE

Germany

TIER DEMO · STATUS PUBLISHED · LAST FULL REVIEW 2026-08-04 · 3 INSTRUMENTS ON RECORD

The verdict.

FOUR DOMAINS · CONFIDENCE-LABELLED · AS CAPTURED 2026-08-04
Data residency & localizationD1 — WHERE DATA MUST LIVE EU regime plusREPORTED
AI-specific regulationD2 — AI ACTS & REGISTRATION DUTIES EU AI actREPORTED
Cloud & procurement sovereigntyD3 — CERTIFICATION & MANDATES Certification schemeVERIFIED
Export & access lawsD4 — EXTRATERRITORIAL REACH Standard EU exposureJUDGMENT
Instruments on record 3
Last full review 2026-08-04
Status PUBLISHED
For a buyer

selling cloud or AI workloads to German public sector or regulated industry effectively means meeting C5 — plan for it early.

Configure your SovereigntyBox for Germany →

ATLAS RECOMMENDATION — MAXIMUM CLEAN-ORIGIN · C5 culture — restricted component-origin policy, no overflow path. Seeded into the configurator; adjust anything.

The dossier.

SOURCES FOOTNOTED · EVIDENCE STATE LABELLED

Domains

D1 — Data residency & localization

GDPR Chapter V governs transfers.1 The BDSG supplements it nationally, and Germany adds sectoral residency beyond the GDPR baseline — tax-relevant records and parts of the health sector carry hosting expectations. The practical posture: strict interpretation, active data-protection authorities, and procurement that treats transfer risk as a scored criterion.

D2 — AI-specific regulation

The EU AI Act applies directly; phased application runs to August 2026 for most obligations.2 Germany's national enforcement structure (market surveillance allocation) was still being settled at capture. (REPORTED)

D3 — Cloud & procurement sovereignty

The BSI's Cloud Computing Compliance Criteria Catalogue — C5:2020 — is the operative attestation: type 1/2 attestations by auditors against ~120 criteria across 17 domains.3 It is technically a voluntary audit catalogue, but in practice it is the admission ticket for public-sector and regulated-industry cloud in Germany.

D4 — Export & access

Standard EU exposure to US lawful access via US-controlled providers. Germany's response is procurement-side: C5 criteria address provider jurisdiction and disclosure duties, and public tenders routinely prefer EU-controlled providers for sensitive workloads.

Extraterritorial exposure

CLOUD Act reach applies to US-controlled providers operating in Germany. The German market's own mitigation is mature: C5 plus procurement preference means "US-controlled but attested" is an increasingly hard sell for sensitive workloads. US reference record deferred to Phase 2.

Disclaimer

This dossier describes the law as captured on 2026-08-04; it is not legal advice, and no compliance determination is made or implied.

  1. Regulation (EU) 2016/679 (GDPR), Ch. V — EUR-Lex CELEX 32016R0679 — fetch blocked by EUR-Lex bot-gating (202), cited to official source. (REPORTED)
  2. Regulation (EU) 2024/1689 (AI Act) — EUR-Lex CELEX 32024R1689 — fetch blocked by EUR-Lex bot-gating (202), cited to official source. (REPORTED)
  3. Cloud Computing Compliance Criteria Catalogue (C5:2020) — BSI — vault atlas-vault/de/de-c5/2026-08-04.pdf, sha256 e0ad7c23…, captured 2026-08-04. (VERIFIED)

The instruments.

3 ON RECORD · 1 GAPS

Regulation (EU) 2016/679 (GDPR), Chapter V — transfers to third countries

REPORTED
TYPE REGULATION (EU, INLINE)STATUS IN-FORCEENACTED 2016-04-27 · IN FORCE 2018-05-25
AuthorityEUR-Lex
Evidencefetch-blocked — EUR-Lex returns 202 to scripted fetch (2026-08-04)
RAGnot-submitted

Cloud Computing Compliance Criteria Catalogue (C5:2020), BSI

VERIFIED
TYPE CERTIFICATION-CRITERIASTATUS IN-FORCEPUBLISHED 2020-02
AuthorityBSI
EvidenceVAULT atlas-vault/de/de-c5/2026-08-04.pdf · SHA256 e0ad7c23… · CAPTURED 2026-08-04
RAGblocked — parser staging 401

Regulation (EU) 2024/1689 (AI Act)

REPORTED
TYPE REGULATION (EU, INLINE)STATUS IN-FORCE (STAGED APPLICATION)ENACTED 2024-06-13 · IN FORCE 2024-08-01
AuthorityEUR-Lex
Evidencefetch-blocked — EUR-Lex returns 202 to scripted fetch (2026-08-04)
RAGnot-submitted
GAP — D4 · VERIFIED 2026-08-04VERIFIED ABSENCE

US CLOUD Act / FISA 702 reference record deferred to Phase 2 (PRD §3.2)

This dossier describes the law as captured 2026-08-04; it is not legal advice, and no compliance determination is made or implied.

SBX CONCIERGEnothing leaves this page