Germany';s regulatory landscape has shifted considerably in recent months, with new obligations taking effect across corporate governance, employment law, data protection, and financial services. For international businesses operating in Germany, staying current with these changes is not optional - non-compliance carries material financial and reputational risk. This guide summarises the most consequential developments of the current quarter, explains what they mean in practice, and identifies the steps businesses should take now.
Germany regulatory 2026: the key themes shaping Q1
Several converging forces are driving the current wave of regulatory activity in Germany. EU-level directives are being transposed into national law on accelerated timelines, the Federal Financial Supervisory Authority (BaFin) has intensified its supervisory posture, and the Federal Ministry of Labour and Social Affairs has issued updated guidance on several employment-related obligations. At the same time, the German courts - particularly the Federal Labour Court (Bundesarbeitsgericht) and the Federal Court of Justice (Bundesgerichtshof) - have issued rulings that materially affect how existing rules are interpreted and enforced.
The practical consequence for foreign-owned businesses is that rules which appeared settled are being re-examined. A common mistake among international founders is to assume that compliance frameworks established at the time of incorporation remain sufficient. In Germany, regulatory obligations evolve continuously, and the burden of monitoring that evolution falls on the company itself, not on any public authority to notify it.
Three themes dominate this quarter: the tightening of supply chain due diligence obligations under the Lieferkettensorgfaltspflichtengesetz (LkSG), updates to the working-time recording regime following recent court guidance, and new anti-money-laundering (AML) requirements affecting a broader range of corporate structures than before.
Supply chain due diligence: expanded scope and stricter enforcement under the LkSG
The Act on Corporate Due Diligence Obligations in Supply Chains - commonly abbreviated as LkSG - has been in force for larger companies for some time. The current quarter marks the point at which the threshold for mandatory compliance has dropped, bringing a significant number of mid-sized businesses into scope for the first time.
Companies now subject to the LkSG must conduct annual risk analyses of their own operations and those of their direct suppliers. Where risks are identified - covering human rights violations and certain environmental harms - the company must adopt preventive measures, establish a complaints mechanism, and document its actions in a publicly accessible annual report. The Federal Office for Economic Affairs and Export Control (BAFA) is the competent supervisory authority and has the power to impose fines and, in serious cases, exclude non-compliant companies from public procurement.
In practice, the compliance burden is heavier than many mid-sized operators anticipated. The risk analysis alone requires structured engagement with suppliers, which takes time and specialist input. A non-obvious requirement is that the complaints mechanism must be accessible to third parties outside the company - not merely to employees - and must be operational before the annual reporting deadline, not simultaneously with it.
Two practical scenarios illustrate the stakes. A German subsidiary of a US manufacturing group that previously fell below the threshold now finds itself in scope. Its parent company';s global supplier code of conduct does not automatically satisfy the LkSG';s specific documentation and procedural requirements, and a gap analysis is necessary before the next reporting cycle. Separately, a German-based trading company sourcing goods from multiple jurisdictions must map its direct supplier relationships and assess which categories of risk are most material - a process that cannot be completed in a matter of days.
Businesses that have not yet begun their LkSG compliance programme should treat this as urgent. BAFA has signalled that it will move from a guidance-oriented approach to active enforcement, and the first formal fines under the regime are expected to be issued in the near term.
Working-time recording: what the current legal position requires
The obligation to record working time in Germany has been clarified significantly by recent court decisions and regulatory guidance. The Federal Labour Court';s ruling - building on the earlier European Court of Justice decision in the CCOO case - established that employers are required to implement an objective, reliable, and accessible system for recording the daily working time of all employees. This obligation applies regardless of whether employees work on-site, remotely, or in hybrid arrangements.
The current regulatory position is that the system must capture not only the start and end of the working day but also breaks. Paper-based records are not prohibited, but they must meet the same standards of objectivity and accessibility as digital systems. Many employers operating informal or trust-based working-time arrangements are now in a legally exposed position.
The Federal Ministry of Labour and Social Affairs has indicated that draft legislation to codify these requirements in the Arbeitszeitgesetz (Working Hours Act) is at an advanced stage. Until that legislation is enacted, the court-derived obligation applies directly. Employers who have not yet implemented a compliant recording system face risk of challenge by works councils, individual employees, or labour inspectorates.
A common mistake is to treat working-time recording as an administrative formality rather than a substantive legal obligation. In Germany, works councils have co-determination rights over the introduction of technical systems used to monitor employee behaviour, including time-recording tools. Introducing a new system without proper consultation with the works council is itself a breach of the Betriebsverfassungsgesetz (Works Constitution Act) and can result in the system being challenged or suspended.
For businesses with remote or internationally mobile employees, the position is more complex. Employees working from home in Germany are subject to the same working-time rules as those on-site. A non-obvious requirement is that the employer';s obligation to record time does not disappear simply because the employee is working autonomously - the employer must put a system in place that makes accurate recording possible and must actively encourage its use.
If your business is navigating the intersection of working-time compliance and remote work arrangements, contact info@vlolawfirm.com. We can assist with documents and filings, and help structure your compliance framework correctly from the outset.
Data protection enforcement and new guidance from German supervisory authorities
Germany';s data protection landscape remains among the most actively enforced in the EU. The country';s sixteen state-level data protection authorities (Landesdatenschutzbehörden), together with the Federal Commissioner for Data Protection and Freedom of Information (BfDI), continue to issue guidance and enforcement decisions at a pace that requires ongoing attention from compliance teams.
Several significant developments have emerged this quarter. First, the Conference of Independent Data Protection Supervisory Authorities (Datenschutzkonferenz, or DSK) has issued updated guidance on the use of artificial intelligence tools in employment contexts. The guidance addresses the use of AI for recruitment screening, performance monitoring, and automated decision-making affecting employees. Under the General Data Protection Regulation (GDPR) as applied in Germany, automated decisions that produce legal or similarly significant effects on individuals require a valid legal basis, and employees must be informed of the logic involved.
Second, enforcement activity targeting cookie consent mechanisms has intensified. Several German supervisory authorities have issued formal warnings and, in some cases, fines against businesses whose websites use consent banners that do not meet the standard of freely given, specific, informed, and unambiguous consent. The use of pre-ticked boxes, consent walls, or dark patterns that nudge users toward acceptance continues to attract regulatory attention.
Third, cross-border data transfers remain a live compliance issue. Following the invalidation of earlier transfer mechanisms and the adoption of the EU-US Data Privacy Framework, businesses transferring personal data to non-EEA countries must ensure that their transfer mechanisms are current and properly documented. German supervisory authorities have indicated that they will scrutinise transfer impact assessments more closely, particularly where data is transferred to jurisdictions with broad government access powers.
In practice, many mid-sized businesses operating in Germany underestimate the resource commitment required to maintain GDPR compliance. A records-of-processing-activities document that was accurate at the time of preparation becomes outdated as business processes change. Regular review - at least annually, and whenever a material change occurs - is a de jure requirement under Article 30 GDPR, not merely a best practice.
AML compliance: new obligations for corporate structures and virtual asset service providers
Germany has transposed the latest EU anti-money-laundering directives into national law through amendments to the Geldwäschegesetz (GwG, the Money Laundering Act). The current quarter brings into effect a set of changes that expand the range of entities subject to AML obligations and tighten the requirements for those already in scope.
The most significant change for corporate clients is the extension of enhanced due diligence requirements to a broader category of high-risk business relationships. Companies that maintain business relationships with counterparties in jurisdictions identified on the EU';s list of high-risk third countries must now apply enhanced customer due diligence measures, including more frequent reviews and senior management approval for the relationship. This applies not only to financial institutions but also to lawyers, notaries, accountants, and tax advisers acting in certain capacities.
The Transparenzregister - Germany';s beneficial ownership register - continues to be a central compliance tool. All legal entities established in Germany are required to maintain accurate and current beneficial ownership information in the register. Recent amendments have reduced the grace period for notifying changes in beneficial ownership, meaning that updates must be filed more promptly than before. BaFin and the Financial Intelligence Unit (FIU) have access to the register and use it as a primary reference in AML investigations.
Virtual asset service providers (VASPs) operating in Germany face a materially more demanding compliance environment following recent regulatory updates. BaFin has clarified its supervisory expectations for VASPs, including requirements for transaction monitoring, suspicious activity reporting, and the application of the travel rule to crypto-asset transfers above specified thresholds. Businesses in this sector that have not yet conducted a gap analysis against the current BaFin guidance should do so without delay.
Two practical scenarios are instructive. A German GmbH with a beneficial owner who is a national of a third country must ensure that the Transparenzregister entry accurately reflects the current ownership structure, including any indirect holdings above the 25% threshold. A change in ownership that is not notified within the required period exposes both the company and its managing directors to fines. Separately, a fintech company providing crypto-asset exchange services must ensure that its AML programme addresses the travel rule in a technically compliant manner - a requirement that many smaller operators have not yet fully implemented.
For businesses that need to review or update their AML compliance frameworks, contact info@vlolawfirm.com. We can help structure the setup correctly the first time and advise on the specific documentation required by German law.
Employment law: recent developments affecting international employers in Germany
Beyond working-time recording, several other employment law developments are relevant for international businesses with German operations this quarter.
The Mindestlohngesetz (Minimum Wage Act) has been updated, with the statutory minimum wage adjusted upward. Employers must ensure that all employees - including those on variable pay structures, piece-rate arrangements, or commission-based compensation - receive at least the statutory minimum for every hour worked. A common mistake is to assume that a high base salary makes minimum wage compliance straightforward. Where employees work variable hours or are expected to be available outside contracted hours, the effective hourly rate may fall below the statutory floor.
The Posted Workers Act (Arbeitnehmer-Entsendegesetz, AEntG) continues to apply to businesses posting employees to Germany from other countries. Employers must register postings with the customs authority (Zoll) before work begins, maintain documentation on-site, and ensure that posted workers receive at least the conditions applicable under relevant collective agreements in the relevant sector. Failure to comply exposes the employer - and in some cases the German client company - to significant fines.
The Federal Labour Court has also issued guidance on the enforceability of non-compete clauses in employment contracts. Under German law, a post-contractual non-compete clause is only enforceable if the employer pays compensation of at least half the employee';s most recent contractual remuneration for the duration of the restriction. Clauses that do not meet this standard are either void or, in some cases, binding on the employer but not the employee - a result that many international employers find counterintuitive.
Finally, the regulation of fixed-term employment contracts under the Teilzeit- und Befristungsgesetz (TzBfG) remains a source of compliance risk. Fixed-term contracts without an objective justification are only permissible for a limited period and may not be renewed more than a specified number of times with the same employee. Courts have taken a strict approach to what constitutes a genuine objective justification, and businesses that routinely use fixed-term contracts as a flexible staffing tool should review their practices against current case law.
Frequently asked questions
What are the most immediate compliance actions a foreign-owned German subsidiary should take this quarter?
The most pressing actions depend on the company';s sector and size, but three apply broadly. First, confirm whether the company has crossed the LkSG threshold and, if so, initiate the risk analysis and complaints mechanism without delay. Second, audit the working-time recording system to ensure it meets the standard required by current court guidance - paper records are acceptable only if they are objective, reliable, and accessible. Third, review the Transparenzregister entry to confirm that beneficial ownership information is accurate and that any recent changes have been notified within the required period. These three steps address the areas where enforcement activity is currently most concentrated.
How long does it typically take to implement a compliant LkSG programme, and what does it cost?
The timeline varies significantly depending on the complexity of the supply chain and the maturity of existing compliance infrastructure. For a mid-sized company with a relatively straightforward supplier base, a basic compliant programme - covering risk analysis, preventive measures, and a complaints mechanism - can typically be established within several months of focused effort. For companies with complex, multi-tier supply chains spanning multiple jurisdictions, the process takes considerably longer. Professional fees for legal and compliance advisory support generally start from the low thousands of EUR for scoping and gap analysis, rising substantially for full programme implementation. The cost of non-compliance - BAFA fines and exclusion from public procurement - is materially higher.
Can a German GmbH use a standard global employment contract template for its German employees?
In most cases, no. German employment law contains a large number of mandatory provisions that cannot be contracted out of, and many standard global templates do not reflect them. Key areas of divergence include notice periods, which are governed by the Bürgerliches Gesetzbuch (BGB) and cannot be reduced below statutory minimums; the treatment of overtime and working-time limits under the Arbeitszeitgesetz; the enforceability of non-compete clauses; and the specific requirements for fixed-term contracts under the TzBfG. A global template that is not reviewed and adapted for Germany creates legal exposure that may not become apparent until a dispute arises. German-law employment contracts should be reviewed by counsel familiar with both the statutory framework and current case law.
Conclusion
Germany';s regulatory environment is demanding and continues to evolve at pace. The developments of the current quarter - across supply chain due diligence, working-time recording, data protection, AML compliance, and employment law - require active attention from businesses of all sizes. Waiting for a dispute or an enforcement action to prompt a compliance review is a costly approach in a jurisdiction where regulators are well-resourced and courts apply statutory obligations strictly.
VLO Law Firms advises international clients on regulatory compliance and corporate matters in Germany. We can assist with LkSG programme implementation, employment contract review, Transparenzregister filings, data protection gap analyses, and AML compliance frameworks. To request a consultation, contact: info@vlolawfirm.com