Legal-Updates
2026-07-09 00:00 Legal-Updates

Regulatory Update in Germany: Q2 2026

Germany';s regulatory environment is shifting across several fronts this quarter, with meaningful changes in corporate compliance, employment law, data protection, and financial regulation. Businesses operating in or entering the German market face a denser compliance calendar than in previous periods. This guide covers the most consequential developments in germany regulatory 2026, explains what each change means in practice, and identifies the steps companies should take to remain compliant.

Corporate compliance: new obligations for companies registered in Germany

The German Commercial Code (Handelsgesetzbuch, HGB) and the Act on the Modernisation of Partnership Law (MoPeG) continue to reshape how German entities report, govern, and disclose. Recent amendments have tightened the rules around annual financial statement filings with the Bundesanzeiger (Federal Gazette), the official publication register operated under the authority of the Federal Office of Justice (Bundesamt für Justiz). Companies that previously fell below certain size thresholds may now find themselves reclassified following updated criteria, triggering additional audit and disclosure requirements.

The transparency register, maintained under the Money Laundering Act (Geldwäschegesetz, GwG), has seen further enforcement activity. Beneficial ownership entries must be current and accurate. Discrepancies between the transparency register and the commercial register (Handelsregister) are now subject to faster escalation by the Federal Administrative Office (Bundesverwaltungsamt), which acts as the supervisory body for the transparency register. Fines for non-compliance can be substantial, and the authority has signalled a more proactive audit posture.

A non-obvious requirement that catches many foreign-owned subsidiaries is the obligation to update beneficial ownership data within a short window - typically no more than a few weeks - whenever a shareholding change occurs at any level of the ownership chain, including changes in the parent company abroad. Many underestimate how quickly this obligation triggers, particularly in group restructurings.

In practice, founders and corporate secretaries should conduct a quarterly review of all register entries to confirm alignment. A common mistake is treating the transparency register as a one-time filing rather than a living record.

Employment law developments affecting German operations

German employment law is governed primarily by the Works Constitution Act (Betriebsverfassungsgesetz, BetrVG), the Protection Against Dismissal Act (Kündigungsschutzgesetz, KSchG), and the Minimum Wage Act (Mindestlohngesetz, MiLoG). Recent developments touch all three.

The statutory minimum wage has been adjusted upward following the recommendation of the Minimum Wage Commission (Mindestlohnkommission). Employers must update payroll systems promptly. Failure to apply the correct minimum wage exposes companies to back-pay claims and administrative fines from the Customs Investigation Office (Zollfahndungsamt), which enforces wage compliance through workplace inspections.

Works council (Betriebsrat) rights have been reinforced through recent Federal Labour Court (Bundesarbeitsgericht, BAG) rulings. The BAG has clarified the scope of co-determination rights in relation to remote work arrangements and algorithmic performance monitoring. Employers using automated tools to track productivity or allocate tasks must now engage the works council before deployment. This applies to software-as-a-service tools as much as to bespoke systems.

A practical scenario: a mid-sized technology company with 60 employees in Berlin introduces a project management platform that logs individual task completion rates. Under current BAG guidance, this constitutes a monitoring measure subject to works council approval. Deploying the tool without that approval risks an injunction and potential damages.

A second scenario: a foreign group relocates a senior manager to Germany on a secondment. If the secondment exceeds a certain duration, German employment law applies in full, including dismissal protection. Many international employers assume that a home-country contract governs throughout; in Germany, this assumption is frequently incorrect.

For questions about structuring employment arrangements correctly, contact info@vlolawfirm.com. We can assist with works council procedures, contract drafting, and compliance reviews.

Data protection: enforcement trends and new guidance from German authorities

Germany';s data protection landscape is shaped by the EU General Data Protection Regulation (GDPR) and the Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG). Germany is unusual in having 16 state-level data protection authorities (Landesdatenschutzbehörden) alongside the Federal Commissioner for Data Protection and Freedom of Information (Bundesbeauftragter für den Datenschutz und die Informationsfreiheit, BfDI). Enforcement is therefore decentralised, and the supervisory authority with jurisdiction depends on where a company is established.

Recent enforcement trends show increased scrutiny of:

  • Cookie consent mechanisms that do not meet the "freely given, specific, informed and unambiguous" standard
  • Data transfers to third countries where adequacy decisions are absent or contested
  • Retention periods that are set by policy but not enforced in practice
  • Processor agreements (Auftragsverarbeitungsverträge) that lack the mandatory clauses required under Article 28 GDPR
  • Employee monitoring practices that conflict with Section 26 BDSG, which governs the processing of employee data

The Conference of Independent Data Protection Supervisory Authorities (Datenschutzkonferenz, DSK) has issued updated guidance on artificial intelligence systems that process personal data. Companies deploying AI-driven recruitment tools, customer profiling systems, or automated decision-making processes must carry out a Data Protection Impact Assessment (DPIA) under Article 35 GDPR before going live. The DSK guidance specifies that a DPIA is required whenever AI outputs have a significant effect on individuals, even if the final decision is made by a human.

A common mistake among companies entering the German market is assuming that a GDPR compliance programme built for another EU member state transfers seamlessly. German authorities apply the BDSG';s additional requirements, particularly around employee data and works council involvement in data processing decisions, more strictly than many other jurisdictions.

Financial regulation and anti-money laundering updates

The German financial regulatory framework is administered primarily by the Federal Financial Supervisory Authority (Bundesanstalt für Finanzdienstleistungsaufsicht, BaFin). Recent quarters have seen BaFin intensify its supervisory activity across payment services, crypto-asset service providers, and investment firms operating under MiFID II passporting arrangements.

The EU';s Markets in Crypto-Assets Regulation (MiCA) is now in effect, and BaFin is the competent authority for authorising crypto-asset service providers (CASPs) established in Germany. Firms that previously operated under transitional arrangements must have submitted their authorisation applications or ceased regulated activities. BaFin has indicated that it will not extend informal grace periods indefinitely. The authorisation process involves a detailed review of governance structures, capital adequacy, and AML/CFT controls.

Anti-money laundering obligations under the GwG have been updated to reflect the EU';s revised AML package. Obliged entities - which include not only banks but also lawyers, notaries, real estate agents, and tax advisers - must apply enhanced due diligence in a broader set of circumstances. The definition of politically exposed persons (PEPs) has been clarified, and the look-back period for PEP status has been extended in certain cases.

A practical scenario: a German GmbH acting as a payment agent for a non-EU parent company is now required to conduct a fresh risk assessment of its correspondent relationships. If the parent is located in a jurisdiction on the FATF grey list, enhanced due diligence applies automatically, regardless of the historical relationship.

Many underestimate the documentation burden. BaFin inspections increasingly focus on whether risk assessments are genuinely tailored to the specific business rather than copied from generic templates. Firms that cannot demonstrate a live, updated risk management framework face remediation orders and, in serious cases, licence suspension.

Sustainability and supply chain compliance: the LkSG in practice

The Act on Corporate Due Diligence Obligations in Supply Chains (Lieferkettensorgfaltspflichtengesetz, LkSG) has been in force for larger companies for some time, and the scope has now extended to mid-sized enterprises meeting the current employee thresholds. The Federal Office of Economics and Export Control (Bundesamt für Wirtschaft und Ausfuhrkontrolle, BAFA) is the enforcement authority.

Under the LkSG, in-scope companies must:

  • Conduct an annual risk analysis of their own operations and direct suppliers
  • Establish a complaints mechanism accessible to affected persons
  • Take remedial action when risks or violations are identified
  • Report annually to BAFA on their due diligence activities

BAFA has moved from a guidance-focused posture to active enforcement. Recent inspection cycles have targeted companies in the automotive supply chain, the textile sector, and electronics manufacturing. Fines are calculated as a percentage of annual global turnover for larger companies, making non-compliance financially significant.

A non-obvious requirement is that the LkSG';s risk analysis must cover not only direct (Tier 1) suppliers but also indirect suppliers where a company has "substantiated knowledge" of a risk. This standard is lower than many compliance teams assume. A credible NGO report or a credible media report about conditions at a Tier 2 supplier can trigger the obligation to investigate and act.

The EU Corporate Sustainability Due Diligence Directive (CS3D) will layer additional obligations on top of the LkSG once transposed into German law. Companies should begin aligning their LkSG frameworks with CS3D requirements now to avoid a second implementation cycle.

For assistance structuring a supply chain compliance programme that satisfies both LkSG and emerging EU requirements, contact info@vlolawfirm.com. We can help with risk analysis frameworks, supplier questionnaires, and BAFA reporting.

FAQ

What are the most immediate compliance risks for foreign companies operating in Germany this quarter?

The most pressing risks cluster around three areas: beneficial ownership register accuracy under the GwG, works council engagement obligations triggered by new technology deployments, and MiCA authorisation deadlines for crypto-asset businesses. Foreign companies often underestimate how quickly German authorities escalate non-compliance. BAFA, BaFin, and the Bundesverwaltungsamt all have active inspection programmes. The practical priority is to audit current register entries, review any new software or AI tools for works council notification requirements, and confirm that any regulated financial activities have the correct BaFin authorisation in place.

How long does it typically take to address a compliance gap identified by a German authority, and what costs are involved?

Timelines depend heavily on the nature of the gap. A transparency register correction can often be completed within days if the underlying corporate documents are in order. A works council consultation process for a new workplace tool typically runs four to eight weeks, depending on the complexity of the measure and the works council';s workload. A BaFin remediation order for AML deficiencies may require several months of structured engagement. Professional fees for regulatory remediation work in Germany generally start from the low thousands of EUR for straightforward matters and rise significantly for complex multi-authority situations. State filing fees are separate and vary by register and entity type.

Should a company operating in Germany maintain separate compliance frameworks for LkSG and GDPR, or can these be integrated?

Integration is possible and increasingly recommended. Both frameworks require risk assessments, documented processes, and evidence of ongoing monitoring. A unified compliance management system can capture supplier due diligence data, data processing records, and incident logs in a single structure. The key is to ensure that the responsible functions - typically legal, compliance, and procurement - coordinate rather than operate in silos. In practice, many mid-sized companies find that a shared risk register with module-specific sections is more sustainable than maintaining entirely separate programmes. External counsel can assist in designing an integrated framework that satisfies both regulatory regimes without duplicating effort.

Conclusion

Germany';s regulatory environment in the current quarter demands active attention from corporate, employment, data protection, financial, and sustainability compliance teams. The common thread across all areas is that authorities are moving from guidance to enforcement, and documentation quality is under scrutiny. Companies that treat compliance as a periodic exercise rather than a continuous process are most exposed.

VLO Law Firms advises international clients on regulatory matters in Germany. We can assist with corporate register compliance, employment law structuring, GDPR and BDSG alignment, BaFin authorisation processes, and LkSG implementation. To request a consultation, contact: info@vlolawfirm.com