Regional regulatory context

Vendor risk and data privacy in Germany

Germany applies GDPR as a member state, with additional requirements under the Federal Data Protection Act (BDSG). Germany has a long history of strong privacy enforcement and strict interpretations of GDPR requirements, including robust works council rights over HR data systems.

Applicable regulations

  • GDPR
  • BDSG
  • TTDSG

Hosting considerations

German data residency is available from AWS (Frankfurt), GCP (Frankfurt), Azure (Frankfurt/Berlin), and numerous German cloud providers. Public sector procurement in Germany increasingly requires BSI cloud certification (C5).

Common questions

What is BSI C5 and when is it required?
The BSI Cloud Computing Compliance Criteria Catalogue (C5) is a German government cloud security standard. It is required for vendors providing cloud services to the German federal government and is increasingly requested in other regulated sectors.

Which of your vendors operate in DE?

TrustVendor tracks vendor hosting regions, subprocessor geographies, and applicable adequacy decisions.

Book a demo