Germany
5 regulators · 6 instruments · 6 obligations · 1 upcoming deadline
| Instrument | Type | Year | Regulator | Summary | Source |
|---|---|---|---|---|---|
| DORA — Digital Operational Resilience Act (Regulation (EU) 2022/2554) | Regulation | 2022 | — | DORA (Digital Operational Resilience Act) is a supreme regulatory framework for Europe th… | official |
DORA (Digital Operational Resilience Act) is a supreme regulatory framework for Europe that has been put together to ensure that all financial institutions in the EU are able to withstand, respond to, and recover from any ICT disruptions and cyberattacks. The new regulation comes at a time when countries such as Germany had BAIT, whereas France had sector-specific national guidelines for ICT risk management in place. This new legislation serves to connect the dots between financial stability and digital security through its extraordinarily wide scope, which covers more than 22,000 entities in 20 different categories of finance, such as credit institutions, investment firms, CASPs, crowdfunding platforms, and, most importantly, critical third-party ICT service providers, including large cloud computing providers. | |||||
| Law on Tracing Proceeds of Serious Crimes (Money Laundering Act - GwG) | Act | 2017 | FIU-DE | Law on Tracing Proceeds of Serious Crimes, widely referred to by the name of its home cou… | official |
Law on Tracing Proceeds of Serious Crimes, widely referred to by the name of its home country as Geldwäschegesetz (GwG), is the key statutory act of the Federal Republic of Germany that acts as the shield to safeguard the national economy from money laundering, tax evasion, and terrorist financing schemes. Initially adopted by the German Bundestag in 1993 and later revised significantly in 2017, this landmark legislation provides for the transposition of European Union anti-money laundering directives into the domestic legislation. It is a legislation enforced through the rigorous scrutiny of BaFin and Financial Intelligence Unit (FIU) that currently operates and remains in force with its most recent structural revisions effective as of 29 June 2026, adjusting domestic provisions to the European transparency registers. Under the terms of the GwG, all kinds of institutions, including traditional banks, real estate agents, gambling facilities, high-value goods traders, and crypto-asset service providers (CASPs), are mandated to implement adequate AML compliance programs. Among other things, the GwG requires thorough Customer Due Diligence (KYC/CDD) procedures, a 5-year financial trails record retention requirement, and a zero-tolerance approach to Suspicious Transaction Reporting (STR) procedures. | |||||
| Supervisory Requirements for IT in Financial Institutions(BAIT) | Circular | 2017 | BaFin | BAIT is a binding administrative circular (Rundschreiben) of the German financial supervi… | official |
BAIT is a binding administrative circular (Rundschreiben) of the German financial supervisory authority BaFin, which is intended to facilitate the translation of the legal regulatory banking framework into technical and organizational standards. It was originally introduced in 2017 and is known as Bankaufsichtliche Anforderungen an die IT. BAIT is regarded as the main technical module that works in conjunction with the general MaRisk framework, specifying particular requirements for information security and IT systems. In its present phased sunset period, BAIT acts as a transitional tool toward the supreme DORA regulation of the EU. Major actors of the financial system have been exempted from BAIT since 17 January 2025 due to their necessity to comply only with DORA, while other financial institutions operating in Germany will be obligated to follow the January 2025 version of BAIT until its total repeal on 31 December 2026. | |||||
| GDPR (Regulation (EU) 2016/679) | Regulation | 2016 | BfDI | The General Data Protection Regulation (GDPR) is the most robust privacy law globally sin… | official |
The General Data Protection Regulation (GDPR) is the most robust privacy law globally since it provides individuals with total control of their personal information while ensuring there is a uniform digital privacy rulebook for modern companies. The regulation came into force in 2016 and began its implementation in 2018, replacing the outmoded 1995 Data Protection Directive and changing the global privacy landscape through the inclusion of extraterritoriality. This implies that the regulation is applicable strictly to any entity worldwide, processing, storing, or handling the personal information of EU citizens without considering the company’s physical location. The GDPR is enforced at the national level by independent data protection authorities, including the BfDI and state data protection bodies in Germany or CNIL in France. It ensures that data privacy is a basic human right with hefty administrative fines of up to €20 million or 4% of a company's global annual turnover being applied to entities failing to comply with the regulation. | |||||
| Securities Trading Act | Act | 1998 | BaFin | The Wertpapierhandelsgesetz (WpHG) is the fundamental legislative act in Germany, aimed a… | official |
The Wertpapierhandelsgesetz (WpHG) is the fundamental legislative act in Germany, aimed at investor protection, confidence-building, and the structural soundness of its securities and derivative market. It is enforced strictly under the sovereign public supervision of BaFin, where the WpHG creates a complete set of legal guidelines for all trading activities, whether within or outside the organized stock exchange. The broad jurisdiction of the law includes investment services firms, issuers, investors, and market infrastructures. This act is the fundamental legal basis which implements the EU investor protection laws into the German corporate law and gives the regulator authority to ban trading, warn investors publicly, and conduct an audit of market operators. | |||||
| German Banking Act | Act | 1961 | BaFin | The Kreditwesengesetz (KWG) represents Germany’s fundamental statute for banking regulati… | official |
The Kreditwesengesetz (KWG) represents Germany’s fundamental statute for banking regulations, formulated with the objective of protecting depositors, securing the safety of assets held by financial companies, and avoiding any structural disturbance in the economy of the nation. The Kreditwesengesetz is regulated through a two-tier structure by BaFin (as the sovereign regulator) and the Deutsche Bundesbank (as the operational auditor). All credit institutions and financial services institutions operating in Germany are governed under the Kreditwesengesetz. The Kreditwesengesetz acts as the ultimate instrument for implementing the prudential directives of Europe into German corporate law. | |||||
| No instruments match these filters. | |||||