Knowledge · As of: 21 August 2026

    IT regulatory radar

    By Redaktion techport.ai, IT-Beratung · Last updated on

    IT regulation has changed more in three years than in the fifteen before. This page summarises what applies today, what has been announced and what you should do now. We update it whenever something relevant changes. It does not replace legal advice, it helps you ask the right questions in time.

    NIS2 and the new German BSI Act

    In force
    Deadline
    In force since 6 December 2025, registration to be caught up
    Scope
    Companies in the sectors of annexes 1 and 2 BSIG, generally from 50 employees or from 10 million euros in turnover and balance sheet total

    The German NIS2 implementation act came into force on 6 December 2025. The duties have applied directly since then, irrespective of registration. The registration portal of the Federal Office for Information Security has been available since January 2026, the regular deadline of 6 March 2026 has passed, as has an extension set by the authority in July 2026. Anyone not yet registered who might be in scope should catch up without delay. Central are the risk management measures under Section 30 BSIG, the reporting duties under Section 32 BSIG with an initial report within twenty-four hours, and the registration duty under Section 33 BSIG. Management has to approve the measures, supervise their implementation and undergo training.

    What to do now: check scope on the record, establish gaps against Section 30 BSIG, set up and rehearse the reporting route, produce evidence, add supplier requirements to contracts.

    Go to the topic pageSource

    The AI Act and the Digital Omnibus

    In force, high-risk deadlines postponed
    Deadline
    High risk under Annex III from 2 December 2027, under Annex I from 2 August 2028
    Scope
    All companies providing or deploying AI systems

    Regulation (EU) 2024/1689 has applied in general terms since 2 August 2026. The prohibitions on certain practices have applied since 2 February 2025, as has the AI literacy duty under Article 4. Obligations for general purpose AI models have applied since 2 August 2025. The Digital Omnibus Regulation (EU) 2026/1744 entered into force on 27 July 2026 and postponed the high-risk duties, for standalone systems under Annex III to 2 December 2027 and for systems embedded in products under Annex I to 2 August 2028. Market surveillance in Germany sits with the Federal Network Agency.

    What to do now: take an AI inventory across all systems, clarify your role as provider or deployer, document the risk classification per application, implement transparency duties, evidence training for the staff concerned.

    Go to the topic pageSource

    EU Data Act

    In force
    Deadline
    Applicable since 12 September 2025, switching charges removed from 12 January 2027
    Scope
    Users and providers of cloud services, manufacturers of connected products

    Regulation (EU) 2023/2854 has applied since 12 September 2025. For users, the rules on changing provider matter most: cloud providers must enable the switch contractually and technically, with a notice period of no more than two months followed by a transition period of usually no more than thirty days. Charges for switching disappear entirely from 12 January 2027. For manufacturers of connected products, obligations on data access are added.

    What to do now: review cloud contracts for switching clauses, export formats and deadlines, test the data export rather than merely agreeing it, and demand the new requirements in new contracts.

    Go to the topic pageSource

    E-invoicing in the B2B area

    Applies in stages
    Deadline
    Obligation to send from 1 January 2027 above 800,000 euros turnover, from 1 January 2028 for everyone
    Scope
    All domestic companies with B2B transactions

    Since 1 January 2025, domestic companies have had to be able to receive e-invoices. Until the end of 2026 other formats remain permissible with the recipient's consent. From 1 January 2027 the obligation to send applies to companies with more than 800,000 euros in total turnover in the previous year, and from 1 January 2028 in principle to all domestic B2B transactions. Only structured formats complying with EN 16931 count as an e-invoice, in Germany primarily XRechnung and ZUGFeRD.

    What to do now: check whether your system can produce, send and archive structured invoices as originals, establish your turnover position for 2027, automate incoming processing, update the process documentation.

    Go to the topic pageSource

    Cyber Resilience Act

    In force, duties staged
    Deadline
    Reporting duties from 11 September 2026, full application from 11 December 2027
    Scope
    Manufacturers, importers and distributors of products with digital elements

    Regulation (EU) 2024/2847 introduces binding cyber security requirements for products with digital elements across their whole life cycle. From 11 September 2026 the reporting duties apply for actively exploited vulnerabilities and severe security incidents, with an early warning within twenty-four hours. From 11 December 2027 the regulation applies in full, and covered products then have to meet the essential requirements and undergo a conformity assessment. This is relevant for mechanical engineering and industry wherever products ship with software.

    What to do now: check whether your products are covered, build vulnerability management and a reporting process, introduce a software bill of materials, define the support period and pass requirements on to suppliers.

    Go to the topic pageSource

    German Accessibility Act

    In force
    Deadline
    Since 28 June 2025
    Scope
    Providers of products and services to consumers, including online shops and customer portals

    The act has applied since 28 June 2025 and obliges electronic commerce for consumers, among others, to be accessible. For services there is an exemption for micro-enterprises with fewer than ten employees and no more than two million euros in annual turnover, which does not apply to products. The benchmark is the European standard EN 301 549. Breaches can be fined, and warnings and complaints to the market surveillance body are additional risks.

    What to do now: clarify scope on the record, have shops and customer portals assessed, fix the paths to contract conclusion first, add accessibility to requirements for new systems and set up the feedback procedure.

    Go to the topic pageSource

    Retention periods and process documentation

    In force
    Deadline
    Shortened period for accounting vouchers since 1 January 2025
    Scope
    All companies subject to accounting obligations

    The Fourth Bureaucracy Relief Act shortened the retention period for accounting vouchers and invoices from ten to eight years, applicable to records whose period had not yet expired on 1 January 2025. For commercial books, inventories, annual accounts and the associated work instructions and organisational documents it remains ten years, and for other business letters six years. Electronic records have to remain legible and machine readable throughout the period.

    What to do now: adjust deletion rules in the archive to the new periods, produce or update the process documentation, describe substitute scanning, and secure access to retired legacy systems for the remaining period.

    Go to the topic pageSource

    Employee data protection and legal bases

    Open
    Deadline
    No date
    Scope
    All employers

    In 2023 the Court of Justice of the European Union held a state law provision equivalent to Section 26 BDSG to be incompatible with Union law. Since then it has been unclear whether Section 26 BDSG carries as a legal basis for processing employee data. A dedicated employee data protection act has been discussed for years without a concluded legislative procedure. For IT this matters particularly for log data, device management, access analysis and security tools.

    What to do now: base processing in the employment context on Articles 6 and 88 GDPR and document it, draft works agreements carefully where they serve as a legal basis, and set deletion periods for log data.

    Go to the topic pageSource

    Codetermination for IT systems

    In force
    Deadline
    Ongoing
    Scope
    Companies with a works council

    Technical systems objectively capable of monitoring employee behaviour or performance are subject to codetermination under Section 87 (1) no. 6 of the German Works Constitution Act. Whether monitoring is intended is irrelevant. In practice this covers device management, ticket systems, security tools, time recording, access logs and many AI features. Planning alone has to be discussed with the works council under Section 90.

    What to do now: review the framework agreement on IT systems and extend it to cloud, mobile devices and AI features, involve the works council before vendor selection, and settle permitted analyses and deletion periods in the procedure.

    Go to the topic pageSource