In two decisions the European Court of Justice (ECJ) held that the General Data Protection Regulation (GDPR) opposes two data processing practices by credit information agencies. While ‘scoring’ is permitted only under certain conditions, the prolonged retention of information relating to the granting of a discharge from remaining debts is contrary to the GDPR.
According to a press release issued today the Cabinet has decided to extend the retention period for accounting documents at banks, insurance companies and securities institutions to ten years. The amendment to the law aims to combat tax evasion and strengthen effective tax enforcement. This will enable large-scale tax evasion cases, such as those involving cum/cum and cum/ex transactions, to be vigorously prosecuted.
In its judgment published today, the European Court of Justice held that the operator of an online marketplace is responsible for the processing of personal data contained in advertisements published on its platform. The operator must identify, before publication, advertisements that contain sensitive data and verify that the advertiser is actually the person whose data appears in such an advertisement or that the advertiser has the explicit consent of that person.
In a most recently published decision, the Supreme Tax Court held that a tax assessment can be corrected at any time if electronically transmitted data is sent to the tax office. It does not make a difference if the content of the data was already known to the tax office.
In a recently published decision, the Supreme Tax Court has for the first time commented on the requirements for claims of damages before the tax court against a tax authority due to violation of data protection regulations. Such action for damages pursuant to Art. 82 of the General Data Protection Regulation (GDPR) is generally inadmissible (for want of being adversely affected or burdened) if there has been no prior out-of-court request of the claim.
In its decision today, the European Court of Justice held that inclusion in a U.S. sanctions list is not, in itself, sufficient grounds to refuse to open a bank account. Such a denial may only be made following a case-by-case assessment by the bank regarding the risk of money laundering and terrorist financing.
On 30 June 2026, the German Central Bank (Deutsche Bundesbank) published a revised edition of its ‘Explanatory Notes on Foreign Trade Reporting’ (the Explanatory Notes). Among other matters, the Explanatory Notes provide further clarification on the reporting requirements for crypto-assets under the German Foreign Trade and Payments Regulation (Außenwirtschaftsverordnung – AWV).
Section 2a (5) no. 2 of the German Fiscal Code states that the provisions of the General Data Protection Regulation (GDPR) apply accordingly to information relating to identified or identifiable corporations. The GDPR does not contain a right to the inspection of files, the Supreme Tax Court said in a most recent decision.
On 4 December 2024 the Council of the EU reached an agreement on a proposed framework for Financial Data Access (FIDA) that aims to open the access of financial institutions to each other’s customer data.
In a recent judgment, the Supreme Tax Court held that Section 8b (6) sentence 2 of the German Corporation Tax Act as part of the tax exemption rules for dividends from participations in corporations and associations does not apply to savings banks that are organized as legal entity governed by private law.
In a recent decision, the Supreme Tax Court commented for the first time on the requirements and scope of the right to information under the General Data Protection Regulation.
North Rhine-Westphalia (NRW) is taking another decisive step in the fight against tax evasion. The State Office for Combating Financial Crime has acquired a terabyte of data relating to customers in offshore tax havens. The impact on taxpayers could be tremendous.
In a recent judgement, the Supreme Tax Court held that the only legitimate type of action for the judicial claim under the General Data Protection Regulation (GDPR) for the provision of a copy of the processed personal data is by way of „appeal for mandatory relief" (Verpflichtungsklage). The filing deadline is one month commencing with the delivery of the challenged administrative act.
In a most recent judgment, the European Court of Justice held that the ban on the export of banknotes denominated in euro or in another official currency of a Member State to Russia also applies when the money is intended to finance medical treatments.
The Council of the EU reached an agreement on a common member states’ position on a new law which will improve cooperation between national data protection authorities when they enforce the General Data Protection Regulation (GDPR).
According to a ruling of the Supreme Tax Court the sole criterion for claiming the banking privilege for trade tax purposes is that the assets from banking transactions and the purchase of monetary receivables outweigh the assets from other business activities. With its decision the court thus keeps to the strict wording of the relevant statute.
The Cologne Higher Regional Court decided on 3 May 2023 that a former chairman of the board of a registered association has no right to have his personal data deleted from the Associations Register.
In a preliminary request from the Administrative Court Wiesbaden (Germany) the Advocate General (AG) is of the opinion that the supervisory authority has an obligation to act when it finds a breach while investigating a complaint. However, the decision as to what corrective action to take depends on the specific circumstances of each individual case.
The German federal government has adopted a draft bill to modernize German cooperative law. According to a press release issued by the Federal Ministry of Justice and Consumer Protection (BMJV), the draft bill adopted on July 15, 2026, is intended to accelerate the formation of cooperatives, further promote digitalization, and strengthen safeguards against the misuse of the cooperative legal form.
In particular, the draft bill provides for the following key changes:
Today the Council of the EU adopted new rules to improve cooperation between national data protection bodies when they enforce the General Data Protection Regulation (GDPR) in order to speed up the process of handling cross-border data protection complaints.