National strategy, investment incentives, and planning
Ambition to double compute and quadruple AI capacity by 2030
On 18 March 2026, the German government published its Data Centre Strategy. The Strategy’s stated aim is to recalibrate the German policy and regulatory environment so that investments in data centre infrastructure can keep pace with the demand generated by accelerating digitalisation and AI deployment across the economy. As noted above, the German Government is aiming to double Germany’s general computing capacity, and quadruple its AI computing capacity, by 2030. The government has identified three key areas of action, in which it plans to take 28 measures in the following 12 months:
- energy and sustainability,
- location and land, and
- technology and sovereignty.
The Strategy proposes a range of measures, such as:
- changing grid access rules to improve capacity allocation and transparency;
- easing regulatory requirements governing energy efficiency and usage of waste heat;
- the acceleration and harmonisation of planning and permitting procedures, including by developing a concept for preferential site designations; and
- the introduction of special provisions for the allocation of the trade tax base (Zerlegung) where data centre operators maintain permanent establishments in multiple municipalities.
It should be noted that the Strategy is non-binding on both the German Government and the legislator, and further legislative steps are necessary to implement the proposed measures. It does not provide for any direct subsidy programmes for data centre projects, although data centre operators may be eligible for support under existing subsidy programmes for climate protection, heat utilisation, or energy efficiency measures.
How legal form and site selection drives the effective tax rate
German tax law does not provide for sector-specific tax incentives applicable to data centres. However, data centre operators can benefit from tax incentives available for renewable energy installations and battery storage, where they install and operate self-generated renewable energy facilities to power the data centre.
The applicable tax regime depends on the legal form of the operator. Corporations are subject to corporate income tax (currently 15%, but scheduled to be gradually reduced to 10% by 2032) plus a solidarity surcharge of 5.5% on the corporate income tax (giving a combined rate of 15.825%) and trade tax (minimum effective rate of 7%, averaging around 15% depending on the applicable municipality). Partnerships are subject to trade tax at the partnership level, while personal or corporate income tax is levied at the level of the individual partners depending on their respective legal form. There are no sector-specific tax rates or special economic zones in Germany, but the trade tax burden can vary significantly depending on the municipality in which permanent establishments are maintained.
Dual NIS2 and CER Directive implementation
Data centres in Germany are subject to the critical infrastructure regulatory regime. The German legislator has implemented the NIS2 Directive and the Critical Entities Resilience Directive through the German Act on the Federal Office for Information Security and on the Information Security of Facilities (Gesetz über das Bundesamt für Sicherheit in der Informationstechnik und über die Sicherheit in der Informationstechnik von Einrichtungen) and the Umbrella Act for Critical Infrastructure Protection (Dachgesetz zur Stärkung der physischen Resilienz kritischer Anlagen) (refer to Section 4: EU-wide regulatory overview). In Germany, data centres with at least ten racks and an IT-capacity of 3.5 MW classify as critical facilities. Server farms with at least 10,000 physical or 15,000 virtual server instances are also classified as critical facilities. The Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) is the competent regulatory authority.
Operators of critical facilities are required to take appropriate, proportionate, and effective organisational and technical measures to prevent incidents affecting the information technology systems, components, or processes used by the operators for their facility. The measures must be based on an “all-hazards” approach, covering both IT-related and physical risks. Additional registration, reporting, and disclosure obligations apply. Non-compliance may result in penalties. A penalty can reach up to €10,000,000 and, where the operator’s annual revenue exceeds €500,000,000, up to 2% of that annual revenue.
Foreign investment screening: the 10% threshold and how to clear a German data centre deal
Data centre acquisitions or investments may trigger a filing obligation under Germany’s foreign investment screening rules. The Federal Ministry for Economic Affairs and Energy (Bundesministerium für Wirtschaft und Energie, “BMWE”) may review certain acquisitions of voting rights in a German company by a non-EU acquirer. Where the target company operates critical facilities or provides certain cloud computing services, notification is mandatory. The non-EU acquirer must file the acquisition with the BMWE without undue delay after signing. Data centres with at least ten server racks and an IT-capacity of 3.5 MW, and server farms with at least 10,000 physical or 15,000 virtual server instances, qualify as critical facilities for these purposes. Acquisitions of target companies that provide cloud computing services are subject to a notification requirement where the facilities used for that purpose (e.g. data centres or server farms) reach or exceed the same thresholds on the basis of their use for the respective cloud computing service.
The filing obligation applies where an investor directly or indirectly acquires at least 10% of the voting rights in the target company through a share deal. The authorities also count certain control rights – such as board seats or veto rights over strategic decisions – toward this threshold, where applicable. German FDI law does not permit investors to offset diluted voting rights when calculating an indirect acquisition. Even a minority stake at an intermediate holding level can therefore push the acquirer above the 10% threshold. Asset deals can also trigger a filing obligation. An investor who acquires a data centre’s key operational assets – rather than shares in the owning company – may also need to file with the BMWE. Greenfield investments are generally not caught by the German investment screening regime.
The transaction is subject to regulatory clearance by the BMWE. If the acquisition requires an FDI filing, the share transfer remains legally ineffective (schwebend unwirksam) until the BMWE clears the acquisition or clearance is deemed granted. Until clearance, the acquirer must not exercise any voting rights attached to the acquired shares (so-called “gun-jumping”). Violations may be sanctioned. The BMWE may also grant clearance subject to remedies, or, in the last resort, prohibit the transaction.
Data localisation in practice: GDPR transfers and German health and tax data constraints
German law does not impose a general data localisation requirement and does not prohibit non-European cloud services. Certain risk-based legal obligations may nonetheless operate as de facto localisation constraints. The GDPR permits transfers of personal data to countries outside the EU or EEA (so-called “third countries”) where they ensure an adequate level of data protection, as demonstrated by an adequacy decision of the European Commission, or where appropriate safeguards are in place between the parties to the transfer, such as standard contractual clauses.
German sector-specific rules can also create de facto data localisation obligations. These include, among other things:
- the cloud processing of personal health and social services data, which is only permitted in EU Member States, EEA countries, Switzerland, or countries with an EU adequacy decision; and
- the storage of accounting records relevant for tax purposes, which may only be stored in third countries under certain conditions and requires prior approval from the competent tax authorities.
Consents that set the German build timetable
German zoning law follows a three-tier system (state, regional, and municipal levels), with no provisions governing the permissibility of data centres. Permissibility is determined on a case-by-case basis, by reference to the zoning permissibility and the permits required.
Where a zoning plan applies, the permissibility of a data centre development depends on the designated specific land use areas under the Federal Land Use Ordinance (Baunutzungsverordnung). Data centres are commercial areas and industrial areas, depending on a case-by-case determination, with the decisive criterion typically being the level of noise and air emissions caused by the specific data centre. A key indicator for the classification of a project as materially disturbing (and therefore permissible only in industrial areas) is whether the installation requires a permit under the Federal Emission Control Act (Bundes-Immissionsschutzgesetz). To avoid such complex delineation, which may also be subject to legal challenges, municipalities and developers often opt for so-called special areas that can be tailored specifically to allow for data centres.
Where no zoning plan exists, fall-back provisions apply. Within a contiguous built-up area (im Zusammenhang bebauter Ortsteil), a project must fit with the character of its immediate surroundings, which is rarely the case for large-scale data centres. In outer areas (Außenbereich), data centres currently do not qualify as privileged projects, making permissibility particularly difficult to establish for large-scale projects. There is no settled case law addressing the zoning classification of data centres with large emergency power generators, a point of legal uncertainty that the Data Centre Strategy proposes to address through clarifying legislation.
A data centre does not, in itself, require an emission control permit. However, fuel- or gas-powered emergency power generators with a rated thermal input exceeding 50 MW do, in line with the IED’s implementation into German law. This permit has a concentration effect (Konzentrationswirkung), replacing most other permits for the emergency power generator (but not the data centre as such). The permit review process, which involves a public participation, typically takes around seven months, provided the submitted permit application documents are complete and accurate. The permitting authority may accelerate the process by approving early commencement of construction works while the review is still pending.
In addition, the data centre itself generally requires a building permit, governed by state law, with a process duration of approximately up to six months. Further permits may be required depending on the project design, including for transformer substations or cooling water supply. The competent authority is determined by state law. Germany has no unified consenting framework or fast-track permitting pathways for data centres, resulting in heterogeneous requirements and, in some cases, protracted proceedings.
In practice, close alignment with the involved municipalities (zoning) and state authorities (permitting) has proven key to expedited approval and implementation.
Back to top