Q3 2026

Spotlight Q&A: Internal Investigations in Germany

Share

Our Employment & Benefits team in Germany recently published a Briefing Series on Internal Investigations examining the legal framework, practical tools, and compliance architecture underpinning internal investigations.

The series has generated considerable interest, so we have asked two of the authors, Pauline Stadler and Hagen Köckeritz, to outline the key highlights for in-house legal teams, HR professionals, and senior management in organisations with a presence in Germany.

Q1. What are the legal foundations of the duty to investigate in Germany?

German companies must initiate and steer internal investigations promptly and proportionately once specific, objective indications of material misconduct arise.

This mandate flows from general corporate legality and the organisational duties of management. It is reflected across specialised regimes, notably the German Whistleblower Protection Act (Hinweisgeberschutzgesetz, “HinSchG”), the German Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz, “LkSG”), the EU Market Abuse Regulation (“MAR”), the German Securities Trading Act (Wertpapierhandelsgesetz, “WpHG”) and the German Anti-Money Laundering Act (Geldwäschegesetz, “GwG”).

For stock corporations, the German Stock Corporation Act (Aktiengesetz, “AktG”) imposes a duty of care on the management board and requires a system for early risk detection. Listed stock corporations must additionally establish an appropriate and effective internal control system and risk management system, which extends beyond the early risk detection requirement. For limited liability companies, the German Limited Liability Act (GmbH-Gesetz, “GmbHG”) imposes analogous duties.

Beyond these general obligations, the specialised statutory regimes add further, concrete requirements. For example, the HinSchG requires certain organisations to maintain internal reporting channels and to follow up on reports within statutory timelines. The LkSG requires in-scope companies to operate a risk management system, perform periodic and ad hoc risk analyses, implement preventive and remedial measures, and maintain a complaints mechanism. For investment firms and trading venues, the MAR requires Suspicious Transaction and Order Reports to be submitted to the competent authority upon reasonable grounds for suspicion of insider dealing and market manipulation. The GwG requires certain entities to implement risk-based preventive systems, and submit suspicious activity reports to the Financial Intelligence Unit.

Q2. Who is responsible for managing internal investigations?

The management board or managing directors hold ultimate responsibility for lawful operations, an effective compliance organisation, and an adequate response to indications of wrongdoing. Even with delegation to compliance or internal audit, management must ensure resourcing, independence, clear mandates, and regular reporting.

The compliance function is typically charged with intake, pre-selection, plausibility checks, and coordination of investigations. Internal audit provides independent assurance and may lead fact-finding for systemic control issues. Legal, HR, IT forensics, and data protection are involved as needed. Specialised officers fulfil regime-specific analysis and reporting responsibilities.

The internal reporting unit under the HinSchG must be independent, impartial, and adequately skilled. The LkSG requires named responsibility for the risk management system and complaints handling. Where material compliance matters arise, the management board must inform the supervisory board without undue delay, with the audit committee typically receiving periodic reporting on investigations, metrics, and remediation.

More guidance on management’s responsibility to conduct internal investigations, including information about triggers, thresholds, and timing, plausibility screening, and escalation pathways, is available in Part I of our Briefing Series on Internal Investigations. 

Q3. What are the key building blocks of an effective compliance management system?

An effective compliance management system (“CMS”) should be credible across jurisdictions and tailored to German corporate practice. Compliance should be organised on a risk-based, independent, and well-documented footing, aligned with recognised frameworks, and supported by structured reporting lines and clearly defined decision-making rights.

From an organisational perspective, companies should operate a three-lines model:

  • The first line (the business) owns compliance within day-to-day processes;
  • The second line (compliance and other control functions) establishes frameworks, provides advice, monitors, and challenges; and
  • The third line (internal audit) delivers independent assurance and reports to the audit committee.

The model should be aligned with the international, certifiable standard, ISO 37301, for international credibility and, in German practice, IDW PS 980, is recognised as the relevant auditing standard for assurance on the design and effectiveness of a CMS.

The key building blocks include:

  • A coherent policy framework cascading from a code of conduct to risk-specific policies and procedures;
  • A systematic, well-documented, compliance risk assessment integrated with enterprise risk management;
  • A speak-up system with multiple intake channels (including anonymous options);
  • Preventive and detective controls embedded directly into business processes;
  • A defined suite of KPIs; and
  • A documentation backbone covering risk assessments, policy versions, training evidence, monitoring and testing results, investigation files, remediation trackers and minutes of management reviews and board briefings.

Q4. How should reporting lines and decision-making be structured within a CMS?

A clear decision-rights matrix should be defined for high-stakes compliance actions. This should include case scoping and prioritisation, approval of forensic measures and dawn raid preparedness, authorisation of interviews and interview sequencing, engagement of external counsel or forensic experts, determination of legal privilege protocols, decisions on external reporting to authorities, disciplinary actions, and notifications to the supervisory board.

Management should receive both regular and ad hoc reporting that consolidates material compliance risks, incidents and outcomes, remediation progress, and assurance findings. The audit committee should be provided with a consolidated, system-level view focusing on CMS effectiveness, emerging trends, and systemic issues, and should actively track remediation measures to closure. Matters involving senior leadership or indicating systemic control deficiencies should be escalated immediately. Each significant case should conclude with a documented analysis and a remediation package addressing control redesign, process enhancements, and targeted training measures.

Further guidance on governance design, reporting architecture and decision-making, and implementation roadmaps is available in Part II of our Briefing Series on Internal Investigations. 

Q5. Are employees obliged to cooperate with internal investigation interviews?

Yes. Under German employment law, employees owe duties of loyalty and cooperation that flow from the employment relationship. Management may, within reasonable discretion, instruct employees to participate in fact-finding interviews and answer questions about their work area, responsibilities, and observations. The scope of cooperation depends on role and function – managers and control roles face broader expectations, while non-managers answer within their area of responsibility. Employers must frame instructions with proportionality and respect for privacy.

The right against self-incrimination is a criminal procedure concept; in employer-led interviews, German practice applies a private law lens, so the employee still must answer job-related questions. However, questions should focus on facts needed for internal risk and corrective action. If an employee refuses to attend or answer a relevant, proportionate question after reasonable instruction, there may be consequences under labour law, but the process must avoid coercion and ensure a fair chance to respond before any decision.

Q6. What practical steps should be taken when planning and conducting employee interviews?

We would recommend starting with a written plan defining objectives, issues, and key documents. The plan should identify interviewees and set a sequence that protects evidence integrity – typically complainants and neutral witnesses first, then subjects.

It is also important to screen for conflicts and independence concerns. Where senior managers or core control functions are implicated, consider alternate teams or external counsel to preserve independence, and coordinate with the reporting framework for potential board reporting (see above and Part II of our Briefing Series on Internal Investigations).

At the outset, interviewers should provide a brief, plain language, corporate counsel warning stating that counsel represents the company, that any legal privilege belongs to the company, that the company may decide to disclose information, and that the employee is free to seek independent legal advice. Interviews should use neutral phrasing, moving from open to focused questions, anchored in established facts. Where helpful, present contemporaneous documents to clarify timelines or events. Allow reasonable breaks, use qualified interpreters when required and ensure strict confidentiality.

Audio or video recording should not be used unless expressly permitted by law and company policy and only after the interviewee has been clearly informed, has explicitly consented prior to the recording, which should be documented in writing. The essentials are clear corporate counsel warnings, disciplined and fact-focused questioning, and respectful, professional conduct throughout.

Contemporaneous, neutral minutes should capture attendees, warnings, key questions and answers, and materials shown, and be stored under legal hold with restricted access and proper retention. The cornerstones are neutral minutes, targeted corroboration, and proportionate corrective action.

It is important to note that the HinSchG imposes strict confidentiality over the identity of the reporting person, persons mentioned, and the subject of the report. Interview planning in whistleblower-led cases must therefore preserve this confidentiality.

Further guidance on the dos and don’ts for employee interviews is available in Part III of our Briefing Series on Internal Investigations.

Q7. What legal framework governs the screening of employee data, documents, and emails during an investigation?

The relevant framework is anchored in the General Data Protection Regulation (“GDPR”), the German Federal Data Protection Act (Bundesdatenschutzgesetz, “BDSG”), the Telecommunications and Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, “TDDDG”) and the Telecommunications Act (Telekommunikationsgesetz, “TKG”).

Employee data screening and workplace searches should be narrow in scope to answer clearly defined investigative questions, and must adhere to the principles of necessity, data minimisation, and purpose limitation. Companies should proceed in an open and transparent manner, with clear notice to affected employees and a documented plan setting out what is being searched, why the measure is necessary and how confidentiality is safeguarded and the use of personal data limited.

For the purposes of German employment law, processing typically relies on Article 6 of the GDPR, read in conjunction with Article 88 of the GDPR, and the applicable national implementing rules. Historically, Section 26 of the BDSG provided a specific employment law legal basis for processing, based on the concept of “necessity” for purposes relating to hiring, performance of the employment relationship, and termination, complemented by a distinct provision for the detection of criminal offences.

Following the ECJ judgment of 30 March 2023, a prudent approach would be to frame processing primarily under Article 6 of the GDPR while observing Section 26 of the BDSG where applicable and documenting necessity and proportionality with rigour. The crime-detection pathway under Section 26(1) sentence 2 of the BDSG is a narrow exception and requires documented suspicion, necessity, proportionality, and exhaustion of less intrusive alternatives.

Companies should anticipate admissibility risks. Serious data protection or privacy violations may lead to the exclusion of evidence in labour court proceedings, particularly where constitutional rights are affected.

Q8. What are the rules around physical searches, CCTV, and covert surveillance in the workplace?

Physical searches should be rare, risk-based, and framed by policy or works agreements. Random, announced bag checks at store exits or controlled access to restricted areas can be permissible if proportionate, non-discriminatory, and transparently communicated. Company property, such as lockers and desks, may be inspected where necessary, ideally in the presence of a witness and with the employee invited to attend. Private belongings require consent or strong, documented grounds in exceptional cases.

Video surveillance must be purpose-limited, confined to justified areas (e.g., entrances, high-risk zones). Cameras are prohibited in locations with a high expectation of privacy, such as changing rooms and sanitary facilities. Covert CCTV is restricted to exceptional crime-detection cases backed by concrete suspicion and as a last resort. Employers should provide clear signage where cameras operate, define short retention periods, and evaluate footage only when a legitimate reason arises.

For more guidance on screening and searches, please see Part IV of our Briefing Series on Internal Investigations.

Q9. What are the legal bases and practical constraints for data processing during an internal investigation?

Each processing step must be supported by a valid legal basis under the GDPR, supplemented by the BDSG where it provides more specific safeguards. In internal investigations, the most relevant bases are Article 88 of the GDPR in conjunction with Section 26 of the BDSG, which covers processing necessary for the performance of the employment contract, including monitoring of conduct and detection of violations or crimes. Additionally, legitimate interests under Article 6(1)(f) of the GDPR may serve as a basis for fact-finding, fraud detection, and IT security, provided the measure is proportionate and does not override employee rights.

Where special-category data (e.g., health or trade union membership) surfaces during the investigation, processing must meet the requirements of Article 9 of the GDPR, typically relying on Article 9(2)(b) (employment and social security obligations) or Article 9(2)(f) (legal claims), alongside the safeguards under Section 22 of the BDSG. Employers should apply data minimisation principles and mask or redact non-essential sensitive elements.

From a litigation perspective, German employment courts apply a balancing test rather than an automatic exclusion rule. Open, transparent, and proportionate monitoring is generally admissible in evidence, even where data protection rules were not fully complied with, provided the measure did not seriously infringe fundamental rights.

Employee data subject rights under Articles 15, 17, and 18 of the GDPR remain applicable during investigations but must be balanced against the rights of the employer and the integrity of the investigation. The right to access may be limited to protect third-party data, whistleblower identities, and trade secrets. The right to erasure may be deferred where data is required for legal claims or compliance purposes. Retention must be limited to what is necessary for the investigation and potential follow-up proceedings, with clear milestones and litigation-hold mechanisms. Further guidance on data processing in internal investigations is available in Part V of our Briefing Series on Internal Investigations.

Q10. When must works councils be involved in internal investigations?

The German Works Constitution Act (Betriebsverfassungsgesetz, “BetrVG”) grants the works council binding co-determination rights in several investigation-relevant areas. Section 87(1) no. 6 of the BetrVG requires co-determination for the introduction and use of any technical device capable of monitoring employee behaviour or performance. The Federal Labour Court interprets this requirement broadly: email systems, “listen-in” headsets, CCTV, and even AI-assisted analytics tools fall within its scope.

In practice, employers should distinguish between system-level and case-level involvement: at the system level, the works council must be informed and consulted on the introduction and configuration of monitoring-capable systems; at the case level, the employer should provide only the information necessary for the works council to perform its statutory functions while minimising disclosure of unrelated personal data and safeguarding whistleblower confidentiality. A breach of co-determination obligations does not automatically result in the exclusion of evidence – the Federal Labour Court has clarified that works agreements cannot create independent rules excluding evidence in judicial proceedings. However, such breaches create separate legal risks, and may result in injunctive relief or the invalidity of dismissals. Further guidance on involving the works council is available in Part VI of our Briefing Series on Internal Investigations.

Stay Up To Date With Our Insights

See how we use a multidisciplinary, integrated approach to meet our clients' needs.
Subscribe