On 22 April 2026, the German cabinet adopted a draft bill for an Act to Introduce IP Address Retention and Expand Data Collection Powers in Criminal Proceedings (Gesetz zur Einführung einer IP-Adressspeicherung und zur Weiterentwicklung der Befugnisse zur Datenerhebung im Strafverfahren). The new Act aims to improve the identification of offenders and, more broadly, facilitate the prosecution of offences committed in a digital context. For this purpose, the draft legislation not only obliges providers of public telecommunications services (“Providers”) to retain IP addresses, but also introduces a legal framework for preservation orders and grants Providers certain processing powers. The original ministerial draft – discussed in our article of 8 January 2026 – already contained corresponding provisions which have now been supplemented or modified in the revised draft.
New rules on processing IP addresses and other traffic data for disclosure purposes
For the first time, the cabinet draft gives providers a statutory power to process traffic data – including IP addresses assigned to subscribers – for the purpose of disclosing information to law enforcement and security authorities (section 175 draft Telecommunications Act (Telekommunikationsgesetz) (“Draft TKG”). This provision closes a gap in existing law. According to the Federal Constitutional Court’s “twin gate” doctrine, lawful access to data both requires a legal basis authorising the relevant authority to collect data and a corresponding legal basis permitting the Provider to process it. The Telecommunications Act (“TKG”) already provides for the use of customer data (basically, end user data relevant to the contract) to disclose information (section 174 TKG), but to date this has not included traffic data, even if such data is regularly requested in practice. The new provision therefore primarily serves to enhance legal certainty.
Requirements for the disclosure of traffic data
Under the draft, IP addresses and other traffic data may continue to be disclosed only if they are requested by one of the authorities expressly designated in the Act. These include law enforcement authorities, public safety authorities at federal state level, the Federal Police and intelligence agencies. Providers will not be required to verify the substantive lawfulness of a request made by the competent authority. But they must maintain confidentiality regarding both the request for information and its disclosure. They are also required to establish and maintain electronic interfaces, and even stricter rules apply to Providers with 100,000 or more subscribers. In addition, before a request for information can be processed, it must be reviewed for compliance with the applicable formal requirements, either by a designated specialist or automatically through the electronic interface. Further processing may only proceed once that review has been successfully completed.
These rules mirror those that already apply to disclosure of customer data. Providers can therefore extend their existing processes to traffic data requests, or gain legal certainty where such practices are already in place.
Retention of IP addresses
To identify subscribers after cyberattacks or other legal violations, the competent authorities generally depend on the cooperation of internet access service providers. These are able to determine which of their subscribers corresponds to a particular IP address. In practice, however, many internet access service providers retain the data needed to match an IP address with a subscriber for only a few days. This can make it difficult, or even impossible, to identify offenders if a violation is not discovered immediately.
To address this issue, internet access service providers will be required to retain certain data for three months, as a precaution. This includes the IP address assigned to a subscriber, connection and user identifiers, the precise period during which the IP address was assigned, recorded to the second, and any other traffic data needed for identification purposes, including associated port numbers (section 177 Draft TKG). Target IP addresses, location data and content data will not be retained, however.
Under the cabinet draft, internet access service providers that do not generate or process all data subject to retention – in particular, where they rely on wholesale operators – must now also ensure that the missing data are nevertheless retained and notify the Bundesnetzagentur, upon request, of who is undertaking the retention. The earlier ministerial draft did not include a comparable provision.
Issuance of preservation orders
The cabinet draft provides for the issuance of preservation orders to secure data needed for law enforcement or threat prevention before such data is deleted (“quick freezes”; section 100g Code of Criminal Procedure (Strafprozeßordnung); section 25a draft Federal Police Act (Bundespolizeigesetz). Conversely, the draft also grants providers subject to such orders the authority to process the relevant data. Preservation orders may remain in force for up to three months, and may be extended by a further three months, subject to judicial review.
In particular, the data to be preserved include information identifying who communicated with whom, when and from where – such as the recipient e-mail address of a message sent from a particular account, and the time at which the message was sent. Unlike the earlier ministerial draft, the cabinet draft explicitly excludes from the scope of preservation orders in criminal proceedings any traffic data already covered by the three-month retention obligation described above. Content data – such as the content of an e-mail message – are likewise excluded from the scope of preservation orders.
The cabinet draft also restricts the scope of such orders to data of persons with a personal or geographical connection to the relevant offence (which must be of significant importance), or in the context of preventive measures, to the threat to be averted or the offence to be prevented. At the same time, the cabinet draft expands the regime by allowing the Federal Police to use preservation orders as a tool for preventing threats to public safety.
As under the earlier ministerial draft, entities subject to a preservation order must implement technical and organisational measures to secure the relevant data and maintain confidentiality. Where a request for information is issued on the basis of a preservation order, the requirements for disclosure of traffic data discussed above must also be complied with (section 176 Draft TKG).
Outlook
The Act is currently expected to enter into force before the end of the year. The Bundesrat expressed its general support for the draft on 12 June 2026, but called for authorities at federal state level to also be empowered to issue preservation orders for the purpose of threat prevention. On 15 July 2026, the Federal Government signalled its openness to this proposal, except where intelligence agencies or the prosecution of regulatory offences are concerned. A timely adoption of the legislation therefore appears achievable at present. However, it is likely that the Act will face further scrutiny regarding its compatibility with EU case law on data retention.
Affected companies should closely monitor the further progress of the legislative process and begin assessing now whether their internal systems meet the new requirements, in particular with regard to the three-month retention of IP addresses and compliance with preservation orders.