Data centers are among the fastest-growing infrastructure projects in Germany, and few factors are driving new construction as strongly as the demand for artificial intelligence capacity. This demand makes the German market attractive to international investors, project developers, and operators, but also challenging, since few other infrastructure projects involve so many areas of law at once.
At Schlun & Elseven Rechtsanwälte, our AI data center lawyers advise international companies on building, acquiring, and operating data centers in Germany, from the initial choice of site through to ongoing operations. Our work covers everything from a hyperscale campus for a single cloud provider to multi-tenant colocation facilities and smaller edge sites outside the major hubs. Our lawyers advise in English and German, both for clients still based abroad and for those already operating in Germany.
If you are planning an AI data center project in Germany, or already have one underway, contact us. We will review your situation, give you an initial assessment, and send you a cost proposal for the next steps.
Last updated: October 2026
The German Data Center Market: Growth and Constraints
Germany’s data center market has grown steadily for more than a decade, and AI is now the main driver of new capacity. The federal government has backed this growth with a National Data Center Strategy (Rechenzentrumsstrategie) that sets out clear expansion targets. Frankfurt am Main and the wider Rhine-Main region remain by far the largest location in Germany and one of the most important data center markets in Europe. Meanwhile, the Berlin-Brandenburg region and sites outside the traditional metropolitan areas are increasingly developing into new clusters.
This growth has also created bottlenecks. Grid connection in particular has become one of the biggest challenges for new projects. In high-demand regions such as Frankfurt, the wait for a grid connection can now run to several years, and delivery times for large transformers also have a direct impact on project planning. For international investors, this often reverses the expected order of a project: grid capacity should be clarified as early as possible, ideally in parallel with the search for a site rather than after a plot has been secured.
What Is an AI Data Center?
An AI data center is a data center built for the much higher power density of AI computing, where a single server rack can require many times the power of a standard colocation rack. Like any data center, it is a building and technical infrastructure that houses servers, storage systems, and network equipment, with its own power and cooling supply and extensive security measures.
Data centers generally fall into three categories by size and use: hyperscale data centers operated by large cloud and AI providers, colocation data centers in which several customers rent server capacity, and smaller edge data centers that process data closer to end users to reduce latency. The high power density of AI facilities has direct consequences for grid connection, cooling, and energy efficiency compliance.
Why AI Data Center Projects Involve So Many Areas of Law
An AI data center project rarely raises just one legal question. The structure an international company uses to enter the German market is a corporate law decision that also shapes how the project is taxed. Once a site is found, land acquisition and permitting usually run in parallel, closely tied to grid connection and energy supply. When the facility goes into operation, the focus shifts to staffing, data protection, cybersecurity, and contracts with customers, suppliers, and service providers. Later in a project’s life, acquisitions, disposals, or disputes with contractual partners and authorities may follow.
In practice, these issues are rarely handled by a single firm. Several specialist advisors are usually involved in parallel and have to coordinate with each other, which costs time and creates friction, especially when deadlines for permits or grid connections are already tight. As a full-service firm, we coordinate projects of this scale under one roof and act as our clients’ single point of contact across every area of law involved.
Corporate Structure and Foreign Investment
For an international investor, the first decision is usually the vehicle for the German investment. Most data center projects are carried out through a German subsidiary, typically a GmbH (the German limited liability company) or a GmbH & Co. KG (a limited partnership with a GmbH as its general partner). Many projects also separate the property-owning company from the operating company, which can make financing and a later sale easier. A branch or permanent establishment is also possible, but it leaves the foreign parent company directly liable for the German business, which is rarely desirable for a project of this size.
Some German formalities surprise foreign investors. Forming a GmbH and buying land both require notarization, and the notary needs the parent company’s documents, often with an apostille or legalization and a certified translation. These steps can usually be completed under a power of attorney without traveling to Germany, but they need to be built into the timeline. German companies must also disclose their beneficial owners in the Transparency Register (Transparenzregister).
Non-EU investors acquiring a stake in a German data center operator should check early whether the transaction requires clearance under German foreign investment screening rules, since data center and cloud businesses can fall within the sectors subject to review. Capital contributions, shareholder loans, and other payments between the foreign parent company and its German subsidiary may also have to be reported to the Deutsche Bundesbank under the Foreign Trade and Payments Ordinance (Außenwirtschaftsverordnung, AWV). Opening a company bank account as a foreign managing director can also take longer than expected and is worth starting early.
Tax considerations also influence site selection. Real estate transfer tax (Grunderwerbsteuer) rates are set by each federal state, and trade tax (Gewerbesteuer) rates vary by municipality, so two otherwise comparable sites can carry different long-term costs. Our corporate lawyers and tax lawyers structure the investment with these factors in mind from the outset.
Planning, Permitting, and Environmental Law
For most large data centers, the building permit is only one part of the approval process. A data center generally needs a site covered by a suitable land-use plan (Bebauungsplan). Where no such plan exists, the municipality must adopt or amend one, which is a political decision within the municipality’s control rather than a standard administrative application. Developers often conclude an urban development agreement (städtebaulicher Vertrag) with the municipality as part of this process, covering matters such as infrastructure costs and design requirements.
The large backup generators that hyperscale and AI data centers rely on can bring a project under the Federal Immission Control Act (Bundes-Immissionsschutzgesetz, BImSchG). Depending on the size of the installation, this means a more demanding permit procedure, which can include public participation and an environmental impact assessment. Where a BImSchG permit is required, it generally incorporates the building permit, so the two cannot be treated as separate tracks. For operators of critical facilities, this creates a particular tension: the KRITIS-Dachgesetz (Critical Infrastructure Umbrella Act) lists emergency power supply among the resilience measures they can take, yet the generators that provide it can be what brings the project under the BImSchG in the first place. Planning backup power with both regimes in mind from the outset avoids having to redesign it later. Other issues regularly arise along the way: noise from cooling systems, permits to use water for cooling, and species protection surveys. Some of these surveys can only be carried out at certain times of year and can delay a project by months.
Our environmental lawyers and construction lawyers review planning and application documents before they are submitted, so that potential objections are identified early. Where neighbors or other parties challenge a permit, we represent our clients before the authorities and in court.
Energy Supply and Grid Connection
Securing power often decides whether and when an AI data center can go into operation. The grid connection agreement with the network operator sets the connection capacity, timeline, and costs, and these terms are frequently on the critical path for the whole project. Our energy lawyers support clients in negotiating grid connection terms and draft and review energy supply agreements. These include power purchase agreements (PPAs) for renewable electricity, which also help operators meet the renewable energy requirements of the Energy Efficiency Act (Energieeffizienzgesetz, EnEfG).
Waste heat is a further issue that international investors may not expect. The EnEfG contains obligations on the reuse of waste heat, and as German municipalities develop local heat plans, they increasingly look to data centers as a heat source for district heating networks. Agreements to supply heat to a municipal utility or network operator need to be negotiated with the long-term operation of the data center in mind.
Employment Law for Construction and 24/7 Operations
A data center employs relatively few people once it is running, but employment law still raises issues that international investors should plan for. During construction, the workforce on site is large and often supplied through several layers of contractors. German law can make contractors liable for their subcontractors’ minimum wage payments, so contractor selection, contract terms, and indemnities deserve careful attention.
Once the facility is operational, round-the-clock shift work must comply with German working time rules, including the restrictions on night and Sunday work. Where on-site services are outsourced, the arrangements need to be structured so that they are not treated as temporary agency work, which is subject to strict rules of its own. If a works council (Betriebsrat) has been established, it has co-determination rights over the introduction and use of technical systems capable of monitoring employees, which in a data center can include CCTV and access control systems. Technical staff transferred from abroad raise questions of social security and income tax as well as residence permits, which our employment lawyers, tax lawyers, and immigration lawyers handle together with the underlying employment contracts.
Data Protection, Cybersecurity, and Commercial Contracts
An AI data center typically processes large volumes of personal and security-sensitive data, so data protection and cybersecurity requirements, including those under the GDPR, need to be built in from the start rather than added after the facility opens. Depending on its size, the facility may also fall under Germany’s cybersecurity and critical infrastructure legislation.
The commercial side of the project rests on a series of contracts: construction and equipment supply agreements, colocation and service agreements with customers, and operations and maintenance agreements with service providers. Our construction lawyers and contract lawyers draft and negotiate these agreements, advise on defects and payment disputes during the build, and represent clients if disputes arise, whether through negotiation, arbitration, or litigation before the German courts.
Regulatory Framework for Data Centers in Germany
Three laws form the core of the regulatory framework for data centers in Germany: the Energy Efficiency Act (EnEfG), the Act on the Federal Office for Information Security (BSI Act) as amended by the NIS2 Implementation Act, and the KRITIS-Dachgesetz. Regulation in this area continues to evolve, and monitoring these changes on our clients’ behalf is a standard part of our work in this sector. Each of the three laws has a different focus, scope, and set of obligations:
| Law | Focus | Who is covered | Key obligations |
|---|---|---|---|
| Energy Efficiency Act (EnEfG) | Energy efficiency | Data centers above certain size thresholds | Limits on power usage effectiveness (PUE), waste heat reuse, renewable electricity, reporting |
| BSI Act (as amended by NIS2) | Cybersecurity | Data center service providers above size thresholds, and all operators of critical facilities | Registration with the Federal Office for Information Security (BSI), risk management, incident reporting, management duties |
| KRITIS-Dachgesetz | Physical resilience | Operators of facilities that meet critical infrastructure thresholds | Registration with the Federal Office of Civil Protection and Disaster Assistance (BBK), risk assessment, resilience measures and plan |
The EnEfG sets requirements for data centers above certain size thresholds. These include limits on power usage effectiveness (PUE), the ratio of a facility’s total energy consumption to the energy used by its IT equipment, as well as obligations to reuse waste heat, requirements to source renewable electricity, and reporting obligations, including EU-level reporting of key performance data. The data center provisions have been amended more than once, and the obligations that apply to a project depend on its size and the date it goes into operation.
The NIS2 Implementation Act (NIS2UmsuCG) transposes the EU NIS2 Directive into German law through a rewritten BSI Act (BSI-Gesetz, BSIG). It has significantly widened the range of companies subject to cybersecurity obligations and supervision by the BSI (Bundesamt für Sicherheit in der Informationstechnik). Providers of data center services are among the types of entity covered, depending on the size of the company, and operators of critical facilities automatically count as particularly important entities, the highest category. Companies within scope must register with the BSI, implement cybersecurity risk management measures, and report significant security incidents within strict deadlines. Management bodies are personally responsible for implementing these measures and overseeing their implementation, must take part in regular training, and can be liable to the company for damage caused by breaching these duties.
The KRITIS-Dachgesetz, which implements the EU Critical Entities Resilience Directive, focuses on the physical resilience of critical facilities: their ability to prevent, withstand, respond to, and recover from incidents that disrupt the services they provide. Data storage and processing is among the critical services covered, with the BSI acting as the competent authority. Operators whose facilities meet the thresholds for critical infrastructure must register with the BBK (Bundesamt für Bevölkerungsschutz und Katastrophenhilfe).
Within a set period after registration, operators of critical facilities must carry out a risk assessment at least every four years, covering risks such as natural hazards, accidents, and hybrid or terrorist threats. They must also take resilience measures and document them in a resilience plan. For a data center, these measures can include physical site protection, access controls, emergency power supply, and security management for staff, including the staff of external service providers. These obligations apply in addition to the operator’s cybersecurity obligations under the BSI Act.
Environmental obligations also continue once a facility is operating. Emission limits, permit conditions for backup generators, and water and noise requirements apply throughout the life of a data center. Our lawyers help operators build environmental compliance structures that identify weak points before they become regulatory or criminal law problems.
At Schlun & Elseven Rechtsanwälte, we assess for each project whether, and to what extent, these rules apply, and build the resulting compliance planning into the project timeline from the start rather than addressing it after the facility goes into operation.
A Single Coordinating Firm for International Clients
At Schlun & Elseven Rechtsanwälte, we act as the coordinating firm for international clients across every area of law an AI data center project involves. As a German firm with offices in Cologne, Düsseldorf, and Aachen, we advise on data center projects throughout Germany, including in the Frankfurt and Berlin-Brandenburg clusters. Our lawyers work in English and German across corporate law, real estate law, construction and permitting law, environmental law, energy law, employment and immigration law, data protection and IT law, contract law, tax law, and M&A and dispute resolution. Our clients do not need to instruct several specialist firms themselves. Instead, they have one dedicated contact who oversees the project across all of these areas.
Our clients include international investors, technology companies, and infrastructure operators entering the German market for the first time, as well as established operators expanding their presence in Germany. We work directly with our clients’ legal, finance, and technical teams, and alongside their existing external advisors in other jurisdictions.
Clients do not need to be in Germany to instruct us, and much of our work with international clients takes place by video call and email. Where a step does require a presence in Germany, such as a notarial appointment, we advise on whether it can be handled through a power of attorney instead. For executives and specialists relocating to Germany as part of the project, our business immigration lawyers advise on the appropriate residence permits. All inquiries are treated confidentially, and we carry out a conflict check before taking on any matter.
Legal Support at Every Stage of an AI Data Center Project
Before a site has been chosen, we advise on the most suitable corporate and tax structure for the investment and support due diligence on potential sites, including an initial assessment of land use, grid capacity, and permitting risk. Once a suitable site has been found, we advise on the land acquisition alongside the permitting process, so that legal and regulatory risks are identified before capital is committed rather than afterwards.
During construction, we take care of the construction contracts and support negotiations with network operators on grid connection terms and timelines, which often determine when a project can be completed. Once the facility goes into operation, the focus shifts to data protection, cybersecurity, and energy efficiency compliance, as well as the employment and immigration arrangements for building up the on-site team.
For clients already operating in Germany, our support continues beyond the initial project. We advise on ongoing compliance and contract management, as well as the legal side of expansion, whether through an additional site, an acquisition, or a joint venture with a local partner. The earlier we are involved in a project, the more effectively legal and regulatory risks can be avoided, so we recommend contacting us at the planning stage.
An Overview: Frequently Asked Questions about AI Data Centers and the Law in Germany
The right structure depends on how the project is financed, on tax planning, and on liability considerations, so there is no standard answer. The GmbH (the German limited liability company) is the most common legal form for the operating company. Depending on the investor group and financing model, a holding structure, a joint venture, or a GmbH & Co. KG (a limited partnership with a GmbH as its general partner) may be a better fit. We advise on the structure early in project planning, before the site has been finalized.
The timeline varies considerably depending on the federal state, the municipality, and the size of the facility. It also depends on whether the site already has a suitable land-use plan (Bebauungsplan) and on whether a formal environmental assessment is required. The grid connection is often the more time-critical factor, so it should be assessed in parallel with the permitting process rather than afterwards.
In some cases. Whether a data center counts as a critical facility depends on thresholds set by government ordinance. Where a facility qualifies, additional obligations apply under the KRITIS-Dachgesetz (Critical Infrastructure Umbrella Act), and its operator automatically counts as a particularly important entity under the cybersecurity rules of the BSI Act. Providers of data center services can also be subject to these cybersecurity obligations if the company meets the relevant size thresholds, even if its facility does not qualify as critical infrastructure. Both classifications are made on a case-by-case basis, and we assess for each project whether it falls within scope.
Yes. The appropriate visa and residence permit depend on the individual’s qualifications, role, and country of origin. Common routes include the EU Blue Card for highly qualified specialists and the ICT Card for employees transferred from a group company abroad. We handle residence permits together with the underlying employment contracts, so that immigration and employment law questions are addressed together rather than separately.
It may. Acquisitions of stakes in German companies by investors from outside the EU can be subject to foreign investment screening by the Federal Ministry for Economic Affairs. Because data center and cloud businesses can fall within the sectors subject to review, a notification obligation may apply, and in some cases the transaction cannot be completed until clearance has been granted. Whether screening applies depends on the target company’s activities, the size of the stake, and the investor’s origin, so this should be checked before signing.
Contact Schlun & Elseven Rechtsanwälte
Please use our online form to outline your request to us. After receiving your request, we will make a brief initial assessment based on the facts described and provide you with a cost offer. You can then decide whether you would like to engage our services.



