🇩🇪 Germany — §393 SGB V: Cloud in the statutory-health system
Requirements for using cloud-computing services to process social and health data in the German statutory health-insurance (GKV) system. Introduced by the Digital-Gesetz (DigiG), in force 1 July 2024.
<WRAP center round important 90%> ⚠️ NOT LEGAL ADVICE — decision-support only. A simplified summary of a fast-moving German rule; verify against the primary text (§393 SGB V) and take qualified advice. 🔶 Volatile: a federal regulation on equivalent certifications and several scope questions are still open.
In one line
For GKV cloud use, social/health data may be processed only in Germany, the EU/EEA, Switzerland or an adequacy third country — no SCCs, no BCRs, no Art. 49 derogations — plus a German establishment and a current BSI C5 attestation.
The point to stress: it does NOT hinge on personal data
<WRAP center round tip 90%> The cloud-service trigger in §393 is independent of whether personal data is involved. The definition of a “cloud-computing service” (§384 Nr. 5 SGB V) mirrors the NIS2 Directive and contains no requirement that personal data be processed. Consequences:
- The localisation, C5 and establishment duties attach to the cloud service used in the GKV context — even for a component (IaaS/PaaS/pure infrastructure) that itself touches no personal data.
- This is not the GDPR “is there a personal-data transfer?” test. In the TIA tool, choosing “no personal-data access → no transfer” takes you out of GDPR Chapter V — but it does not take you out of §393 SGB V, which can still require an EU/EEA/adequacy location, a German establishment and a C5 testat for the cloud service.
- Practically: scope §393 by the cloud service and the GKV data category — not by whether a given task processes personal data.
Who is in scope
- Leistungserbringer in the statutory-insurance system (Fourth Chapter of SGB V).
- Statutory health & long-term-care insurance funds (Kranken-/Pflegekassen).
- Their processors (Art. 28 GDPR).
Private-pay care and purely private research that do not touch GKV social/health data stay on the ordinary GDPR Chapter V / §203 StGB baseline — though scope at the edges (e.g. pharma / medical-device research using in-scope processors) is contested.
Localisation & third-country transfers
| Question | §393 SGB V answer |
|---|---|
| Where may processing occur? | Germany, EU, EEA, Switzerland, or a third country with an Art. 45 adequacy decision. |
| SCCs / BCRs / Art. 49 derogations? | Not available. Adequacy is the only third-country route. |
| United States? | Only via a DPF-certified importer (US holds an adequacy decision). |
| China, India, most others? | Not permitted — no adequacy decision. |
| Fallback if adequacy is lost (a “Schrems III”)? | None — repatriate to the EEA. |
This is stricter than GDPR Chapter V, which allows SCCs + TIA for non-adequate countries. §393 removes that option for GKV cloud.
Other core requirements
- German establishment — the datenverarbeitende Stelle must maintain a Niederlassung im Inland. Who exactly this binds — provider, insurer and/or processor — is debated, and its EU-law compatibility has been questioned.
- BSI C5 attestation (Cloud Computing Compliance Criteria Catalogue) covering the systems used, with the “customer criteria” implemented:
- C5 Type 1 acceptable until 30 June 2025;
- C5 Type 2 required from 1 July 2025 (new systems: ~18-month grace);
- a forthcoming federal regulation may recognise equivalent/higher certifications.
- State-of-the-art technical & organisational security, on top of the baselines in §390 (physicians/dentists), §391 (hospitals) and B3S-GKV/PV (insurers).
Practical adaptation
- Host in EU/German regions on a provider holding a current BSI C5 (now Type 2) attestation; verify the C5 scope actually covers the services in use — don’t assume.
- Confirm the provider has a German establishment.
- Contract: pin down who holds the C5 attestation and who bears the (re-)certification cost — the statute doesn’t allocate this.
- US: usable only through a DPF-certified importer; keep an EEA-repatriation plan given the no-SCC-fallback exposure.
- Expect rising reliance on German / EU “sovereign cloud” offerings as a direct consequence.
Relationship to other rules
- GDPR — §393 sits on top of GDPR; it does not replace the Art. 9 condition or (where personal data is transferred) Chapter V. But its cloud scope is broader / independent (see above).
- §203 StGB — professional secrecy still applies; §393 adds the cloud-specific localisation / certification layer for the GKV system.
- EHDS — the EU European Health Data Space adds its own secure-processing-environment rules for secondary use; §393 is the national GKV-cloud overlay. See the transfers matrix.
Sources
- §393 SGB V (gesetze-im-internet) — primary text
- §384 SGB V — definitions (Nr. 5 cloud-computing service, NIS2-based)
- Noerr — Neue Anforderungen an Cloud-Computing-Dienste im Gesundheitswesen
- Piltz Legal — Gutachten für den bvitg (Fragen zum §393 SGB V)
- Fieldfisher — Health data in the cloud: new German law raises the bar
- datenschutz-notizen — Cloud-Computing im Gesundheitswesen ab Juli 2024
As of 2026-09-08. Not legal advice — verify against the primary text and take qualified advice.