NISG 2026 course All courses

Lesson 3.2 · 5 min

Who is liable: fines, damages, a ban

Open in the coursewith narrated slides, a checklist to tick off and a quiz

At a glance

In detail

The fines hit the business

The district administrative authority can fine a legal person or registered partnership if the offence was committed by someone in a leading position: with the power to represent it, to take decisions for it or to exercise control within it § 44(3) NISG 2026. It is also liable where a lack of supervision or control by such a person enabled an employee to commit the offence § 44(4) NISG 2026.

No administrative fines are provided for members of the management body; the fines are directed solely at the entity (notes on § 45). If the legal person is fined, a responsible officer under § 9 of the Administrative Penal Act (VStG) is not punished for the same breach § 44(5) NISG 2026.

How much

Breachessential entityimportant entity
training, risk management, reporting, informing customers, ordered measures § 45(1)up to €10m or 2% of the previous year's worldwide turnover, whichever is higher (2)up to €7m or 1.4% (3)
registration, self-declaration, audit report, obstructing inspections and others § 45(4)up to €50,000, up to €100,000 if repeatedthe same

The turnover is that of the undertaking to which the entity belongs § 45(2) and (3) NISG 2026. If the data protection authority has already fined the same conduct under the GDPR, there is no second fine under the NISG 2026 § 44(7) NISG 2026.

What sets the amount

To be taken into account in particular § 44(6) with § 39(7) NISG 2026: how serious the breach is, where repetition, a failure to report or fix significant incidents, not fixing shortcomings after a binding instruction, wilfully obstructing audits and knowingly false information always count as serious; its duration; earlier breaches; the damage caused; intent or negligence; the risk management measures taken; approved codes of conduct or certifications; and cooperation with the authority.

Personal liability

A breach of duty by members of the management body can lead to liability for damages if damage was caused unlawfully and culpably. What matters is whether the person acted without due care and whether that caused the damage; someone who was outvoted, for instance, or had no influence is not liable (notes on § 31). How such claims are enforced under company law is outside this course.

Bans and publication

Checklist

Quiz

Whom are the fines under § 45 NISG 2026 directed at?

  1. The head of IT
  2. The entity as a legal person
  3. Each managing director personally
  4. The IT service provider
Show the answer

The answer is B: The entity as a legal person. § 44(3) and (4) NISG 2026; according to the notes on § 45 there are no administrative fines for members of the management body. Personally they face at most a claim for damages.

Sources

This lesson's statements rest on:

Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.