[codicts-css-switcher id=”346″]

Global Law Experts Logo
administrative and criminal investigations germany

Our Expert in Germany

How to Handle Parallel Administrative and Criminal Investigations in Germany (2026): a Step-by-step Guide for Companies

By Global Law Experts
– posted 48 minutes ago

Administrative and criminal investigations germany run in parallel more often than most boards expect, and in 2026 the frequency of overlap has increased as sanctions, export-control and supply-chain enforcement intensify. When a supervisory authority such as BaFin, the Bundeskartellamt or BAFA opens a regulatory inquiry at the same time as the public prosecutor (Staatsanwaltschaft) begins a criminal probe, a company faces two distinct legal machines operating under different standards of proof, different disclosure rules and different privilege regimes. The wrong first move, destroying metadata, volunteering an unnecessary admission, or failing to issue a legal hold, can convert a manageable regulatory matter into a criminal exposure.

This guide sets out a disciplined, step-by-step procedure for in-house counsel, compliance officers and investigation teams to manage concurrent probes, preserve evidence, protect privilege and make a defensible self-reporting decision.

Overview: Why Parallel Administrative and Criminal Investigations Are Rising in 2026

The overlap between regulatory and prosecutorial action is not new, but the pressure points have shifted. Companies increasingly find that a single set of facts, a mis-screened export shipment, an unreported transaction, an environmental breach, triggers both an administrative fine procedure under the Law on Regulatory Offences (Ordnungswidrigkeitengesetz, OWiG) and a criminal investigation under the Criminal Procedure Code (Strafprozessordnung, StPO). Outcomes range from administrative penalties and supervisory orders to indictment, custodial sentences for individuals and the confiscation of proceeds (Einziehung).

It is important to note that German law does not currently provide for genuine corporate criminal liability in the Anglo-American sense. Corporate exposure is principally channelled through the OWiG, in particular the association fine (Verbandsgeldbuße) under § 30 OWiG and the breach-of-supervisory-duty provision under § 130 OWiG, alongside confiscation measures. Individuals, by contrast, may face full criminal liability under the Criminal Code.

Enforcement drivers in 2026

Three forces are converging. First, sanctions and export-control enforcement has accelerated, with BAFA and customs authorities scrutinising screening controls and dual-use classifications more aggressively. Second, financial-sector supervision through BaFin continues to combine administrative measures with referrals to prosecutors where facts suggest criminal conduct. Third, supply-chain and competition enforcement, the latter driven by the Bundeskartellamt, routinely produces dawn raids that seed both administrative and criminal lines of inquiry. The practical effect is that companies can no longer treat a regulatory letter and a prosecutor’s search as separate events.

Who is involved, regulators versus prosecutors

On the administrative side sit the sectoral regulators: BaFin for financial services, the Bundeskartellamt for competition, BAFA for export controls, and various environmental and data-protection authorities. On the criminal side sit the public prosecutor’s offices, the Federal Public Prosecutor (Generalbundesanwalt) for the gravest matters, and the police (including the Federal Criminal Police Office, Bundeskriminalamt, BKA) as an investigative arm. Each has distinct powers and consequences, summarised in the comparison table below, and each may share information with the other. Managing administrative and criminal investigations germany therefore demands a single coordinated response, not two isolated workstreams.

Eligibility: Which Investigations Run in Parallel (When This Guide Applies)

This guide applies where a company faces, or reasonably anticipates, a regulatory or administrative inquiry running alongside a criminal investigation arising from the same or connected facts. Typical triggers include fraud and accounting misstatement, sanctions and export-control breaches, cartel conduct, environmental non-compliance, money-laundering suspicions and serious data-protection failures. The administrative track proceeds under the OWiG and the relevant sector statute; the criminal track proceeds under the StPO and the Criminal Code (Strafgesetzbuch).

Overlap most commonly arises in three patterns: a regulator uncovers facts during supervision and refers them to the prosecutor; a prosecutor’s search alerts the regulator to a supervisory failing; or a whistleblower report reaches both authorities simultaneously. In each pattern the company must assume that anything disclosed to one authority may reach the other.

Exclusions and when to use specialised counsel

This procedure is a management framework, not a substitute for legal advice. Where individual executives face personal criminal exposure, where custody or arrest is a realistic prospect, or where cross-border authorities (for example US or EU bodies) are involved, engage specialist criminal defence and regulatory counsel immediately. The interaction of administrative and criminal investigations germany is procedurally complex, and definitive positions on privilege, disclosure and self-reporting should always be confirmed with qualified counsel.

Step-by-Step Procedure for Managing Administrative and Criminal Investigations Germany

The following twelve steps form the procedural heart of any concurrent investigation response. Work through them in order, but expect several to run in parallel during the first 72 hours. Each step identifies the responsible lead, the immediate to-dos and, where relevant, the governing statute.

  1. Step 1: Immediate triage and internal notification

    Lead: Chief Compliance Officer, escalating to General Counsel and CEO. Within the first 0–24 hours, establish what is known, which authority has acted, and whether the matter is administrative, criminal or both. Convene a small, need-to-know incident group. Do not circulate wide internal emails describing the allegations.

    Sample initial internal notification (script): “We have received formal contact from [authority]. A confidential internal review is now underway under the direction of the General Counsel. Preserve all records relating to [matter]; do not delete or alter any documents or messages. Direct all external enquiries to the General Counsel. Further instructions will follow.”

    • Do: restrict knowledge, log the time and nature of the authority’s contact, and start a confidential file.
    • Don’t: make admissions, brief staff by open email, or contact the other party to the transaction.
  2. Step 2: Secure evidence and forensic preservation

    Lead: IT forensics with General Counsel and external counsel. Within 24–72 hours, issue a legal hold and suspend automatic deletion routines. Instruct a certified forensic vendor to image relevant servers, endpoints and executive mobile devices, preserving metadata and maintaining a hash chain of custody. Forensic integrity is decisive: images that cannot demonstrate an unbroken chain of custody risk being challenged in German proceedings.

    • Do: preserve originals, document every collection step, and secure backups off-network.
    • Don’t: allow custodians to “tidy up” files or wipe devices before imaging.
  3. Step 3: Appoint internal and external legal team with privilege planning

    Lead: General Counsel, with board approval where the matter is material. Within 24–72 hours, retain external counsel and instruct the forensic vendor through counsel to strengthen the prospect of protecting materials from seizure. In Germany, communications and documents relating to a defence mandate, particularly where held by external defence counsel, enjoy stronger protection than internal work product, so structure the investigation to route legal advice through external counsel from the outset.

  4. Step 4: Communication and embargo strategy

    Lead: General Counsel with communications. Impose a communications embargo. Designate a single spokesperson. Prepare holding statements for regulators, employees and, if the matter risks becoming public, media, but release nothing until the legal position is understood. Every external statement in a dual investigation can be used by either the regulator or the prosecutor.

  5. Step 5: Employee interviews and witness handling

    Lead: External counsel with HR. Over 3–14 days, plan interviews carefully. Give employees a clear “who counsel represents” warning, clarifying that counsel acts for the company and not the individual. Observe works council (Betriebsrat) co-determination obligations where interview programmes affect employees collectively. Keep witness logs, and segregate any notes reflecting legal advice.

    • Do: record who was interviewed, when, and by whom; advise interviewees of their status.
    • Don’t: pressure employees or ignore works council consultation rights.
  6. Step 6: Liaison with the regulator

    Lead: External counsel with General Counsel. Within 3–7 days or as the notice requires, open a controlled channel with the regulator (for example BaFin, BAFA or the Bundeskartellamt). Confirm the scope and deadlines of any information request in writing. Provide what is legally required, no more, and note that regulator and prosecutor coordination in Germany means disclosures may be shared.

  7. Step 7: Liaison with the public prosecutor

    Lead: External counsel with General Counsel. Where a prosecutor is involved, engage within 3–7 days. Criminal procedure under the StPO gives the prosecutor powers of search and seizure that the regulator may lack, so establish early whether coercive measures are contemplated. Coordinate the messaging to both authorities so that positions do not diverge.

  8. Step 8: Self-reporting decision, the decision tree

    Lead: General Counsel, external counsel, CEO and board. Reach a decision within 7–14 days, faster where there is immediate risk. Self-reporting in Germany is strategic, not automatic. Weigh the severity of the conduct, the strength of the evidence, the likelihood of independent discovery, and the mitigation or leniency available, the Bundeskartellamt operates a formal leniency programme in cartel matters, and prosecutors and authorities may treat genuine cooperation as mitigating.

    A simplified decision tree: Is the conduct likely to be discovered independently? If yes, and evidence is strong, early self-reporting usually improves outcomes. If discovery is unlikely and the evidence is contested, disclosure may prematurely expand exposure, obtain counsel’s view before acting. Never self-report without first understanding the criminal consequences for individuals.

  9. Step 9: Managing searches, dawn raids and seizures

    Lead: External counsel with an on-site legal team. Acting immediately, from the first minutes of a search, deploy your dawn-raid protocol. Under the StPO (in particular §§ 94 et seq. on seizure and §§ 102 et seq. on searches), prosecutors and police may search premises and seize evidence, generally on the basis of a judicial order. Record the warrant details, verify the scope, accompany investigators at all times, photograph seized items and log everything removed. Cooperate with lawful measures but do not consent to searches beyond the warrant’s scope.

    On-site checklist: call external counsel; check and copy the warrant; assign an escort to each investigator; note every item seized; assert protection over defence-related lawyer communications; keep a running log.

  10. Step 10: Responding to formal information requests

    Lead: External counsel with IT forensics. Typically within 7–30 days per the notice, respond precisely to the scope of each request. Produce documents in a defensible format with a production log. Assert any applicable protections and record the basis. Track deadlines centrally so that the administrative and criminal timelines do not collide.

  11. Step 11: Parallel negotiation and remediation

    Lead: External counsel, General Counsel and remediation team. Over weeks to months, pursue resolution on both tracks. An administrative fine procedure under the OWiG may run alongside negotiations with the prosecutor. Sequence carefully: an admission that resolves the regulatory matter may prejudice the criminal position, and vice versa. Begin remediation, control fixes, policy updates, personnel measures, as authorities weigh cooperation and remediation heavily.

  12. Step 12: Post-investigation reporting and board briefings

    Lead: Compliance, external counsel and any third-party monitor. Over months to years, deliver a closing report to the board, implement agreed remediation, and administer any monitoring arrangement agreed as part of a resolution. Document lessons learned and update the incident-response policy so the next matter is handled faster.

Step / Who / Duration timeline table

Step Who (lead) Typical duration / timing
1. Immediate triage and notification CCO (notify GC and CEO) / external counsel First 0–24 hours
2. Legal hold and forensic preservation IT forensics + GC + external counsel 24–72 hours for imaging
3. Appoint counsel and forensic vendor GC / board if material 24–72 hours
4. Document review and segregation External counsel (lead) 48–120 hours initial; ongoing
5. Employee interviews and witness logs External counsel + HR 3–14 days by scope
6. Liaison with regulator(s) External counsel + GC Within 3–7 days or per notice
7. Liaison with public prosecutor External counsel + GC Within 3–7 days if involved
8. Decision: self-report or decline GC + external counsel + CEO/board 7–14 days (fast track if urgent)
9. Respond to formal requests External counsel + IT forensics 7–30 days per notice
10. Manage searches / dawn raids External counsel + on-site team Immediate (hours) until search ends
11. Resolution / remediation negotiations External counsel + GC + remediation Weeks–months
12. Post-investigation monitoring Compliance + counsel + monitor Months–years

Comparison table, regulator versus public prosecutor

Topic Regulator / administrative authority Public prosecutor / criminal authority
Typical powers Document requests, administrative fines, supervisory orders, compliance measures, on-site inspections Searches and seizure under StPO, arrest, criminal charges, indictment
Standard of proof Administrative standard for regulatory offences Full judicial conviction standard at trial
Immediate remedies Fines, injunctions, business restrictions, licence withdrawal Custodial sentences, fines, criminal records for individuals
Typical timeline Often faster for administrative action; variable Longer overall, but searches may be immediate
Protection of materials Limited protections applied variably; no broad common-law privilege Stronger protection for defence-mandate materials; internal work product more exposed
Coordination May coordinate with or refer to prosecutors May request regulatory materials; can treat cooperation in mitigation

Required Documents and Evidence Preservation in Germany

Evidence preservation in Germany begins the moment a company becomes aware of an investigation. Deletion of relevant records, even accidental deletion through routine IT housekeeping, can undermine any cooperation narrative and, depending on circumstances, expose individuals to obstruction-related risks. Preserve the following, and maintain a chain-of-custody log for every item.

Document / item Why preserve Handling note
Legal hold notice(s) Prevent deletion; start preservation Issue to all relevant custodians immediately
Forensic disk images (servers, endpoints) Preserve original metadata and integrity Use certified vendor; maintain hash chain
Email archives and collaboration logs Key communications evidence Preserve PST/EML/Slack/Teams with metadata
Transaction logs / ERP records Evidence of transactions and approvals Export system reports; verify timestamps
Sanctions / export-control screening records Show compliance checks performed Preserve screening results and dated policies
Customer / supplier contracts and onboarding docs Show duty, knowledge and obligations Retain executed versions and amendments
Internal investigation notes and interview summaries Evidence and witness statements Segregate legal-advice notes; flag them clearly
Board and compliance committee minutes Board oversight evidence Preserve final minutes and relevant drafts
CCTV / access logs (if relevant) Corroborative physical evidence Export and preserve with chain of custody
Mobile device images (executive devices) Often crucial in fraud/sanctions matters Image with appropriate legal basis or consent

Document tagging and legal hold notices

Issue the legal hold to every likely custodian on day one, then track acknowledgements. Tag material by relevance, source and sensitivity at collection so that later review is faster and defensible. Do not rely on custodians to self-select, collect broadly and cull under counsel’s supervision.

Handling privileged materials and cross-border transfer

Protection of internal investigation materials in Germany is narrower than in common-law systems. Documents relating to a defence mandate, particularly those held by external defence lawyers, enjoy the strongest protection against seizure, while purely internal materials may be more exposed, the scope of protection has been the subject of significant case law, so positions should be confirmed with counsel. Segregate legal-advice communications physically and logically, mark them, and document the basis for treating them as protected. Where forensic collection involves personal data crossing borders, the General Data Protection Regulation (GDPR) applies: identify a lawful transfer basis such as standard contractual clauses and consider the guidance of the competent supervisory authorities before exporting data for review.

Note that data-protection supervision in the private sector is primarily handled by the data protection authorities of the individual federal states (Länder), with the Federal Commissioner (BfDI) competent chiefly for federal public bodies and certain sectors such as telecommunications and postal services.

Timeline and Deadlines, What to Expect

Timelines differ markedly between the two tracks, and the interaction of statutory limitation periods with active proceedings can be decisive. Administrative measures under the OWiG can move quickly, while criminal investigations under the StPO frequently take months to years. Coercive measures, searches and seizures, happen in hours.

The Step / Who / Duration table above sets out the internal workflow. As a quick “how long” reference: the immediate response phase (triage, legal hold, forensic imaging) should be complete within 72 hours; the regulator and prosecutor coordination phase spans the first one to two weeks; the self-reporting decision should be resolved within 7–14 days; formal document productions run on 7–30 day cycles set by each notice; and resolution, remediation and any monitoring extend over months to years. Track both administrative and criminal deadlines on a single master calendar so that a response to one authority never breaches a deadline set by the other.

Costs and Fees, What Companies Should Budget

Budgeting early prevents mid-investigation surprises. The dominant cost drivers are data volume, cross-border complexity and the length of any criminal proceedings. Stage procurement, fixed fees for the initial response phase, then scoped mandates, to keep spend proportionate. The figures below are broad indicative ranges only and will vary significantly by matter.

Cost category Indicative range (EUR) Notes / drivers
External counsel (initial response and advice) Tens of thousands upward Complexity; hourly vs fixed fee
Forensic vendor (imaging and review) Low five figures to six figures Data volume drives cost
Document review / eDiscovery Five to six figures and beyond Volume, language, cross-border issues
Administrative fines / penalties Highly variable (up to millions) Regulator and sector dependent; competition fines can be substantial
Remediation and compliance upgrades Five to seven figures Depends on fixes and monitoring
Monitors / third-party oversight Six to seven figures p.a. where used Where required by resolution
Business interruption / reputational cost Variable Indirect costs may exceed legal spend

Note that association fines under § 30 OWiG can be significant, and in competition matters the Bundeskartellamt may impose fines calibrated to turnover; confiscation of economic advantage can apply in addition. Current fine ceilings and calculation methods are set by the applicable statutes and authority guidance.

What Changed in 2026 for Administrative and Criminal Investigations Germany

Several developments make 2026 a distinct enforcement environment for administrative and criminal investigations germany:

  • Sanctions and export-control enforcement uptick. BAFA and customs authorities have increased scrutiny of screening controls and dual-use classifications, raising the likelihood that an administrative export-control finding will be referred for criminal assessment.
  • Financial-sector supervision. BaFin continues to combine administrative penalties and supervisory orders with referrals to prosecutors where conduct may be criminal, tightening the link between the two tracks.
  • Competition dawn raids. The Bundeskartellamt remains active with unannounced inspections and leniency incentives, frequently generating material that feeds parallel criminal inquiries.
  • Cross-border data-protection scrutiny. Guidance on international data transfers continues to shape how forensic evidence may lawfully be collected and exported for review, affecting investigation logistics directly.

Practical implications for company timelines and self-reporting

The likely practical effect is that companies have less time between discovery and coercive action, and that a self-reporting decision must be made earlier and with sharper regard to the criminal consequences for individuals. Regulators and authorities generally reward genuine, timely cooperation, but typically only where it is matched by verifiable remediation. Build a compressed 2026 timeline into your incident-response playbook now.

Common Pitfalls and Mitigation (Do’s and Don’ts)

  • Over-sharing with authorities. Provide only what is legally required; verify scope in writing before producing.
  • Destroying or altering metadata. Suspend auto-deletion and image before anyone touches files.
  • Delaying external counsel. Engage counsel on day one to protect sensitive materials and structure the review.
  • Ignoring works council obligations. Consult the Betriebsrat where interview programmes affect employees collectively.
  • Confusing the two tracks. Coordinate messaging so administrative and criminal positions do not diverge.
  • Premature admissions. Nothing said to a regulator should undercut the criminal defence, and vice versa.
  • Weak chain of custody. Log every collection and transfer to preserve evidentiary value.
  • Unmanaged cross-border transfers. Fix a GDPR transfer basis before exporting data for review.
  • Treating protection as automatic. Segregate and mark legal-advice communications from the outset.
  • Late board escalation. Notify the board promptly on material matters with a short written brief.

Conclusion

Managing administrative and criminal investigations germany in 2026 is a test of preparation and discipline. The companies that emerge best are those that triage within hours, preserve evidence defensibly, structure the review through external counsel, coordinate a single consistent message to regulator and prosecutor, and make the self-reporting decision deliberately rather than reactively. Treat this twelve-step procedure as the backbone of your incident-response playbook, refine it against the compressed 2026 enforcement timeline, and confirm each strategic decision with qualified counsel. This guide is general information and not a substitute for legal advice on a specific matter. For further reading on when specialist support is warranted, see When do I need a regulatory lawyer in Germany.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Dr. Carolin Raspe at YPOG, a member of the Global Law Experts network.

Sources

  1. German Criminal Procedure Code (Strafprozessordnung, StPO), Gesetze im Internet
  2. Law on Regulatory Offences (Gesetz über Ordnungswidrigkeiten, OWiG), Gesetze im Internet
  3. German Criminal Code (Strafgesetzbuch, StGB), Gesetze im Internet
  4. Federal Office for Economic Affairs and Export Control (BAFA)
  5. Federal Financial Supervisory Authority (BaFin)
  6. Bundeskartellamt (German Federal Cartel Office)
  7. Bundeskriminalamt (BKA)
  8. Federal Commissioner for Data Protection and Freedom of Information (BfDI)
  9. Bundesrechtsanwaltskammer (German Federal Bar)
  10. Bundesgerichtshof (Federal Court of Justice)

FAQs

What should a company do first when both a regulator and the public prosecutor open investigations?
Triage immediately: notify the General Counsel and board, issue a legal hold, appoint external counsel and a forensic vendor, and secure critical evidence within 24–72 hours. Restrict knowledge to a need-to-know group and do not volunteer admissions to either authority.
Timelines vary. Administrative probes can run for weeks to months, while criminal investigations often take months to years. The immediate phases, searches, seizures and forensic preservation, occur within hours to days. Track both tracks on one master calendar.
Preserve legal hold notices, forensic images, email and collaboration archives, transaction and ERP records, contracts, sanctions screening records, board minutes and segregated legal-advice notes. Maintain a chain-of-custody log for every item collected.
Self-reporting is strategic. Weigh the severity of the conduct, the strength of the evidence, the likelihood of independent discovery and available leniency. Follow the decision tree in Step 8 and obtain counsel’s view, including on individual criminal exposure, before any disclosure.
Protection is narrower than in some common-law systems. Materials relating to a defence mandate, particularly those held by external defence lawyers, are better protected; internal work product is more exposed and the scope has been shaped by case law. Route legal advice through external counsel, and segregate and mark sensitive materials from the start.
Cooperate with lawful measures but limit disclosure. Deploy a trained on-site team, check and copy the warrant, escort each investigator, photograph and log seized items, assert protection over defence-related lawyer communications, and ensure external counsel attends. Follow the dawn-raid protocol in Step 9.
Material matters require timely board notification. Provide a short written brief, recommend immediate control measures, and apply the escalation thresholds set in your incident-response policy.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Handle Parallel Administrative and Criminal Investigations in Germany (2026): a Step-by-step Guide for Companies

Send welcome message

Custom Message