In November 2018 the Federal Financial Supervisory Authority (“Bundesanstalt für Finanzdienstleistungsaufsicht”, “BaFin”) and Deutsche Bundesbank published a guidance on outsourcing of services to cloud service providers (“Guidance on Cloud Services”). According to BaFin and Deutsche Bundesbank the Guidance on Cloud Services has not stipulated any new requirements, but has condensed the

Lars Lensdorf
Lars Lensdorf is a partner in the Frankfurt office. He focuses on IT law, outsourcing, digitalization/ industry 4.0, IT related bank regulatory matters and data protection. Dr. Lensdorf's practice covers all types of IT and outsourcing agreements, all matters of digitalization and industry 4.0, including online procurement platforms, IT-compliance matters (including cybersecurity) as well as data protection.
Furthermore, he is also focused on interfaces to other practice areas to the extent that IT related matters are affected, e. g. regulatory requirements for banking and financial services as well as public procurement law. A significant part of Dr. Lensdorf’s practice is currently advice in connection with the implementation of the GDPR (data protection) in Europe.
German Federal Financial Supervisory Authority Publishes Guidance on the Regulatory Framework for Cloud Services
The German Federal Financial Supervisory Authority (“BaFin”) recently published an article that provides guidance on the regulatory framework for cloud computing. This is a follow-up to the circular letter Minimum Requirements for Risk Management (“MaRisk”), which was published in German in October 2017 and the circular letter Supervisory Requirements for IT in Financial Institutions (“BAIT”),…