IP Address Retention in Germany: What ISPs and MVNOs Must Store Under the New § 177 TKG

IP address retention in Germany: public IP, port, line ID and timestamp stored for three months in a separated retention store under § 177 TKG

Хранение IP-адресов is back on the German agenda. Under the government bill on IP address retention (Bundestag printed paper 21/6581), every provider of internet access services will have to store which public IP address, and behind CGNAT which ports, was assigned to which connection, for three months. The purpose is narrow: authorities should be able to identify the subscriber behind an IP address observed in an investigation.

For ISPs, mobile operators and MVNOs, the obligation raises practical questions. Which data exactly? Is RADIUS accounting enough? What about CGNAT, IPv6 and always-on connections? And who is responsible when the IP address is assigned in the host network? This article answers these questions on the basis of the current draft.

Status: This article reflects the government draft as introduced in the Bundestag (first reading on 24 June 2026, now in committee). Details may still change.

Основные выводы

  • Only providers of internet access services are obligated under § 177 TKG-E, which the explanatory memorandum puts at around 700 companies. Hosting, e-mail, messenger and VoIP providers are not.
  • Providers must store the публичный IP-адрес (IPv6: the assigned prefix), the ports where they are needed for attribution, the line and user identifier, and start and end of the assignment, to the second, with time zone.
  • Destination addresses, URLs, volumes, content and location data are not part of the obligation and must not enter the retention store.
  • The retention period is three months. When exactly this period starts for long-running sessions is still being debated.
  • The data may only be used to identify subscribers (§ 174 TKG) and for e-Evidence subscriber requests. It must be stored separately and deleted irreversibly.
  • RADIUS accounting covers most fields, but not CGNAT port mappings. NAT logging is required.
  • MVNOs and resellers must make sure that the data is stored even if the IP assignment happens at the wholesale partner (§ 177 (2)).
  • Providers will have six months after entry into force to comply.

Why IP Address Retention, and Why Now?

Germany’s previous data retention rules have not been enforced since 2017, and in 2022 the Court of Justice of the EU (CJEU) found them incompatible with EU law (SpaceNet). The CJEU has, however, accepted that general retention of IP addresses assigned to the source of a connection can be permissible for a limited period, for a limited period. In 2020 it allowed this to fight serious crime (La Quadrature du Net), and in 2024 it extended this to criminal offences in general, provided the data is kept in genuinely watertight separation from other data (La Quadrature du Net II). The new bill builds on this case law. It limits retention to the data needed to identify a subscriber and pairs it with the targeted быстрая заморозка procedure described in our previous article. A new legal challenge before the CJEU is nevertheless considered likely.

Who Is Obligated?

Covered: anyone who provides internet access services (§ 3 No. 23 TKG):

  • Fixed-line ISPs (DSL, cable, fibre), including resellers on a wholesale basis
  • Mobile data providers: MNOs, full MVNOs, light MVNOs and service providers with their own customer contract. For light MVNOs and service providers, the wholesale clause of § 177 (2) applies.
  • Public Wi-Fi hotspot operators, where the service is publicly available (to be assessed case by case)

Not covered:

  • Pure hosting, e-mail, messenger, VoIP and SMS providers. Those that provide telecommunications services remain subject to quick freeze and traffic data requests.
  • Non-public networks, such as corporate LANs, and according to the prevailing view guest Wi-Fi offered as an ancillary service

What Exactly Must Be Stored?

§ 177 (1) Данные Notes
No. 1 Public IP address assigned to the subscriber IPv4 address; for IPv6 the assigned prefix
No. 2 Port numbers or port blocks, plus further traffic data if needed for unique attribution Relevant for CGNAT, NAT44 and NAT64
No. 3 Unique line identifier and assigned user identifier Line ID, IMSI/MSISDN, contract number, login name
No. 4 Date and time of start and end of the assignment, to the second, with time zone Applies to IP and port assignments

Explicitly excluded: destination IP addresses, services or URLs accessed, data volumes, content, location and cell data, and data about the use of other services.

Retention period: three months each. According to the wording, the period runs from the end of the assignment. For always-on fixed-line connections, this can mean much longer storage in practice, and industry associations have asked for clarification.

Is RADIUS Accounting Enough?

For most fields, yes. RADIUS accounting (or the Diameter/CDR equivalents in mobile networks) is the natural source:

RADIUS attribute § 177 field
Acct-Status-Type (Start / Interim-Update / Stop) with Event-Timestamp Start and end of the assignment (No. 4)
Framed-IP-Address, Framed-IPv6-Prefix, Delegated-IPv6-Prefix Assigned IP address or prefix (No. 1)
User-Name, Calling-Station-Id, 3GPP-IMSI, NAS-Port-Id / line ID Line and user identifier (No. 3)
Acct-Session-Id Correlation key

In mobile networks, Diameter Gy/Rf records, PGW or SMF/CHF charging records, or RADIUS accounting on the Gi/SGi interface (session start and stop, assigned IP address) serve the same purpose.

Behind CGNAT, RADIUS is not enough. Port blocks and port mappings are created in the NAT gateway, not in the AAA system. Providers need CGN logging, such as port block allocation (PBA) logs, syslog or IPFIX export from the NAT gateway. The records are then correlated: private IP and time (RADIUS) plus public IP, port block and time (CGN log) identify the line. The explanatory memorandum notes that NAT systems that cannot do this will have to be replaced, and this is expected to be the largest cost item. Deterministic NAT, with fixed port blocks per subscriber, dramatically reduces log volumes and simplifies lookups.

Provider Obligations Step by Step

1. Collection

  • Define the data sources: session and accounting records, and CGNAT logs.
  • Make sure all four data categories are recorded completely and to the second, including at session transitions such as re-authentication, handover, IP changes and new port block assignments.
  • Synchronise time (NTP) and record the time zone or UTC consistently.

2. The Wholesale Case (§ 177 (2)): MVNOs and Resellers

A provider that does not generate all the data itself, for example because IP assignment and NAT happen at the host MNO or an aggregator, must ensure that the missing data is still stored. There are two options:

  • A contractual retention obligation for the wholesale partner, including a commitment to answer requests, or
  • A data feed into the provider’s own or an outsourced retention store.

On request, the provider must tell the BNetzA without delay who stores the data. Failing to do so is an administrative offence. In practice, the attribution of IP address and port to the MVNO’s customer must remain resolvable through the identifier (IMSI/MSISDN) on the MVNO side. For background, see LI for eSIM-only MVNOs и MVNO vs MNO responsibilities.

3. Storage and Protection

  • Apply state-of-the-art technical and organisational measures against unauthorised access and use.
  • Keep the data technically separated from all other end-user data: its own database or system, and no mixing with billing or CRM.
  • Store it so that the subscriber can be identified without delay, with a lookup from IP address, port and timestamp to the line and user.
  • Delete it irreversibly after three months, with an automated deletion job and evidence of deletion.

4. Strict Purpose Limitation

The retained data may only be used for:

  1. Subscriber data requests based on an IP address (§ 174 (1) sentence 3 TKG), on the basis of the StPO, BKAG, BPolG or state law
  2. Subscriber data for European Production and Preservation Orders under the Регламент о электронных доказательствах

Any other use, such as marketing, abuse handling or civil disclosure claims, is not allowed from this data set. If you need such data for operations, keep a separate operational data set with its own, shorter retention period. The retained data may also not be disclosed as traffic data under § 100g StPO.

5. Answering Requests

  • Formal check of the request by a qualified employee, or automatically via the interface.
  • Complete transmission without delay and confidentiality towards the subscriber.
  • ETSI-ESB for providers with 100,000 or more contract partners (in addition to the E-Mail-ESB), E-Mail-ESB only for smaller providers.
  • Logging under § 35 TKÜV, including the legal basis on which the data was stored.
  • Compensation: EUR 15 for up to three identifiers (JVEG No. 201; currently EUR 45 for up to ten identifiers).

6. Supervision

  • Отправить implementation documents (systems, procedures, separation, deletion) to the BNetzA without delay once the service starts, and report changes.
  • Expect regular checks. The TKÜV and TR TKÜV will specify systems, procedures and technical facilities.
  • Deadline: no later than six months after the law enters into force.

Blueprint: A Compliant Retention Store

  1. Stream RADIUS/Diameter accounting and CGN logs into a dedicated retention store. Do not simply keep the AAA database for three months, because that violates the separation requirement.
  2. Store only the § 177 fields (data minimisation). Drop operational fields such as volumes or NAS IP addresses, or keep them separately with a shorter retention period.
  3. Record interim updates for long sessions, so that always-on assignments remain traceable. Whether parts of an ongoing assignment may be deleted early depends on the final wording of the law.
  4. Delete automatically three months after the end of each assignment, with logging.
  5. Provide a lookup API for the disclosure team: (public IP, port, timestamp, time zone) → line identifier → subscriber data.
  6. Connect to ESB / E-Mail-ESB for incoming requests and responses.
  7. Document everything for the BNetzA.

How ICS Helps: Your Designated Retention Store

ICS International Carrier Services имеет more than 20 years of experience in telecommunications, законный перехват and compliance и содержит multiple BNetzA acceptances. For ISPs and especially for MVNOs, ICS can operate the retention store as the designated storage entity under § 177 (2), the entity you name to the BNetzA.

  • Анализ пробелов of your RADIUS/Diameter, packet core and CGNAT logging against § 177.
  • Data feeds and connectors from your AAA systems, PGW/UPF and NAT gateways, or from your host MNO.
  • A separated, encrypted retention store holding only the required fields, with automated deletion and deletion evidence.
  • Lookup and disclosure service: IP/port/time-based subscriber identification, answered via ESB or E-Mail-ESB, including JVEG billing.
  • BNetzA documentation and support during audits.
  • Subscriber data warehouse: fast, audit-ready subscriber searches across billing, provisioning and CRM systems. See our Data Retention solutions.
  • Combined with quick freeze and e-Evidence processes, so that all request types are handled in one place.

The six-month deadline is short, especially if NAT gateways need to be replaced. Связаться с ICS to start your readiness assessment.

Часто задаваемые вопросы

What is IP address retention?

IP address retention is the obligation for internet access providers to store which public IP address, and where relevant which ports, was assigned to which connection and when. The purpose is to identify the subscriber behind an IP address later on.

How long must IP addresses be stored in Germany?

Under the government draft of § 177 TKG, for three months. According to the wording, the period starts at the end of the assignment, which industry associations have asked to clarify for long-running sessions.

Do MVNOs have to store IP addresses?

Yes, if they provide internet access with their own customer relationship. If the IP address is assigned in the host network, the MVNO must ensure through a contract or a data feed that the data is stored, and must be able to name the storing entity to the BNetzA.

Is RADIUS accounting sufficient for IP address retention?

It covers the assigned IP address, the identifiers and the timestamps. Behind carrier-grade NAT, however, port mappings are only known to the NAT gateway, so CGN logging (for example port block allocation logs) is also required.

No. The retained data may only be used for subscriber data requests by authorities and for e-Evidence subscriber requests. Other purposes require a separate operational data set with its own legal basis.

Disclaimer: This article provides general information based on the German government draft (BT-Drs. 21/6581) as of September 2026. It does not constitute legal advice. Provisions, deadlines and technical details may change during the parliamentary process and in the TKÜV / TR TKÜV.

Внешние ресурсы

Прокрутить вверх
ICS
Обзор конфиденциальности

На этом сайте используются файлы cookie, что позволяет нам обеспечить наилучшее качество обслуживания пользователей. Информация о файлах cookie хранится в вашем браузере и выполняет такие функции, как распознавание вас при возвращении на наш сайт и помощь нашей команде в понимании того, какие разделы сайта вы считаете наиболее интересными и полезными.