Country:德国 · Employment & Visa
High confidenceUpdated 2026-07-15Handbook

Germany · Employment & Visa

Employment in Germany is governed by the immigration office (Ausländerbehörde) and the Federal Employment Agency. Non-EU foreign employees require a work permit and residence permit; highly qualified professionals can use the EU Blue Card (lower salary threshold). Managing directors may be foreign, but non-EU nationals require corresponding residence/work permits. Mandatory social insurance (pension, unemployment, health, care, accident). Strict dismissal protection; employment contracts must comply.

Key points

Procedure

  1. Assess position and salary (Blue Card eligibility)
  2. Apply to immigration office/employment agency for work permit and residence
  3. Employee enters and completes biometric registration
  4. Sign employment contract (compliant terms)
  5. Social-insurance registration

Hard requirements

Costs

Visa/permit fee; social insurance (employer portion ~20%+); advisor fee⏱ ⏱ Timeline:Work permit and residence about weeks

⚠ Common risks

  • Non-EU director needs visa; easily delayed during formation
  • Dismissal protection makes employment rigid
  • Blue Card salary threshold and eligibility review
  • High social-insurance cost
Handbook

📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)

Applies to:Visa/residence, social insurance and employment compliance for hiring employees in Germany (including foreign managing directors and non-EU skilled talent).

Prerequisites

  • GmbH registration / business registration
  • Position and salary assessment (Blue Card eligibility)
  • Compliant German employment contract template
StepActionOwnerTimelineCostOfficial form / systemNotes & penalties
1Assess position and salary (Blue Card eligibility)
Assess EU Blue Card eligibility under the Residence Act (AufenthG) §18g; 2026 standard annual salary threshold €50,700, shortage occupation/new graduate/IT specialist €45,934.20 (adjusted annually by the Federal Ministry of the Interior).
Company / AdvisorThe salary threshold is updated annually; verify the current year's value before signing.
Penalty:Salary below threshold cannot use the Blue Card track
2Apply for work permit and residence (non-EU)
Non-EU employees apply for residence at the immigration office (Ausländerbehörde); the Federal Employment Agency (BA) participates in approval (Blue Card, etc.).
Ausländerbehörde + Federal Employment Agency (BA)Permit fee (Blue Card first issue ~€100)Residence/Blue Card application (§18g AufenthG)A concrete job offer is required first.
Penalty:Employing without a permit is illegal
3Employee entry and biometric registration
After entry, the employee completes biometric registration and receives the electronic residence card (eAT).
Employee / AusländerbehördeeAT electronic residence cardFailure to register in time invalidates residence.
Penalty:Failure to register in time invalidates residence
4Sign employment contract (compliant terms)
Sign a compliant German employment contract including remuneration, working hours, dismissal-protection and other clauses.
Company / LegalGerman employment contractMust comply with the Dismissal Protection Act and other mandatory rules.
Penalty:Non-compliant clauses can be sued
5Social-insurance registration (five schemes)
Upon starting, register for the five social-insurance schemes: pension, unemployment, health, care, accident; shared by employer and employee (employer portion ~20%+).
Company / Social-insurance institutionEmployer portion ~20%+ (plus employee portion)Social-insurance registrationFailure to register may be penalized.
Penalty:Failure to register for social insurance is penalized
6Managing-director residence applied alongside company formation
Non-EU managing directors must apply for lawful residence/work permit in parallel with company formation to avoid operational disruption.
AusländerbehördeFeeManaging-director visa/residenceCan use the accelerated skilled-worker procedure (§81a AufenthG).
Penalty:Non-EU managing director without lawful residence disrupts operation
7Ongoing employment compliance
Comply with dismissal protection, annual leave, working-hours and other rules; establish an annual employment-compliance calendar (including annual Blue Card salary-threshold re-check).
Company / HRDismissal protection is strict; requires compliant grounds and procedure.
Penalty:Non-compliant dismissal compensation

✅ Self-check list

⚠ Common pitfalls

Blue Card salary threshold影响:2026 standard €50,700 (shortage/new graduate/IT €45,934.20), adjusted annually; signing below blocks the Blue Card.规避:Verify the current year's threshold before signing.
Non-EU director visa影响:During formation the managing director needs lawful residence; easily delayed and disrupts operation.规避:Apply in parallel with company formation (use the accelerated procedure).
Strict dismissal protection影响:The Dismissal Protection Act restricts arbitrary dismissal; non-compliant compensation is high.规避:Compliant grounds + procedure + written notice.
High social-insurance cost影响:Employer portion ~20%+ adds to salary, raising employment cost.规避:Budget includes full social insurance.
Contract violation影响:German contract clauses must comply, otherwise can be sued.规避:Use compliant template + lawyer review.
Annual threshold change影响:Blue Card salary adjusted annually by the Interior Ministry; old values misused.规避:Establish an annual re-check mechanism.

📅 Ongoing post-incorporation obligations

  • Continuous social-insurance payment (monthly)
  • Residence/Blue Card renewal
  • Annual salary-threshold re-check (Blue Card)
  • Ongoing dismissal/employment compliance
  • Report major changes to Ausländerbehörde/BA

🔗 Official portals

用工数据子模板

🔐 Employee Personal Data — GDPR Obligations (EU)

Benchmarked against the twin landmines Deel / Remote / Papaya-style EOR platforms keep hitting — 'worker misclassification + cross-border employee data'. This checklist turns the scattered GDPR employee-data obligations into do-this steps, not statute recitals.

Hiring an employee in any EU country (including via an EOR nominal employer, or by mislabeling someone as a contractor) triggers the full set of GDPR obligations over employee personal data. If the Chinese parent can access EU employee data, cross-border transfer (SCC) obligations stack on top. Misclassification does not change where data-protection responsibility sits under the factual employment relationship.
触发场景:Hiring employees in any EU country (DE / ES / GR), including via an EOR nominal employerMonitoring employees (attendance, email, CCTV, productivity software, GPS / field tracking)Transferring EU employee data back to China HQ or any non-adequacy third countryProcessing sensitive / special-category data (health, race, union, biometrics)Using contractors / freelancers who are in fact managed and controlled (misclassification risk)
Handbook

📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)

Applies to:EU-member-state employers, EOR nominal employers, and Chinese parent / affiliate companies that can access EU employee data (as joint controllers or recipients).

Prerequisites

  • Confirm the employment law relationship: employee / contractor / EOR — this decides who the current GDPR controller is
  • Map the employee-data flow (collection points, storage location, whether it leaves the EU to China)
  • If the Chinese company has no EU establishment, appoint an EU Representative under Art.27
StepActionOwnerTimelineCostOfficial form / systemNotes & penalties
1Establish the legal basis for processing (Art.6)
Do NOT rely on 'consent' as the primary basis for employee data (power imbalance makes it easily invalidated); use 'necessary to perform the contract', 'legal obligation', or 'legitimate interests' with a documented LIA balancing test.
DPO / HR + LegalFinalize before onboarding0Records of Processing Activities (RoPA)
Penalty:Wrong basis: fines up to 2% of global annual turnover or €10M (whichever is higher)
2Issue the Employee Privacy Notice (Art.13/14)
Provide employees a privacy notice: purposes, legal basis, data categories, retention, cross-border transfer arrangements and how to exercise rights; in EOR setups disclose the joint-controller relationship and respective roles.
HROn the first day of employment0Employee Privacy Notice
Penalty:Lack of transparency is a frequent enforcement trigger
3Special-category data assessment (Art.9)
Health, race, union membership, biometrics are prohibited in principle; if genuinely needed, rely on an explicit exemption and apply technical isolation and least-access.
DPOBefore processing0Data classification inventory
Penalty:Special-category breaches carry heavier fines (4% / €20M)
4Employee monitoring & DPIA (Art.35)
Any systematic monitoring (CCTV, email review, productivity tracking, GPS) requires a Data Protection Impact Assessment (DPIA); high-risk processing must be consulted with employee representatives / works council first.
DPO + Employee representativesBefore monitoring goes live0DPIA reportIn Germany, consult the Betriebsrat (works council) in parallel
Penalty:Failure to run a DPIA is a standalone penalty item
5Cross-border transfer to China (Chapter V)
China is not an adequacy country; transfers to HQ require Standard Contractual Clauses (SCC) plus a Transfer Impact Assessment (TIA), with supplementary measures (encryption / pseudonymization) where needed.
DPO + China LegalBefore first transfer0SCC + TIAMirrors the 'China data export' obligations in the data dimension
Penalty:Unlawful transfer: fines 4% / €20M
6Respond to employee data-subject rights (Art.15-22)
Operate an access / rectification / erasure / portability / restriction (DSAR) channel, respond within 1 month; handle post-exit retention per policy.
DPOOngoing0DSAR workflow
7Appoint DPO and EU Representative (Art.37/27)
If core activities involve large-scale systematic monitoring or special-category processing, appoint a Data Protection Officer (DPO); a Chinese company without an EU establishment must appoint an EU Representative.
ManagementBefore processing activities start0DPO appointment / EU Rep agreement

✅ Self-check list

⚠ Common pitfalls

Relying on 'employee consent' as the processing basis影响:Under power imbalance, consent can be invalidated by the regulator, breaking the lawfulness of the entire processing chain规避:Use contract performance / legal obligation / legitimate interests, and keep the LIA on file
Mislabeling an employee as a contractor to dodge employer duties (Deel-type misclassification)影响:Under the factual employment relationship, both GDPR employee-data duties AND labor-law employer liability return; misclassification also triggers tax back-pay, social-insurance recovery and heavy fines规避:Determine the relationship by 'factual control'; in EOR setups sign a joint-controller agreement and clarify data flow and respective duties
China HQ reads EU employee data directly with no SCC影响:Constitutes an unlawful cross-border transfer, fines 4% / €20M规避:Sign SCC + complete TIA, with encryption / pseudonymization as supplementary measures
Monitoring employees without DPIA or works-council consultation影响:In high-regulation countries like Germany, easily triggers complaints and penalties, and poisons labor relations规避:Run DPIA before monitoring + consult the Betriebsrat / employee representatives
Unclear retention of ex-employee data影响:Over-retention violates the data-minimization principle规避:Define a retention schedule and destroy / archive on time

📅 Ongoing post-incorporation obligations

  • Maintain RoPA (records of processing activities) continuously
  • Re-assess transfer measures every 12 months
  • Keep the data-subject rights channel running as business-as-usual
  • Re-run DPIA on material processing changes (new system / new monitoring)

🔗 Official portals

📎 Source:GDPR (Reg. 2016/679) Art.6/9/13/27/30/33/35/37/44; EDPB employee-monitoring guidance; Germany BDSG and Betriebsrat co-determination rules. This card is an operational checklist, not legal advice — rely on counsel and official publications for implementation.
📎 Source:德国联邦内政部;外管局;《居留法》(AufenthG);蓝卡EU
Want to turn this into an actionable compliance workflow?

CompliGo · Outbound Compliance Automation

You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.

CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.