CybersicherheitJune 20, 2026·7 min read

The 7 most expensive compliance mistakes made by German SMEs

From the missing LUCID registration to the late data breach notification: these seven omissions regularly cost mid-sized companies five- to seven-figure sums.

Compliance gaps are rarely bad faith

Most violations at mid-sized companies arise not from intent but from ignorance: new obligations arrive year after year, and no one in the company feels responsible. The following seven mistakes appear most frequently in audits, cease-and-desist actions, and fine proceedings — ordered by their typical damage potential.

1. Ignoring NIS2 because you consider yourself too small

Many managing directors never even check whether NIS2 applies to them. Yet 50 employees or €10 million in turnover in one of the 18 regulated sectors is enough — which ones these are is shown in the overview NIS2: affected sectors. Fines range up to €10 million or 2% of global annual turnover, plus the personal liability of company management under the BSIG (Germany's NIS2 implementation act).

2. Placing packaging on the market without LUCID registration

Anyone who commercially places filled packaging on the German market for the first time — including online retailers with shipping boxes — must register in the LUCID register beforehand. Without registration, a sales ban applies; fines under the German Packaging Act (VerpackG) range, depending on the violation, up to €100,000 (missing registration) or €200,000 (missing system participation). How registration works is explained in the guide Applying for a LUCID number.

3. Reporting data breaches too late or not at all

The 72-hour deadline of Art. 33 GDPR starts upon awareness of the breach, not upon its full clarification. Violations of the notification duty can be fined under Art. 83(4) GDPR with up to €10 million or 2% of global annual turnover; if inadequate data security is also involved, the bracket doubles to €20 million or 4%.

4 to 7: The other classics

  • No cancellation button under § 312k BGB (German Civil Code): consumers can cancel at any time without notice, minimum terms come to nothing — plus cease-and-desist actions that, including the declaration, quickly cost several thousand euros
  • No internal reporting channel under the HinSchG (German Whistleblower Protection Act): mandatory from 50 employees; obstructing reports or retaliation risks fines of up to €50,000 under § 40 HinSchG plus damages
  • Sleeping through the e-invoicing mandate: non-compliant invoices jeopardize the customer's input VAT deduction from the 2027/2028 deadlines and lead to rejections and payment delays
  • Wrong customs tariff numbers: underpaid customs duties are recovered retroactively for up to three years under Art. 103 UCC (Union Customs Code) — in cases of intent, the charge of tax evasion under § 370 AO (German Fiscal Code) looms

The pattern behind the mistakes

All seven cases have one thing in common: the obligation was known for a long time, and implementation would have been cheap — only the omission became expensive. An annual compliance inventory with clear responsibilities costs a few working days and uncovers most gaps before authorities, competitors, or cease-and-desist associations do.

Matching tool

Comply with NIS2 before the BSI comes knocking.

Check now with the BSI →

Frequently asked questions

Which compliance violation is pursued most frequently at SMEs?

In practice, competition-law cease-and-desist actions top the statistics — for example over a missing cancellation button, a faulty legal notice, or a missing LUCID registration. They are actively hunted by competitors and associations because the violation is visible from the outside. Fine proceedings by authorities usually only follow after complaints or incidents.

Is company management personally liable for compliance violations?

Increasingly, yes. NIS2 (BSIG) provides for express personal liability of company management for overseeing the cybersecurity measures. In addition, management can be liable under general principles (§ 43 GmbHG, § 93 AktG) for damage caused by organizational fault if it ignored recognizable obligations.

Are fines tax deductible?

No. Fines, regulatory penalties, and warning fines from German authorities or EU bodies are not deductible as business expenses under § 4 para. 5 no. 8 EStG (German Income Tax Act). The costs of the defense in fine proceedings, by contrast, may be deductible.

Where do I start with a limited budget?

Prioritize by visibility and damage potential: first the obligations verifiable from the outside (LUCID registration, cancellation button, mandatory website information), then the obligations with high fine brackets and personal liability (NIS2, GDPR notification processes), and finally internal documentation duties. Many basic steps such as the LUCID registration are free of charge.

Related articles

Cybersicherheit

NIS2: Who is affected and what to do now

A practical guide to the applicability analysis and the key obligations under the German BSIG.

Buchhaltung & Logistik

German Packaging Act: LUCID registration without the stress

From registration to volume reporting — the obligations under the VerpackG at a glance.

← All articles