Germany: After the Berlin Pride Attack, the IP Retention Bill Is Back on the Table

27.07.2026 4
Germany: After the Berlin Pride Attack, the IP Retention Bill Is Back on the Table

Four days after a van was driven into a crowd at Berlin Pride, Germany's stalled IP address retention bill is back at the centre of the political agenda. A CDU lawmaker has called on parliament to pass the pending security package, which would require every internet provider in the country to record which subscriber held which IP address, for three months, for everyone. The bill was already approved by cabinet in April. What the attack changed is not its content but its urgency.

What happened in Berlin

On the evening of 25 July 2026 a van was driven into people gathered on a pedestrian path in the Tiergarten during Berlin's Christopher Street Day. A 65-year-old woman from Poland was killed and 29 people were injured. The suspect, a 21-year-old German of Lebanese descent, fled on foot and was found the next evening in Spandau, where he was shot dead by a police special unit during the arrest attempt. Interior Minister Alexander Dobrindt described the incident as an Islamist terrorist attack.

Within two days the political response had moved to legislation. CDU member of parliament Alexander Throm publicly urged lawmakers to pass the pending security bill, of which IP address retention is the central element.

The bill that is now being pushed

The draft carries the unwieldy title Act to Introduce IP Address Retention and Expand Data Collection Powers in Criminal Proceedings. It was published by the Federal Ministry of Justice and Consumer Protection on 22 December 2025 and approved by the federal cabinet on 22 April 2026, coordinated between Justice Minister Stefanie Hubig and Interior Minister Alexander Dobrindt. It then sat, waiting for parliamentary time.

  • What gets stored: the IP address assigned to a subscriber and, where needed, the accompanying port numbers, for three months.
  • Who is covered: every internet access customer, with no prior suspicion required for the storage itself.
  • What is excluded: target IP addresses, content data, location data and other traffic data are explicitly outside the retention mandate.
  • Beyond retention: new preservation orders for traffic data that would otherwise be deleted, and a widening of cell tower dumps.

That last point deserves attention because it is easy to miss. Cell tower dumps, which reveal every phone connected to a mast near a crime scene, would be extended from "particularly serious crimes" to "crimes of substantial significance". That reverses a restriction the Federal Court of Justice imposed in January 2024.

What actually changes, and what does not

A point that gets lost in the shouting: German investigators can already request subscriber information tied to an IP address. The law firm Gleiss Lutz, analysing the draft, notes that access powers are not being widened here. What is new is the obligation on providers to actually keep the data so that there is something to request. Access still requires reasonable suspicion of an offence and a showing that the data is necessary for the investigation.

That distinction matters, and it cuts both ways. Supporters can accurately say the bill grants no new investigative powers. Critics can equally accurately say it converts a patchwork, where some records happen to exist and most do not, into a guaranteed nationwide log of who was behind which address on any given day of the quarter. Today, whether an IP can be traced back three months is largely an accident of which provider you use. Under this bill it becomes a certainty.

Important: An IP address on its own looks like a technical detail. Combined with a timestamp and a provider record, it is an identity: it links a person to the moment they were online, and by extension to whatever a service logged at that moment.

Industry and the CCC say it will not survive court

The Association of the Internet Industry, eco, has opposed the bill since February 2026 and repeated its objections after the cabinet decision. Its core argument is that indiscriminate retention keeps failing the standards set by the Court of Justice of the European Union, which struck down the Data Retention Directive in 2014. eco also points to its own 2023 win alongside member company SpaceNet, when Germany's Federal Administrative Court confirmed that the previous retention rules were contrary to EU law.

Beyond legality, eco raises a procedural objection that is easy to overlook: judicial control shifts from prior review to subsequent notification. Board member Klaus Landefeld argues these "cannot ensure effective legal protection to the same extent", warning that oversight would be weakened in practice. He also notes the cost side, saying companies are again being asked to invest in infrastructure whose legal status is questionable.

Constanze Kurz, spokeswoman for the Chaos Computer Club, called the proposal a mass surveillance law. The German debate over Vorratsdatenspeicherung has run for close to two decades, and courts have repeatedly sent versions of it back. The Justice Ministry's answer is that this draft is narrower by design, limited to IP addresses rather than the broad set of traffic data that was rejected before, and that recent European case law leaves room for exactly that narrower model.

The uncomfortable detail

The suspect was not unknown to the authorities. He had previously attempted to travel onward to join the Islamic State, was arrested in Lebanon and sentenced there, and was on the radar of German security services. Whatever failed in this case, it was not an inability to identify a stranger from an IP address. That gap between the measure being demanded and the facts of the case it is being demanded over is the part worth watching as the bill moves.

For anyone in Germany, the practical effect of the bill would be that the provider becomes a mandatory record-keeper of your address history. This is the point where the VPN question comes up honestly rather than as a sales pitch: routing traffic through a VPN does not remove your provider's record that you connected, it changes which address the services you visit actually see and log. The two are different exposures, and the bill only touches one of them. Readers following this file can also revisit our earlier coverage of the German ISP data retention draft when it first appeared and of how Chat Control advanced in the EU despite a majority against it.

Conclusion

Conclusion: Germany's IP retention bill did not change after the Berlin Pride attack, but its political weather did. A draft that had been parked since April now has momentum, and the argument for it rests on a case where the suspect was already known to the state. The substantive question stays where it was: whether a three-month log of every subscriber's address survives contact with the Court of Justice, which has rejected broader versions of this idea more than once.
Tags: germany privacy surveillance digital rights legislation censorship vpn

Read also