Cross-Border Investigations: Germany and the US DOJ (EN)
Executive summary
Cross-border investigations involving German prosecutors and the US Department of Justice have become a fixture of modern corporate enforcement. What used to be the exception – parallel criminal proceedings on two continents involving the same conduct – is now a common pattern, particularly in FCPA matters, sanctions cases, cybercrime, tax investigations, and antitrust enforcement. The core challenges are structural: incompatible discovery regimes, different privilege rules, the GDPR barrier to producing personal data to US authorities, and asymmetric plea/settlement mechanisms. Coordination is possible but must be actively managed. This guide explains how the two systems interact, what the MLAT framework provides (and does not), how to structure defense coordination between German and US counsel, and where the biggest strategic mistakes typically occur.
Table of contents
1. Why cross-border matters have become the norm
2. The formal cooperation framework: MLAT and beyond
3. Structural asymmetries between German and US enforcement
4. The FCPA/§ 299 StGB overlap – parallel corruption jurisdiction
5. Data transfer under GDPR: the discovery problem
7. Coordination of defense: two counsel, one strategy
8. Settlement architecture: DPAs, § 153a StPO, and their interplay
9. Practical playbook for in-house counsel
10. Frequently asked questions
1. Why cross-border matters have become the norm
Several structural forces have driven the increase in parallel Germany-US enforcement:
Extraterritorial reach of US statutes. The FCPA reaches any issuer with US securities, any domestic US concern, and any foreign national who takes an act in furtherance of a bribery scheme within US territory. Sanctions provisions under IEEPA reach any US person and any transaction touching the US financial system. Antitrust conspiracy claims reach any conduct affecting US commerce. Together, these grant DOJ jurisdiction over conduct that is often primarily German in nature.
Expanded German enforcement. Germany has strengthened economic crime enforcement over the past decade – specialized economic crime prosecutor units, higher fines under Article 83 GDPR, aggressive asset forfeiture under §§ 73 ff. StGB, and NIS-2-implementing legislation with personal liability provisions. German prosecutors are no longer content to defer to US enforcement.
Coordinated agency-level cooperation. DOJ, FBI, SEC, OFAC and Europol, BKA, BaFin, and German prosecutors' offices operate direct liaison relationships. Information moves faster and more informally than treaty-based cooperation would suggest.
Whistleblower dynamics. The US SEC whistleblower program and – separately – the German Hinweisgeberschutzgesetz create pipelines of internal reports that can trigger parallel proceedings on both sides.
Corporate self-reporting. Companies facing US enforcement often report to Germany simultaneously to control the narrative. Companies facing German enforcement do the same in reverse. Voluntary parallel notification has become an accepted strategy for global corporations.
The consequence: an executive whose conduct is investigated in Germany today faces a non-negligible probability of parallel US scrutiny, and vice versa. Defense strategy must anticipate both from the start.
2. The formal cooperation framework: MLAT and beyond
The formal channels of cooperation are anchored in international agreements, but daily practice involves substantially more informal exchange.
2.1 The Germany-US MLAT
The Mutual Legal Assistance Treaty between Germany and the United States entered into force in 2009 (TIAS 09-1018). It establishes procedures for:
Taking testimony and statements
Providing documents, records, and articles of evidence
Locating or identifying persons
Serving documents
Executing requests for searches and seizures
Transferring persons in custody for testimony
Assisting in proceedings related to forfeiture
Central authorities: The US Attorney General (in practice DOJ's Office of International Affairs) and the German Federal Ministry of Justice coordinate MLAT requests. Direct prosecutor-to-prosecutor requests occur but are typically routed through the central authorities.
What MLAT achieves: Formal, court-usable evidence transfers. A German prosecutor requesting bank records held in the US will receive them via MLAT with the proper procedural chain preserved.
What MLAT does not achieve: Fast turnaround, informal information exchange, coordinated strategy. Typical MLAT request response times run six to eighteen months. For fast-moving cross-border matters, MLAT is the backbone but not the primary channel.
2.2 The Cybercrime Convention (Budapest Convention)
For cyber-related investigations, the 2001 Council of Europe Convention on Cybercrime (Budapest Convention), to which both Germany and the US are parties, provides supplementary cooperation channels – expedited preservation of electronic evidence, transborder access to publicly available data, and 24/7 network contact points.
2.3 The EU-US Umbrella Agreement
The 2016 EU-US Data Protection Umbrella Agreement establishes a framework for the protection of personal data transferred between EU and US law enforcement authorities. It reduces – without eliminating – GDPR obstacles to law-enforcement data sharing.
2.4 Informal cooperation
The most consequential exchanges often happen outside formal channels. Direct calls between DOJ prosecutors and German Staatsanwälte, joint task-force meetings at Europol, secondments, and back-channel case coordination all fall under this heading. For defense counsel this means: assumption that any information provided to one enforcement authority can rapidly reach the other.
3. Structural asymmetries between German and US enforcement
Understanding the different systems is essential before designing a coordinated defense.
3.1 Prosecutorial discretion vs. mandatory prosecution
US federal prosecutors have broad discretion to decline, defer, or negotiate. German prosecutors operate under the Legalitätsprinzip (§ 152(2) StPO): once credible suspicion exists, they must investigate. In principle, they cannot decline based on cost-benefit or policy considerations.
Consequence: A "convince DOJ not to charge" strategy has no direct German equivalent. In Germany, the leverage points are earlier disposition (§ 153, § 153a StPO diversion) and outcome shaping (charging decisions, plea equivalents, sentencing).
3.2 Discovery vs. investigative file access
The US model of adversarial discovery – Rule 16 disclosures, subpoenas, depositions, Brady/Giglio obligations – has no counterpart in Germany. German defense counsel receives access to the investigative file (Akteneinsicht) under § 147 StPO. This is comprehensive but different: it provides read access to what the prosecution has, not a mechanism to compel additional productions.
3.3 Trials
US federal jury trials with adversarial cross-examination. German trials before judicial panels with judge-led questioning. Fundamentally different mechanics – strategy and witness preparation must be adapted, not translated.
3.4 Sentencing
US Federal Sentencing Guidelines produce numerical outcomes with formal offense levels. German sentencing operates on §§ 46 ff. StGB principles with substantial judicial discretion within the statutory range. Direct sentence-comparison shopping between jurisdictions is misleading – the mechanics are too different.
3.5 Corporate liability
The US recognizes corporate criminal liability. Germany does not have a true corporate criminal law yet – instead, corporate sanctions run through § 30 OWiG administrative fines and asset forfeiture under §§ 73 ff. StGB. This asymmetry creates leverage in some negotiations and complications in others.
3.6 Plea/settlement mechanisms
US: guilty pleas, deferred prosecution agreements, non-prosecution agreements. Germany: Verständigung under § 257c StPO, diversion under § 153a StPO, Strafbefehl orders. The mechanisms are procedurally distinct and produce different documented outcomes. A US DPA does not create a German equivalent record – but the German § 153a-Einstellung has no US analog either.
4. The FCPA/§ 299 StGB overlap – parallel corruption jurisdiction
Corruption cases are the archetypal cross-border matter. The Foreign Corrupt Practices Act and German anti-bribery law (§§ 299, 331 ff. StGB) frequently address the same conduct.
4.1 Jurisdictional overlap
FCPA jurisdiction: Issuers (companies with US-listed securities), domestic concerns (US persons and entities), foreign nationals acting within US territory in furtherance of a bribery scheme. Applied broadly – emails routed through US servers, dollar-denominated transactions clearing through US correspondent banks, US-based executives receiving briefings.
German jurisdiction: § 299 StGB Abs. 3 explicitly extends to foreign commerce. §§ 335 ff. StGB address foreign public officials. Corporate liability via § 30 OWiG and asset forfeiture apply.
4.2 Practical patterns
A German subsidiary of a US public company pays commissions to foreign agents in ways that violate FCPA. US enforcement triggers – and German prosecutors investigate in parallel under § 299 or §§ 331 ff. StGB.
A German company operating in the US market pays kickbacks to US business partners. FCPA does not apply (no foreign officials), but the Travel Act or federal wire fraud may reach the conduct. Meanwhile, § 299 StGB Abs. 3 covers the foreign-commerce dimension.
Both regimes prosecute the individuals and the entity. Global settlements typically require coordinating multiple resolutions.
4.3 Coordination challenges
Fact patterns and legal theories. DOJ and German prosecutors may characterize the same conduct differently – bribery vs. commercial bribery, principal vs. accessory.
Timing. US matters typically resolve faster; Germany can take years. Defense strategy must sequence resolutions carefully to avoid one side undermining the other.
Financial exposure. Duplicative fines and asset forfeitures are real risks. Anti-bis-in-idem protections under EU and international law provide some protection, but only when properly asserted.
5. Data transfer under GDPR: the discovery problem
One of the most operationally difficult aspects of parallel proceedings.
5.1 The core tension
US authorities request or subpoena documents from a German subsidiary. The documents contain personal data (employee names, customer information, communications). Transfer to the US authorities is a data transfer under GDPR Article 44 – requiring a transfer mechanism.
Options include:
Article 49(1)(d) – transfer necessary for the establishment, exercise, or defense of legal claims. Sometimes usable, but narrowly interpreted.
Article 49(1)(e) – transfer necessary for important reasons of public interest. Even narrower.
BCR/SCC – contractual mechanisms typically inadequate for law-enforcement transfers.
Adequacy – US no longer has general adequacy status; the EU-US Data Privacy Framework applies to commercial transfers, not law-enforcement contexts.
5.2 The Umbrella Agreement gap
The EU-US Umbrella Agreement covers government-to-government transfers between law enforcement authorities. It does not authorize direct company-to-DOJ productions. Companies producing documents to US authorities in response to subpoena or grand jury demand still must find a lawful basis under GDPR.
5.3 Practical solutions
In-country hosting. Documents reviewed and produced from EU-based counsel rather than shipped to US counsel.
Redaction and pseudonymization. Removing or anonymizing personal data before production. Increasingly demanded by German data protection authorities.
Employee consent frameworks. Where individuals consent to transfer, one Article 6 GDPR basis is established – but consent must be freely given, which is difficult in employment contexts.
Blocking statutes. France, Germany, and Switzerland have laws that restrict compliance with foreign discovery. These can be tactical shields but must be asserted carefully.
Court supervision. In some cases, EU courts have supervised productions to US proceedings, providing legitimacy under Article 6(1)(c).
5.4 The consequences of getting it wrong
Producing GDPR-covered data to US authorities without a proper transfer mechanism creates:
German data protection authority enforcement risk (fines up to €20 million or 4% of turnover).
Civil liability from data subjects.
Reputation damage in Europe that can affect ongoing operations.
Corporate defendants in cross-border matters have paid nine-figure Article 83 fines for improperly executed law-enforcement productions.
6. Privilege across borders
Attorney-client privilege operates very differently in Germany and the US.
6.1 US privilege
Broad common-law privilege for attorney-client communications and attorney work product. Extends to in-house counsel in most circumstances. Waiver rules are complex but generally require intentional disclosure to break privilege.
6.2 German privilege
Narrower and more differentiated:
Strafverteidiger (criminal defense counsel). Strong protection under § 97 StPO – documents and communications generally not subject to seizure.
External counsel outside criminal defense. Protection is weaker. Documents held by external counsel may be subject to seizure in some circumstances (see Jones Day/BVerfG 2018 case law).
In-house counsel. Generally not privileged in Germany. In-house legal work is typically treated as company work product without the § 97 StPO shield.
6.3 The cross-border trap
Companies routinely make privilege assumptions that do not survive travel:
US in-house counsel communications, treated as privileged in the US, may lose that treatment when moved to a German subsidiary.
German internal investigation materials, prepared for German § 97 StPO purposes, may be treated as unprivileged in US discovery.
Communications intended to protect against US claims may be discoverable in German proceedings, and vice versa.
6.4 Practical safeguards
Use of criminal defense counsel on both sides for materials intended to be maximally protected.
Segregation of workstreams – separate matter management for materials by jurisdiction.
Common interest agreements where multiple defendants coordinate.
Careful sourcing – awareness of where documents were created, held, and traveled to.
Legal opinions on privilege status before critical productions.
7. Coordination of defense: two counsel, one strategy
The management of parallel proceedings requires structural coordination.
7.1 Retainer architecture
Two typical models:
Lead counsel model. One firm coordinates across jurisdictions, engaging local counsel where required. Simpler client management but privilege concerns must be managed carefully.
Coordinated retainer. Independent US and German counsel with an explicit coordination agreement. More flexibility, more complexity in client-side coordination.
7.2 Communication protocols
Regular joint calls between US and German counsel with the client on the line.
Common document repository with jurisdiction-specific access controls.
Written joint strategy memoranda (privileged) capturing key decisions.
Escalation procedures for divergent recommendations.
7.3 Consistent messaging
Inconsistent statements to different authorities are one of the most common – and most damaging – errors in parallel matters. A defense position that "we did not know" in one jurisdiction and "we investigated fully" in another creates a factual conflict prosecutors can exploit. All statements to authorities should be reviewed by both counsel teams.
7.4 Timing coordination
Sequencing of settlements. Which resolution first? Coordinated resolution requires balance – early US settlement can trigger German scrutiny; early German resolution can leave US-side leverage without a benefit.
Coordinated interviews. When both sides want to interview the same individuals, timing and content coordination protect the individuals and preserve consistency.
Cooperation credit. Both DOJ and German prosecutors offer cooperation benefits. Coordinated cooperation increases the total benefit; uncoordinated cooperation reduces it.
8. Settlement architecture: DPAs, § 153a StPO, and their interplay
Coordinated resolutions are increasingly common but structurally complex.
8.1 US DPA/NPA
The US Deferred Prosecution Agreement or Non-Prosecution Agreement typically involves:
Statement of facts (public)
Monetary penalty
Compliance monitor (in significant cases)
Cooperation obligations
Term of years for probationary period
8.2 German equivalents
§ 153a StPO diversion. Termination against conditions – typically monetary payment. No conviction; entered against individuals or against the entity via § 30 OWiG proceedings.
§ 30 OWiG administrative fine. Direct fine against the entity, often paired with asset forfeiture under §§ 73 ff. StGB.
Verständigung under § 257c StPO. For matters going to trial, a court-approved understanding on outcome. Requires confession of some scope.
Strafbefehl. Written penal order, accepted or contested. Useful for smaller matters.
8.3 Coordinated resolution structure
Best-practice architecture for global corporate settlements:
Global fact narrative – consistent across US and German dispositions.
Deconfliction of penalty amounts – total exposure sized against ability to pay and comparable precedent.
Coordination of monitor requirements – single monitor covering both jurisdictions where feasible.
Coordinated public announcement – timing and language.
8.4 Individual dispositions
Executives often face individual charging decisions on both sides. Resolution structures include:
Individual criminal plea in US, § 153a diversion in Germany
Individual criminal charge in US, deferred position in Germany
Cooperation-based no-charge outcomes with statements-of-facts requirements
Each combination has different implications for future employment, professional licensing, and reputation.
9. Practical playbook for in-house counsel
For companies facing potential parallel proceedings:
Phase 1: Identification and preservation
Preservation notice to affected employees – US and Germany simultaneously
Data mapping – where the potentially responsive documents are located, custodians, retention status
Preliminary GDPR assessment – what data can be transferred, on what basis
Whistleblower protection assessment – if the trigger is internal, ensure protections are in place
Phase 2: Counsel engagement
German Strafverteidiger retained for criminal exposure assessment
US white-collar counsel for FCPA/DOJ dimensions
Coordination framework established in writing between the counsel teams
Client-side single point of contact designated
Phase 3: Investigation and assessment
Internal investigation structured to serve both jurisdictions – Upjohn-analogue employee notifications, coordinated with German BetrVG considerations
Fact pattern development through both counsel teams, cross-checked
Individual counsel for exposed executives where appropriate
Board briefing with coordinated risk assessment
Phase 4: Regulatory engagement
Voluntary disclosure decision – if beneficial, coordinated timing and content
Response to inbound inquiries – single message, consistent statements
Regulator management – expectations on cooperation, monitoring, disclosure
Phase 5: Resolution
Coordinated settlement architecture where feasible
Individual dispositions structured for consistency
Post-resolution compliance program designed to satisfy both jurisdictions
10. Frequently asked questions
If I am under investigation in Germany, is DOJ likely to be involved?
It depends on the conduct. FCPA, sanctions, cybercrime, tax fraud with US dimensions, and antitrust matters with US commerce implications regularly generate parallel proceedings. Pure German domestic matters typically do not. Cross-border companies with US securities or US operations should assume US risk in most serious matters.
Can I use the same statement in both jurisdictions?
You can, but only after careful coordination between counsel. Statements have different legal meanings, evidentiary consequences, and privilege implications in each system. Formal statements should typically be prepared jointly by both counsel teams.
Does the US Fifth Amendment apply in Germany?
No. German procedure has its own self-incrimination protections (§ 136 StPO for beschuldigte Personen, § 55 StPO for witnesses) but they operate differently. A US executive appearing before German prosecutors should be advised on German rights, not US rights.
Can DOJ subpoena documents held by a German subsidiary?
DOJ can subpoena the US parent, which controls the German subsidiary. Production of documents held in Germany requires GDPR-compliant transfer mechanisms. Direct DOJ subpoenas to German entities without US presence are typically executed through MLAT.
Does US cooperation credit apply if I also cooperate with Germany?
Both DOJ and German prosecutors offer cooperation benefits. Coordinated cooperation typically maximizes total benefit. Cooperation in one jurisdiction that undermines defense in the other is a common – and costly – error.
What is the biggest risk in coordinating US and German investigations?
Inconsistent statements. A factual position taken to one authority that conflicts with a position taken to the other creates cross-border credibility problems that are extremely difficult to unwind.
Are penalties additive across jurisdictions?
Not automatically. Anti-double-punishment principles apply, particularly under EU law. Coordinated resolutions often size total penalties against combined conduct rather than adding jurisdictional maxima. But without coordination, duplicative penalties are a real risk.
Which counsel takes the lead?
Depends on the primary risk. If the criminal exposure is dominant in one jurisdiction, that counsel typically leads. Where risks are balanced, co-lead structures work – but only with explicit coordination protocols.
Conclusion
Cross-border enforcement between Germany and the US has become sophisticated enough that ad-hoc responses no longer work. The systems are legally and procedurally different, the cooperation channels are both formal (MLAT) and informal (agency-to-agency), and the coordination challenges cut across privilege, discovery, data protection, and settlement architecture.
For companies and executives facing parallel proceedings, three principles matter most: coordinate defense counsel from day one, assume information flows between authorities, and plan settlement architecture holistically rather than jurisdiction by jurisdiction. Those who invest in cross-border defense capabilities early operate through complex investigations with meaningful control over outcomes. Those who improvise typically pay significantly more, spend significantly longer in enforcement, and face more damaging public dispositions.
The bridge between the two systems is not built at the moment of crisis. It is built earlier, in the retainer structure, in the coordination protocols, and in the awareness that – in modern corporate enforcement – there is no such thing as an isolated jurisdiction.
Legal disclaimer
This article is for informational purposes only and does not constitute legal advice. Every case is different. For advice on a specific matter, please schedule a confidential consultation.
About the author
Niklas Hanitsch is a German criminal defense attorney focused on economic crime, IT and cyber criminal law, compliance, and data protection criminal law. He advises executives, in-house counsel, and companies on cross-border investigations at the intersection of German and US enforcement. Founder and CEO of SECJUR, a venture-backed compliance and cybersecurity automation company selected for the Google for Startups Cybersecurity Accelerator. Member of the Federal Commission on Cybersecurity of the German Economic Council (CDU). Named Capital 40 Under 40 (2023) and winner of the German Startup Cup for Cybersecurity (GFFT, 2022). Previous positions: Legal at Amazon, Taylor Wessing Silicon Valley (advising US companies on European data protection law), Taylor Wessing Germany, and Bird & Bird.
Schedule a confidential consultation →