On August 25, 2026, Waymo said it will bring its robotaxi service to Munich, with commercial operations expected toward the end of 2027. TechCrunch reports that Waymo holds no German permits yet and is working with the Federal Motor Transport Authority (KBA) and with state and local authorities. Mobileye and Volkswagen already hold testing permits, according to KBA data cited in the same report. Waymo would be the first US robotaxi operator to work under Germany's Level 4 framework. That makes a quiet part of the law worth examining: its data regime.
What the law actually requires
Germany's 2021 amendments to the Road Traffic Act (StVG) created a legal path for driverless vehicles operating in defined areas. Under § 1e StVG, a vehicle must handle the driving task within its defined operating area without a driver. It must also fall back to a "risk-minimized state" when it cannot comply with traffic law, and it must maintain a secure link to a remote human supervisor, the Technische Aufsicht. The KBA grants the operating permit.
The data obligations sit in § 1g StVG. The vehicle holder must store a defined list of data during autonomous operation. It includes the vehicle identification number, position data, times of use and of activation and deactivation of the autonomous function, and technical parameters such as speed, acceleration, weather conditions and the status of security systems. Storage is triggered by events such as technical-oversight interventions, conflict situations including accidents and near-misses, and unplanned lane changes. On request, the holder must pass the data to the KBA to monitor safe operation. It must also pass data to the competent authorities responsible for the operating area, or to private infrastructure operators, so they can verify the area meets approval requirements.
The strongest case for the regime
The case for this regime is serious. A driverless car has no driver to interview after a crash. Without mandatory logs, regulators and injured parties would depend on the operator's own account of what the software did. Event-triggered records of interventions, near-misses and lane changes are the equivalent of an aviation flight recorder. They let a regulator find failure patterns before they become fatalities, and they let the public trust a technology that has no human at the wheel. Germany also built in a deletion rule: the KBA and area authorities must delete data promptly, and no later than three years after operation of the vehicle ends. Third parties who obtain data to pursue legal claims must delete it once it is no longer needed.
That design is more defensible than the alternatives. It is targeted at safety events rather than continuous capture, and it is written into statute rather than left to case-by-case agency demands.
Where proportionality needs work
The regime is reasonable, but three points deserve scrutiny as a fleet of driverless cars begins operating in a dense European city.
Position data is the sensitive core. A robotaxi fleet logs precise locations tied to rides. Under the GDPR, personal data must be "adequate, relevant and limited to what is necessary" for its purpose (Article 5(1)(c)), and public authorities can process data where it is necessary for a task in the public interest (Article 6(1)(e)). For fleet safety, vehicle-level logs suffice. Regulators should make clear that access to position data linked to an identifiable passenger is the exception, and that the statutory list does not authorise routine passenger tracking.
Three years after operation ends is a long tail. The deletion cap runs from the end of operations, not from the date of the record. A vehicle operating for a decade could leave a decade of records with authorities. A rolling limit, for example a fixed period for routine records and longer retention only for incident-linked data, would keep the safety value and shrink the surveillance risk. The EFF's August 2026 position on automated license plate readers is a useful reminder of how mobility data collected for one purpose becomes searchable for others. Its concern is about ALPR networks, not robotaxis, but the lesson about downstream access carries over.
Access by "competent authorities" and private infrastructure operators is broad. Requests should be logged, purpose-bound and reviewable. The law is silent on who audits the auditors.
None of these points argues for loosening safety logging. They argue for tightening the access and retention side while keeping the safety side intact.
Why this matters for competition and innovation
The regime also has a market dimension. Germany was first in the EU to legalise Level 4 operation, and the framework has drawn testing activity from established carmakers and start-ups. A clear, statutory data duty is easier for a foreign entrant to plan around than open-ended discretion. Waymo says it will start with mapping and phased testing, so it can build compliance into its systems from the start.
The risk lies elsewhere: if authorities read the request powers expansively, or if the operating-area approvals are slow, the practical burden will fall hardest on smaller entrants without large compliance teams. Note also that § 1e provides that appeals against revocation of an operating permit have no suspensory effect. That lets regulators act quickly on safety, but it raises the stakes on the quality of their data requests and decisions.
What to watch
Before commercial launch, the useful questions are concrete. Will the KBA publish guidance on what counts as a proportionate data request? Will position data be pseudonymised at the operator level? Will retention be tied to record age rather than end of operations? Germany has an unusually workable statute, and Waymo's arrival is a chance to show that a safety-first data regime can also be a privacy-respecting one. If regulators answer those questions in public before late 2027, the German model will be easier to defend, and to export.