ED07 - Retention Periods & Immutability: Git Hooks, Evidence Packages
Problem
GoBD and AO require long-term retention - but in practice implementation fails:
- "10 years? The cloud handles that." - many entrepreneurs believe the cloud software handles retention automatically - but on cancellation of the account the data is often no longer available (see ED01 pain point 6-7)
- Cloud account cancelled, data gone - the payroll account was paused, the old payroll accounts are only reactivatable at extra cost - GoBD violation (§ 146 Abs. 5 AO)
- Old software versions not reactivatable - the backups
require the old software version, which is no longer installable
- GoBD violation (§ 147 Abs. 2 AO: "immediately readable")
- No immutability - retroactively changed bookings without traceability - GoBD violation (Rz. 146)
- No evidence packages - during a field audit the auditor cannot be supplied with a data carrier (Z3) - GoBD violation (§ 147 Abs. 6 AO)
- Retention periods unknown - 10 years? 8 years? 6 years? Many entrepreneurs do not know the periods for their records
Core Statement
GoBD-compliant retention with Git means:
- Git bundles are self-contained - no cloud account, no
software license, no service provider -
git cloneis enough - Retention periods are documented in the repo - every
artifact carries its period in the sidecar (
obsolescence+ period date) - Immutability through tags and protected branches - released states are cryptographically immutable
- Evidence packages for period closings -
git bundle+ static web (Z3+) for auditors (see ED04) - Period check as Git artifact -
checks/FRISTEN_CHECK.mdwarns of impending deadlines
Compliance by Design: Retention is not retroactive - it emerges through the choice of medium. Git bundles are self-contained and outlast every cloud lock, every software version change, every service provider cancellation.
Retention periods according to AO § 147
Aufbewahrungsfristen"] AO --> J10["10 Jahre
§ 147 Abs. 1 Nr. 1"] AO --> J8["8 Jahre
§ 147 Abs. 1 Nr. 4"] AO --> J6["6 Jahre
§ 147 Abs. 1 Nr. 2/3/5"] J10 --> D10["Bücher, Aufzeichnungen
Inventare, Jahresabschlüsse
Eröffnungsbilanz
Arbeitsanweisungen"] J8 --> D8["Buchungsbelege
E-Rechnungen (XML)
Lohnbelege"] J6 --> D6["Handels- / Geschäftsbriefe
E-Mails (EML)
Sonstige Unterlagen"] style AO fill:#0F1B33,stroke:#0F1B33,color:#FBFAF7 style J10 fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style J8 fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style J6 fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style D10 fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style D8 fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style D6 fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33
| Period | Record type | Legal basis | Examples |
|---|---|---|---|
| 10 years | Books, records, inventories, annual financial statements, opening balance, work instructions | § 147 Abs. 1 Nr. 1 AO | General ledger (JSON), procedure documentation, chart of accounts |
| 8 years | Booking vouchers | § 147 Abs. 1 Nr. 4 AO | E-invoices (XML), payroll statements, SV notices |
| 6 years | Commercial / business letters, other records | § 147 Abs. 1 Nr. 2/3/5 AO | E-mails (EML), correspondence, notes |
Important - start of period: The period begins with the end of the calendar year in which the last entry was made, the annual financial statement was prepared, the voucher was received or the record was made (§ 147 Abs. 4 AO). A booking of 15.08.2026 starts the period on 31.12.2026 - 10 years end on 31.12.2036.
Immutability through Git
Commit"] B --> H["SHA-256-Hash
des Commits"] H --> T["Tag
(Freigabe-Marker)"] T --> P["Protected Branch
(kein Force-Push)"] P --> U["Unveränderbarkeit
GoBD Rz. 146"] K["Korrektur nötig"] K --> NC["Neuer Commit
+ Obsoleszenz-Markierung"] NC --> O["Original bleibt
nachvollziehbar"] style B fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style H fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style T fill:#10A987,stroke:#0A7F5C,color:#FBFAF7 style P fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style U fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style K fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style NC fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style O fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33
| Mechanism | Git feature | GoBD reference |
|---|---|---|
| Commit hash | SHA-256 hash per commit - every change produces a new hash | Rz. 146 (immutability) |
| Tags | Immutable markers for released states | Rz. 146 (release) |
| Protected branches | main protected, no force push, no rebase |
Rz. 146 (no rewriting) |
| Obsolescence | Corrections as new commits with superseded_by |
Rz. 146 (traceability) |
| GPG signature | Commits signed - authenticity verifiable | Rz. 146 (authorship) |
Important - linear history: Only linear history without rewriting is GoBD-compliant.
git rebase,git commit --amendandgit push --forceonmainare prohibited. The pre-commit hook checks that no force pushes occur and that corrections are made as new commits with obsolescence marking.
Evidence packages for retention
z. B. FY2026"] FY --> EP["Tenant Evidence Package
(Periodenabschluss)"] EP --> GB["git bundle
self-contained Archiv"] EP --> SW["Static-Web
(Z3+ Browser)"] EP --> MF["Manifest
+ SHA-256-Checksummen"] GB --> USB["USB-Stick
oder Off-Site-Backup"] SW --> USB MF --> USB USB --> PR["Prüfer
git clone oder index.html
offline, ohne IAM"] style FY fill:#0F1B33,stroke:#0F1B33,color:#FBFAF7 style EP fill:#10A987,stroke:#0A7F5C,color:#FBFAF7 style GB fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style SW fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style MF fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style USB fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style PR fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33
A Tenant Evidence Package (see ED04 Z3+) for a fiscal year contains:
| Component | Content | GoBD reference |
|---|---|---|
| git bundle | Complete repo (history, commits, tags) | § 147 Abs. 6 AO (Z3 data carrier) |
| Static web | Browser-navigable website (HTML/PDF/JSON) | Z3+ (auditor access without IAM) |
| Manifest | SHA-256 checksums per file, V7GUID index | Rz. 146 (integrity) |
| Procedure documentation | Rendered as HTML | Rz. 64-91 (procedure documentation) |
| DMS documents | All vouchers (PDF, XML, EML) | § 147 Abs. 1 (retention) |
| Contracts | Cross-period documents | § 147 Abs. 1 Nr. 2/3 (commercial letters) |
The safest retention: A USB stick with
git bundle+ static web + manifest is self-contained, offline, without IAM, without cloud account, without software license. It outlasts every service provider cancellation, every software version change, every cloud lock. That is the safest form of GoBD-compliant retention - because there are no dependencies.Of course, the physical security of the USB stick must be considered (safe, fire protection, off-site backup).
Deadline management in the repo
checks/FRISTEN_CHECK.md
# Fristen-Check
## Vorlauf (bis 010926) - PRIO 1
- [ ] 200826: ELSTER-Organisationszertifikat anfordern
- [ ] 250826: Gefahrtarifstelle festlegen
- [ ] 300826: D&O-Versicherung GF-Haftung
## Aufbewahrungsfristen (laufend)
| Frist | Unterlagen-Typ | Endet | Status |
|---|---|---|---|
| 10 Jahre | Grundbuch FY2026 | 31.12.2036 | aktiv |
| 8 Jahre | E-Rechnungen FY2026 | 31.12.2034 | aktiv |
| 6 Jahre | E-Mails FY2026 | 31.12.2032 | aktiv |
Auto-warning on impending deadlines
(Git-Artefakt)"] FC --> P14["über 14 Tage
grün"] FC --> P7["7–14 Tage
gelb"] FC --> P0["unter 7 Tage
orange/rot"] P0 --> W["Warnung
an Unternehmer"] style FC fill:#0F1B33,stroke:#0F1B33,color:#FBFAF7 style P14 fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style P7 fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style P0 fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style W fill:#FDBA74,stroke:#C2410C,color:#0F1B33
| Deadline type | Warning | Action |
|---|---|---|
| Retention period ends | 30 days before | Document destruction after expiry |
| Authority deadline (ELSTER, SV) | 14 days before | Prepare transmission |
| Limitation period (§ 169 AO) | 90 days before | Do not destroy records |
Risk-Leverage
| Today (cheap) | Tomorrow (audit-proof) | Risk mitigated |
|---|---|---|
git bundle as self-contained archive |
10-year retention without cloud account | GoBD violation through account cancellation |
| Tags + protected branches | Immutability after release | GoBD violation through retroactive change |
| Evidence package (Z3+) | Auditor access without IAM, offline | GoBD violation through inaccessible data |
| Deadline check as Git artifact | Missed deadlines avoided | Late payment surcharges § 152 AO |
| Obsolescence marking | Corrections traceable | Hidden changes |
| GPG-signed commits | Authenticity verifiable | Dispute of authorship |
| Static web (Z3+) | Browser navigability for auditors | GoBD violation through auditor-unfriendly data |
Harness requirement (preview)
Derivable from ED07:
| ID | Requirement | Priority |
|---|---|---|
| FA-4.1 | Deadline check file (checks/FRISTEN_CHECK.md) |
MUST |
| FA-4.2 | Deadline entries with date, type, tenant, voucher reference | MUST |
| FA-4.3 | Auto-warning for deadlines < 14 days | SHOULD |
| FA-6.5 | 10-year retention via evidence packages (Git bundles) | MUST |
| FA-6.6 | Immutability after release (tags, protected branches) | MUST |
| FA-6.7 | Static web generator for period closing (Z3+) | SHOULD |
| TA-2.4 | Pre-commit: obsolescence status check | SHOULD |
The complete requirement list in Harness-Anforderungen.md.
Sources
- GoBD (BMF letter, Rz. 146 - immutability, Rz. 152 - retention periods)
- AO (§ 146 Abs. 5 - availability, § 147 - retention periods 10/8/6 years, § 147 Abs. 4 - start of period, § 147 Abs. 6 - Z3 data access)
GitCover.Ledger/docs/02-Tenant-Evidence-Package.md- Tenant Evidence Package conceptAFJD/agents/(anonymized) - SSoT concept with deadline check, evidence packages
Source topology and CDN reference links
| Role | Location | Purpose |
|---|---|---|
| Primary / SSoT | git.gitcover.org/GCC | Canonical storage (GPG-signed, versioned) |
| Public OSS Mirror / CDN | codeberg.org/gitcover-commons | Read-only mirror; FLOSS discovery |
| Community Hub | github.com/gitcover-commons | Issues & discussions; source code reference on Codeberg |
Note: This assignment of sources, mirror and community hub reflects the current state and may change. Please check the respective canonical source on gitcover.org for the current state.