ED08 - Retention Periods & Immutability: Git Hooks, Evidence Packages

Problem

GoBD and the AO require long-term retention - but in practice, implementation fails:

Key Message

GoBD-compliant retention with Git means:

  1. Git bundles are self-contained - no cloud account, no software license, no service provider - git clone is enough
  2. Retention periods are documented in the repo - every artifact carries its period in the sidecar (obsolescence + deadline date)
  3. Immutability through tags and Protected Branches - released states are cryptographically immutable
  4. Evidence Packages for period-end closings - git bundle + Static-Web (Z3+) for auditors (see ED05)
  5. Deadline check as Git artifact - checks/FRISTEN_CHECK.md warns about approaching deadlines

Compliance by Design: Retention is not retroactive - it arises from the choice of medium. Git bundles are self-contained and outlast every cloud lockout, every software version change, every service provider termination.

Retention Periods under AO § 147

%%{init: {'theme':'base','themeVariables':{'primaryColor':'#FBFAF7','primaryTextColor':'#0F1B33','primaryBorderColor':'#6B7280','lineColor':'#6B7280'}}}%% flowchart TD AO["AO § 147
Retention Periods"] AO --> J10["10 years
§ 147 Abs. 1 Nr. 1"] AO --> J8["8 years
§ 147 Abs. 1 Nr. 4"] AO --> J6["6 years
§ 147 Abs. 1 Nr. 2/3/5"] J10 --> D10["Books, records
Inventories, annual financial statements
Opening balance sheet
Work instructions"] J8 --> D8["Accounting vouchers
E-invoices (XML)
Payroll vouchers"] J6 --> D6["Commercial / business letters
E-mails (EML)
Other documents"] style AO fill:#0F1B33,stroke:#0F1B33,color:#FBFAF7 style J10 fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style J8 fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style J6 fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style D10 fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style D8 fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style D6 fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33
Period Document type Legal basis Examples
10 years Books, records, inventories, annual financial statements, opening balance sheet, work instructions § 147 Abs. 1 Nr. 1 AO Grundbuch (JSON), procedure documentation, chart of accounts
8 years Accounting vouchers § 147 Abs. 1 Nr. 4 AO E-invoices (XML), payroll statements, social insurance notices
6 years Commercial / business letters, other documents § 147 Abs. 1 Nr. 2/3/5 AO E-mails (EML), correspondence, notes

Important - start of the period: The period begins with the end of the calendar year in which the last entry was made, the annual financial statements were prepared, the voucher was received, or the record was made (§ 147 Abs. 4 AO). A booking dated 15.08.2026 starts the period on 31.12.2026 - 10 years end on 31.12.2036.

Immutability through Git

%%{init: {'theme':'base','themeVariables':{'primaryColor':'#FBFAF7','primaryTextColor':'#0F1B33','primaryBorderColor':'#6B7280','lineColor':'#6B7280'}}}%% flowchart TD B["Booking
Commit"] B --> H["SHA-256 hash
of the commit"] H --> T["Tag
(release marker)"] T --> P["Protected Branch
(no force-push)"] P --> U["Immutability
GoBD Rz. 146"] K["Correction needed"] K --> NC["New commit
+ obsolescence marking"] NC --> O["Original remains
traceable"] style B fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style H fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style T fill:#10A987,stroke:#0A7F5C,color:#FBFAF7 style P fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style U fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style K fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style NC fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style O fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33
Mechanism Git feature GoBD reference
Commit hash SHA-256 hash per commit - every change produces a new hash Rz. 146 (immutability)
Tags Immutable markers for released states Rz. 146 (release)
Protected Branches main protected, no force-push, no rebase Rz. 146 (no rewriting)
Obsolescence Corrections as new commits with superseded_by Rz. 146 (traceability)
GPG signature Signed commits - authenticity verifiable Rz. 146 (authorship)

Important - linear history: Only linear history without rewriting is GoBD-compliant. git rebase, git commit --amend and git push --force on main are forbidden. The pre-commit hook checks that no force-pushes occur and that corrections are made as new commits with obsolescence marking.

Evidence Packages for Retention

%%{init: {'theme':'base','themeVariables':{'primaryColor':'#FBFAF7','primaryTextColor':'#0F1B33','primaryBorderColor':'#6B7280','lineColor':'#6B7280'}}}%% flowchart TD FY["Fiscal year
e.g. FY2026"] FY --> EP["Tenant Evidence Package
(period-end closing)"] EP --> GB["git bundle
self-contained archive"] EP --> SW["Static-Web
(Z3+ browser)"] EP --> MF["Manifest
+ SHA-256 checksums"] GB --> USB["USB stick
or off-site backup"] SW --> USB MF --> USB USB --> PR["Auditor
git clone or index.html
offline, without IAM"] style FY fill:#0F1B33,stroke:#0F1B33,color:#FBFAF7 style EP fill:#10A987,stroke:#0A7F5C,color:#FBFAF7 style GB fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style SW fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style MF fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style USB fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style PR fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33

A Tenant Evidence Package (see ED05 Z3+) for a fiscal year contains:

Component Content GoBD reference
git bundle Complete repo (history, commits, tags) § 147 Abs. 6 AO (Z3 data medium)
Static-Web Browser-navigable website (HTML/PDF/JSON) Z3+ (auditor access without IAM)
Manifest SHA-256 checksums per file, V7GUID index Rz. 146 (integrity)
Procedure documentation Rendered as HTML Rz. 64–91 (procedure documentation)
DMS documents All vouchers (PDF, XML, EML) § 147 Abs. 1 (retention)
Contracts Cross-period documents § 147 Abs. 1 Nr. 2/3 (commercial letters)

The most secure retention: A USB stick with git bundle + Static-Web + manifest is self-contained, offline, without IAM, without cloud account, without software license. It outlasts every service provider termination, every software version change, every cloud lockout. This is the most secure form of GoBD-compliant retention - because there are no dependencies.

Of course, one must also consider the physical security of the USB stick (safe, fire protection, off-site backup).

Deadline Management in the Repo

checks/FRISTEN_CHECK.md

# Fristen-Check

## Vorlauf (bis 010926) - PRIO 1

- [ ] 200826: ELSTER-Organisationszertifikat anfordern
- [ ] 250826: Gefahrtarifstelle festlegen
- [ ] 300826: D&O-Versicherung GF-Haftung

## Aufbewahrungsfristen (laufend)

| Frist | Unterlagen-Typ | Endet | Status |
|---:|:---|---:|:---|
| 10 Jahre | Grundbuch FY2026 | 31.12.2036 | aktiv |
| 8 Jahre | E-Rechnungen FY2026 | 31.12.2034 | aktiv |
| 6 Jahre | E-Mails FY2026 | 31.12.2032 | aktiv |

Automatic Warning for Approaching Deadlines

%%{init: {'theme':'base','themeVariables':{'primaryColor':'#FBFAF7','primaryTextColor':'#0F1B33','primaryBorderColor':'#6B7280','lineColor':'#6B7280'}}}%% flowchart LR FC["Deadline check
(Git artifact)"] FC --> P14["over 14 days
green"] FC --> P7["7–14 days
yellow"] FC --> P0["under 7 days
orange/red"] P0 --> W["Warning
to entrepreneur"] style FC fill:#0F1B33,stroke:#0F1B33,color:#FBFAF7 style P14 fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style P7 fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style P0 fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style W fill:#FDBA74,stroke:#C2410C,color:#0F1B33
Deadline type Warning Action
Retention period ends 30 days before Document destruction after expiry
Authority deadline (ELSTER, SV) 14 days before Prepare transmission
Limitation period (§ 169 AO) 90 days before Do not destroy documents

Risk Leverage

Today (cheap) Tomorrow (audit-proof) Risk mitigated
git bundle as self-contained archive 10-year retention without cloud account GoBD violation through account termination
Tags + Protected Branches Immutability after release GoBD violation through retroactive modification
Evidence Package (Z3+) Auditor access without IAM, offline GoBD violation through inaccessible data
Deadline check as Git artifact Missed deadlines avoided Late-filing surcharges § 152 AO
Obsolescence marking Corrections traceable Covert changes
GPG-signed commits Authenticity verifiable Denial of authorship
Static-Web (Z3+) Browser navigability for auditors GoBD violation through auditor-unfriendly data

Harness Requirement (Preview)

Derivable from ED08:

ID Requirement Priority
FA-4.1 Deadline check file (checks/FRISTEN_CHECK.md) MUST
FA-4.2 Deadline entries with date, type, tenant, voucher reference MUST
FA-4.3 Automatic warning for deadlines < 14 days SHOULD
FA-6.5 10-year retention via Evidence Packages (Git bundles) MUST
FA-6.6 Immutability after release (tags, Protected Branches) MUST
FA-6.7 Static-Web generator for period-end closing (Z3+) SHOULD
TA-2.4 Pre-commit: obsolescence status check SHOULD

The complete requirements list in Harness-Anforderungen.md.

Sources

Role Location Purpose
Primary / SSoT git.gitcover.org/GCC Canonical storage (GPG-signed, versioned)
Public OSS Mirror / CDN codeberg.org/gitcover-commons Read-only mirror; FLOSS discovery
Community Hub github.com/gitcover-commons Issues & Discussions; source code reference on Codeberg

Note: This mapping of sources, mirror and community hub reflects the current state and may change. Please check the respective canonical source on gitcover.org for the current state.