ED08 - Retention Periods & Immutability: Git Hooks, Evidence Packages
Problem
GoBD and the AO require long-term retention - but in practice, implementation fails:
- "10 years? The cloud takes care of that." - many entrepreneurs believe, the cloud software handles retention automatically - but when the account is terminated, the data is often no longer available (see ED01 pain point 6–7)
- Cloud account terminated, data gone - the payroll account was paused, the old payroll accounts can only be reactivated at extra cost - GoBD violation (§ 146 Abs. 5 AO)
- Old software versions cannot be restored - the backups
require the old software version, which can no longer be installed
- GoBD violation (§ 147 Abs. 2 AO: "readable without delay")
- No immutability - bookings changed retroactively without traceability - GoBD violation (Rz. 146)
- No Evidence Packages - during an external audit, the auditor cannot be provided with a data medium (Z3) - GoBD violation (§ 147 Abs. 6 AO)
- Retention periods unknown - 10 years? 8 years? 6 years? Many entrepreneurs do not know the periods for their documents
Key Message
GoBD-compliant retention with Git means:
- Git bundles are self-contained - no cloud account, no
software license, no service provider -
git cloneis enough - Retention periods are documented in the repo - every
artifact carries its period in the sidecar (
obsolescence+ deadline date) - Immutability through tags and Protected Branches - released states are cryptographically immutable
- Evidence Packages for period-end closings -
git bundle+ Static-Web (Z3+) for auditors (see ED05) - Deadline check as Git artifact -
checks/FRISTEN_CHECK.mdwarns about approaching deadlines
Compliance by Design: Retention is not retroactive - it arises from the choice of medium. Git bundles are self-contained and outlast every cloud lockout, every software version change, every service provider termination.
Retention Periods under AO § 147
Retention Periods"] AO --> J10["10 years
§ 147 Abs. 1 Nr. 1"] AO --> J8["8 years
§ 147 Abs. 1 Nr. 4"] AO --> J6["6 years
§ 147 Abs. 1 Nr. 2/3/5"] J10 --> D10["Books, records
Inventories, annual financial statements
Opening balance sheet
Work instructions"] J8 --> D8["Accounting vouchers
E-invoices (XML)
Payroll vouchers"] J6 --> D6["Commercial / business letters
E-mails (EML)
Other documents"] style AO fill:#0F1B33,stroke:#0F1B33,color:#FBFAF7 style J10 fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style J8 fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style J6 fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style D10 fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style D8 fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style D6 fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33
| Period | Document type | Legal basis | Examples |
|---|---|---|---|
| 10 years | Books, records, inventories, annual financial statements, opening balance sheet, work instructions | § 147 Abs. 1 Nr. 1 AO | Grundbuch (JSON), procedure documentation, chart of accounts |
| 8 years | Accounting vouchers | § 147 Abs. 1 Nr. 4 AO | E-invoices (XML), payroll statements, social insurance notices |
| 6 years | Commercial / business letters, other documents | § 147 Abs. 1 Nr. 2/3/5 AO | E-mails (EML), correspondence, notes |
Important - start of the period: The period begins with the end of the calendar year in which the last entry was made, the annual financial statements were prepared, the voucher was received, or the record was made (§ 147 Abs. 4 AO). A booking dated 15.08.2026 starts the period on 31.12.2026 - 10 years end on 31.12.2036.
Immutability through Git
Commit"] B --> H["SHA-256 hash
of the commit"] H --> T["Tag
(release marker)"] T --> P["Protected Branch
(no force-push)"] P --> U["Immutability
GoBD Rz. 146"] K["Correction needed"] K --> NC["New commit
+ obsolescence marking"] NC --> O["Original remains
traceable"] style B fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style H fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style T fill:#10A987,stroke:#0A7F5C,color:#FBFAF7 style P fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style U fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style K fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style NC fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style O fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33
| Mechanism | Git feature | GoBD reference |
|---|---|---|
| Commit hash | SHA-256 hash per commit - every change produces a new hash | Rz. 146 (immutability) |
| Tags | Immutable markers for released states | Rz. 146 (release) |
| Protected Branches | main protected, no force-push, no rebase |
Rz. 146 (no rewriting) |
| Obsolescence | Corrections as new commits with superseded_by |
Rz. 146 (traceability) |
| GPG signature | Signed commits - authenticity verifiable | Rz. 146 (authorship) |
Important - linear history: Only linear history without rewriting is GoBD-compliant.
git rebase,git commit --amendandgit push --forceonmainare forbidden. The pre-commit hook checks that no force-pushes occur and that corrections are made as new commits with obsolescence marking.
Evidence Packages for Retention
e.g. FY2026"] FY --> EP["Tenant Evidence Package
(period-end closing)"] EP --> GB["git bundle
self-contained archive"] EP --> SW["Static-Web
(Z3+ browser)"] EP --> MF["Manifest
+ SHA-256 checksums"] GB --> USB["USB stick
or off-site backup"] SW --> USB MF --> USB USB --> PR["Auditor
git clone or index.html
offline, without IAM"] style FY fill:#0F1B33,stroke:#0F1B33,color:#FBFAF7 style EP fill:#10A987,stroke:#0A7F5C,color:#FBFAF7 style GB fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style SW fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style MF fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style USB fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style PR fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33
A Tenant Evidence Package (see ED05 Z3+) for a fiscal year contains:
| Component | Content | GoBD reference |
|---|---|---|
| git bundle | Complete repo (history, commits, tags) | § 147 Abs. 6 AO (Z3 data medium) |
| Static-Web | Browser-navigable website (HTML/PDF/JSON) | Z3+ (auditor access without IAM) |
| Manifest | SHA-256 checksums per file, V7GUID index | Rz. 146 (integrity) |
| Procedure documentation | Rendered as HTML | Rz. 64–91 (procedure documentation) |
| DMS documents | All vouchers (PDF, XML, EML) | § 147 Abs. 1 (retention) |
| Contracts | Cross-period documents | § 147 Abs. 1 Nr. 2/3 (commercial letters) |
The most secure retention: A USB stick with
git bundle+ Static-Web + manifest is self-contained, offline, without IAM, without cloud account, without software license. It outlasts every service provider termination, every software version change, every cloud lockout. This is the most secure form of GoBD-compliant retention - because there are no dependencies.Of course, one must also consider the physical security of the USB stick (safe, fire protection, off-site backup).
Deadline Management in the Repo
checks/FRISTEN_CHECK.md
# Fristen-Check
## Vorlauf (bis 010926) - PRIO 1
- [ ] 200826: ELSTER-Organisationszertifikat anfordern
- [ ] 250826: Gefahrtarifstelle festlegen
- [ ] 300826: D&O-Versicherung GF-Haftung
## Aufbewahrungsfristen (laufend)
| Frist | Unterlagen-Typ | Endet | Status |
|---:|:---|---:|:---|
| 10 Jahre | Grundbuch FY2026 | 31.12.2036 | aktiv |
| 8 Jahre | E-Rechnungen FY2026 | 31.12.2034 | aktiv |
| 6 Jahre | E-Mails FY2026 | 31.12.2032 | aktiv |
Automatic Warning for Approaching Deadlines
(Git artifact)"] FC --> P14["over 14 days
green"] FC --> P7["7–14 days
yellow"] FC --> P0["under 7 days
orange/red"] P0 --> W["Warning
to entrepreneur"] style FC fill:#0F1B33,stroke:#0F1B33,color:#FBFAF7 style P14 fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style P7 fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style P0 fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style W fill:#FDBA74,stroke:#C2410C,color:#0F1B33
| Deadline type | Warning | Action |
|---|---|---|
| Retention period ends | 30 days before | Document destruction after expiry |
| Authority deadline (ELSTER, SV) | 14 days before | Prepare transmission |
| Limitation period (§ 169 AO) | 90 days before | Do not destroy documents |
Risk Leverage
| Today (cheap) | Tomorrow (audit-proof) | Risk mitigated |
|---|---|---|
git bundle as self-contained archive |
10-year retention without cloud account | GoBD violation through account termination |
| Tags + Protected Branches | Immutability after release | GoBD violation through retroactive modification |
| Evidence Package (Z3+) | Auditor access without IAM, offline | GoBD violation through inaccessible data |
| Deadline check as Git artifact | Missed deadlines avoided | Late-filing surcharges § 152 AO |
| Obsolescence marking | Corrections traceable | Covert changes |
| GPG-signed commits | Authenticity verifiable | Denial of authorship |
| Static-Web (Z3+) | Browser navigability for auditors | GoBD violation through auditor-unfriendly data |
Harness Requirement (Preview)
Derivable from ED08:
| ID | Requirement | Priority |
|---|---|---|
| FA-4.1 | Deadline check file (checks/FRISTEN_CHECK.md) |
MUST |
| FA-4.2 | Deadline entries with date, type, tenant, voucher reference | MUST |
| FA-4.3 | Automatic warning for deadlines < 14 days | SHOULD |
| FA-6.5 | 10-year retention via Evidence Packages (Git bundles) | MUST |
| FA-6.6 | Immutability after release (tags, Protected Branches) | MUST |
| FA-6.7 | Static-Web generator for period-end closing (Z3+) | SHOULD |
| TA-2.4 | Pre-commit: obsolescence status check | SHOULD |
The complete requirements list in Harness-Anforderungen.md.
Sources
- GoBD (BMF letter, Rz. 146 - immutability, Rz. 152 - retention periods)
- AO (§ 146 Abs. 5 - availability, § 147 - retention periods 10/8/6 years, § 147 Abs. 4 - start of the period, § 147 Abs. 6 - Z3 data access)
GitCover.Ledger/docs/02-Tenant-Evidence-Package.md- Tenant Evidence Package conceptAFJD/agents/(anonymized) - SSoT concept with deadline check, Evidence Packages
Source Topology and CDN Reference Links
| Role | Location | Purpose |
|---|---|---|
| Primary / SSoT | git.gitcover.org/GCC | Canonical storage (GPG-signed, versioned) |
| Public OSS Mirror / CDN | codeberg.org/gitcover-commons | Read-only mirror; FLOSS discovery |
| Community Hub | github.com/gitcover-commons | Issues & Discussions; source code reference on Codeberg |
Note: This mapping of sources, mirror and community hub reflects the current state and may change. Please check the respective canonical source on gitcover.org for the current state.