Sebastian Janus

Interim CFO in Germany: liability, NDA and data access

Three things need to be settled before an interim CFO's first working day in a German company: the capacity they act in, the insurance behind them, and the system access they get. The three liability positions under German law, what a Vermögensschadenhaftpflicht covers, and an eight-point checklist.

Updated on

The short answer

Three things need to be settled before the first working day: the capacity the person acts in (adviser or formally appointed officer), the insurance standing behind them, and the access they get — to bank accounts, accounting and personnel data. All three belong in the written contract, not in a verbal understanding.

This piece describes common practice in Germany. It is not legal advice; the specific arrangement should be reviewed with your own lawyer or tax adviser.

Three levels of liability

Who answers for what depends on the capacity the person works in. In practice there are three cases, and they are regularly confused.

1. Advisory and subject to instruction — the normal case. The interim CFO works under a service contract (Dienstvertrag). They owe careful work, not a result. Decisions with external effect — statutory accounts, payments, contracts — are taken and answered for by the managing directors. Liability arises from breach of duty and is usually capped contractually.

2. Appointed as managing director. If the person is entered in the commercial register as Geschäftsführer, full officer liability under section 43 of the German Limited Liability Companies Act applies — including the notably strict liability for payments made after the company becomes insolvent. That is a deliberate decision with a different price, a different insurance position and a different contract. It is not a side effect.

3. De facto management — the case nobody plans for. Someone who acts externally like a managing director can be held liable like one even without a formal appointment. The protection against it is mundane and effective: clear decision rights in the contract, payment release under four-eyes approval, and no sole representation towards the bank, the tax office or the shareholders.

Describe the role cleanly at the start and this point is dealt with.

Professional indemnity insurance

The relevant cover in Germany is called Vermögensschadenhaftpflicht — professional indemnity for pure financial loss. It covers exactly what can go wrong in finance work: a matter missed in the accounts, an incorrect filing, a deadline gone by. Ordinary public liability insurance does not cover this; it responds to injury and physical damage.

Three questions are enough to check it:

  • Does it exist, and for what sum insured? Ask for evidence, not an assurance.
  • Does it cover this specific activity? Some policies exclude officer roles or cross-border work.
  • Does it match the liability cap in the contract? A cap set above the sum insured is worthless in the event that matters.

Where the person is appointed as an officer, there is one more question: does the company's D&O policy include them? Many policies only do so once they have been expressly notified.

The non-disclosure agreement

An NDA before the first substantive conversation is standard and should not be a negotiation topic. Four points matter in practice:

  • Scope. Figures, contracts, customer data, shareholder matters, personnel data — and expressly the existence of the mandate itself where external confidentiality matters, which is the rule in transactions and restructurings.
  • Term. Two to five years beyond the end of the mandate is usual; trade secrets without a time limit.
  • Onward disclosure within the team. If several people from the provider work on the mandate, the NDA has to cover them.
  • Non-compete clauses. A blanket sector ban is not workable for an interim provider. What is reasonable is a defined period covering named direct competitors.

The same applies in reverse on the provider side: references are named only with clearance. That is why mandate descriptions show the situation and the outcome but not, in every case, the client's name.

Data access and data protection

An interim CFO sees personnel data, account movements and contract data. Two constellations need to be told apart.

Where the person works inside the organisation and subject to instruction — the normal case — they generally do not act as a processor under the GDPR but like the company's own staff; what is needed is a confidentiality undertaking. Where a service involving separate data processing is delivered outside the organisation, for instance bookkeeping or payroll on the provider's own systems, a data processing agreement is the right framework. Which of the two applies should be decided before access is granted, not afterwards.

Either way, five rules have proven themselves:

  • An individual, named account in every system. No shared logins — otherwise it cannot be reconstructed afterwards who did what.
  • Read instead of write wherever read is enough. Analysis does not require posting rights.
  • Bank access with submission rights only. Release stays with the managing directors under four-eyes approval. That protects both sides — and is at the same time the most effective protection against an allegation of de facto management.
  • Personnel data as needed. Salary data for planning, yes; access to complete personnel files is rarely necessary.
  • Withdrawal at the end of the mandate, with a date and a list. Forgotten access rights are the most common loose end after a mandate, and they belong in the handover.

A word on employment status

On longer full-time mandates with tight integration, the question of Scheinselbstständigkeit — bogus self-employment — arises. Against the risk: a clearly delimited assignment with defined deliverables, free scheduling, the contractor's own working tools and several clients. In favour of it: full time over many months, being subject to instruction like an employee, and a fixed place in the organisation. Where there is real doubt, a status determination procedure with the German pension insurance (Statusfeststellungsverfahren, Deutsche Rentenversicherung) is the clean route.

Checklist before the first working day

  • NDA signed, mutually.
  • Role and decision rights in writing, including payment release.
  • Evidence of professional indemnity cover, with the sum insured.
  • Liability cap in the contract, aligned to that sum insured.
  • Data protection position decided: confidentiality undertaking or data processing agreement.
  • Access list per system, named, with permission level.
  • Bank rights: submit yes, release no.
  • Withdrawal date and handover format agreed.

At nugrow, points 1 to 5 are in place before the first meeting; points 6 to 8 are set together in the first week.

Frequently asked questions

Is an interim CFO personally liable?

In the advisory role they are contractually liable for breaches of duty, usually capped and backed by professional indemnity insurance. If appointed as managing director, full officer liability under section 43 GmbHG applies.

What insurance does an interim CFO need?

Professional indemnity insurance for pure financial loss (Vermögensschadenhaftpflicht). Ordinary public liability does not cover this. The sum insured and the evidence belong on the table before the mandate starts.

Is a data processing agreement required?

Only where personal data is processed outside the organisation on the provider's own systems, for instance with outsourced bookkeeping. For integrated work subject to instruction, a confidentiality undertaking is normally the right route. The classification belongs before access is granted.

Should an interim CFO have access to the bank account?

Submission rights yes, sole release no. Payments stay with the managing directors under four-eyes approval. That protects the company and the interim manager equally.

What is de facto management, and how is it avoided?

Someone acting externally like a managing director can be liable as one even without appointment. It is avoided through clear decision rights in the contract, four-eyes approval on payments, and no sole representation towards the bank, the tax office or the shareholders.

How long should an NDA run?

Two to five years beyond the end of the mandate is usual, trade secrets without a time limit. What matters is that it covers the provider's team and the existence of the mandate where external discretion counts.

Read on

Interim CFO — how a mandate runs. Interim CFO for private equity portfolios. One interim CFO across several portfolio companies. Rates.

Sources and status

This piece is based on nugrow's contracting and mandate practice and on the relevant provisions of the German Limited Liability Companies Act and the GDPR. It is not legal advice. Status: September 2026.

Sebastian Janus
Interim CFO for private-equity and venture-capital backed companies, founder of nugrow GmbH

Sebastian Janus is an interim CFO for private-equity and venture-capital backed companies, with more than 15 years in finance leadership, fundraising, M&A and restructuring. He founded one of the first German online shoe retailers in 2005, took it through two exits and then served as e-commerce CFO at a listed retail group. He has run nugrow GmbH in Bochum since 2018.

About the author

This article is by Sebastian Janus, interim CFO and finance operating partner. He founded one of the first German online shoe retailers in 2005, took it through two transactions and then served as e-commerce CFO at a listed retail group. Since 2018 he has run nugrow GmbH in Bochum, taking on finance responsibility on a temporary basis – mostly at private-equity and venture-capital backed SaaS and tech companies.

Sebastian Janus: profile and career

Strengthen your finance function – from reporting to finance leadership

Interim CFO, CFO as a service and financial modelling – from over 200 projects since 2019. First profiles within 24 hours.
Book an intro call
Or call us directly: +49 234 47995220