Home / Articles / GEG §71a, EU Taxonomy and CSRD

Article · Compliance

What the new rules actually demand

Four pieces of German and EU law are quietly turning building automation and reporting from a nice-to-have into a legal obligation. Here is the plain-language map.

By puniq Team21 Jun 20268 min read

For years, making a building "smart" was a choice. You did it if the payback looked good, and you skipped it if the budget was tight. That window is closing. A stack of German and European rules now puts automation, monitoring and structured reporting on the legal critical path. Miss them and you face fines, blocked financing, and assets that quietly lose value.

The rules are not written for engineers, so they read as fog. This article cuts through it. We walk through the four that matter most for commercial real estate, say in plain words what each one demands, and show where the demand becomes a concrete document or data feed you have to produce. That last part is where most owners get stuck, and it is exactly the gap puniq was built to close.

GEG §71a: automation is now the law in Germany

The Gebäudeenergiegesetz, Germany's Building Energy Act, was amended to add §71a. In one sentence: larger non-residential buildings must install and run building automation and monitoring systems by the end of 2024, with the obligation widening over the years that follow.

The trigger is heating and air-conditioning capacity. Once a building's systems pass the threshold set in the law, the owner is required to fit automation that can continuously track, log and benchmark energy use, and to flag where performance drifts. It is not enough to have a controller in the basement. The system has to actually monitor consumption and surface inefficiency.

For owners this lands hard, because most large buildings already run several vendor systems that do not talk to each other. You may have heating from one supplier, ventilation from another, metering from a third. None of them shares a common record. So even where the hardware exists, the building cannot produce the continuous, comparable monitoring §71a expects. The compliance problem is not missing equipment. It is missing readability.

  • It applies to existing buildings, not just new builds, so retrofits are in scope.
  • It expects continuous monitoring and benchmarking, not an annual spot check.
  • It assumes the data is comparable across systems, which fragmented buildings cannot deliver on their own.
The compliance problem is not missing equipment. It is missing readability.

EU Taxonomy: the definition of a "green" building

The EU Taxonomy is the rulebook that decides which economic activities count as environmentally sustainable. For real estate it sets the technical screening criteria a building has to meet to be labelled Taxonomy-aligned, covering construction, ownership and renovation.

This matters because money follows the label. Banks, funds and insurers increasingly steer capital toward Taxonomy-aligned assets and away from the rest. A building that cannot prove alignment pays more to finance, sells at a discount, and slips down the priority list for institutional buyers. The label is not cosmetic. It is balance-sheet relevant.

Crucially, alignment is something you have to evidence, not assert. The Taxonomy expects measured energy performance and operational data, not a one-off certificate from years ago. That means metered, continuous, auditable building data, the same readable layer §71a is pushing toward. The two rules point in the same direction.

CSRD: now you have to report it

The Corporate Sustainability Reporting Directive, CSRD, is the EU rule that forces a large and growing set of companies to publish detailed, audited sustainability information. It dramatically expands who must report and how rigorously, and it phases in over several years to capture more companies each cycle.

For property owners and corporate tenants, buildings are a major line in that report. Energy consumption, emissions and efficiency of the real estate portfolio all have to be disclosed, and the numbers have to stand up to external assurance. An auditor will ask where each figure came from. "Our facilities team estimated it" is no longer an acceptable answer.

This is the quiet shift that catches teams out. CSRD does not just want a number. It wants a number with a traceable source behind it. That demands a building that can export structured, time-stamped, verifiable data on demand. A spreadsheet rebuilt by hand every quarter does not survive an audit. A documented, continuous data layer does.

  • Reporting must be audited, so estimates and manual workarounds fail.
  • Building energy and emissions data sit squarely inside the disclosure.
  • Every figure needs a traceable origin, which means structured operational data.

EU Data Act 2024: your building data belongs to you

The EU Data Act, which entered into force in 2024, rebalances who controls the data that connected devices generate. In plain terms, it gives the user of a connected product the right to access the data that product creates, and to share it with third parties of their choosing.

For building owners this is a release valve. A great deal of operational data has historically been locked inside vendor systems, readable only through that vendor's own tools and licences. The Data Act pushes against that lock-in. You gain a stronger claim to your own controller, meter and sensor data, and a clearer right to move it into an open, vendor-neutral system.

That right only helps if you can act on it. Holding a legal claim to data trapped in five incompatible proprietary formats is not the same as having usable data. The Data Act opens the door. Someone still has to walk the data through it and turn it into one coherent record.

The four rules at a glance

What each one actually requires

Read separately they look like four unrelated burdens. Read together they ask for the same thing: a building whose data is readable, structured and verifiable.

RULE 01

GEG §71a

Larger non-residential buildings in Germany must run automation and continuous energy monitoring. Requires readable, comparable data across all systems.

RULE 02

EU Taxonomy

Defines what counts as a sustainable building. Alignment must be evidenced with measured, auditable performance data, and it drives access to financing.

RULE 03

CSRD

Forces audited sustainability reporting. Building energy and emissions figures need a traceable source that survives external assurance.

RULE 04

EU Data Act 2024

Gives the building owner the right to access and move data locked inside vendor systems into an open, vendor-neutral layer.

The demand these rules create is already in the numbers

0

German BMS market by 2035, up from $1.53B in 2024

0

CAGR for German building management systems

0

European smart-building market by 2032/33

0

The common thread: from compliance to a documented layer

Read together, these four rules ask for the same underlying thing. §71a wants continuous monitoring. The Taxonomy wants measured, evidenced performance. CSRD wants audited, traceable figures. The Data Act says the data is yours to consolidate. Each one assumes a building whose data is readable, structured and verifiable. Most buildings are none of those.

This is the exact gap puniq closes. Our Data Auditor goes into an existing multi-vendor building, inventories every controller, protocol and data point, and unifies them into one readable, vendor-neutral layer on-premises. Where no automation exists at all, the Infrastructure Blueprint designs the open layer from scratch so it is compliant by construction.

It is the difference between a building that claims to be monitored and one that can prove it to an auditor, a bank or an inspector.

The deliverable that makes this stand up to a regulator is the Documented Data Map. It is the record we hand over at project close: every system, every data point, every source, mapped and traceable. Legacy integrators and PropTech SaaS do not produce it. It is the difference between a building that claims to be monitored and one that can prove it to an auditor, a bank or an inspector.

On top of that, our AI Optimization layer turns the unified data into the benchmarking, forecasting and compliance output these rules expect. It stays advisory and human-in-the-loop by design, which keeps it outside the heavier audit regimes while still producing the reports your CSRD and Taxonomy filings need.

What to do now

The deadlines are not theoretical and they do not move to suit your renovation calendar. The practical first step is to find out, honestly, whether your building can already produce continuous, traceable, comparable energy data. For most owners the answer is no, and the reason is fragmentation, not a lack of equipment.

Start by mapping what you have. Once the building is readable, compliance with all four of these rules stops being four separate scrambles and becomes one engineering outcome. That is the order German rigor demands: make it readable first, and the reporting follows.

For practical templates and checklists on getting building data audit-ready, see our Tools & Guides, or read how this plays out on real buildings in our Case Studies.

puniq Team

German-engineered building intelligence, written for the people who own and operate the assets. We make fragmented, multi-vendor buildings readable, compliant and intelligent.

Keep reading

Where this plays out next

Turn four compliance scrambles into one

Tell us about the systems you run today. We will map the path to one readable, audit-ready intelligence layer.

العربية