Loading…
When evaluating an online broker, many investors stop at a single question: "Is it in the BaFin database?" The answer—yes or no—feels definitive. But authorization itself is only the beginning. The BaFin company database lists all banks, insurance companies and financial service providers with an authorization, notified providers, or those maintaining a representation in Germany. What it doesn't immediately show is *what those providers are actually allowed to do*.
BaFin database search results display not only the company name and address, but also the individual permissions and activities authorized. These permissions form a permission matrix—the legal scope of what that broker can offer. This distinction is critical for evaluation.
For example, two brokers might both appear in the database with "Wertpapierdienstleister" (securities service provider) status, but one might hold authorization for "investment advice and brokerage," while another is limited to "execution only, no advice." A proper BaFin regulation check requires looking at the precise legal entity in BaFin's database, then comparing its permissions with the services the broker actually offers. When a broker advertises advisory services but its database entry shows no advisory permission, that is a red flag.
Securities service providers must execute customer orders for account transfers without delay; BaFin has specified this should occur within three weeks. This obligation appears in the database as an authorized activity. But permission to *accept* account transfers and permission to *handle custody* are different entitlements. A broker might be authorized for execution and dealing but not for safekeeping of client assets—in which case it must partner with a custodian, a fact the database entry should reflect.
When you search BaFin's public company database, you can search by firm name or registration number, and the result shows in seconds whether an authorization exists and what business it covers. Look specifically for:
If a broker claims to offer a service not listed in its authorization fields, that's not a minor gap—it's a regulatory violation.
If a compensation event occurs, statutory guarantee schemes ensure legal entitlement to compensation up to a maximum of €100,000 per depositor and per bank, with deposit protection in Germany provided by schemes for different categories of banks. But what counts as a "covered deposit" depends on the entity type and its authorization scope. A broker authorized only for securities trading (not deposit-taking) may not fall under the bank compensation scheme at all—instead, client protection may depend on segregation rules or a different scheme entirely. The authorization entry clarifies this.
1. Note the broker's claimed legal entity name—not its trading brand. 2. Search the BaFin database via its research portal. 3. Confirm the entity appears and is "active." 4. Review the full list of permissions—not just authorization status. 5. Cross-reference the permissions against services offered on the broker's website. 6. If there's a mismatch (the website promises something the database doesn't show as authorized), contact BaFin directly or seek independent advice.
Permission scope is not glamorous, but it is foundational. It's the legal boundary between what a broker *can* do and what it *cannot*. A sophisticated evaluation framework treats this boundary as a data point—not proof of trustworthiness on its own, but a non-negotiable baseline. If a broker's actual service offering extends beyond its authorized scope, no amount of positive reviews or low fees can offset that structural risk.
Analysis, not investment advice.