Who owns duty of care when an energy-transition site changes phase?

Germany’s energy build-out spans redevelopment, construction, commissioning, operations, maintenance, logistics, and contractor activity. On a large site, several of those phases can exist at once. The difficult question is not whether another alert can be sent. It is whether leaders can establish who may be affected, who has responded, who owns each action, and why important decisions were taken.

Published on
September 9, 2026
Project, operations, and contractor leads reviewing a site plan at a German brownfield energy transition project

 

Why does the pace of transition change the accountability problem?

Germany added nearly 21 gigawatts of renewable generation capacity in 2025, taking installed renewable capacity to just under 210 gigawatts. Solar capacity reached 117 gigawatts, while onshore wind reached 68.1 gigawatts. The federal policy objective remains for renewables to supply at least 80 per cent of gross electricity consumption by 2030.1, 2

Those numbers describe an energy-system change across changing workplaces. Assets are built, modified, retired, or repowered as projects pass into operations and maintenance.1 People, work, organisations, and access rules can change faster than the physical site.

This is where duty of care can become fragmented. A project, its operations team, and each contractor may have competent arrangements, yet an incident can still expose the gaps between them. The owner may know the asset, a contractor may know the current workfront, and security may know which vehicles passed the gate. No single party necessarily begins with a reliable picture of everybody who could be affected.

The answer is not to erase organisational boundaries. German occupational-safety law and incident-management good practice both recognise that different employers and organisations retain responsibilities while needing to cooperate.3, 4 The objective is to make those boundaries usable under pressure. Leaders need an operating model that identifies the relevant population, distinguishes confirmed facts from assumptions, assigns actions, and preserves decisions across the lifecycle of the site.

 

Why do brownfield and redevelopment sites require a different starting point?

A redevelopment site is not empty land with a blank history. The German Environment Agency notes that brownfield reuse can be complicated by existing buildings, old utility lines, old foundations, and environmental damage arising from previous use. Its current guidance on contaminated sites describes a process that begins with records and historical investigation, including previous operations, accidents, maps, aerial images, interviews, and site inspections, before risk assessment, remediation, and monitoring.5, 6

That history affects incident accountability as well as engineering. A boundary that looks simple on a project map may contain restricted ground, remediation zones, retained infrastructure, temporary routes, live services, or areas released for one activity but not another. During redevelopment, the same geographical site can contain different risk contexts and different authorities.

The incident model should therefore begin with operational geography, not a generic site name. The organisation needs to define which areas are active, who controls access to them, what other activities continue nearby, and which response assumptions apply. A person inside a turbine construction zone, a contractor inspecting legacy infrastructure, and a delivery driver waiting outside a controlled area may all be “on the site”, but they do not create the same response question.

Historical information also needs to remain connected to current decisions. A newly identified constraint may alter a muster route, vehicle access, rescue access, contractor instructions, and the population that could be affected. A mature system turns the change into an operational update with an owner and effective time, rather than relying on everybody to interpret the latest document in the same way.

 

Who remains responsible when several organisations share the site?

Section 8 of Germany’s Occupational Safety and Health Act requires employers sharing a workplace to cooperate, exchange necessary information about work-related hazards, and coordinate preventive measures. It also requires an employer to ensure that workers from other employers operating in its undertaking have received appropriate instructions about relevant risks.3

The Construction Site Ordinance adds a project-specific coordination structure. Where employees of several employers work on a construction site, the responsible party must appoint one or more suitable coordinators. The ordinance requires coordination of safety and health principles, organisation of cooperation between employers, and adaptation of the safety and health plan when execution changes. Appointing a coordinator does not remove the client’s responsibility, and it does not displace each employer’s responsibility for its own workers.4

Incident accountability cannot be solved by putting one person’s name at the top of an emergency plan. Legal responsibility, operational command, employment responsibility, site control, technical authority, and action ownership may sit with different people. Those roles need to be defined before an event.

A shared operational picture should show separate duties without implying that one dashboard has transferred responsibility from one employer to another. One organisation may decide whether an area is evacuated, another may account for its employees, and site management may coordinate access for external responders.

BAuA describes coordination as making information understandable and available, aligning the safety measures required for different work activities, and organising collaboration. It also emphasises that communication, coordination, and cooperation are central to safe construction.7 The practical test is simple. Can each responsible person see the information needed for their role, and can the incident lead see whether each required action has an owner?

 

Who should count as affected during an incident?

The most dangerous shortcut is to treat the employee directory as the accountability list. The relevant population is event-specific. It may include employees, subcontractors, agency workers, original-equipment technicians, drivers, security personnel, visitors, and people from an adjacent operation. It may also include people expected to enter the affected area soon, even if they are not there yet.

German law requires emergency arrangements to reflect the workplace, activities, number of workers, and presence of other people. Employers must also establish necessary connections to outside services for first aid, emergency medical care, rescue, and firefighting.8 Accountability is therefore more than a payroll question.

The accountable population should be assembled from the best available operational evidence. That can include current shifts, contractor attendance, visitor records, access information, work permits, journey plans, vehicle assignments, Check-Ins, and location information where its use is appropriate and authorised. None of those sources should be treated as infallible. A gate record may show entry without proving current position. A permit may identify a team without confirming attendance. A location point may be old. A roster may not reflect a late substitution.

Good incident practice preserves the provenance and time of each fact. “Vehicle entered at 07:41” is different from “vehicle is currently inside”. “Message sent” is different from “message delivered”. “Worker listed for the shift” is different from “worker confirmed safe”. The shared picture becomes more trustworthy when it keeps those distinctions visible.

 

What should “accounted for” actually mean?

Accountability is not a single tick. It is a sequence of states that should be defined in advance. A person may be believed to be in scope. A message to them may have been sent or recorded as delivered. The person may have acknowledged it, reported safe, requested help, or remain unresolved. A vehicle may have an identified driver, a last-known location, a planned destination, or no confirmed occupant information. An action may be assigned but not accepted, accepted but not complete, or completed with evidence still outstanding.

This vocabulary matters because optimistic labels can hide uncertainty. An outgoing message does not demonstrate receipt. A lack of response does not prove injury. A recent location does not prove that somebody remains there. The control room needs to retain what the evidence supports, then follow the approved procedure for resolving what it does not.

ISO 22320 frames incident management around processes and structures, defined roles and responsibilities, task and resource management, and cooperation between organisations. It applies where organisations work together while retaining their own structures.9 A disciplined status model supports that cooperation because two teams can interpret the same term in the same way.

AtlasNXT Check-Ins can help an organisation request and record responses from people in scope. The operator can see responses and non-responses, then follow the customer’s standard operating procedure. This does not automatically determine that an emergency exists, escalate every missed response, or guarantee message delivery. It gives the response team a clearer record of what has and has not been confirmed.

Closure also needs a definition. The organisation may still need to confirm the remaining population, close assigned actions, record the basis for stand-down, and identify follow-up work after the most visible alarm has stopped.

 

How should accountability survive the handover from construction to operations?

Project handover often concentrates on the asset. Incident readiness depends on handing over the operating assumptions around it. BAuA’s guidance on the required file for later work says its purpose is to support safe future work and to avoid improvisation and information deficits that can contribute to disruption, damage, or accidents. The Construction Site Ordinance likewise requires the coordinator to compile information that must be considered during possible later work on the completed structure.10, 4

That principle should extend into the accountability model. The operating team needs more than final drawings and equipment manuals. It needs to understand controlled areas, safe access and egress, isolation assumptions, emergency contacts, muster logic, communications limitations, contractor interfaces, unresolved constraints, and the evidence behind temporary arrangements that have become permanent.

The handover should also identify what is no longer true. Temporary muster points may have disappeared, access routes may have changed, and the contractor who maintained attendance records may have demobilised. Treating those changes as a transition of operational control prevents an old plan from surviving only because nobody retired it.

AtlasNXT Remits can help define geographic responsibility and authorised views around sites, regions, or operating areas. When a site changes phase, the relevant people, responsibilities, and permissions can be reviewed against the new operating model. Remits do not replace legal appointments, risk assessments, or emergency plans. They can help make the agreed structure visible to those authorised to use it.

 

What changes when communications are uneven or disrupted?

Communications resilience should be designed before the incident. Germany’s Federal Office of Civil Protection and Disaster Assistance states that reliable communications structures are decisive for effective crisis management and that communication must remain possible when normally used systems are disrupted. Its guidance recommends keeping alternative communications available and identifies options such as SIM cards for different mobile networks, satellite communications, operational radio, and trunked radio.11

The lesson is not that every worker needs every device. It is that critical communication tasks need a planned fallback appropriate to the site, role, and consequence of failure. A smartphone may be the most practical primary channel where cellular data is available. Selected users working beyond dependable cellular coverage may require compatible satellite devices, subject to the hardware, airtime, configuration, training, and permissions chosen by the organisation. Other sites may rely on radio or fixed systems as part of their arrangement.

The incident picture must show the limits of the channel as well as the content of the message. A timestamp, source, delivery state, and last confirmed contact help operators distinguish current information from stale information. AtlasNXT can bring supported smartphone and compatible satellite inputs into the organisation’s duty-of-care workflow.

Resilience also depends on people and process. Someone must monitor the channel, understand what a missed Check-In means in context, know which alternative to try, and have the authority to assign the next action. A technically diverse communications plan still fails if the receiving role is unclear or if the handover between shifts loses the exception.

 

How can location support duty of care without becoming permanent surveillance?

Location can answer important incident questions. It can indicate who may have been inside a defined area, show where a person last reported, or help relate a Check-In to a journey or site. Its value depends on purpose, freshness, accuracy, and governance. Collecting more location data does not automatically create a better response.

The GDPR principles are directly relevant. The European Commission summarises them as including a specified purpose, collection limited to what is necessary, storage no longer than necessary, appropriate security, and access limited on a need-to-know basis. It also explains that data protection should be built into processing from the design stage and reflected in privacy-protective defaults.12

For a German energy operator, that supports a proportionate design. Depending on the role, risk, policy, and applicable requirements, location may be live, event-led, or consent-based where appropriate. A time-limited construction task, a journey across a remote area, and normal office work do not necessarily justify the same arrangement. People should understand when location is used, why it is used, who can see it, and when it stops.

AtlasNXT can apply authorised geographic views through Remits and support different location approaches where appropriate. The customer remains responsible for deciding the lawful basis, policy, retention, access, and worker-engagement arrangements that apply. The platform should support a defined duty-of-care purpose, not turn that purpose into open-ended monitoring.

 

What should senior leaders be able to see during the first hour?

Senior leaders do not need a wall of undifferentiated data. They need a defensible operational picture. It should identify the event and its current boundaries, the people and organisations believed to be in scope, the status of contact and welfare confirmation, the actions outstanding, the owner of each action, the decisions taken, and the evidence that changed the response.

ISO 22361 treats crisis management as a strategic capability involving leadership, difficult decision-making, crisis communication, training, validation, and learning.13 That is a useful reminder that a dashboard is not the capability. It is one part of the information environment in which leaders exercise judgement.

AtlasNXT’s Incident Room can keep significant updates, actions, communications, decisions, and status changes with one incident. This can give authorised participants a shared place to understand what is known and what remains unresolved. It does not replace command arrangements or make decisions automatically.

Decision records should be concise but meaningful. “Evacuate zone” is incomplete without scope, authority, time, and the reason the decision was taken. “All safe” is unreliable unless the accountable population and confirmation standard are clear. “External response requested” should identify who made contact, which service was contacted, what information was passed, and whether the request was acknowledged.

German occupational-safety law already treats documentation of risk assessment, selected protective measures, and review outcomes as a formal requirement.14 An incident record serves a different purpose, but the same discipline is valuable. It helps the current team reconstruct the situation, supports a controlled shift handover, and gives the later review a more reliable basis than memory and disconnected messages.

 

How should the model be tested before the site changes phase?

Testing should follow the lifecycle rather than wait for final commissioning. Redevelopment exercises can test changing access zones, construction exercises can test several employers and visitors, commissioning can test project-to-operations overlap, and operational exercises can test maintenance contractors and communications disruption.

The exercise should force uncertainty into the system. One source should be stale, one person should not respond, one vehicle assignment should have changed, and one action should pass across an organisational boundary. The test is whether operators recognise the limits of the information, assign ownership, preserve the decision trail, and close the loop.

ISO 22361 includes training, validation, and learning within crisis-management capability.13 Exercises should therefore test leadership and information behaviour, not just message delivery. Useful measures include the time taken to define the affected area, establish the accountable population, identify unresolved people, assign critical actions, and record the basis for a change in strategy.

Lessons should then enter the next phase’s operating model. If a redevelopment exercise exposes an unclear site boundary, it should change the construction arrangement. If commissioning exposes a communications gap, it should be addressed before routine maintenance relies on the same route. Readiness improves when learning crosses the handover rather than remaining in the project that discovered it.

 

What does mature incident accountability look like?

It does not look like permanent surveillance or a promise of perfect information. It looks like disciplined uncertainty. Leaders can see which facts are current, which are inferred, which people remain unresolved, and which actions still need an owner. Employers retain their responsibilities while sharing the operational information needed to cooperate. Communications have planned alternatives. Location is proportionate to purpose. Decisions remain understandable after the people who made them have left the room.

Germany’s energy transition will continue to create sites that move between old and new uses, between project and operation, and between one set of responsible organisations and another. Duty of care becomes stronger when accountability is designed to move with the site.

Book a free AtlasNXT demonstration to explore how Remits, Check-Ins, supported location options, and the Incident Room could be configured around your sites, contractors, communications arrangements, and incident procedures.

 

References

1. Bundesnetzagentur, Growth in renewable energy in 2025, 8 January 2026. https://www.bundesnetzagentur.de/SharedDocs/Pressemitteilungen/EN/2026/20260108_EEG.html

2. Federal Ministry for Economic Affairs and Energy, FAQ on the energy-transition monitoring report, updated 28 August 2026. https://www.bundeswirtschaftsministerium.de/Redaktion/DE/FAQ/Energiewende/faq-zum-monitoringbericht-zur-energiewende.html

3. Federal Ministry of Justice and Federal Office of Justice, Occupational Safety and Health Act, Section 8: Cooperation between several employers. https://www.gesetze-im-internet.de/arbschg/__8.html

4. Federal Ministry of Justice and Federal Office of Justice, Ordinance on Safety and Health Protection at Construction Sites. https://www.gesetze-im-internet.de/baustellv/BJNR128300998.html

5. German Environment Agency, Land recycling and inner development. https://www.umweltbundesamt.de/themen/boden-flaeche/flaechensparen-boeden-landschaften-erhalten/flaechenrecycling-innenentwicklung

6. German Environment Agency, Managing contaminated sites, updated 3 February 2026. https://www.umweltbundesamt.de/themen/boden-flaeche/altlasten/altlasten-bearbeiten

7. Federal Institute for Occupational Safety and Health, Construction Site Ordinance: planning and coordinating occupational safety. https://www.baua.de/DE/Themen/Arbeitsgestaltung/Arbeitsstaetten/Bauwirtschaft/Baustellenverordnung_node

8. Federal Ministry of Justice and Federal Office of Justice, Occupational Safety and Health Act, Section 10: First aid and other emergency measures. https://www.gesetze-im-internet.de/arbschg/__10.html

9. International Organization for Standardization, ISO 22320:2018 Security and resilience: emergency management: guidelines for incident management. https://www.iso.org/standard/67851.html

10. Federal Institute for Occupational Safety and Health, RAB 32: File for later work. https://www.baua.de/DE/Angebote/Regelwerk/RAB/pdf/RAB-32.pdf?__blob=publicationFile

11. Federal Office of Civil Protection and Disaster Assistance, Communication in crises and crisis management. https://www.bbk.bund.de/DE/Themen/Kritische-Infrastrukturen/Sektoren-Branchen/Informationstechnik-Telekommunikation/Krisenkommunikation/krisenkommunikation_node.html

12. European Commission, Principles of personal data processing under the GDPR. https://commission.europa.eu/law/law-topic/data-protection/information-business-and-organisations/principles-gdpr_en

13. International Organization for Standardization, ISO 22361:2022 Security and resilience: crisis management: guidelines. https://www.iso.org/standard/50267.html

14. Federal Ministry of Justice and Federal Office of Justice, Occupational Safety and Health Act, Section 6: Documentation. https://www.gesetze-im-internet.de/arbschg/__6.html