Search results for
Lawyers
Markus von Fuchs advises in intellectual property law, in particular in competition, patent, and trademark law as well as on the protection of know-how. He advises companies on protecting and commercially exploiting intellectual property, for example through licensing, sales, R&D, and cooperation agreements. He also focuses on the judicial and extrajudicial defense of intellectual property rights in interim injunction and principal proceedings. He further advises on border seizing procedures, initiates and advises on criminal measures relating to product and brand piracy, and on the infringement of business and business secrets. Markus von Fuchs also advises many companies on developing and introducing new technologies and business models. He has particular expertise in the optical and medical technology sectors.
Norbert Klingner specializes in national and international movie/TV and advertising film production, financing, insurance, and distribution. He represents well-known producers, distributors, global distributors, and movie financing entities. His expertise ranges from negotiating and drafting contracts from the beginning of the material development to all matters related to production and financing up to the strategically correct exploitation and licensing. A selection of the film productions in which Mr. Klingner was involved can be found on the Internet Movie Database IMDb.
Margret Knitter advises her clients in all matters of intellectual property and competition law. This includes not only strategic advice, but also legal disputes. Her practice focuses on the development and defense of trademark and design portfolios, border seizure proceedings and advice on developing marketing campaigns. She advises on labelling obligations, packaging design, marketing strategies and regulatory questions, in particular for cosmetics, detergents, toys, foodstuffs and Cannabis. She represents her clients vis-à-vis authorities, courts and the public prosecutor's office.
In the field of media and entertainment, she mainly advises on questions of advertising law, in particular product placement, branded entertainment and influencer marketing. She is a member of the board of the Branded Content Marketing Association (BCMA) for the DACH region and member of the INTA Non-Traditional Marks Committee.
Dr. Matthias Nordmann advises international groups, mid cap companies, investors and entrepreneurs on company, commercial and corporate law in particular on structuring and mergers & acquisitions. He has a special focus on transactions in IP/IT driven industries as well as real estate.
Dr. Andreas Peschel-Mehner has provided legal counsel to all forms of digital business since the inception of the world wide web. His advisory spans start-ups, multi-channel offerings and international internet companies and focuses on all applicable legal fields with a particular emphasis on data protection and usage, terms and conditions, consumer protection, compliance, advertising, gaming and competition law, among numerous others. Dr. Andreas Peschel-Mehner also commands broad expertise in media and entertainment law, in particular issues touching on the film and television industry and those related to media production finance and the global exploitation thereof, with digital media advisory on changes to utilization models, revenue streams and video on demand platforms composing a significant part of his counsel.
An excerpt of the projects Dr. Andreas Peschel-Mehner has accompanied can be found on the Internet Movie Database IMDb. His advisory expertise is augmented by decades of involvement with and counsel of national and international computer game publishers and studios. Finally, developments and use of KI technologies across all his expert areas has become a strategic element of his practice.
Legal expertise – digitally sophisticated
Stefan Schicker has been advising clients at the intersection of law, technology, and innovation for over 20 years. As an experienced and award-winning lawyer specializing in IT and IP law, he assists national and international companies in the legally compliant design of digital business models – from the design of complex internet platforms to the protection of intellectual property.
One of Stefan Schicker's special areas of expertise is the legal structuring of corporate influencer initiatives: with specially developed workshops, he supports companies in setting up corporate LinkedIn communication in a legally compliant and effective manner – in accordance with copyright, personality rights, competition law, etc. – More information.
Legal tech & law firm development – with leadership experience
In parallel to his legal practice, Stefan Schicker is one of the most prominent legal tech experts in the German-speaking world. As former COO and CEO of SKW Schwarz, he played a key role in shaping the digital transformation of the law firm – from strategy to operational implementation.
Today, he supports law firms and legal departments in establishing and expanding modern structures:
- Development and introduction of AI-supported tools
- Establishing internal teams of experts and training concepts
- Change processes for the sustainable anchoring of digital working methods
- Organization of law firms as companies
Stefan Schicker brings a unique combination of legal depth, technological experience, and operational law firm management to the table – recognized, among other things, as one of the “Top 3 Legal Leaders of the Year” (Best of Legal Awards).
For companies and law firms that don't want to wait for the future
Whether companies with digital business models or law firms undergoing change: Stefan Schicker combines legal certainty with entrepreneurial foresight – and makes complex transformations understandable, feasible, and effective – More information.
News
The E-Evidence Regulation Is Coming: What Service Providers Need to Know Now - Part 1
What Does the E-Evidence Regulation Cover – And Who Does It Apply To?
From 18 August 2026, Regulation (EU) 2023/1543 on European Production Orders and European Preservation Orders for electronic evidence in criminal proceedings – the e-Evidence Regulation, or EEVO for short – will become directly applicable in all Member States, including Germany, following a three-year transitional period. This date is no longer a distant prospect: in Germany, the implementing legislation, the Electronic Evidence Implementation and Enforcement Act (Elektronische-Beweismittel-Umsetzungs- und Durchführungsgesetz, EBewMG), was promulgated in March 2026; the Federal Office of Justice (Bundesamt für Justiz) has been designated as the central authority, while the Federal Network Agency (Bundesnetzagentur) is responsible for technical regulation.
Before turning to the EEVO itself, a look at the position under the law as it currently stands helps put matters into context. With the EEVO, the legislator responds to a state of affairs that has proven increasingly “very difficult” over the years. Cross-border access to electronic evidence has so far been governed by the classic mutual legal assistance procedure: a foreign authority had to submit a request to the competent German authority, which would then examine it and, where appropriate, issue its own order – only at that point was a service provider under any obligation to produce data. Depending on the case, this route could take weeks or months, while the request itself remained without consequence for the service provider in the meantime. A foreign request received directly by a service provider did not, on its own, give rise to any obligation to review or respond – it could, and generally had to, remain unanswered as long as no German order had been issued.
In this two-part publication, we now present the EEVO, which addresses precisely this point. The first part covers its basic structure – the new instruments EPOC and EPOC-PR, the range of service providers concerned, and the scope of application. The second part will then set out the applicable deadlines, the review obligations that apply, and the sanctions that may follow non-compliance.
In addition to these two articles, we have created a cheat-sheet that provides a quick overview of the key deadlines and review steps.
>> Read cheat-sheet <<
Two New Instruments: EPOC and EPOC-PR
At the heart of the EEVO are two new types of order that allow law enforcement authorities in one Member State to address service providers in another Member State directly in future – without the previously customary detour via mutual legal assistance proceedings. The European Production Order (EPOC) requires a service provider to produce specified electronic evidence, such as content, traffic, or subscriber data. The European Preservation Order (EPOC-PR) operates a step earlier: it merely requires the service provider to preserve data for a specified period so that it is not deleted before a production order, where applicable, follows.
For affected companies, this means one thing above all: both types of order take immediate effect. Unlike before, no separate involvement of a German authority is required – an order issued by another Member State becomes binding as soon as it reaches the designated point of contact within the company. What was previously described as a passive role thus becomes an active obligation to act. Whereas a service provider was previously permitted to leave a foreign request unanswered without consequence, it is now directly obligated in its own right from the moment an EPOC or EPOC-PR is received.
Who Is Subject to the EEVO?
The EEVO addresses service providers with a connection to the EU under Article 2(1) EEVO, irrespective of whether they are established in the EU at all. This marks an important difference from many other pieces of European legislation: a cloud provider without any European establishment can be just as affected as a German company. Under Article 3(3) EEVO, this covers in particular providers of electronic communications services (such as messaging or VoIP services), domain name registries and registrars, as well as other information society services – a category under which the Regulation expressly includes platform operators such as social networks and file-hosting services, as well as hosting providers and cloud services.
The addressee of an order is, as a general rule, the controller within the meaning of Article 4(7) GDPR, i.e. whoever determines the purposes and means of the processing. Only exceptionally may an EPOC be addressed directly to a processor: where the controller cannot be identified by the issuing authority despite reasonable efforts, or where the investigation would otherwise be jeopardized (Article 5(6) EEVO).
When Is There a “Connection to the EU”?
The Regulation first requires that the services be accessible to persons in a Member State – identifiable, for example, by language, currency, or targeted marketing. That alone, however, is not sufficient. In addition, there must be a substantial connection to one or more Member States, such as an establishment carrying out genuine economic activity, a significant number of users, or activity that is clearly directed at the relevant Member State. Mere technical accessibility of a website is expressly not sufficient for this purpose under Recital 29 EEVO – a service that happens to also be accessible from Germany does not thereby automatically fall within the scope of the Regulation.
Who Receives the Orders?
Once the question of whether a provider is covered has been resolved, the practical question remains of where an order is actually to be sent. Under Article 3(1) of Directive (EU) 2023/1544, every service provider must designate an establishment or a legal representative for the receipt of EPOCs and EPOC-PRs – by 18 August 2026 at the latest, or within six months of commencing service provision in the EU. Orders are, as a general rule, addressed exclusively to this designated point of contact (Article 7(1) EEVO). If it fails to respond in time in an emergency, or if no point of contact has yet been designated, the authority may exceptionally address another establishment of the company (Article 7(2) EEVO).
In practice, it is therefore advisable for the function internally responsible for EPOC/EPOC-PR matters – such as Legal or Compliance – to correspond to the externally designated point of contact and to be genuinely reachable. Otherwise, there is a risk that an emergency order with a particularly short deadline ends up with a group entity that is unprepared and consequently unable to respond in time.
This sets out the legal framework. What this looks like in practice – which specific deadlines apply, when an order may be refused, and what consequences follow non-compliance – is the subject of the second and final part of this series.
Would you like to assess whether, and to what extent, your company is subject to the EEVO, or do you need support in designating a point of contact for receiving orders? We would be glad to assist you with the legal assessment and with preparing for 18 August 2026.
Cyber Resilience Act: The Five Key Takeaways from the European Commission's Guidelines
The Cyber Resilience Act (CRA) introduces extensive new cybersecurity requirements for manufacturers of software, connected devices, and other products with digital elements. While most obligations will apply from 11 December 2027, manufacturers will already be required, from 11 September 2026, to report actively exploited vulnerabilities and severe security incidents.
As companies prepare for the CRA, numerous practical questions arise: When is a new software version considered a new product? What are the consequences of a substantial update? How long must security updates be provided? And do products that have already been developed need to be redesigned to comply with the CRA?
The European Commission has now published guidelines on the application of the CRA. Using practical examples, the Commission explains how it interprets key concepts and obligations under the Regulation. Although the guidelines are not legally binding, they provide important guidance for companies and, likely, for the competent authorities responsible for enforcing the CRA.
Below, we summarize the aspects of the guidelines that are particularly relevant in practice.
1. The 24-hour reporting deadline does not start with the first suspicion
From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents. The guidelines explain when these short reporting deadlines begin to run.
An unconfirmed indication alone does not trigger the reporting deadline. However, the manufacturer must assess it without undue delay. The reporting period begins once this initial assessment establishes with sufficient certainty that:
- a vulnerability contained in the product is being actively exploited; or
- a severe security incident has occurred and has affected the security of the product.
From that point onward, an initial early warning report must generally be submitted within 24 hours. A follow-up notification must be submitted within 72 hours.
For an actively exploited vulnerability, the complete report must generally be submitted within 14 days after a corrective or mitigating measure becomes available. For a severe security incident, the deadline is one month after the 72-hour notification.
Companies therefore need not only a technical reporting mechanism but also clear responsibilities for the initial assessment and escalation of potential incidents. The process should cover both external reports and findings from internal security testing. The guidelines emphasize that the initial assessment must be carried out without undue delay, particularly where the potential vulnerability poses a significant risk. These procedures should be tested in practice before 11 September 2026.
2. A software version is generally placed on the market only once
According to the European Commission, software that is offered as a standalone product is placed on the market when the completed version is first made available on the EU market. This applies regardless of when individual customers purchase or download the software.
The guidelines illustrate this with an example: If software version 1.0.0 is first made available for download on 1 January 2028, it is considered to have been placed on the market on that date-even if some customers download it only at a later stage. A later version, such as 1.0.1, is not considered to have been newly placed on the market unless the changes are substantial. Consequently, the original placement-on-the-market date remains decisive.
The situation may differ for different variants of the same software, for example, builds for different operating systems or packages with different functionalities. Such variants may qualify as separate products. A new software version is also considered to be placed on the market again if it has undergone a substantial modification.
This distinction is particularly important for the CRA's transitional provisions. Manufacturers should document when individual versions were first made available, which variants they treat as separate products, and what changes were introduced subsequently.
3. Products that have already been developed do not automatically need to be redesigned
Many products that will only be placed on the market after 11 December 2027 are already under development today or have even been fully developed. According to the guidelines, the CRA does not automatically require these products to be redesigned.
However, manufacturers must assess the cybersecurity risks of the product. Based on the technical documentation, they must be able to demonstrate that the product achieves an appropriate level of cybersecurity and complies with the CRA requirements. The required conformity assessment, the EU Declaration of Conformity, and CE marking also remain mandatory.
However, the Commission does not require manufacturers to retrospectively recreate all evidence and testing from earlier development phases. If it is no longer possible to demonstrate how cybersecurity risks were addressed during the original development process, the manufacturer may instead carry out a current risk assessment and explain how the existing product design and security measures mitigate the identified risks.
This clarification is particularly relevant for industrial products with long development cycles. Companies should review which evidence is already available for ongoing product developments and identify any documentation gaps that still need to be closed.
4. For software updates, the decisive factor is the cybersecurity risk-not the scope of the update
Not every major update constitutes a "substantial modification" within the meaning of the CRA. Conversely, even a small change may qualify as substantial. The decisive factor is whether the intended use of the product changes or whether new or increased cybersecurity risks arise that were not previously considered.
The Commission provides the example of a system that initially only displays operational data from machines. If the system is later updated to allow it to control those machines, its intended use changes. The update must therefore be regarded as a substantial modification.
The guidelines also set out a non-exhaustive list of assessment criteria. In particular, it should be examined whether the update:
- introduces additional interfaces, communication channels, execution environments, or external dependencies;
- enables new attack scenarios; or
- significantly changes the likelihood or potential impact of attack scenarios that have already been considered.
By contrast, a significant functional enhancement does not necessarily constitute a substantial modification if it was already planned during the original development and taken into account in the risk assessment. Updates that merely remediate vulnerabilities or strengthen existing security measures generally do not constitute a substantial modification, provided that they neither change the intended purpose of the product nor introduce new or increased cybersecurity risks.
Companies should therefore align their product roadmaps with their cybersecurity risk assessments at an early stage. A technical classification as a major or minor release is not sufficient for the legal assessment. It is advisable to establish a documented process for evaluating security-relevant updates against the CRA criteria.
5. Five years is not a standard support period
As a general rule, the CRA requires a support period of at least five years. If a product is expected to be used for a shorter period, the support period may also be shorter. Conversely, where a product has a longer expected service life, five years will not automatically be sufficient.
This is particularly relevant for industrial installations, control systems, and other long-life products. For such products, the support period must reflect the realistically expected service life. The guidelines expressly clarify that five years should not be regarded as a universal standard for all products.
A substantial modification also does not automatically trigger a new five-year support period. The decisive question is whether the modification also affects the product's expected service life. For example, if a software update merely introduces new functionalities without extending the lifetime of the hardware or changing users' expectations, the remaining original support period generally continues to apply.
For continuously evolving software, manufacturers may, under certain conditions, limit vulnerability remediation to the most recently placed-on-the-market version. Users must be able to upgrade to that version free of charge and without additional costs. Normal efforts such as testing or configuration changes are generally not regarded as additional costs. However, if users are required to purchase new hardware or fundamentally rebuild their system environment, the manufacturer cannot rely on this simplification.
Practical Tip
The guidelines do not create any additional legal obligations. However, they provide important clarification on key issues that companies must address when implementing the CRA.
Manufacturers should, in particular, review whether software versions and updates are documented in a traceable manner, whether the cybersecurity risk assessment is integrated with product planning, whether support periods have been determined realistically, and whether the reporting process will be operational by September 2026.
The guidelines also address, among other topics, free and open-source software, cloud-based functionalities, spare parts, and the interaction of the CRA with vehicle regulation, the Radio Equipment Directive, and the Machinery Regulation.
Discover Our CRA Compliance Suite
Our CRA Compliance Suite provides modular, fixed-fee consulting services to help manufacturers, importers, and distributors of digital products implement the requirements of the Cyber Resilience Act (CRA). Contact us for more information.
Protection of Trade Secrets in Employment Relationships: New Article Published in RüSiR
How can companies effectively protect their trade secrets in employment relationships?
This question is explored by our partners Dr. Rembert Niebel and Alexander Möller in their article "Trade Secret Protection in Employment Relationships", published in the latest issue of RüSiR – Journal for Defence, Homeland Security, Cyber & Space.
Trade secrets are among a company's most valuable assets. This is particularly true in the security and defence sector, where employees regularly have access to sensitive information and technical know-how. The article examines the legal framework governing trade secret protection in employment relationships and explains the safeguards already provided by the German Trade Secrets Act (Geschäftsgeheimnisgesetz – GeschGehG), as well as how these can be effectively complemented through employment contract provisions.
The authors also discuss recent case law of the German Federal Labour Court (Bundesarbeitsgericht – BAG) on confidentiality agreements. They explain why broad, generic confidentiality clauses are often insufficient and outline alternative contractual approaches available to employers. Particular attention is given to tiered confidentiality agreements for employees with access to particularly sensitive information, as well as additional legal instruments for protecting confidential business information.
While the article is primarily aimed at companies operating in the security and defence industry, it also provides valuable guidance for employers across all sectors seeking to align their trade secret protection strategies with the latest legal developments.
You can download the full article as a PDF here.
Protection of Military Inventions: New Expert Article Published in RüSiR
How can military inventions be effectively protected without disclosing security-sensitive information? Our partner Markus von Fuchs addresses this question in his expert article, “The Protection of Military Inventions through Secrecy During Development, Commercialization and Infringement Proceedings”, published in the latest issue of RüSiR – Journal for Defence, Homeland Security, Cyber & Space.
Against the backdrop of an evolving security landscape and the growing importance of dual-use technologies, the article examines the challenges of protecting military innovations. It explains why traditional patent strategies do not always provide adequate protection in the defence sector and explores the role of secret patents and trade secret protection. The article also discusses how technological developments – particularly in the fields of drone and cyber technologies – influence the choice of appropriate protection strategies.
Another key focus is the legal framework governing secret patents under German law. The article outlines the requirements for classifying an invention as a secret patent, the procedures before the German Patent and Trade Mark Office (DPMA), and the legal implications of secrecy orders. It also examines the impact on patent infringement proceedings, security clearance requirements, and the commercial exploitation and licensing of security-relevant technologies.
Finally, the article demonstrates that the choice between patent protection and confidentiality has become an increasingly strategic decision. Particularly for technologies with short innovation cycles or significant security relevance, a multi-layered protection strategy – combining technical intellectual property rights with a robust confidentiality framework consisting of technical, organisational and contractual measures – may provide the most effective means of safeguarding innovation over the long term.
You can download the full article as a PDF here.
CJEU Judgment on Geoblocking: The Limits of the Borderless Internet
While information on the internet is accessible worldwide at any time, its legal regulations and intellectual property rights are always subject to strict territorial limits. Anyone who publishes content online must therefore be aware of the risk of infringing third-party rights abroad. The Court of Justice of the European Union (CJEU) has now ruled that effective geoblocking can prevent such infringements in other countries (judgment of 9 July 2026, Case C-788/24 – Anne Frank Fonds).
The Anne Frank Case: Geoblocking as Protection Against Copyright Claims
The legal proceedings involved a dispute between the Anne Frank Fonds and the Anne Frank Stichting regarding the online publication of the diaries of the world-famous Jewish teenager. While the works are already in the public domain in Belgium, they remain partially protected by copyright in the Netherlands until 2037. The defendants published a scientific edition on a Belgian website but blocked access for users from the Netherlands using geoblocking. The Anne Frank Fonds nevertheless considered this an infringement of its copyrights, arguing that users could bypass the restriction via standard VPN services.
The CJEU ruled that an unauthorized "communication to the public" — and thus an infringement of the copyrights still existing in the Netherlands — does not occur, provided that the geographical restriction is effective. To achieve this, the block must primarily correspond to the latest state of the art. Absolute security is not required. A user-side circumvention by means of VPN services does not automatically render the restriction ineffective.
Relevance Beyond Copyright Law
At the same time, the CJEU emphasizes conversely that an active duty applies to anyone who knows or ought to know about existing intellectual property rights abroad. Anyone who, with knowledge of such rights, fails to implement effective geoblocking measures is deemed to be targeting their content at the entire global audience (para. 42 of the judgment). The CJEU left open when such knowledge (the duty to know) can be assumed. Previous business relationships or the existence of delimitation agreements could already be sufficient.
This duty by no means affects copyright law alone. Geoblocking is also playing an increasingly important role in trademark law. An infringement of a national trademark on the internet requires that the use of the trademark actually takes place within the domestic territory. In this context, courts examine whether the use of the sign produces a noticeable economic effect in the domestic market—the so-called "commercial effect".
Whether such a domestic nexus exists must generally be assessed based on the specific circumstances of each case. Relevant factors include, among others, the language of the website, the top-level domain, information provided on the website, or—if available—specific delivery options, as well as other circumstances such as economic activity in the country. Now confirmed by the CJEU, the absence of geoblocking measures is at least a strong, if not decisive, indication that the website in question is (also) directed at the domestic public. This is likely to be particularly relevant for global websites.
Liability of the Website Operator, Not the VPN Provider
According to the CJEU, it is solely the website operator who is liable for ineffective technical measures — not the VPN provider whose service is used to circumvent them. This applies even if the VPN provider is aware that its service can be used to access protected content without the rights holders’ consent.
Conclusion
The CJEU judgment provides much-needed clarity for online business practices. Geoblocking has become a central tool for legally secure market segmentation in intellectual property law. At the same time, the lack of geoblocking measures can indicate that accessing the content from abroad is intentionally desired. Conversely, anyone who deliberately restricts their online activities to specific countries and implements this technically soundly via geoblocking can effectively eliminate liability risks abroad.
CJEU: Consumers Cannot Waive Their 14-Day Right of Withdrawal When Signing Up for a Streaming Subscription
Is the supply of a streaming service to be classified as an offer of ‘digital content’ or of a ‘digital service’ within the meaning of Articles 2(11) and (16) of the Consumer Rights Directive 2011/83/EU (hereinafter the ‘CRD’)? With regard to this question, whether a waiver of the right of withdrawal is possible (digital content) or not (digital services), opinions differ sharply.
Austria's Supreme Court sought clarity and referred this question – which ultimately determines when consumers' right of withdrawal lapses and thus goes well beyond a mere semantic distinction – to the Court of Justice of the European Union (CJEU). On July 9, the CJEU ruled in favor of stronger consumer protection (Judgment of 9 July 2026, Case C-234/25).
Personalized Streaming Services Constitute ‘Digital Services’
Consumers who wish to access films, series, or live sports on Sky or other streaming platforms before the expiration of the 14-day withdrawal period are typically required to waive their right of withdrawal when concluding the contract. Article 16(1)(m) in conjunction with Article 2(11) CRD provides such an exception to the right of withdrawal laid down in Article 9(1) – but only for ‘digital content’.
Following the view of the European Commission and the Advocate General, which the CJEU has adopted, streaming subscriptions generally do not constitute ‘digital content’, but rather ‘digital services’, to which this exception does not apply. Instead, the consumer's right of withdrawal expires only once the streaming provider has fully performed the contractual service (Article 16(1)(a) in conjunction with Article 2(16) CRD).
Unlike the supply of ‘digital content’, the supply of a ‘digital service’ is ‘necessarily defined by the dynamic nature of the offering proposed by the trader concerned, which goes beyond the mere stable and, as the case may be, continuous provision of specific content.’ According to the CJEU, this is the case, in particular, where ‘the offering is designed to adapt to the consumer’s individual behaviour or expectations, or to influence the manner in which the consumer uses the services concerned, for example by recommending specific content to the consumer.’ Such recommendation systems are an integral part of virtually all modern streaming services, helping users navigate an overwhelming volume of available content.
No Risk of Abuse Due to Appropriate Compensation
Sky Österreich Fernsehen GmbH (hereinafter ‘Sky Austria’) was unsuccessful in arguing that such an interpretation would open the door to abuse. Sky Austria pointed out that subscription numbers typically spike when a popular series’ first or final season is released, or when decisive matches in football championships take place. If customers were able to cancel their subscription immediately after viewing such content, they could effectively receive this premium programming for free.
The CJEU held that the legislature had already addressed this concern in Article 14(3) CRD, which entitles the trader to compensation proportionate ‘to what has been provided until the time the consumer has informed the trader of the exercise of the right of withdrawal, in comparison with the full coverage of the contract.’ In this regard, the trader is not required to calculate this compensation purely on a time‑proportionate basis (pro rata temporis); it may instead take the market value of the service provided as a starting point in order to reflect the differences in economic value between the offered content (for example, the final stage of a sporting competition compared with a daily television series). In plain terms, this means the compensation a consumer owes could actually exceed the monthly subscription fee; either way, charging at least a pro-rata (time-proportional) fee remains permissible. Seen in this light, the CJEU ruling is likely to be a theoretical victory for consumers – in practice, not much is likely to change, and probably rightly so.
Applicability to German Law
Since the Austrian provision at the centre of this request, Section 18(1)(1) and (11) of the Distance and Off‑Premises Contracts Act (Fern‑ und Auswärtsgeschäfte‑Gesetz), essentially corresponds to Sections 356(5) and (6) of the German Civil Code (Bürgerliches Gesetzbuch), the decision can readily be transposed to German law. In addition, the CRD does not expressly refer to the law of the Member States for the interpretation of the term ‘digital content’, which is why that term must be interpreted autonomously and uniformly under EU law.
Outlook
With this decision, the CJEU is significantly shaking up the existing landscape of streaming subscriptions, particularly since, on the one hand, the architecture of streaming services in the form of recommendation systems is affected, and on the other hand, claims for compensation in the event of withdrawal following prior streaming consumption are likely to meet with little acceptance at first.
Indirectly, the decision is also likely to have repercussions for other streaming models – whether the streaming of music tracks and podcasts via Spotify, audiobooks via Audible, or the magazine subscription with the Süddeutsche Zeitung – wherever the provider's performance goes beyond the mere provision of a single digital item. The CJEU has thus cut a dogmatic swath that points far beyond the specific question referred. In economic terms, this swath will be less significant, since compensation fees will become established for the usage that occurred prior to withdrawal.
KI-Flash: EDPB Publishes Guidelines on Web Scraping in the Context of Generative AI
Web scraping is practically indispensable for training large AI models – and, from a data protection perspective, one of the biggest open questions: who is liable if personal data ends up in a training dataset through the automated harvesting of the open internet? On 7 July 2026, the European Data Protection Board (EDPB) addressed this question in Guidelines 03/2026, presenting a concrete assessment framework for the first time. Having already reported on the EDPB's Opinion 28/2024 on AI models in an earlier KI-Flash, we now turn to this second major development from the same plenary session. We reported separately on the Guidelines on the Anonymization of Personal Data adopted at the same time. The new web scraping guidelines are likewise open for public consultation until 30 October 2026.
Web Scraping for AI Training Purposes
More precisely, web scraping refers to the automated extraction of large volumes of data from publicly accessible internet sources – one of the central methods for sourcing training data for generative AI models. Until now, there was no specific, EU-wide guidance on how this practice can be reconciled with the requirements of the GDPR. The new guidelines close this gap and build on the Opinion 28/2024 mentioned above, as well as on Guidelines 1/2024 on Article 6(1)(f) GDPR. They are addressed to private entities that scrape data themselves, engage third parties to do so, or use already-scraped datasets for training or fine-tuning.
Controllership: Who Is Responsible for the Scraping Process?
A key question in practice concerns the allocation of roles under data protection law: the EDPB clarifies that the entity carrying out the scraping is not automatically a controller within the meaning of the GDPR. What matters instead is who determines the purposes and means of the processing. If an AI developer engages a service provider to carry out scraping under documented instructions, that provider will generally qualify as a processor, while the developer is treated as the controller. Where an already-scraped dataset is reused by a third party, the scraper and the reusing AI developer are, in principle, separately responsible for their own respective processing. Only where both parties jointly determine the purposes and means does joint controllership come into consideration.
Transparency: When Does the Individual Duty to Inform Not Apply?
With controllership clarified, this also raises the question of adequate transparency: the information obligations under Articles 13 and 14 GDPR pose practical difficulties for controllers engaged in web scraping, since data subjects are often not individually identifiable where data is collected indirectly. The EDPB acknowledges that individual information may be dispensed with where it proves impossible or would involve disproportionate effort (Article 14(5)(b) GDPR). This exception, however, does not apply across the board; it requires weighing the effort involved against the impact on the data subjects concerned, considering the volume and age of the data and the safeguards already in place. As a minimum measure, the EDPB requires controllers in such cases to make the information publicly available, for instance through a privacy notice specifying the categories of data, the sources and, where possible, the characteristics of the crawler used.
Data Minimisation: Measures Before, During and After Collection
The principle does not rule out training on large volumes of data as such, but it does require that personal data not needed for the purpose should not be collected in the first place. The EDPB proposes a multi-layered set of measures to this end. Before collection, controllers should, among other things, consider using synthetic data, define precise selection criteria, and exclude websites that structurally contain particularly sensitive data or that technically oppose scraping, for example through robots.txt, ai.txt or CAPTCHA. During and after collection, syntax-based filtering, pseudonymization and anonymization come into consideration as well. In addition, the EDPB requires controllers to ensure data quality by relying on reliable sources, timestamping the data and carrying out sample checks, to meet the principle of accuracy.
Legitimate Interest as the Key Legal Basis
The question of which legal basis could justify any of this in the first place usually leads, in practice, to Article 6(1)(f) GDPR: consent is practically impossible to obtain in the case of indirect, large-scale collection, which is why web scraping for generative AI is regularly based on legitimate interest instead. The EDPB applies the familiar three-step test: the existence of a legitimate interest, the necessity of the processing, and a balancing of interests. As examples of legitimate interests, it cites the development of chatbots or improvements to threat detection. In the balancing exercise, particular weight is given to data subjects' ability to control their own data, possible chilling effects arising from a sense of being under surveillance, and data subjects' reasonable expectations, for example whether a website technically excludes scraping or whether the data was made recognizably and publicly available.
Where the balancing test comes out against the data subjects, mitigating measures such as opt-out lists, shortened retention periods or enhanced transparency measures can restore the lawfulness of the processing.
Special Categories of Personal Data
Handling sensitive data also poses a particular challenge: special categories of personal data under Article 9 GDPR are, in principle, subject to a prohibition on processing that can only be lifted where one of the exceptions under Article 9(2) GDPR applies. Because it is difficult to reliably rule out in advance that sensitive data will also be captured when scraping large volumes of data, the EDPB transposes the CJEU's reasoning in GC and Others (C-136/17), concerning the responsibility of search engine operators, to the web scraping context: the prohibition under Article 9(1) GDPR then applies only within the framework of the controller's responsibilities, powers and capabilities, provided the controller takes appropriate measures to prevent and delete such data before, during and after AI development. This transposition is subject to narrow conditions: it applies only where the activity is structurally comparable to that of a search engine, and only to the incidental, unintended capture of sensitive data.
Practical Note
Even though the guidelines have not yet been finally adopted, they already provide clear guidance that national supervisory authorities are likely to apply when reviewing existing and future training data pipelines. Companies that scrape data themselves, commission scraping, or purchase already-scraped datasets should promptly review their own documentation on the balancing of interests, data minimization measures and the handling of special categories of data against the criteria set out in the guidelines. The ongoing consultation also offers an opportunity to feed practical experience and concerns directly into the final text.
We would be glad to assist you in reviewing your training data pipelines for compliance with the new EDPB guidelines, as well as in preparing or updating your data protection documentation for AI training processes.
Margret Knitter named once again among the “Top 250 Women in IP”
Managing IP has published the latest edition of its “Top 250 Women in IP” ranking, once again recognising our partner Margret Knitter among the world's leading women in intellectual property.
Published annually since 2013, the “Top 250 Women in IP” ranking highlights outstanding female IP practitioners from more than 30 jurisdictions who have distinguished themselves through exceptional work for clients and their firms. The selection is based on extensive research conducted by the IP STARS editorial team.
Margret Knitter’s continued inclusion in this list reflects her longstanding expertise in trademark, design and unfair competition law, as well as her strong reputation within the international intellectual property community.
This recognition complements SKW Schwarz's excellent performance in the IP STARS 2026 rankings, where the firm was once again recognised among the leading firms for trademark and copyright law, with several of its practitioners receiving individual distinctions.
Congratulations to Margret Knitter on this well-deserved international recognition.
Guidelines on the Anonymisation of Personal Data – European Data Protection Board (EDPB) Launches Public Consultation
On 7 July 2026, the EDPB published its long-awaited Guidelines on the anonymisation of personal data (“Guidelines”). These Guidelines are currently in draft form and are expected to be adopted following the public consultation process, which is open until 30 October 2026.
What is this about?
The key criterion for the application of the General Data Protection Regulation (“GDPR”) is the processing of personal data (“PD”). This concept is defined broadly in Article 4(1) GDPR. According to Recital 26, sentence 5 GDPR, the principles of data protection do not apply to anonymous information. Consequently, the GDPR does not apply to information that does not relate to an identified or identifiable natural person. Existing links between information and an identifiable individual can be removed through anonymisation.
Although this fundamental distinction in data protection law already existed before the GDPR came into force, determining when information has been anonymised to a legally sufficient standard remains both a technical and legal challenge in practice.
The former Article 29 Working Party had already addressed this issue in its respective Opinion from 2014. Over the past ten years, the Court of Justice of the European Union (CJEU) has also issued several judgments on the subject (see, for example, most recently the SRB decision).
Key Content of the Guidelines
The EDPB aims to provide greater clarity in distinguishing between anonymous information and personal data by establishing a practical assessment framework.
According to the EDPB, the three key criteria are No Record Isolation, No Linkage, and No Inference (see paragraphs 52 et seq. of the Guidelines).
The first criterion, No Record Isolation, requires that a dataset does not contain any attributes capable of identifying an individual. Considered on its own, the data must not constitute personal data.
The second criterion, No Linkage, builds on the first. It requires that the dataset cannot be linked to another dataset in a way that would enable the identification of a natural person.
The third criterion, No Inference, requires that no conclusions about a specific individual can be drawn from the available data. Such conclusions or inferences must also not be possible through the combination of the data with reasonably available additional information. In practical terms, it must not be possible to re-identify a natural person through analysis, linkage, or statistical inference.
These three criteria interact with one another and may be satisfied to varying degrees. What matters is that, when assessed as a whole, the information has been effectively anonymised (see paragraph 53 of the Guidelines).
What Happens Next?
The EDPB invites all interested stakeholders to participate in the public consultation until 30 October 2026. As discussions are currently ongoing at EU level regarding the GDPR-related provisions of the Digital Omnibus Act-which also focus (or have focused) on the concept of personal data-we expect a significant number of submissions.
In our view, the Guidelines represent an important step towards making the GDPR's requirements and the relevant case law on anonymisation more practical and easier to apply.
We will also publish an analysis once the final version of the Guidelines has been adopted.
SKW Schwarz Among the Top 10 Mid-Sized Employers for Career Starters
SKW Schwarz has been ranked among the Top 10 mid-sized employers for early career lawyers and has been nominated for the iurratio awards 2027.
The nomination recognizes the firm's commitment to providing outstanding training and attractive career opportunities for young legal professionals. In the category "Best Employers for Career Starters – Best Mid-Sized Law Firm," SKW Schwarz is one of the ten nominated firms.
The iurratio awards are presented annually based on a comprehensive employer survey and a nationwide talent survey of law students, trainee lawyers (Referendare), research assistants, and fully qualified lawyers. The evaluation covers a range of criteria, including training and professional development, working models and career prospects, health and well-being initiatives, work-life balance, diversity and social responsibility, as well as legal tech and digitalization.
This nomination reflects our commitment to providing aspiring lawyers with an outstanding environment to launch their careers—offering challenging mandates, personalized development, and a wide range of opportunities for professional growth. We are delighted to receive this recognition and would like to thank all of our colleagues whose dedication has made this achievement possible.
You can find the full list of nominated law firms here:
https://iurratio.de/die-besten-arbeitgeber-fuer-referendariat-berufseinstieg-2027
The winners of the iurratio awards 2027 will be announced in November 2026.
NIS2 – LAST CALL: New Registration Deadline!
NIS2 is a European directive under which significantly more companies than before will be required to implement IT security measures within their operations, including many organizations that likely never expected to be classified as important entities for Germany’s critical infrastructure. The requirements of the EU directive have already been incorporated into the German BSI Act and are directly applicable without any transitional periods.
Among the obligations of affected entities is the registration with the German Federal Office for Information Security (BSI). The deadline for this registration, which is subject to administrative fines, officially expired on March 6, 2026.
So far, however, the BSI has shown some leniency despite the low number of registrations received. According to statements by the authority, fines (of up to €500,000) were not expected to be imposed at this stage (as we reported here).
Is that changing now? It appears so!
The BSI has now sent a letter to business associations in which the authority has noticeably tightened its tone.
Affected entities are expected to complete their registration no later than July 31, 2026. According to the BSI, these registrations are overdue. Even in difficult cases involving uncertainty about whether an entity falls within the scope of the regulation, the authority is showing increasingly little tolerance for further delays. Such entities are requested to submit their consolidated questions to the BSI and, if they are found to be within scope, complete their registration within six weeks after receiving the authority’s response.
In other words: “Last Call” for anyone who has not yet devoted sufficient attention to this issue.
The scope of the new IT security requirements is broad and by no means limited to traditional “critical infrastructure” operators. We have previously reported here on examples of rather unexpected cases falling within the scope of the regulation.
Our NIS2 applicability assessment tool (here) provides a free and easy starting point for companies that now need to determine whether they are affected.
SKW Schwarz at the Bitkom Social Media Roundtable
On June 12, 2026, the Bitkom Social Media Stammtisch met in person for the first time. Also in attendance: the SKW Schwarz team.
This time, the event focused on corporate influencers as part of modern corporate communications. Social media is personal – people follow people. Corporate influencers provide insights, build trust, and make messages more tangible than traditional corporate communications.
But what does this look like in practice? What legal considerations must be taken into account? Johannes Schäufele and Fabian Bauer, representing our Branded Content and Influencer Marketing focus group, provided an overview of the legal framework governing the use of corporate influencers. The discussion focused in particular on:
- Legally compliant use of copyrighted content
- Disclosure requirements
- Use cases and practical recommendations
Bitkom’s Social Media Roundtable is a networking and discussion forum for social media managers, communications, and marketing experts. At regular meetings, participants discuss current developments, trends, and challenges in digital communication. The focus is on practical insights, best practices, and an open exchange of experiences regarding strategies, platforms, and formats. At the same time, the roundtable offers the opportunity to make new contacts, learn from one another, and gain valuable inspiration for one’s own work. Detailed information can be found on the organizer’s website.
Events
Focus topics
Expertise
Mixed
Further insights
Explore the latest legal developments, insights, publications and news from our firm.
- Legal insights
- Whitepaper
- Law firm update
- In the Media
08/06/2026
The E-Evidence Regulation Is Coming: What Service Providers Need to Know Now - Part 1
07/30/2026
Cyber Resilience Act: The Five Key Takeaways from the European Commission's Guidelines
07/28/2026
Protection of Trade Secrets in Employment Relationships: New Article Published in RüSiR
07/27/2026
European Commission Publishes Guidance on the Cyber Resilience Act
















































