Search results for

Lawyers

44

Dr. Dorothee Altenburg represents clients in all aspects of intellectual property law. She is particularly experienced in the area of trademark law. Operating in Germany as well as internationally, Dr. Altenburg devises legal strategies to establish and defend trademarks, design rights, and patents. She represents clients before the relevant authorities in Germany, in the European Union, and in WIPO proceedings. She conducts trademark registrations worldwide. She has substantial experience in drafting licensing agreements. She is acquainted with the litigation issues that arise in the environs of intellectual property and (unfair) competition law. She represents clients before customs authorities counterfeiting cases. She also coordinates EU-wide customs seizure proceedings against counterfeit products.

Dr. Altenburg further represents publishers, media companies, and artists in matters to do with copyright, publishing law, and personality rights. 

Nikolaus Bertermann has been a lawyer for a Europe-wide leading internet service provider for ten years and can therefore rely on in-depth technical expertise, a sound knowledge of the IT industry, and many years of experience as a company lawyer.

He provides comprehensive advice on all forms of classic and agile software creation and IT project contracts, the use and adaptation of open source software, and cloud computing within and outside the EU.

Mr. Bertermann conducts data protection audits, advises companies on the legally compliant design of data processing procedures within and outside corporate structures, and accompanies clients in projects to implement the requirements of the EU General Data Protection Regulation. He commented on the central provisions of the GDPR for publishing house C.H.Beck.

Eva Bonacker advises German and international clients on diverse matters of competition, M&A, corporate and general commercial law, with a special focus on European and German antitrust and competition law.

Eva Bonacker has advised clients from various industries including media, IT and software, e-commerce, publishing, information and business intelligence, energy, climate technology, and consumer goods.

Dr. Mathias Pajunk advises on all issues of public commercial law. The main focus of his work lies on advising public authorities on the award of public contracts and service concessions. This includes the monitoring of awards at all stages, including the drafting of contracts. At the same time, Dr. Mathias Pajunk represents both public authorities and bidders in the context of review proceedings. His other fields of activity include dealing with complex issues in the areas of state aid and antitrust law.

Dr. Brock specializes in IP law (trademarks, patents, designs, copyright law, etc.), unfair competition law (including advertising law), IT law, data protection law as well as distribution and contract law.

He advises comprehensively on IP matters, including the filing of national and international intellectual property rights as well as licensing and enforcement in disputes in and out of court. He further advises on innovation and know-how protection (including trade secrets), on cross-border research and development projects, on employees’ inventions law, and on standard essential patents (SEP). Furthermore, his advice includes the development of brand-based labeling and quality seal systems.

While his client base covers a wide selection of industries (for instance health care & life sciences, information technology and consumer goods), he focuses on technology-driven and innovative companies, ranging from start-ups to mid-sized companies to globally operating corporations.

Dr. Oliver M. Bühr has been advising on IT matters for many years. This includes software, hardware, projects, and outsourcing. He frequently supports his clients in all matters relating to data protection, especially in the implementation of the GDPR. He also has extensive experience in e-business and advises companies on designing their offerings on the internet. Innovative topics such as cloud computing or the advising of FinTechs are also a key part of his work. Many of the projects on which he advises have an international dimension, and he works closely with lawyers from foreign legal systems.

As a notary, he works particularly in the areas of property law, corporate law, and inheritance law.

Markus von Fuchs advises in intellectual property law, in particular in competition, patent, and trademark law as well as on the protection of know-how. He advises companies on protecting and commercially exploiting intellectual property, for example through licensing, sales, R&D, and cooperation agreements. He also focuses on the judicial and extrajudicial defense of intellectual property rights in interim injunction and principal proceedings. He further advises on border seizing procedures, initiates and advises on criminal measures relating to product and brand piracy, and on the infringement of business and business secrets. Markus von Fuchs also advises many companies on developing and introducing new technologies and business models. He has particular expertise in the optical and medical technology sectors.

Christoph Haesner’s work comprises the entire range of media law, copyright law, and entertainment law. He advises clients in the fields of film and TV, and in sales and licensing on legal issues at all stages of development, production, distribution, and evaluation of audiovisual productions, both nationally and internationally.

His work focuses on all matters pertaining to movie financing, not only for purely national projects, but also for those with major international connections.

He also advises on transactions (M&A) in the media sector. Christoph Haesner regularly supports companies throughout the transaction phase and advises on all matters arising from M&A transactions, under corporate law, contract law, copyright law, and media law.

Dr. Johann Heyde provides comprehensive legal advisory throughout media and entertainment law, in which film and television compose a main focus of his practice. Mr. Heyde advises on all aspects of national and international film and TV productions from film financing and subsidization, right clearance particularly in terms of copyright and privacy law, as well as licensing and exploitation of such productions.

Moreover, Dr. Johann Heyde’s advisory work spans all levels of digital commerce and business with a particular emphasis on improving internet portals, online services and other digital media (including on- demand platforms) and counseling on all relevant legal issues in e-commerce, some of which include terms and conditions, consumer protection, advertising and competition law, licensing and the dissemination of all forms of content over the internet.

Dr. Johann Heyde’s expertise includes his command of music law and especially collecting societies law in particular with respect to digital media.

Dr. Magnus Hirsch advises both German and international clients on a wide variety of matters which fall within the area of trademarks, designs, copyrights, patents, and unfair competition – in both preventative and contentious situations.

He also has more than 25 years of intellectual property litigation experience, having worked on numerous litigation matters regarding all kinds of IP issues and has appeared in many Federal District Courts, as well as Courts of Appeal, throughout Germany, and has represented several clients in proceedings up to the Federal Court of Justice.

In particular, his specialization comprises portfolio management as well as enforcing clients’ rights against counterfeiters, parallel importers and domain name pirates, both through court proceedings, as well as international dispute systems. Mr. Hirsch also represents clients before the German Patent and Trademark Office and the European Union Intellectual Property Office (EUIPO) registering or opposing German national trademarks and Community Trade Marks, respectively. He also has significant experience in drafting IP-related agreements, such as trademark license agreements, priority agreements and agreements with publicity agencies.

A further focus lies in the field of trademark and competition infringements on the Internet, in particular in the conduct of litigation in and out of court, also in connection with Internet domains, as well as the litigation of patent infringements.

Dr. Magnus Hirsch spent several months practicing at the Hong Kong office of an international law firm where he focused on Asian IP law, especially the enforcement of intellectual property rights in and out of court and the prosecution of product piracy and trademark counterfeiting in Southeast Asia.

Dr. Oliver Hornung advises national and international IT service providers and users in the legal structuring and negotiation of IT, project, and outsourcing contracts, as well as in matters of copyright and licensing. He is also regularly involved in distressed projects (dispute management) and advises clients in conciliation and arbitration proceedings and, where necessary, in litigation.

The regulatory environment for the use of data and corresponding technologies is complex and new legal acts are constantly being added by the European Commission. In this dynamic environment, Dr. Oliver Hornung advises his clients on all legal issues, in particular with a focus on AI compliance, Data Act, NIS-2, cyber security, cloud computing and data law.

Another focus of his legal advice is data protection with a focus on digital health and the EU's Digital Decade. If necessary, Dr. Oliver Hornung and his team defend the rights of his clients before supervisory authorities or in court.

Finally, Dr. Oliver Hornung advises start-ups on all questions relating to IT law and data protection law. In addition to his extensive practical work, Dr. Oliver Hornung is also a frequently requested lecturer in IT law and data protection law.

Klaus Jankowski advises on complex investment projects and company settlements, with a focus on public building and planning law.

For several years, he has also been advising the public sector on legislative projects and sensitive infrastructure projects.

He plays a leading role in the international network of lawyers First Law International and has excellent contacts to law firms worldwide.

Dr. Bernd Joch advises on corporate restructuring in employment law and corporate law, conducts balancing of interests and social plan negotiations, and represents his clients in arbitration proceedings.

He has many years of experience in advising companies, executive board members, general managers, and employees, in particular also in the field of dismissal protection matters.

In the area of commercial law, he advises and represents companies, in particular, in the areas pertaining to agencies and representatives.

René M. Kieselmann specializes in EU public procurement law and associated legal fields. Among others he is a member of SKW Schwarz’s IT & Digital Business and Life Sciences & Health Practice Group and has wide-ranging technical expertise in various areas. In addition to IT law, he advises on state aid law, subsidy law/grant law, and on rescue services and civil protection, i.e. the prevention of health hazards. Jointly with his team he is designing complex public procurement projects. René Kieselmann ensures adequate communication between bidders and clients, constructively conducting negotiations. SKW Schwarz advises on major bidding projects, including in the housing, in healthcare/pharmaceuticals and IT/banking sectors. He is also familiar with the structures of rescue services, civil protection, and disaster control as well as the regulatory context (SGB). Here he constructively designs award procedures on a long-term basis (“planning model”). In this connection, he also deals with issues of medical law ranging from emergency physicians to paramedics. While he is not litigating in court or before the Public Procurement Tribunal frequently, he has nevertheless gained considerable forensic experience since 2009, including at the Court of Justice of the European Union.

Norbert Klingner specializes in national and international movie/TV and advertising film production, financing, insurance, and distribution. He represents well-known producers, distributors, global distributors, and movie financing entities. His expertise ranges from negotiating and drafting contracts from the beginning of the material development to all matters related to production and financing up to the strategically correct exploitation and licensing. A selection of the film productions in which Mr. Klingner was involved can be found on the Internet Movie Database IMDb.

Margret Knitter advises her clients in all matters of intellectual property and competition law. This includes not only strategic advice, but also legal disputes. Her practice focuses on the development and defense of trademark and design portfolios, border seizure proceedings and advice on developing marketing campaigns. She advises on labelling obligations, packaging design, marketing strategies and regulatory questions, in particular for cosmetics, detergents, toys, foodstuffs and Cannabis. She represents her clients vis-à-vis authorities, courts and the public prosecutor's office.

In the field of media and entertainment, she mainly advises on questions of advertising law, in particular product placement, branded entertainment and influencer marketing. She is a member of the board of the Branded Content Marketing Association (BCMA) for the DACH region and member of the INTA Non-Traditional Marks Committee.

Dr. Olaf Kreißl is a notary and lawyer specialising in real estate, corporate and inheritance law. He provides support in real estate transactions, property development projects, land and residential property purchase agreements, corporate transactions (M&A) and all corporate law matters (corporate housekeeping, capital increases, conversion and restructuring measures, etc.). In the area of asset management and succession planning or anticipated succession, he drafts and certifies gifts, wills, marriage contracts, divorce agreements, and powers of attorney for precautionary and special purposes.

He also has many years of legal expertise in the field of real estate management and private construction and architectural law.  The focus here is also on advising on legal issues in connection with the management of real estate (commercial leasing, asset management, etc.), the realisation of construction projects and the drafting and negotiation of the corresponding real estate-specific contracts. 

Stefan Kridlo regularly advises national and international companies on all material issues of business law, commercial law, and corporate law, in particular also on corporate acquisitions.

The main focus of his many years of work is the support of real estate investors pertaining to real estate transactions and real estate portfolios, their structuring and administration. Stefan Kridlo worked as a notary until April 2025 in the areas of corporate law, real estate law and inheritance law. He also works as an executor.

Sabine Kröger is a Certified Expert for Commercial and Corporate Law as well as for Banking and Capital Markets Law and advises and represents national and international companies, executives and shareholders comprehensively in the field of corporate law and banking law.

As an experienced litigator, she also comprehensively represents her clients in court (corporate litigation / banking litigation).

Ms. Kröger's activities focus in particular on:

  • advising and representing mid-sized enterprises (SMEs) or their managing directors or shareholders in shareholder disputes and internal company disputes;
  • the assumption of committee representation for shareholders;
  • advising and representing financial investors and credit institutions in the field of credit law and collateral security law and in defending claims of clients/investors, including the representation in mass claim proceedings.

Eberhard Kromer’s traditional focus in media law is entertainment and music. He counsels artists, publishers, labels, internet service providers, managements, as well as tour promoters. He has been active and well-versed in digital commerce issues since the inception of the internet. Eberhard’s practice is constantly affected by rapidly changing e-commerce models, social media platforms and ongoing digitization (Web 4.0, Internet of Things).

Dr. Kromer’s many years of experience as General Counsel and VP Business Affairs for a global media corporation give him the insight to recognize a corporation’s operational strengths and weaknesses. This enables him to find the best solution together with and for the client.

Franziska Ladiges advises clients on all questions of IT and data protection law. Thanks to secondments and many years of experience, she has in-depth knowledge of data protection. In this area, she supports companies (from small businesses to listed companies) from various industries with the implementation of data protection compliance. In addition, she advises on various individual data protection issues, including order processing, data subject rights and international data transfer. Finally, she regularly carries out data protection quick checks for companies on site.

In addition, Franziska Ladiges has experience in drafting contracts regulating the creation, use or transfer of software. She also drafts and reviews general terms and conditions (both purchasing and sales and internet platforms) and advises on the development of online shops and internet platforms. She often represents her clients before state courts in contract disputes or data protection matters.

In the area of private clients, Christoph Meyer has special expertise in establishing and managing family foundations, the creation of succession rules for medium-sized companies and high-net-worth individuals, as well as in all matters pertaining to family law, with a focus on more complex asset situations. The drafting of wills, powers of attorney, and marriage contracts also play an important role, with a considerable proportion of cases having international relevance. Should amicable solutions not be achievable, Mr. Meyer advises the clients, with careful strategic and tactical planning, but also with the required readiness to resolve disputes, through possible legal proceedings before civil and financial courts.

Dr. Ulrich Muth advises companies, in particular banks and financial service providers.

In particular, he specializes in consulting for creditors of loan claims secured by real estate, in the monitoring of credit and reorganization negotiations, in the prevention of damage claims on account of alleged breaches of the duty of disclosure and consultation as well as in the enforcement of creditor interests in the event of the insolvency of the debtor. Based on many years of experience of proceedings in the fields of banking, commercial and company law, as well as in disputes involving competition law, Dr. Muth works together with the clients to develop economic solutions for avoiding legal disputes as well as efficient trial strategies.

Dr. Matthias Nordmann advises international groups, mid cap companies, investors and entrepreneurs on company, commercial and corporate law in particular on structuring and mergers & acquisitions. He has a special focus on transactions in IP/IT driven industries as well as real estate.

Dr. Orthwein was admitted to the bar in 2003 and became a partner at SKW Schwarz in 2011. He received his Master of Laws (LL.M.) in American Law from Boston University (USA) in 2000 and his doctorate from the University Muenster in 2003 with a topic in telecommunications law.

He advises his clients in all areas of IT law, in particular cloud and software contract law using new agile software developing and contract methods, the commercial use of data and artificial intelligence (AI) as well as digital transformation projects. Together with his clients, he develops and brings to life new digital platforms and business models. He is an experienced expert in national and international data protection law issues in particular with regard to the use of cloud services.

The Lexology Index Germany 2025 lists him as a “world's leading practitioner” in the data category. In 2025, Handelsblatt / Best Lawyers again recommends him as a lawyer in the categories “IT law” and “data protection law.” He is once again listed in the JUVE Handbook 2025 as a “frequently recommended lawyer” for IT and data protection law.


Dr. Orthwein is a lecturer for IT and data protection law in applied AI at the Technical University of Rosenheim.

Dr. Orthwein is member of the German Society for Law and Informatics, the International Association of Privacy Professionals, the German Outsourcing Association and the German-American Lawyers Association. He is Senior Vice Chairman of the Technology Law Committee of the International Bar Association.

Dr. Andreas Peschel-Mehner has provided legal counsel to all forms of digital business since the inception of the world wide web. His advisory spans start-ups, multi-channel offerings and international internet companies and focuses on all applicable legal fields with a particular emphasis on data protection and usage, terms and conditions, consumer protection, compliance, advertising, gaming and competition law, among numerous others. Dr. Andreas Peschel-Mehner also commands broad expertise in media and entertainment law, in particular issues touching on the film and television industry and those related to media production finance and the global exploitation thereof, with digital media advisory on changes to utilization models, revenue streams and video on demand platforms composing a significant part of his counsel. 

An excerpt of the projects Dr. Andreas Peschel-Mehner has accompanied can be found on the Internet Movie Database IMDb. His advisory expertise is augmented by decades of involvement with and counsel of national and international computer game publishers and studios. Finally, developments and use of KI technologies across all his expert areas has become a strategic element of his practice.

Ulrich Reber is a certified expert in international business law. Mr. Reber advises and represents German and foreign companies in civil and commercial matters with an emphasis on corporate litigation, for example in commercial and corporate disputes before civil courts and arbitration tribunals. He commands particular expertise in cross-border debt enforcement cases in and out of court. His clients include leading European and non-European companies requiring legal assistance in Germany, to whom he provides corporate legal advice with a special focus on insolvency law. Numerous clients come from the media, entertainment and IT sectors.

Legal expertise – digitally sophisticated

Stefan Schicker has been advising clients at the intersection of law, technology, and innovation for over 20 years. As an experienced and award-winning lawyer specializing in IT and IP law, he assists national and international companies in the legally compliant design of digital business models – from the design of complex internet platforms to the protection of intellectual property.

One of Stefan Schicker's special areas of expertise is the legal structuring of corporate influencer initiatives: with specially developed workshops, he supports companies in setting up corporate LinkedIn communication in a legally compliant and effective manner – in accordance with copyright, personality rights, competition law, etc. – More information.
 

Legal tech & law firm development – with leadership experience

In parallel to his legal practice, Stefan Schicker is one of the most prominent legal tech experts in the German-speaking world. As former COO and CEO of SKW Schwarz, he played a key role in shaping the digital transformation of the law firm – from strategy to operational implementation.

Today, he supports law firms and legal departments in establishing and expanding modern structures:

  • Development and introduction of AI-supported tools
  • Establishing internal teams of experts and training concepts
  • Change processes for the sustainable anchoring of digital working methods
  • Organization of law firms as companies

Stefan Schicker brings a unique combination of legal depth, technological experience, and operational law firm management to the table – recognized, among other things, as one of the “Top 3 Legal Leaders of the Year” (Best of Legal Awards).
 


For companies and law firms that don't want to wait for the future

Whether companies with digital business models or law firms undergoing change: Stefan Schicker combines legal certainty with entrepreneurial foresight – and makes complex transformations understandable, feasible, and effective – More information.

Dr. Tatjana Schroeder has extensive experience in stock corporation law and also accompanies the development of this very specific legal field through regular publications. Stock corporation law also always depends on trends in the capital market and is subject to continuous change.

Mathias Schwarz advises on movie and TV productions, copyright and personality rights, licensing, and media financing. His clients are financial institutions, private investors, movie and TV producers, as well as broadcasting and publishing companies. He also represents a number of renowned individuals in the German media industry. In addition, he has been advising a number of family offices and private clients for a long time.

Marketing Manager
HR assistance
Head of Finance
Head of IT
Head of Marketing & Communication
Head of Business Development
Head of HR
HR Manager
Management Accounting
Legal Tech & Innovation Manager
Business Development and Marketing Manager

News

30

KI-Flash: ChatGPT as a very large online search engine under the Digital Services Act

On 31 August 2026, the European Commission designated ChatGPT as a very large online search engine (VLOSE) under the Digital Services Act (DSA). It is the first designation of a generative AI service. Reddit and Roblox were classified as very large online platforms (VLOP) on the same day. All three services had reported to the Commission that they meet the threshold of 45 million average monthly users in the Union under Article 33(1) DSA. For ChatGPT, OpenAI reported around 159.1 million users of its search functions for the six-month period ending 31 March 2026.

The designation coincided closely with the launch of advertising: ads had gone live in Germany a week earlier, and self-service access through the Ads Manager opened on the same day.

This article is the second part of a three-part series on current developments around AI assistants. The first part set out the advertising and data protection standards applying to the advertising model (available here). This part looks at the obligations that follow from the designation, at the gaps the DSA may leave for advertising in AI assistants, and at the supervisory bodies that have a say alongside the Commission. Like the first part, it is addressed to companies that advertise in this environment or deploy AI assistants in their own operations. The third part deals with the responsibility and liability of advertisers and agencies.

 

ChatGPT as a search engine

The Commission bases the classification as a search engine on the fact that the service accesses internet content directly when answering queries. OpenAI has not contested the designation and has stated that the search function of ChatGPT operates as a search service within the meaning of the DSA. The DSA was designed for classic platforms and search engines and contains no separate category for generative systems of this kind. The Commission has therefore applied an existing framework to a new type of service.

The designation starts a four-month period (Article 33(6) DSA) which, according to the Commission, expires around the turn of the year 2026/2027. Section 5 of Chapter III DSA then applies. It covers the assessment of systemic risks under Article 34 and their mitigation under Article 35, expressly including advertising systems, as well as independent audits under Article 37, the advertisement repository under Article 39, data access for researchers under Article 40, extended transparency reporting under Article 42 and the annual supervisory fee under Article 43. Articles 37, 39 and 40 DSA, which the first part identified as starting points for verifying the provider’s promise that advertising does not influence its answers, therefore only apply from that date. For Section 5, supervisory and enforcement competence lies exclusively with the Commission.

 

An asymmetry in the DSA advertising rules

By its wording, Article 39(1) DSA addresses „providers of very large online platforms or of very large online search engines“. The substantive advertising requirements in Section 3, by contrast, consistently address only „providers of online platforms“: Article 25 on the design of the online interface, Article 26 on the labelling of advertising and on profiling using special categories of data, Article 27 on the transparency of recommender systems and Article 28 on the protection of minors, including the prohibition of profiling-based advertising directed at minors. On the wording, OpenAI as a VLOSE is therefore subject to the repository obligation, but not to the requirements on labelling, transparency of recommender systems, manipulative design and targeting of minors.

This literal reading is not undisputed. It is argued in the literature that Article 26 DSA applies at least to advertising-funded online search engines, and that the transparency requirements for recommender systems extend functionally to very large online search engines via Article 38 DSA. The asymmetry produces the inconsistencies described above and is accordingly the subject of ongoing debate. Advertisers and providers would be well advised not to rely on the gap in the wording holding in the long run.

It should also be noted that the Commission has designated ChatGPT as a VLOSE, but has not thereby decided that the service is not also an online platform within the meaning of Article 3(i) DSA. If it also meets the platform criteria, the provisions of Section 3 could apply in addition.

There are several starting points for that argument. Article 3(i) DSA requires a hosting service that stores information at the request of a recipient and disseminates it to the public. That applies first of all to the advertisements themselves, which the provider stores and displays on behalf of its advertising customers. It may also apply to features that allow users to make their own content publicly accessible, such as sharing individual conversations through retrievable links or offering self-configured assistants in a public directory. Whether such features qualify as a minor and purely ancillary feature within the meaning of Article 3(i) DSA determines whether the platform classification holds.

 

German media law is already engaged

Alongside the DSA, German authorities have been applying German media law since July 2026. On 14 July 2026, in two proceedings conducted by the state media authorities of Hamburg/Schleswig-Holstein and Berlin-Brandenburg, the Commission on Licensing and Supervision (ZAK) issued its first decisions against AI services, concerning Google’s AI Overviews and Perplexity. It found that AI answers are the providers’ own content and that the liability exemption under the DSA does not apply to them. The levers used are the diversity rules for media intermediaries under sections 91 to 94 of the Interstate Media Treaty (MStV), in particular the transparency requirement and the non-discrimination rule, which in principle presuppose the transmission of third-party information. Google has announced an appeal; the decisions are not yet final.

The proceedings concerned Google and Perplexity. Whether the reasoning can be transferred to ChatGPT is likely to depend on how source selection and linking are designed in detail. On the distinction set out in the first part, classification as a media intermediary requires that the service aggregates third-party content, selects it and determines how easily it can be found, without combining it into an overall offering of its own, which is difficult to assume for content that providers generate themselves and are liable for. It is disputed in the literature whether presenting generated answers is sufficient or whether visibly displayed third-party content with an identifiable source reference is required. An expert opinion commissioned by the state media authorities concludes that large language models are to be classified as media intermediaries to the extent that they reproduce source links within their own generated answers. That is said to apply only where the sources are not given as mere evidence, but as „further sources“, with the result that third-party content is transmitted. How that distinction is to look in practice is left open.

 

Two supervisory regimes side by side

If ChatGPT were both a media intermediary under sections 91 et seq. MStV and a VLOSE under the DSA, two supervisory structures would meet: the state media authorities on one side, and on the other the Commission, which is solely competent for Section 5, together with Coimisiún na Meán as Digital Services Coordinator for the remaining obligations given the Irish establishment. Between them stands the country-of-origin principle under section 3 of the Digital Services Act implementation statute (DDG) and Article 3 of Directive 2000/31/EC. Whether section 93 MStV is enforceable against providers established in another Member State has been left open by the Administrative Court of Berlin and the Higher Administrative Court of Schleswig, which referred the question to the Court of Justice of the European Union. In Germany, the Federal Network Agency also acts as Digital Services Coordinator; the lead data protection authority is the Irish Data Protection Commission.

There is also the allocation of competence under the German AI market surveillance act (KI-MIG), which the first part described for Article 50 AI Act: the Federal Network Agency is the central market surveillance authority, while for media services serving journalistic or advertising purposes the authorities competent under state law remain responsible under section 2(8) KI-MIG. The question of competence therefore needs clarification both between the Union and state level and within German supervision. We have set out the draft Interstate Treaty on Digital Media and the allocation of competence it provides for in a separate article (available here).

 

What the enforcement pattern shows so far

The Commission has concluded three DSA cases with a fine to date. On 5 December 2025, X was fined 120 million euros for the misleading design of its verification mark, an incomplete advertisement repository and insufficient data access for researchers, all of them verifiable transparency obligations. On 28 May 2026, a fine of 200 million euros against Temu followed, and on 20 July 2026 a fine of 550 million euros against AliExpress. In both cases the focus was not on transparency obligations but on the assessment and mitigation of systemic risks in connection with illegal, unsafe or counterfeit products. In the Temu case, according to the Commission, the risk assessment relied on general information about risks in the e-commerce sector instead of evidence relating to the service itself.

For ChatGPT, the second line may be the more informative one, because the risk assessment is among the first obligations to apply once the period expires. In the Temu case in particular, the Commission did not merely check whether an assessment had been submitted, but whether it holds up in substance. Fines may reach up to six per cent of worldwide annual turnover; the amounts imposed so far have remained well below that.

 

Consequences for the advertising system

The advertising system went live a week before the designation and must feed into the first systemic risk assessment before the period expires. Article 34(1)(b) and (d) DSA covers negative effects on fundamental rights, including consumer protection and the rights of the child, as well as on the protection of minors and on physical and mental well-being. Under Article 34(2) DSA, the systems for selecting and displaying advertising are among the factors to be taken into account in the risk assessment. The selection of ads by the topic of the ongoing conversation, described in the first part, should therefore be subject to that assessment, regardless of whether Article 26 DSA applies on its wording.

 

What comes next

Two developments are on the horizon. At Union level, the Commission is expected to propose a Digital Fairness Act in the fourth quarter of 2026, focusing on manipulative interface design, unfair personalisation and the protection of minors. At state level, the Broadcasting Commission discussed the draft of an Interstate Treaty on Digital Media (part 2) on 16 September 2026. Under that draft, providers of AI information systems are to be responsible for the content these systems generate. One option under consideration is to treat AI services as media intermediaries, another to create a new category of telemedia. The public consultation is still planned for 2026.

The expiry of the period around the turn of the year will show how the Commission assesses the risk assessment of a conversational service. Until then, the question that matters most for companies that deploy such services or advertise in them is which supervisory regime governs their own role. The third part of the series addresses that role.

If you have questions about the regulatory classification of your campaigns or of your use of AI assistants, or about what the DSA designation means for your advertising environment, we are happy to help.

10/06/2026, Dr. Anna Kellner, Helena Kasper, Moritz Mehner

AI Flash: What AI start-ups could still clarify before their next review in light of Suno, LAION and the AI Act

Since this summer, several legal questions have become more tangible for AI start-ups. On 31 July 2026, the Munich Regional Court (Landgericht München I) held that the music generator Suno infringes copyright in works from GEMA’s repertoire (case no. 42 O 763/25, not yet final). On 3 September 2026, the German Federal Court of Justice (Bundesgerichtshof) heard the case concerning the creation of the LAION training dataset and intends to deliver its judgment on 17 December 2026 (case no. I ZR 281/25). The transparency obligations under Art. 50 AI Act have applied since 2 August 2026. Products placed on the market from 9 December 2026 are subject to new product liability rules that expressly cover software.

Such topics are therefore likely to come up in due diligence for a financing round, in a customer audit, in a procurement review by a large company or in an exit. We have compiled six questions that an AI start-up should ask itself in advance in order to be prepared for such reviews and negotiations.

 

Were the training data lawfully obtained and licensed?

In the Suno case, the Munich Regional Court did not apply the text and data mining exception in Section 44b of the German Copyright Act (UrhG) to the extent that works had been memorised in the model. According to the judgment, there was also no lawful access, because Suno had downloaded the works from YouTube by circumventing technical protection measures. In the LAION proceedings, the Federal Court of Justice has to decide, among other things, when a reservation of rights is machine-readable. Anyone training on third-party data might therefore be well advised to keep a traceable record of where the data come from and how they were accessed.

Helpful documentation: a register of data sources with access route, licences and terms of use, and documentation of how reservations of rights are observed.

 

Can the model reproduce protected content, and who is liable if it does?

In the Suno case, the court inferred from reproducible outputs that the works were stored in the model and treated this as reproduction under Section 16 UrhG. According to the judgment, simple, open-ended user prompts do not break the attribution to the provider; the position might be different for prompts that deliberately steer the output. The same chamber had already found copyright infringement in November 2025 in GEMA v OpenAI concerning song lyrics (judgment of 11 November 2025, case no. 42 O 14139/24). Whether the higher courts will follow is open. Until then, it might even make sense to test one’s own model specifically for such outputs and to document the results.

Helpful documentation: test logs on the reproduction of training content, a description of the output filters and a procedure for complaints from rights holders.

 

Does the company hold the rights to its code, data and model?

For employees, the economic rights in computer programs generally vest in the employer under Section 69b UrhG. This rule does not, however, apply to code written by founders before incorporation or to work by freelancers and agencies. Here it would need to be checked whether, and to what extent, rights of use were granted. Since a grant of rights is, in case of doubt, limited to the purpose of the contract (Section 31(5) UrhG), express provisions could avoid later doubts. Open-source components and open model weights may bring further licence conditions, for example on redistribution, purpose of use and attribution. Most commentators deny copyright protection for model weights as such; to our knowledge, the courts have not yet decided the question. Contracts and protection as trade secrets under the German Trade Secrets Act (GeschGehG), which requires appropriate confidentiality measures, are therefore likely to carry all the more weight.

Helpful documentation: founder and employment contracts with IP clauses, freelancer agreements, a list of open-source components and models with their licences, and a description of the confidentiality measures.

 

What role and which obligations does the company have under the AI Act?

The obligations depend on whether the company is a provider or a deployer, whether it develops or modifies a general-purpose AI model and which risk category its system falls into. Art. 50 has applied since 2 August 2026. Providers of generative systems placed on the market before that date must implement the machine-readable marking under Art. 50(2) by 2 December 2026. Following the Digital Omnibus, the obligations for high-risk systems under Annex III apply from 2 December 2027. Providers established outside the EU may also need to appoint an authorised representative in the Union: for general-purpose AI models already now (Art. 54), for high-risk systems under Annex III from December 2027 (Art. 22).

Helpful documentation: a classification of role and risk category, evidence of the marking and, where applicable, the technical documentation and the summary of training content.

 

Is the processing of personal data in training and operation secured?

If training data contain personal data, training requires a legal basis. Which one is available depends on where the data come from. For publicly available data, legitimate interests under Art. 6(1)(f) GDPR are likely to be the main option; the European Data Protection Board set out criteria for the balancing test in its Opinion 28/2024. Where the data come from the company’s own users, consent under point (a) or, again, legitimate interests may also be considered. The contract with the user under point (b) is likely to cover training only to the extent that it serves the service for that particular user, not the general improvement of the model. Consent can be withdrawn, and as things stand, individual data can hardly be removed from a trained model in a targeted way. In operation, the contract with the user can cover the processing to the extent that the AI service forms part of the contract. If the start-up processes data on behalf of its customers, the question of the legal basis lies primarily with them. If it also uses the same data for its own training, it pursues, according to a widely held view, a purpose of its own and to that extent acts outside the scope of processing on behalf of its customers.

Helpful documentation: records of processing activities with the legal bases chosen, depending on the basis a legitimate interests assessment or the consent texts, a data protection impact assessment and data processing agreements with clear rules on the use of customer data for training.

 

What do the contracts with customers and model providers provide, and what changes for liability from December?

Many AI products are built on a model from a large provider whose terms largely determine use, liability and changes unilaterally. It might be worth checking whether one’s own customer contracts fit these terms, for example regarding indemnities for infringements caused by outputs, liability caps and commitments on data use. Under Directive (EU) 2024/2853, manufacturers are strictly liable for products placed on the market from 9 December 2026, including defective software and AI systems. This liability cannot be excluded or limited by contract vis-à-vis injured persons. Between businesses, on the other hand, liability arrangements remain possible, for example for recourse within the supply chain. The German implementing act has not yet been adopted.

Helpful documentation: the model providers’ terms of use, template customer contracts and an overview of liability provisions and insurance.

The main open question is whether, on 17 December, the Federal Court of Justice will treat the creation of training datasets as covered by the text and data mining exception or refer questions to the Court of Justice of the European Union. This could determine how robust datasets based on publicly available content are. In a review, the key question is therefore likely to be whether a start-up knows its risks and can show how it deals with them, regardless of whether every legal question has been settled. Compiling the documents listed above now could pay off, also as a basis for negotiations on warranties and indemnities. We are happy to help with questions on individual points.

09/29/2026, Moritz Mehner

EmpCo 2026: Section 15b UWG and Existing Stock

The decision has been made just days before the EmpCo rules take effect: On 24 September 2026, the German Bundestag adopted a new Section 15b of the German Act Against Unfair Competition (UWG). For certain goods already placed on the market before 27 September 2026, the new provision 

requires courts to take particular account of the principle of proportionality when assessing claims for injunctive relief relating to certain environmental claims and labels. However, the new rule does not introduce a general sell-off period.

The new EmpCo rules will apply from 27 September 2026. Until now, one of the key questions has been how to deal with goods that were already placed on the market before this date but may no longer comply with the new requirements.

The German legislator has now responded to this issue. As part of the modernisation of German design law, the Bundestag has adopted the new Section 15b UWG.

What does this mean for existing stock?

For certain EmpCo violations involving goods placed on the market before 27 September 2026, claims for injunctive relief will in future have to be assessed in accordance with the principles of good faith and proportionality.

The legislation specifically identifies four factors that are relevant to this assessment:

  • the severity of the infringement; 
  • the company's efforts to remedy the infringement;  
  • the costs associated with remedying the infringement; and 
  • the environmental impact that would result from the measures taken. 

The special provision is temporary and is scheduled to expire on 27 September 2028.

No general sell-off period

The new provision does not make an EmpCo violation automatically permissible and does not create a general transitional or sell-off period. However, it may provide significant flexibility in individual cases. According to the explanatory memorandum to the legislation, the balancing of interests may, depending on the circumstances, result in measures such as additional information requirements, a specific sell-off period for certain products, or even the exclusion of an injunctive claim altogether.

An important distinction is that the special provision does not apply generally to all goods produced before the cut-off date. It applies only to goods that had already been placed on the market before 27 September 2026.

What should companies do now?

For companies with potentially affected stock, documentation is becoming even more important. Companies should, in particular, document:

  • which goods are affected; 
  • when they were placed on the market; 
  • which corrective measures have already been taken or are still possible; and 
  • what costs and environmental impacts would result from those measures. 

For communications that can be changed quickly – such as websites, online shops or social media – the EmpCo deadline remains fully relevant. The new provision therefore does not eliminate the risk of legal disputes. It does, however, create additional arguments and potential defence options for companies.

For existing stock, the key question may therefore no longer be limited to: “Is the environmental claim permissible?”

It may also be: “Is the injunction being sought proportionate under the circumstances?”

EmpCo Compliance & Litigation

SKW Schwarz supports companies in implementing the new EmpCo requirements – from reviewing environmental and sustainability claims and addressing packaging and existing stock to defending companies against cease-and-desist claims, injunctive relief and regulatory fines.

More about our EmpCo Compliance & Litigation services  (LINK)

09/25/2026, Dr. Daniel Kendziur

Information Notice on Export Controls and Technology Transfer in Ukraine (Resolution No. 875)

With Resolution No. 875, Ukraine introduced a new procedure as of 1 July 2026 for the export of military goods, certain dual-use goods, and related technologies. The aim is to enable Ukrainian manufacturers to gain faster access to international markets while at the same time maintaining control over security-relevant technologies. The procedure applies for the duration of the currently prevailing martial law and for an additional six months thereafter.

This information notice provides an overview of the new export regime under Resolution No. 875, outlines the key requirements applicable to exporters and foreign importers, and explains why product classification, compliance structures, and contractual arrangements are essential prerequisites for resilient supply chains.

 

Which goods and business constellations are covered?

Resolution No. 875 covers military goods listed on Ukraine’s military goods list as well as certain dual-use goods and technologies. This is particularly relevant in practice for companies that develop, manufacture, or trade in UAV and UGV systems (unmanned aerial and ground vehicles) or related technologies. Both complete systems and components and individual parts are covered, provided that they are functionally associated with the respective system.

As a general rule, the new procedure requires the underlying export contract to have a value of at least UAH 15 million (approximately EUR 290,000). Individual parts or components may, however, also be covered at lower values if they are embedded in broader procurement or project structures.

The export regime is also limited to certain destination countries. Exports are only permitted to third countries that have concluded an agreement on military-technical or defence-industrial cooperation with Ukraine. This includes, for example, states that have concluded so-called “Drone Deals” with Ukraine. Six such “Drone Deals” have already been concluded for a period of 10 years. Numerous EU and NATO member states are expected to fall within the scope of these privileged third countries. For companies from these countries, the new regime generally opens up facilitated access to Ukrainian military goods and technologies, while at the same time creating a more closely regulated framework for technological and security-related cooperation.

 

Structure of the approval procedure and role of the authorities

Export licences are issued by the State Service of Export Control (SSECU). Decisions concerning goods that are not included on the list of “critical products” are to be issued within 30 days under a “fast-track” procedure. Such “critical products” are subject to stricter review, with a 90-day deadline. Defence and security authorities are involved in the decision-making process; if they do not provide their position within the statutory deadlines, a deemed approval mechanism applies.

For exporters, this means that, provided the application documents are complete and plausible, significantly shorter processing times can be expected. At the same time, there is increased pressure to prepare and document the application carefully, particularly with regard to the end-use and end-user, the customer structure, and the overall project architecture.

 

Shift of compliance responsibilities to companies

A significant part of the compliance review is shifted to the companies involved. Foreign importers and other customers must, in particular, ensure that they are not themselves subject to sanctions, are not controlled by an “aggressor state”, and do not have among their shareholders, beneficial owners, or executives any persons with links to such an aggressor state.

For exporters, this results in an increased need for structured review processes. The requirements typically go beyond conventional sanctions-list screening and also include an analysis of ownership and control structures as well as relevant business relationships. In practice, the Ukrainian authorities can be expected to require comprehensible documentation of these checks, and the corresponding processes will need to be integrated into standardised export control workflows.

 

Technology transfer, intellectual property and onward-transfer controls

Resolution No. 875 expressly permits the transfer of technologies, while retaining control over intellectual property and onward-transfer rights in Ukrainian hands:

  • As a general rule, only a right of use is to be granted; ownership of the intellectual property remains with the Ukrainian rights holder.
  • Any transfer, re-export, or other use beyond the purpose originally approved requires the prior consent of the competent Ukrainian authorities.
  • Technology transfer agreements must be structured in such a way that the allocation of rights (IP ownership vs. rights of use), the permitted purposes of use, and any onward-transfer rights are clearly defined and aligned with Ukrainian requirements.

For foreign companies, early involvement of IP and export control compliance functions is advisable. Already at the offer and contract stage, IP provisions, end-use clauses, and re-export restrictions should be reviewed and harmonised with the requirements of Resolution No. 875.

 

State guarantees of the importing state and assurance of end-use

For numerous exports – particularly in the case of sensitive military goods and technologies – state guarantees from the importing country are required. These  guarantees serve to

  • secure the end-use of the goods,
  • establish binding re-export restrictions, and
  • ensure compliance with the conditions governing the transfer of technology.

In practice, this means that exporters will regularly need to coordinate not only with the foreign customer but also with authorities in the importing country as part of a coordinated process. Contractual arrangements and project planning should therefore be designed to ensure that the relevant state end-use and guarantee letters are obtained in good time and integrated into the scheduling of delivery and payment milestones.

 

Fee structure and economic implications

The new export regime provides for significant value-based fees:

  • A fee of 20% of the value of the goods is payable for finished military and dual-use products as well as technology transfers.
  • For components and parts, the fee amounts to 30% of the value of the goods.
  • The fee is already due upon submission of the application; no refund is made if the export licence is refused.

In addition, a fee may also be incurred if products manufactured using Ukrainian technology are subsequently exported to third countries. Companies must factor the economic impact of these fees into their pricing and project calculations at an early stage and structure their payment arrangements accordingly. This includes, among other things, allocating the fee burden between the contracting parties, reflecting the fees in payment schedules, and taking potential approval risks into account in the contractual architecture.

 

Priority of Ukrainian procurement needs and project risks

Ukraine reserves the right to defer exports in favour of its own procurement needs. If there is a domestic defence requirement, export licences may be refused and licences that have already been issued may subsequently be suspended.

For companies, this means that even after an approval has been granted, a degree of uncertainty remains regarding the actual feasibility of the export. Long-term supply agreements should take this possibility into account contractually, particularly with regard to

  • delivery obligations and delivery deadlines,
  • liability provisions and warranty structures, as well as
  • force majeure or hardship clauses.

A clear allocation of risks between the parties is required in order to appropriately address approval risks and the possibility of government intervention.

 

Conclusion and recommendations for action

Companies wishing to benefit from the new export regime or already involved in the relevant supply chains should, as a first step, systematically assess and document

  • whether their products, components, or technologies are covered by the Ukrainian military goods list or the relevant dual-use areas,
  • whether the applicable value thresholds and destination countries (privileged third countries with cooperation agreements) are met, and
  • which project structures (end customers, intermediaries, technology transfers, licensing models) are envisaged.

On this basis, the following measures are particularly advisable:

  • adapting internal export control and compliance processes to the requirements of Resolution No. 875,
  • conducting an in-depth analysis of customer, ownership, and control structures in order to exclude sanctions exposure and links to aggressor states,
  • reviewing and restructuring technology transfer agreements, IP provisions, and end-use agreements in light of the Ukrainian requirements,
  • incorporating state end-use and guarantee letters into project planning and contractual arrangements, as well as
  • integrating the value-based fees and approval risks into pricing, financing, and project calculations.

We would be pleased to support you with the legal assessment of specific export and import projects, the structuring of contractual and compliance frameworks, and the strategic assessment of the new export regime under Resolution No. 875 in relation to your business models.

Dr. Oliver Hornung will be pleased to assist you with any questions or structuring matters relating to export controls and technology transfer in Ukraine.

09/24/2026, Dr. Oliver Hornung

Information Notice on the Bundeswehr Infrastructure Acceleration Act (BwIBG)

With the draft Bundeswehr Infrastructure Acceleration Act (Bundeswehr-Infrastrukturbeschleunigungsgesetz – BwIBG), the Federal Government is responding to the significantly increased need for the expansion of military infrastructure against the backdrop of the changed security and defence policy situation in Europe. The draft law aims to significantly accelerate the planning, approval and implementation of defence-related construction and infrastructure projects while ensuring the long-term operational reliability of military properties and facilities.

To this end, the BwIBG consolidates provisions in a separate Federal Military Construction Act (Bundeswehrbaugesetz – BwBauG) and introduces accompanying amendments, inter alia, to environmental, nature conservation, water and forestry law, the law governing restricted areas and land acquisition, the Code of Administrative Court Procedure and the Federal Administrative Services Act.

This information letter outlines the key provisions of the draft and assesses its practical implications, particularly for companies involved in Bundeswehr infrastructure projects or considering such involvement.

 

1. Federal Military Construction Act: New Framework for the Construction and Operation of Military Infrastructure

The core element of the BwIBGA major element of the planned reforms is the new Federal Military Construction Act (BwBauG). It defines its scope of application, regulates responsibilities for construction tasks and establishes key acceleration and prioritisation decisions.

Scope of application: The BwBauG applies to the planning and implementation of construction projects for the purposes of the Bundeswehr and allied armed forces, as well as to the operation of the relevant military properties and buildings. It therefore covers both new construction and expansion measures as well as the operation and adaptation of existing infrastructure, including the infrastructural preparations required for crises and defence situations.

Construction tasks and direct federal execution: In addition to the existing performance of construction tasks by the construction administrations of the Länder on behalf of the Federal Government under the principle of delegated federal administration (Organleihe) pursuant to Section 5b of the Financial Administration Act (FVG), the Federal Government is to be able to carry out its construction tasks directly in the future. The management, coordination and execution of construction tasks may be transferred to the Bundeswehr administration unless a Land assumes responsibility for the construction task under a procedure agreed in advance. This creates an additional channel alongside the traditional federal construction administrations, which is intended to increase implementation capacity, particularly for time-critical projects.

Corporate participation: The Federal Government is expressly to be authorised to establish a company under private law or to acquire an interest in such a company for the construction and operation of military infrastructure. This creates scope for project-specific corporate structures, for example for resilient energy and supply infrastructure at military sites, and enables greater involvement of private-sector expertise in planning, construction and operation.

A central policy decision concerns the classification of military infrastructure projects as projects in the overriding public interest. Pursuant to Section 4 BwBauG, the construction and operation of facilities for the purposes of the Bundeswehr and allied armed forces are deemed to be in the overriding public interest and to serve the security of the Federal Republic of Germany. Accordingly, defence interests are given particularly significant weight in balancing decisions, for example in planning approval or other approval proceedings; nevertheless, where several interests are considered to be in the overriding public interest, a case-by-case balancing of those interests remains necessary.

 

2. Acceleration of Proceedings: Legal Remedies and Concentration of Jurisdiction

The BwIBG provides for various instruments aimed at shortening proceedings and increasing planning certainty:

Legal remedies without suspensive effect: Pursuant to Section 3(1) BwBauG, legal remedies against the admissibility or implementation of construction projects under Section 1 BwBauG are generally not to have suspensive effect. This means that measures may initially continue despite pending lawsuits or objections. Effective legal protection remains available through interim proceedings and the decision on the merits; however, the threshold for bringing construction to an effective standstill is raised.

First and final instance jurisdiction of the Federal Administrative Court: Section 3(2) BwBauG provides for the concentration of administrative court jurisdiction in the Federal Administrative Court (Bundesverwaltungsgericht – BVerwG) for certain defence-related projects with a high degree of infrastructure and security relevance. This includes, inter alia, disputes concerning restricted-area orders and measures under the Restricted Areas Act, certain military transmission and supply infrastructure extending across Länder, permits and permit exemptions for military airfields, and designations under the Land Acquisition Act. In these cases, the BVerwG will have first and final instance jurisdiction. Multi-level judicial proceedings are thereby avoided, divergent decisions by different administrative courts are reduced and the duration of proceedings is shortened.

Consultation and recognition arrangements under water hazard law: Section 5 BwBauG authorises the Federal Ministry of Defence (BMVg) to designate and recognise, for its area of responsibility, its own expert organisation (e.g. the Bundeswehr Technical Inspection Authority) to carry out technical inspections under the Ordinance on Installations for the Handling of Substances Hazardous to Water. This strengthens in-house expertise, reduces reliance on external bodies and facilitates the crisis-resilient maintenance of critical supply infrastructure.

 

3. Environmental, Nature Conservation, Water and Forestry Law: Privileges and New Compensation Mechanisms

The draft does not provide for a general reduction of substantive environmental standards. Instead, it establishes specific procedural simplifications and priorities for defence purposes.

Environmental Impact Assessment (EIA): For certain defence projects on defence areas or areas designated accordingly, the BMVg or a body designated by it may, on a temporary basis until the end of 2035, refrain from carrying out an EIA. In such cases, the examination of the requirements for an exemption and publication of the decision may be dispensed with if defence interests would otherwise be adversely affected, for example due to security classification requirements.

Immission control law: Material modifications to certain military installations where noise is the only factor triggering an amendment permit are to be eligible for processing under a simplified notification procedure in the future. Substantive protection requirements remain in place; the acceleration concerns the formal procedure.

Water law and drinking water protection: Military areas are only to be designated as drinking water protection areas for the first time if a local water supply cannot otherwise be provided at reasonable cost and effort. With regard to water protection and flood protection measures, it is clarified that the intended use of defence areas must generally be ensured, provided that key water-law protection objectives are not jeopardised.

Forestry law and military areas: Certain defence-related areas – such as cleared training grounds, sealed bunker areas or defined safety strips around military installations – will expressly no longer be considered forests within the meaning of the Federal Forest Act. In addition, Section 45 of the draft Federal Forest Act (BWaldG-E) gives priority to the intended use of areas serving, inter alia, defence purposes. Provisions of Land law, particularly those concerning forest planning, are only applicable to the extent that they do not impair military use.

Nature conservation law and compensation: The Federal Nature Conservation Act will permit, for certain military interventions on defence areas, a departure from conventional area-based compensatory and replacement measures: unavoidable impacts may be permissible until the end of 2035 if, instead, a compensatory payment is made in accordance with the Federal Compensation Ordinance. The compensatory payment is to be appropriately increased in comparison with other projects in the overriding public interest and is to be used for equivalent or higher-value ecological improvements in the affected or adjacent natural area. In addition, military use, the construction and operation of military installations, and certain hazard prevention and maintenance measures will be exempted from individual nature conservation prohibitions. In the future, the BMVg or the Bundeswehr will largely be responsible for exemptions and derogations under species protection law for defence-related projects; decisions will be taken in consultation with the competent nature conservation authorities.

 

4. Restricted Areas and Land Acquisition Acts: Early Safeguarding and Deadlines with Approval Fictions

The Restricted Areas Act and the Land Acquisition Act are being adapted to current requirements.

Restricted Areas Act: The purpose of defence will be defined broadly and expressly extended to include alliance obligations and international treaties. In future, the term “defence installation” will also include specifically planned installations and designated areas, allowing restricted areas to be established at an early planning stage. A three-month period, with the possibility of a one-time extension, will be introduced for consulting the Länder; once the deadline has expired, it will be presumed that there are no objections. In addition, decisions concerning structural and other installations within a restricted area will be placed more strongly under the responsibility of the restricted-area authority (BMVg or a designated body), combined with decision-making deadlines and a deemed-consent mechanism.

Land Acquisition Act: The consultation procedure for the Länder and municipalities in land acquisition measures will likewise be structured through deadlines with deemed approval. For properties already owned by the Federal Government that were previously used for military purposes and remain unused, a simplified designation and allocation procedure will be introduced, which, under certain conditions, makes it unnecessary to repeat the entire land acquisition procedure. At the same time, the extent to which the designation of a property for defence purposes restricts municipal planning autonomy will be clarified.

 

5. Implications for Companies and Other Stakeholders

For companies involved, or considering becoming involved, as service providers, contractors or project partners in Bundeswehr infrastructure projects, the draft BwIBG has several practical implications:

New cooperation and operating models: The express possibility for the Federal Government to establish or acquire interests in companies under private law for the construction and operation of military infrastructure creates scope for structured partnerships, for example in the context of energy, supply and operating concepts. Contractual arrangements, governance and risk allocation must take these public-law framework conditions into account.

Changed responsibilities and decision-making processes: The strengthened role of the Bundeswehr administration and the BMVg – including their own expert organisations and regulatory decision-making powers in nature conservation law – changes points of contact, decision-making processes and escalation paths in projects.

Accelerated procedures and legal-remedy framework: Deadlines with deemed-approval and deemed-consent mechanisms, the removal of the suspensive effect of legal remedies, and the first and final instance jurisdiction of the BVerwG result in faster but also more condensed proceedings. Companies must adapt their project planning, internal decision-making processes and compliance structures accordingly, as time windows will become tighter and legal risks will need to be addressed at an early stage.

A new balance in environmental, nature conservation and forestry law: While substantive standards remain in place, the weighting shifts in favour of defence-related projects. In practical project terms, this means different requirements for environmental and nature conservation concepts, a greater role for monetary compensation and the need to reconcile land and site decisions at an early stage with the specific privileges and restrictions.

 

Conclusion and Recommendations for Action

Once a consolidated or final version of the legislation is available, affected companies should systematically analyse their project portfolios to determine the extent to which they are affected by the new instruments, priorities and transfers of responsibility, and what adjustments may be required with regard to strategy, contractual arrangements, compliance structures and risk assessment.

Dr. Oliver Hornung will be pleased to answer any questions regarding this information letter on the Bundeswehr Infrastructure Acceleration Act.

09/24/2026, Dr. Oliver Hornung

How the Digital Interstate Media Treaty regulates media, platforms and AI

With the Digital Interstate Media Treaty (Digitale Medien-Staatsvertrag), the German states intend to adapt the Interstate Media Treaty (Medienstaatsvertrag, MStV) to new European requirements for digital media, political advertising and artificial intelligence. The draft of the first part (Ninth Interstate Media Amendment Treaty, version of 10 June 2026) mainly affects media companies, online platforms, providers of journalistic content and the state media authorities (Landesmedienanstalten) as supervisory authorities. The heads of government of the states approved the draft on 25 June 2026 and intend to sign it by January 2027 at the latest. It is scheduled to enter into force on 1 August 2027; if not all instruments of ratification have been deposited by 31 July 2027, it will become void.

The Interstate Media Treaty primarily contains the provisions required to give effect to the European Media Freedom Act (EMFA), the Regulation on the transparency and targeting of political advertising and the AI Act. The Regulations are, in principle, directly applicable; the Interstate Media Treaty mainly determines who monitors compliance with them. For companies, this means: new transparency, cooperation and compliance obligations meet extended supervisory powers of the state media authorities. For the first time, the draft also brings the press within the scope of the Interstate Media Treaty and defines what is to be regarded as a print product (Druckerzeugnis) and as a periodical print product (periodisches Druckerzeugnis) (Section 1(1) and (2), Section 2(2) nos. 32 and 33 MStV-E; MStV-E refers to the Interstate Media Treaty as amended by the draft).

 

New competences regarding AI

The state media authorities are given an express role as market surveillance authorities for AI applications in the media sector.

This competence builds on the federal AI Market Surveillance and Innovation Promotion Act (KI-Marktüberwachungs- und Innovationsförderungsgesetz, KI-MIG), which entered into force on 29 July 2026. Under Section 2(1) KI-MIG, the Federal Network Agency (Bundesnetzagentur) is the market surveillance authority for the AI Act unless the Act provides otherwise. Section 2(8) KI-MIG provides for an exception for media service providers within the meaning of Art. 2(2) EMFA that provide, take into service or use AI systems in operating, offering, distributing and making available media services for journalistic or advertising purposes. For these cases, the federal act leaves market surveillance to the authorities competent under the law of the states. In this area, the Federal Network Agency merely receives complaints and forwards them to the competent authority (Section 8 KI-MIG). The new Section 111(5) MStV-E builds on Section 2(8) KI-MIG and designates the state media authority competent under Section 106 MStV as the market surveillance authority.

The state media authorities are therefore competent only where two conditions are met. The first concerns the provider: only media service providers within the meaning of the EMFA are covered, i.e. providers whose professional activity is to provide a media service, who have editorial responsibility for the choice of the content and who determine the manner in which it is organised. These include private television and radio broadcasters, providers of on-demand services, press publishers, journalistic online services and the public service broadcasters. Online platforms are covered only where, exceptionally, they themselves have editorial responsibility for the choice of their content. Search engines do not fall within the EMFA definition, and providers of AI services such as chatbots are, as a rule, not media service providers because they lack editorial responsibility. For them, the Federal Network Agency remains the market surveillance authority; for general-purpose AI models, it is the European Commission’s AI Office. The second condition concerns the purpose: the AI system must be used for journalistic or advertising purposes. If a publisher uses AI e.g. in recruitment or accounting, the Federal Network Agency remains competent. Depending on the specific use cases, the same media company may therefore be subject to two supervisory authorities.

Section 111(5) MStV-E does not limit supervision to individual provisions of the AI Act. The state media authorities monitor all obligations incumbent on the media service provider as provider or deployer of an AI system; an earlier draft had limited their competence to the enforcement of Art. 50 AI Act. In practice, supervision will mainly concern the transparency obligations under Art. 50 AI Act. Anyone deploying AI to generate or manipulate image, audio or video content constituting a deep fake must disclose this; where the content forms part of an evidently artistic, satirical or fictional work, disclosure in an appropriate manner that does not hamper the display or enjoyment of the work is sufficient (Art. 50(4), first subparagraph, AI Act). The scope of the term “deep fake” is disputed. On 5 June 2026, the Broadcasting Commission of the states (Rundfunkkommission) criticised the broad interpretation in the European Commission’s draft guidelines on Art. 50 AI Act, arguing that press, audio and video content published under editorial responsibility would otherwise be subject to disproportionate labelling obligations. AI-generated text published with the purpose of informing the public on matters of public interest must also be disclosed. This obligation does not apply where the text has undergone a process of human review or editorial control and a person or company holds editorial responsibility for their publication (Art. 50(4), second subparagraph, AI Act). As a rule, the disclosure obligation therefore does not apply to texts published under editorial responsibility; the AI Act provides for no comparable exception for image, audio and video content. Where a media house operates its own AI applications, such as a chatbot on its website, the provider obligations under Art. 50(1) and (2) AI Act apply in addition: human beings must be informed that they are interacting with an AI system, and synthetic content must be marked in a machine-readable format.

Fines for infringements of the AI Act are imposed by the respective market surveillance authority (Section 17(1) KI-MIG), which will in future be the state media authority in the media sector. For infringements of Art. 50 AI Act, Art. 99(4) AI Act provides for administrative fines of up to EUR 15 million or up to 3 % of total worldwide annual turnover for the preceding financial year, whichever is higher. The state media authority may initiate proceedings against public broadcasters and against providers of periodical print products only after consulting the competent supervisory body or the German Press Council (Deutscher Presserat), respectively. Their opinion is binding, provided that the limits of the margin of appreciation have been observed (Section 111(6) MStV-E). For cooperation with the Federal Network Agency, the Digital Services Coordinator and the European Commission, the state media authorities appoint a joint representative.

The period until the Interstate Media Treaty enters into force remains unresolved. The transparency obligations under Art. 50 AI Act have applied since 2 August 2026. Since then, Section 2(8) KI-MIG has assigned market surveillance in the media sector to the authorities competent under the law of the states, but does not itself designate any authority; the Interstate Media Treaty is to designate the state media authorities only with effect from 1 August 2027. Supervision under the Interstate Media Treaty continues irrespective of this: on 14 July 2026, the Commission on Licensing and Supervision (ZAK) for the first time issued decisions against AI services of Google and Perplexity. However, the Interstate Media Treaty does not confer the powers of a market surveillance authority under the AI Act, since Section 109 MStV requires an infringement of the Interstate Media Treaty itself. Neither the KI-MIG nor the Interstate Media Treaty specifies which authority may pursue infringements of Art. 50 AI Act by media service providers until August 2027.

 

Competences and new sanctions under the EMFA

To enforce the European Media Freedom Act, the draft extends the catalogue of administrative offences. Infringements of certain obligations, for example relating to functionalities of online platforms, transparency information, dialogue procedures with media service providers or the visibility of media offerings on user interfaces, may be prosecuted as administrative offences (Section 115(1a) MStV-E). The fine may amount to up to EUR 1.5 million (Section 115(2) MStV-E); the limitation period for prosecution will in future expire only after 24 months instead of six months (Section 115(5) MStV-E).

These obligations include, for example, Art. 18 EMFA, which requires providers of very large online platforms such as Facebook, Instagram, TikTok and YouTube to provide media service providers that have declared themselves as such to the platform with a statement of reasons before suspending the provision of their services in relation to that content or restricting its visibility because the content is incompatible with the platform’s terms and conditions, to give them the opportunity to reply, and to process and decide upon their complaints with priority. In addition, the state media authorities will also monitor compliance with Art. 20 EMFA, which, from 8 May 2027, requires manufacturers, developers and importers of devices and user interfaces controlling or managing access to and use of media services to enable users to change the settings, including the default settings, freely and easily, and to ensure that the visual identity of media service providers is clearly visible.

Art. 24 EMFA applies where a service operates an audience measurement system, for example where data on usage, reach, views, viewing time, interaction or target groups are collected and processed for decisions on advertising, pricing, purchases and sales, planning or distribution. Art. 24 EMFA requires audience measurement methodologies that are transparent, impartial, inclusive, proportionate, non-discriminatory, comparable and verifiable. Providers of proprietary audience measurement systems must, in addition, disclose their methodology, have it audited annually by an independent body and, upon request, provide media service providers with the audience measurement data relating to their offering, including non-aggregated data.

Another focus of the new Digital Interstate Media Treaty is transparency of ownership and shareholding structures in the media sector. The Commission on Concentration in the Media (KEK) is to maintain a publicly accessible and regularly updated database (Section 60(8) MStV-E). It is to contain, in particular, information on the owners and shareholdings of relevant media companies. This is intended to make it easier to understand who is behind a media offering and which economic interconnections exist. 

 

Political advertising under supervision

The draft allocates competences for the new EU Regulation on the transparency and targeting of political advertising. In future, the state media authorities are to monitor the obligations under Arts. 11 and 12 of the Regulation in respect of telemedia providers, and the obligations under Arts. 5, 7 to 17 and 21 in respect of media service providers and of telemedia providers that are not intermediary services within the meaning of the Digital Services Act (Section 111(4) MStV-E). This covers, in particular, requirements relating to the labelling, transparency and delivery of political advertising. Infringements are to be sanctioned under the federal Political Advertising Transparency Act (Politische-Werbung-Transparenz-Gesetz), which is still in the parliamentary process (Section 115(1b) MStV-E). 

 

AI-supported media supervision

Of particular practical relevance is the newly proposed express legal basis for the use of technical means in media supervision (Section 109a MStV-E). In future, the state media authorities may use automated systems that check text, image, audio and video content for possible infringements. This may also include content that is not freely accessible. The use of such systems is intended, among other things, to detect infringements of media law and youth protection in the media. 

At the same time, the draft contains safeguards: a possible infringement detected automatically must be reviewed by a human being without undue delay. If the suspicion is not confirmed, the personal data processed must be deleted; if no review takes place, they must be deleted after 30 days at the latest. Data required for supervisory proceedings after a suspicion has been confirmed are subject to strict purpose limitation and must be deleted after six months at the latest, unless supervisory proceedings are pending by then. In supervisory proceedings, the provider concerned must be informed that technical means were used. 

Online platforms may also be required to provide the state media authorities with suitable technical interfaces, insofar as this is technically and economically reasonable. The details are to be specified by the state media authorities in joint statutes; the main results of the use of technical means are to be reported annually. 

 

Competences at a glance

Area of regulationState media authoritiesFederal Network Agency and other bodies
AI Act: media service providers using AI for journalistic or advertising purposes

Market surveillance and fines once the Interstate Media Treaty enters into force (Section 111(5) MStV-E, Sections 2(8) and 17(1) KI-MIG)

 

Federal Network Agency only as complaints body (Section 8 KI-MIG)
AI Act: all other uses of AI, including in media houses (e.g. HR, accounting)–

Federal Network Agency (Section 2(1) KI-MIG); sectoral authorities such as the Federal Financial Supervisory Authority (BaFin)

 

General-purpose AI models

 

–AI Office of the European Commission

EMFA: Art. 18 (very large online platforms), Art. 20 (user interfaces), Art. 24 (audience measurement)

 

Supervision and fines (Section 115(1a) MStV-E)–
Political advertising (Regulation (EU) 2024/900)Arts. 11 and 12 for telemedia; Arts. 5, 7 to 17 and 21 for media service providers and for telemedia that are not intermediary services (Section 111(4) MStV-E)

Federal authorities under the Political Advertising Transparency Act, in particular for intermediary services (legislative procedure ongoing)

 

Interstate Media Treaty, including in respect of AI search and chatbotsSupervision under Sections 104 et seq. MStV (law already in force)–

 

What the draft means for media services

Overall, the draft extends media regulation further into the digital space. Media houses, platform operators and advertising marketers have to prepare for new transparency, organisational and documentation obligations for their services, advertising processes and AI applications. In parallel, the states are deliberating on a second part of the Interstate Media Treaty. According to press reports, it is intended, among other things, to make providers of AI information systems responsible for the content they generate; no consultation draft has been published so far. It also remains unclear how such responsibility relates to the liability rules of the Digital Services Act where AI answers are integrated into search engines and platforms.

09/22/2026, Moritz Mehner, Dr. Anna Kellner

EmpCo: Special rule planned in Germany for certain existing stock – what companies need to know now

Just days before the new EmpCo rules take effect, an important amendment to the German Act Against Unfair Competition (UWG) is taking shape. A special rule is planned for certain goods that were placed on the market before 27 September 2026. However, the proposed amendment would not introduce a general sell-through or grace period. For companies, the key priorities now are to document, prioritise and prepare for potential disputes.

On 27 September 2026, the new rules implementing the Empowering Consumers Directive (EmpCo) will take effect under the German Act Against Unfair Competition (UWG). From that date, environmental and sustainability communications will have to comply with stricter requirements.

One question is particularly pressing for companies: What happens to goods that are already on the market where the packaging contains environmental or sustainability claims that may no longer comply with the new requirements?

So far, the UWG does not provide for a general transition, grace or sell-through period for such goods. Just days before the deadline, however, an important amendment is now taking shape.

Proposed Section 15b UWG: proportionality test for claims for injunctive relief

According to a draft legislative resolution currently available, a new Section 15b UWG is to be introduced into German law.

Under the proposed provision, claims for injunctive relief based on certain EmpCo infringements relating to goods placed on the market before 27 September 2026 would have to be asserted in good faith and in accordance with the principle of proportionality.

As part of a comprehensive balancing of interests, four factors in particular would have to be taken into account:

  1. the seriousness of the infringement; 
  2. the efforts made by the company to remedy the infringement; 
  3. the costs associated with remedying the infringement; and 
  4. the environmental impact associated with remedying the infringement. 

The German Bundestag is expected to vote on the Act to Modernise Design Law on 24 September 2026, in the context of which the amendment to the UWG is, according to the information currently available, expected to be introduced. The proposed new provision has not yet been adopted.

No general sell-through or grace period

For companies, it is important to understand what the proposed rule would not do: based on the wording currently available, it would not introduce a general transition, grace or sell-through period.

Section 15b UWG-E would not automatically make an EmpCo infringement lawful. Instead, the provision is intended to make the enforcement of claims for injunctive relief in relation to certain goods already placed on the market subject to a proportionality test.

In a specific dispute, it could therefore be relevant, for example, whether a contested claim can be corrected by applying stickers or relabelling, what costs this would entail, or whether an immediate stop to distribution would result in the destruction of significant quantities of goods and the associated environmental impact.

Depending on the individual case, this balancing of interests may affect the nature and scope of injunctive relief. How the provision will be applied in practice, however, is likely to become clear only over time and, potentially, through case law.

Key distinction: “placed on the market” does not mean “produced”

One detail of the proposed wording is particularly important.

The special rule would not apply across the board to all goods produced before the deadline. Instead, it expressly refers to goods that were already placed on the market before 27 September 2026.

Companies holding significant quantities of goods or packaging should therefore carefully assess which inventory may fall within the scope of the proposed provision.

In particular, companies should now ensure that they can document when the relevant goods were placed on the market.

What companies should document now

The proposed rule makes documentation even more important. The information companies record today may later prove crucial when assessing whether injunctive relief is proportionate.

Companies should document in particular:

  • Which goods are affected? Which products or packaging contain potentially problematic environmental or sustainability claims? 
  • When were they placed on the market? Delivery records, inventory management data and other relevant evidence should be secured without delay. 
  • What measures have already been taken? For example, changes to future packaging, relabelling, stickers or information provided to retailers and other distribution partners. 
  • What further adjustments are possible? And what organisational and economic effort would they require? 
  • What costs would arise? For example, from relabelling, product recalls, changes to production or, where applicable, destruction of goods.  
  • What would the environmental impact be? This may be particularly relevant where significant quantities of goods or packaging would otherwise have to be destroyed. 

The latter four aspects in particular directly reflect the criteria that, according to the draft currently available, are to be considered as part of the proportionality assessment.

No extension for websites, online shops or social media

The proposed special rule should not be understood as a general extension of the EmpCo implementation deadline.

Based on the wording currently available, Section 15b UWG-E expressly refers to goods placed on the market before the deadline. Other forms of environmental and sustainability communication would not generally benefit from the proposed rule.

Companies should therefore continue to review and, where necessary, adapt websites, online shops, social media communications, digital campaigns and other communications that can be changed at short notice by 27 September.

EmpCo remains a litigation issue

The proposed amendment does not eliminate the risk of legal disputes.

Competitors, associations and qualified entities can take action against unlawful environmental and sustainability communications. The new provision would instead add another question to potential disputes: Is the claim for injunctive relief sought proportionate in the circumstances of the individual case?

In addition to the legal assessment of the claim itself, it may therefore become crucial how well a company has documented its existing inventory, the remedial measures already taken and the associated costs and environmental impact.

Companies should use the remaining days to focus on two areas:

1. Compliance:
Prioritise communications that can still be changed, review claims and secure the necessary supporting evidence.

2. Litigation readiness:
Document affected inventory and when it was placed on the market, assess potential remedial measures and record their economic and environmental impact.

What happens next?

The German Bundestag is expected to vote on the Act to Modernise Design Law on 24 September 2026. It remains to be seen whether the proposed Section 15b UWG will be adopted and, if so, in what final form.

For companies, the message is clear: Monitor developments – but do not wait for them.

The EmpCo deadline remains 27 September 2026. The proposed special rule could provide new arguments in the defence against claims for injunctive relief in relation to certain goods already placed on the market. However, it does not replace the need to review existing claims or to prepare for potential legal disputes.

Prioritise claims. Secure evidence. Document existing stock. Prepare for potential disputes.

EmpCo Compliance & Litigation

SKW Schwarz supports companies in implementing the new EmpCo requirements – from our EmpCo Quick Check and the legal review of environmental and sustainability claims to dealing with packaging and existing stock, as well as defending against cease-and-desist demands, claims for injunctive relief and regulatory fine proceedings.

Find out more about our EmpCo Compliance & Litigation services Click here

 

09/22/2026, Dr. Daniel Kendziur

KI-Flash: Advertising Law and Data Protection as Ads Launch in ChatGPT

Since August 24, 2026, German ChatGPT users have also been seeing ads.

OpenAI has opened the advertising channel for 31 European markets. For users on the free Free and Go plans, ChatGPT’s functions are now available only with ads, while the Plus, Pro, Business, Enterprise and Edu plans remain ad-free according to the provider’s announcement of 18 August 2026. Ads are also shown only to logged-in users who have reached the age of majority.

One week later, on 31 August 2026, OpenAI opened self-service access through the Ads Manager for the same markets in a beta version. Advertisers based in Germany have since been able to book ads without an agency or technology partner. Booking through the provider’s ads solutions team and through agency and technology partners remains available alongside this.

Ad-funded generative AI is therefore no longer an announced plan in the German market but live operation. This article sets out the standards of review under advertising and data protection law. It is addressed to companies that advertise in this environment or deploy AI assistants in their own operations; the provider’s own obligations are described only to the extent that they matter from that perspective. No statements by the competent authorities on this advertising model are available so far. 

This article opens a three-part series on current developments around AI assistants. The second part deals with the designation of ChatGPT as a very large online search engine under the Digital Services Act and the obligations attached to it. The third part asks to what extent advertisers and agencies are responsible for the content of ads placed in AI assistants and liable for the statements they make. The question of when a provider must have AI answers attributed to it as its own content was already covered in our KI-Flash of 2 July 2026.

 

No personalised advertising in the EEA so far

For ads on online platforms, a distinction is drawn between personalised and non-personalised advertising. The legal requirements for the two differ considerably. 

In the first phase, currently implemented in the European Economic Area, ads are selected without personalisation in the sense of profiling. What is used is the topic of the ongoing conversation together with limited contextual information such as approximate location, language, time of day and device type. Earlier chats and stored information are expressly excluded according to the provider. Advertisers receive aggregated performance data only, and no conversation content, no real names and no precise location data.

Personalised advertising requires separate consent. Only then do chat history, stored information and a user’s behaviour in response to earlier ads feed into the selection. Users’ consent is required for this, as OpenAI also expressly describes in the version of its European privacy policy of 2 June 2026. This personalised advertising option has not yet been activated in the EEA.

One point that has largely gone unnoticed deserves attention here: behaviour in response to earlier ads can only feed into the selection if it has been collected beforehand, and, at least according to the provider, that does not happen in the first phase. The change therefore does not consist solely in evaluating existing data but first of all in building up a new set of data. Consent would have to cover that step as well.

 

How must advertising in an AI assistant be labelled?

The provider describes the ads as clearly labelled and visually separated from the answer. Under advertising law, the question is usually discussed under Section 5a(4) UWG. No. 11 of the Annex to Section 3(3) UWG may also apply, which covers the use of editorial content financed by a trader and disguised as information. That provision presupposes, however, that editorial content exists at all, and whether an AI-generated answer qualifies is an open question. For comparison portals and search engines, editorial content is in part affirmed even though there is no editorial team in the traditional sense. What speaks against that classification is precisely the position taken by the ZAK, the joint commission of the German state media authorities, according to which AI answers are the provider’s own content and therefore do not appear as neutral reporting. Added to this are Section 6(1) DDG for commercial communication in digital services and, where the service qualifies as a media intermediary or a media-like offering, Section 22 MStV. Classification as a media intermediary depends on whether the service aggregates third-party content, selects it and determines how easily it can be found. That is exactly what the ZAK relied on in relation to source citations and link lists. A service that generates only its own answers does not meet that test.

The structural risk, however, lies not in the design of the ad block but in the selection logic. An ad selected on the basis of the topic of the ongoing conversation appears at a moment when the user has just articulated a specific concern. In functional terms it works like native advertising, even where it is presented as “formally separated”. Whether a visual separation is enough to address this problem of contextual proximity is a question of the specific implementation. 

 

Are AI answers the provider’s own content?

Against the labelling obligations under Section 22 MStV and Section 6 DDG it could be argued that a chat interface has no editorial part from which advertising would have to be distinguished in the first place. On the line that has emerged so far, that defence does not hold: in its judgment of 28 May 2026 (26 O 869/26), the Regional Court of Munich I treated a search engine’s “AI Overview” function as the provider’s own substantive statement and found that the provider had adopted the content as its own (paras. 33 f.). Three aspects were decisive: the function produces a self-contained running text that summarises, structures and evaluates search results; it forms statements that are not contained in the sources relied on; and, from the perspective of a reasonably informed average user, it appears as an answer for which the provider is responsible rather than as a neutral list of results. On 14 July 2026, in proceedings of the Hamburg/Schleswig-Holstein and Berlin-Brandenburg state media authorities, the ZAK issued its first orders against AI services operated by Google and Perplexity, holding that AI answers are the providers’ own content and that the liability exemption under the DSA does not apply. Neither decision is final and binding yet, and appeals have been announced. For Section 5a(4) UWG this preliminary question is irrelevant. For No. 11 of the Annex it matters, because editorial content is a constituent element there.

 

The promise about the answers

OpenAI promotes the principle that advertising does not influence the answers. Beyond being a product description, this also appears to be a statement about a material characteristic of the service within the meaning of Section 5 UWG. If the actual design departs from it – for instance through influence on ordering, product mentions or shopping integration – a misleading commercial practice would come into consideration. In practice the question of evidence arises immediately: how does a competitor prove a distortion in the model’s behaviour? How the model works lies solely within the provider’s sphere, which speaks in favour of a secondary burden of substantiation: the competitor puts forward tangible indications and the provider then has to respond in substantiated form. It can be countered that a secondary burden of substantiation is ruled out to the extent that the competitor can test the answering behaviour itself. Starting points are offered by the audit obligations under Art. 37, the ad repository under Art. 39 and researcher access under Art. 40 DSA – provisions that now apply as a result of the designation as a very large online search engine of 31 August 2026. More on this in the next article.

 

Who is subject to the consent requirement?

Section 25 TDDDG applies to access to information on terminal equipment through cookies. The OpenAI measurement pixel sets a first-party cookie on the advertiser’s domain. The consent requirement therefore falls not on the platform operator but on the booking party. The provider also makes a server-side interface for conversion measurement available; its use, too, is processing carried out by the booking party itself. 

Section 25 TDDDG does not apply to server-side transmission, because no access to terminal equipment takes place there. The only benchmark in that respect is the GDPR.

 

May chat histories be used to select ads?

This is where the real point of examination lies. Chats are shared for the purpose of completing a task, not for optimising advertising. Drawing on the history for ad selection must therefore be measured against Art. 5(1)(b) and Art. 6(4) GDPR, regardless of whether consent is obtained.

Art. 9 GDPR also comes into play. Conversation histories regularly reveal health data, religious or philosophical beliefs, sexual orientation or political opinions. In Cases C-252/21 and C-446/21 the CJEU applied a broad standard for when special categories of data are involved and set strict requirements for the validity of consent. In Case C-446/21 it also found a breach of the data minimisation principle because personal data had been processed for targeted advertising purposes without any distinction according to their nature. Irrespective of this, Art. 21(2) GDPR provides an unconditional right to object to direct marketing, which is not open to any balancing exercise. The right attaches solely to the purpose of the processing and not to the legal basis. It therefore also covers the delivery of non-personalised ads to the extent that these constitute direct marketing.

 

Self-commitment does not replace a legal basis

The provider has set category exclusions for physical health, mental health and politics; political advertising is currently not permitted at all. Exclusions of this kind are contractual self-commitments. They replace neither a legal basis under Art. 9 GDPR nor an assessment of sector-specific advertising bans. How a prohibition under the law on advertising for medicinal products is to be enforced in an interface in which users are describing their symptoms is an open question. 

The reverse case also arises. Under the provider’s advertising policies, regulated industries, among them legal, health and financial services, are excluded from booking outside the United States. For companies in these sectors, the first question is therefore not one of admissibility but one of access.

The protection of minors, too, operates through a technical self-commitment: ads are not served where the user is presumed to be a minor, as determined by age estimation. That protective measure is itself processing that calls for justification. Section 6 JMStV and No. 28 of the Annex to Section 3(3) UWG have to be taken into account in addition. Section 6 JMStV is a rule governing market conduct within the meaning of Section 3a UWG and can therefore also be enforced under unfair competition law. No. 28 of the Annex covers direct exhortations to children to buy, that is to persons under the age of fourteen. Art. 6(1)(f) GDPR comes into consideration as the legal basis for age estimation. It cannot be based on Art. 6(1)(c) GDPR to the extent that it rests on a voluntary self-commitment rather than on a specific legal obligation.

 

Transparency and labelling

The information obligations under Art. 12 to 14 GDPR are under particular scrutiny in 2026: on 19 March 2026 the EDPB launched a coordinated enforcement action on precisely these provisions, with 25 supervisory authorities taking part. A privacy policy revised shortly beforehand, which for the first time includes advertising as a processing purpose, therefore falls within an ongoing year of review.

Art. 50 AI Act has applied since 2 August 2026 in addition. Digital Omnibus Regulation (EU) 2026/1744 postponed only the machine-readable marking under Art. 50(2) AI Act for systems placed on the market before that date, namely to 2 December 2026. As regards competence, a distinction has to be drawn in Germany: under the KI-MIG, the Federal Network Agency is the central market surveillance authority, but for media services used for journalistic or advertising purposes competence remains, pursuant to Section 2(8) KI-MIG, with the authorities designated under state law.

 

What remains open for the booking party

What remains unresolved above all is which labelling obligations apply to the booking party itself, independently of how the platform operator implements them, and who is the controller under data protection law once the booking party deploys its own measurement tools. The third article in this series addresses both questions. For companies whose staff use ad-funded plans in their day-to-day work, there is the added point that conversation content feeds into ad selection there. What this means for trade secrets and for professionals bound by professional secrecy has barely been examined so far.

We would be glad to support you in reviewing your campaigns in the AI environment, in designing labelling and measurement, and in assessing the allocation of roles under data protection law.

09/21/2026, Helena Kasper, Moritz Mehner

The New EU FDI Screening Regulation – What Companies Should Consider Now

At the beginning of 2026, the European Commission, the Council of the European Union, and the European Parliament reached an agreement on the reform of the European Investment Control Regulation (Regulation (EU) 2019/452). However, the new regulation (EU) 2026/1386, known as the "EU Screening Regulation 2026," will primarily take effect from 2028. Nevertheless, it is advisable for companies to assess the implications of this regulation now and to take early action.

 

When Do the New Rules Take Effect?

The timing of the new rules is particularly significant for companies. The EU Screening Regulation 2026 was published on June 26, 2026, and will come into force on July 16, 2026. After an 18-month transition period, it will apply directly from January 17, 2028. By this date, all EU member states must have investment screening mechanisms that meet at least the requirements set forth in the regulation.

Germany will incorporate these regulations into a standalone Investment Screening Act (IPG), which will consolidate and systematize the existing regulations currently spread across the Foreign Trade Act (AWG) and the Foreign Trade Regulation (AWV). This should facilitate the examination of approval or notification requirements for companies in the future. The IPG is expected to be initiated "in a timely manner" according to previous announcements.

 

What Changes Are Fundamental in the EU?

The most significant structural change is the requirement for all member states to establish an investment screening regime. While the previous regulation allowed member states to decide whether to control foreign investments, the reform now mandates minimum harmonization. The era in which certain countries deliberately opted out of FDI screening, thus providing more attractive "hubs" for foreign investors, is over.

The regulation also establishes a common minimum catalog of sectors that must undergo prior screening for foreign investments and cannot be executed without approval. This includes companies developing, manufacturing, or marketing dual-use goods as defined by the EU Dual-Use Regulation, companies involved with goods or technologies listed on the EU Military Goods List, and companies in particularly sensitive technology sectors such as semiconductors, quantum technology, or certain forms of artificial intelligence. Additionally, operators of critical energy, transport, and digital infrastructure, companies exploring, extracting, processing, or stockpiling strategic raw materials, central financial market infrastructures, and operators of specific systems for conducting and evaluating elections are included.

The regulation introduces a two-stage review process modeled after merger control practices. In the first phase, the competent authority must decide within 45 days of a complete application whether to approve the investment or require a more in-depth review. This standardizes the often heterogeneous duration of the initial review phase across member states. Although the regulation does not set a binding deadline for the second phase, it remains at the discretion of the member states. However, the clearly defined first phase provides companies with greater planning certainty for short-term deal timing.

Another key point is the possibility of ex officio reviews. Even investments that are not subject to reporting can be reviewed within a period of up to five years, depending on the nature of the acquisition, if there are indications of potential impacts on security or public order. This existing regulation in Germany means that even seemingly "small" or "low-risk" transactions will not completely escape the authorities' scrutiny.

The substantive review criteria will also be tightened. While the review standard remains formally unchanged-focusing on potential negative impacts on security and public order-the regulation adds a detailed list of protected goods and investor-related factors that must be considered.

Finally, the cooperation mechanism within the EU will be reformed. The number of cases required to be reported and commented on will be reduced and focused on particularly critical investments. Simultaneously, the accountability of member states will increase: they will now have to explain to the Commission and other states to what extent they have considered opinions and comments and why they may have made different decisions. This increases the likelihood that investment decisions in one member state will also be made under the scrutiny of other states and the Commission.

Additionally, the establishment of a European database is planned to track whether and what measures have been taken against foreign investors.

 

What Does the Reform Mean for German Companies?

Germany is among the member states that have had an extensive investment screening regime for many years. From the perspective of German companies, the new EU regulation is not a completely new instrument but rather a tightening and structuring of what is already established practice.

The German investment review already covers both direct and indirect acquisitions, including investments through EU companies controlled by non-EU entities. Therefore, the explicit inclusion of indirect investments at the EU level is more of a confirmation than a disruption for Germany. The two-stage review process-preliminary review and formal review-is already standard practice in Germany.

Nonetheless, German companies will experience significant changes. Firstly, there will be a comprehensive assessment of all dual-use goods and goods listed in the EU Common Military List, ensuring that security-relevant products and technologies are systematically included in the review. Secondly, the scope of artificial intelligence will explicitly extend to defense and aerospace-appropriate AI systems; simultaneously, the definition of AI will be aligned with the provisions of the EU AI Act to ensure uniform and contemporary regulation. Furthermore, critical infrastructures will be mandatorily considered, particularly in the areas of transport, digital infrastructure, financial services, and election infrastructure, to adequately reflect the sensitivity of these sectors. Finally, the list of critical raw materials will be expanded to better account for supply security and the strategic importance of these materials within the investment review.

A central change also concerns the previous privileging of certain third countries. In the German investment review, investors from EFTA states like Switzerland or Norway were partially treated as EU investors and thus privileged in sensitive areas. The EU Screening Regulation 2026 prohibits discriminatory differences between third countries. For German companies with EFTA investors, this means that transactions previously considered "quasi EU-internal" will now fall fully under the scope of third-country investment control.

The procedural deadlines will also change. The first review phase currently lasts two months under German law; at the EU level, a uniform period of 45 days is now established.

Importantly, the information requirements for applications will be expanded. The documents and information previously specified in a general decree will not suffice to cover all the information required under the cooperation mechanism. Companies will now be expected to disclose their corporate structure in detail, describe activities in other member states, identify participations in EU projects of particular interest, and specify larger EU grants received in the past. Transparency in ownership and control structures will be particularly important: the more complex and opaque a structure is, the more likely authorities will view it as a risk indicator.

 

What Should Companies Do Now?

For companies, the reform means that they can no longer treat investment control as a "post-factum specialty" but must integrate it into their governance and transaction processes. They need to identify early on whether and to what extent they are active in any of the sectors that will be particularly sensitive in the future. This requires a detailed analysis of products, technologies, raw materials, and infrastructure functions. Particularly for dual-use goods, it is insufficient to consider only classic export goods; research, development, and pure marketing activities may also fall within the scope of application.

Simultaneously, companies should critically review their investor and ownership structures. Open questions regarding economic entitlement, potential state influences, or connections to sanctioned or high-risk jurisdictions should be clarified early on. The better these structures are documented and transparent, the lower the risk that they will be perceived as a risk factor in the review.

Additionally, it is advisable to clearly define internal responsibilities. Investment control is not solely a legal issue; it touches on strategy, finance, compliance, IT, and sometimes public policy. Companies are well advised to designate fixed points of contact, establish processes for the preparation and coordination of applications, and harmonize interfaces with other regulatory areas-particularly antitrust law, export controls, and sanctions law. Where complex international transactions are planned, a central "FDI Taskforce" can help synchronize different review regimes and deadlines, thereby avoiding delays.

Finally, German companies should closely monitor the development of the Investment Screening Act. It will be crucial to see how the German legislator implements the EU minimum catalog in detail, whether additional sectors will be voluntarily included, and how threshold values and review standards will be defined. Industries that are mentioned in the regulation as protected goods but not as mandatory review segments-such as manufacturers of critical pharmaceuticals or certain media companies-will have a particular interest in the specific national implementation.

09/21/2026, Maria Rothämel

AI Flash: AI literacy Under Article 4 of the AI Act: A Look at the New (Old) Questions

Following our report on the GEMA v. Suno case in our last AI Flash, we would like to continue providing you with regular legal insights into current developments in AI law.

 

Today’s topic: AI literacy under Article 4 of the AI Act

Hardly any provision of the AI Regulation affects as many companies in practice as Article 4 of the AI Act on so-called “AI literacy.” It applies regardless of risk class or industry and thus to anyone who offers or operates AI systems. This is already relevant simply when using ChatGPT, Copilot, or comparable tools in everyday work. The provision has now been amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744 of July 8, 2026, in effect since July 27, 2026). This is reason enough to take another detailed look at the regulation.

 

I. What Has Changed?

In its original version, Article 4 of the Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence  (AI Act) required providers and operators to ensure, to the best of their ability, that their personnel possessed a sufficient level of AI literacy. This wording faced criticism for implying a success that companies could hardly guarantee reliably.

The Digital Omnibus on AI has made adjustments. Article 4 AI Act now states:

(1) Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.

(2) The Commission and the Member States shall support and facilitate the efforts of providers and deployers of AI systems, in particular SMEs, in fulfilling their obligation under paragraph 1 of this Article. For that purpose, the Commission shall publish practical examples of how to comply with that obligation on the single information platform referred to in Article 62(3), point (b).

(3) The Board shall adopt recommendations, taking into account European competence frameworks, to support the Commission and Member States in the promotion of AI literacy required under paragraph 1, including by setting out common objectives.

Thus, the obligation has shifted from "ensuring" a level of competence to supporting the development of AI literacy through appropriate measures - explicitly without guaranteeing a specific individual competence level. 

Notably, what was not included in the new version of the regulation is significant: the original Commission proposal aimed to largely shift the responsibility for promoting AI literacy to the EU and the Member States. This fundamental realignment did not prevail in the trilogue. The obligation remains-albeit mitigated-with the providers and operators themselves. The only new aspect is the accompanying support from the Commission, Member States, and the AI Committee (paragraphs 2 and 3).

 

II. What Does "AI literacy" Actually Mean?

The term "AI literacy" is not defined in Article 4 AI Act but is elaborated in the definition provided in Article 3 No. 56 AI Act. According to this, AI literacy refers to the "skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations in the context of this Regulation, to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and possible harm it can cause."

Thus, AI literacy is not merely technical niche knowledge but a bundle of technical understanding, risk awareness, and legal and ethical basic understanding. It addresses all actors along the AI value chain - from developers and operational staff to individuals who use AI systems on behalf of the company, such as external service providers.

Importantly for practice: Article 4 AI Act does not prescribe a specific training format, certification, or a dedicated "AI Officer." Internal training, e-learning, workshops, or external training are all permissible-what matters is that the measures fit the technical knowledge level, experience, context of use, and risk profile of the respective target group. Both the Federal Network Agency and the AI Service Center Austria of the RTR explicitly recommend documenting the measures taken (type of training, content, timing, affected groups) to demonstrate compliance with Article 4 AI Act if necessary, even though no legally mandated proof standard currently exists.

 

III. The (Highly Problematic) Question of Sanctions

The question remains, particularly contentious in practice: What happens if a company fails to promote AI literacy?

1. No Immediate Fine Under Article 99 AI Act

First, the good news: Article 99 AI Act lists the provisions subject to fines exhaustively. Article 4 AI Act is not mentioned there. Therefore, the regulation does not provide for an immediate fine specifically for violations of the AI literacy obligation - this is confirmed by both the Austrian AI Service Center of the RTR and the Federal Network Agency.

However, a violation is not without consequences. Some literature suggests that national market surveillance authorities - in Germany, the Federal Network Agency - can address violations of Article 4 AI Act based on national regulations with other enforcement measures. Moreover, and practically more significant, Article 4 AI Act exerts its effect mainly indirectly, through general civil and corporate law.

2. Employer Liability Under § 278 BGB

If a company uses AI systems, it bears the entrepreneurial risk as an operator and is responsible for the proper organization of operations and work equipment. If damage occurs to customers or business partners - due to incorrect operation of an AI system, unverified adoption of erroneous AI outputs, or inputting business secrets into an external AI system - the employer is liable under § 278 BGB for the fault of its employees as vicarious agents. Article 4 AI Act reinforces an existing duty of care and effectively becomes the benchmark against which the appropriateness of the organizational measures taken is assessed. If there is a complete lack of a traceable training and governance structure, the assumption of a breach of duty of care is likely.

3. Recourse Against Employees

Conversely, a company that suffers damage can seek recourse from responsible employees under the principles of internal damage compensation. Here, an interesting interaction emerges: in cases of slight negligence, the employee is typically not liable; in cases of moderate negligence, only partially; full liability generally only arises in cases of gross negligence or intent. Literature suggests that the success of a recourse claim may depend on whether the employer has fulfilled its training obligation under Article 4 AI Act. A company without a robust training concept may find itself at a disadvantage in a serious case - even with potentially gross negligence on the part of employees.

4. Liability of Management and Board

Finally, the question also concerns the management level itself. Managing directors of a GmbH (§ 43 Abs. 1 GmbHG) and board members of an AG (§§ 76, 93 Abs. 1 AktG) are obliged to take the necessary organizational measures to ensure compliance with legal behavior within the company - such as through a compliance management system that also incorporates the AI literacy obligation. If they violate this obligation culpably and the company suffers damage as a result, internal liability under § 43 Abs. 2 GmbHG or § 93 Abs. 2 S. 1 AktG may apply. The recognized business judgment rule in German law provides only limited assistance here: whether or not to establish a compliance system with a training concept is not a matter of entrepreneurial discretion but is legally mandated. Entrepreneurial discretion exists only regarding the specific design - as long as an appropriate minimum standard is maintained.

Interim Conclusion: While Article 4 AI Act is not subject to fines, it is by no means without consequences. The actual "sanctioning" occurs through the backdoor of general liability law - and this makes the norm more relevant for business practice than the absence of a fine might initially suggest.

 

IV. Looking Beyond the Obligation: Added Value in Practice

While the legal discussion of liability risks is certainly justified, our consulting practice with numerous in-house training sessions and workshops on AI literacy reveals another often underestimated effect: the real value does not arise only in disputes but already in the training room itself. In almost every format we have facilitated, most of the staff's open questions - from responsibility for AI outputs to handling confidential data and copyright issues - could be clarified through direct exchange.

Practical uncertainties in daily interactions with AI tools can often be resolved easily before they become actual problems. Moreover, through shared exchange, a collective awareness within the company is created. AI literacy is then not perceived as an abstract compliance requirement but as a jointly developed standard that the staff supports.

 

V. Conclusion and Outlook

The Digital Omnibus on AI has made Article 4 AI Act more practical without abandoning the obligation itself. The absence of a fine does not change the fact that deficiencies in AI literacy can become relevant under general civil, labor, and corporate law - for the company, for employees in recourse cases, and for the management level alike. Those who take this framework seriously and simultaneously leverage the practical value of training and workshops not only create legal certainty but also foster a sense of shared sovereignty in dealing with AI within the company.

 

SKW Schwarz is happy to assist you in designing suitable training programs and accompanying you in conducting initial workshops on AI literacy in your company. Please feel free to contact us so that we can jointly create the greatest possible value for your business.

09/07/2026, Marius Drabiniok, Dr. Oliver Hornung

Beyond EU Borders: What the Kodak/Fujifilm Decision Means for UPC Patent Litigation

Under certain conditions, the Unified Patent Court (UPC) can also rule on claims concerning the UK part of a classic European patent. This was clarified by the UPC Court of Appeal in its decision of 2 June 2026 in the Kodak/Fujifilm case (UPC_CoA_312/2025).

Following Brexit, the United Kingdom does not participate in the UPC. The UPC therefore has no jurisdiction over purely national UK patents. The situation can be different for the UK part of a classic European patent: Where the UPC has international jurisdiction over the defendant, in particular because the defendant is domiciled in a UPC Contracting Member State, the UPC may, according to the case law in Fujifilm v Kodak, also rule on alleged acts of infringement in the United Kingdom.

The Court of Appeal thus confirms the practical significance of the UPC’s so-called “long-arm jurisdiction”. This may offer considerable advantages for patent proprietors, as cross-border infringement claims can potentially be consolidated before a single court rather than pursued in parallel proceedings across multiple jurisdictions. This can streamline litigation, reduce costs and minimise the risk of conflicting decisions.

At the same time, relying on the UPC’s long-arm jurisdiction requires careful analysis and preparation. International jurisdiction merely provides access to the Court; it does not relieve the patent proprietor of the need to establish both infringement and the individual defendant’s responsibility for the alleged infringing acts. This is precisely where Fujifilm’s case ultimately failed. The Court of Appeal set aside the first-instance decision. In Germany, Kodak was able to rely on a right of prior use. As regards the United Kingdom, Fujifilm had failed to establish that the German Kodak entities named as defendants had themselves committed relevant acts of infringement in the UK or could be held legally responsible for acts committed by a UK group company. The Court’s assessment turned on the specific supply chain, ownership structure and economic control over the products. The mere fact that a German group company manufactured products for a UK company was not sufficient to attribute the latter’s importation or distribution activities in the UK to the German entity.

At the same time, the assessment remains challenging and requires particularly careful preparation: International jurisdiction merely provides access to the court. It neither dispenses with the need to establish patent infringement nor with the requirement to attribute the alleged acts to the specific defendant entity. This was precisely where Fujifilm failed in the case at hand. The Court of Appeal set aside the first-instance decision. In Germany, Kodak was able to rely on a right of prior use. With regard to the United Kingdom, however, it had not been sufficiently established that the German Kodak companies being sued had themselves carried out relevant acts of infringement there or that they were legally liable for such acts by a UK group company. The decisive factors were the specific supply chain, ownership structures and the economic control over the products. The mere fact that a German group company manufactured products for a UK company was not sufficient to hold the German entity responsible for the UK company’s subsequent import and distribution activities in the United Kingdom.

The decision therefore does not provide a carte blanche for cross-border litigation before the UPC. It does, however, demonstrate that, when dealing with classic European patents, companies should not shape their patent and litigation strategies solely around the territorial boundaries of the UPC Contracting Member States.

For defendants, intra-group manufacturing and distribution structures may offer potential lines of defence. For each market concerned, the patent proprietor must specifically plead and prove which group entity is responsible for the relevant acts of infringement; mere membership of the same corporate group is not sufficient. Companies facing infringement claims should therefore ensure that their manufacturing locations, supply chains and contractual arrangements, transfers of title, as well as the entities exercising actual decision-making authority and control over distribution, are clearly documented from an early stage.

Fujifilm v Kodak thus confirms that the UPC’s reach may extend beyond UPC Contracting Member States. Whether a cross-border infringement claim ultimately succeeds, however, will depend on the specific acts of infringement at issue and, crucially, on whether those acts can be attributed to the individual defendant.

 

09/01/2026, Margret Knitter

SKW Schwarz is advising the MM Group on the acquisition of the recycled cardboard plant from the R.D.M. Group

SKW Schwarz advised Mayr-Melnhof Karton AG (MM Group) on the acquisition of the business operations of the recycling cartonboard mill in Arnsberg from the R.D.M. Group. Through the transaction, structured as an asset deal, the MM Group is investing in its core business and expanding its production network. The Arnsberg mill is one of the established production sites for recycled cartonboard in Europe.

The closing of the transaction is still subject to regulatory approval under competition law. The acquisition is expected to be completed by the end of the year.

Based in Vienna, the MM Group is a leading provider of fiber-based packaging solutions, with a focus on recycling and sustainability. The listed company employs around 13,000 people at 60 sites across three continents.

Headquartered in Milan, the R.D.M. Group is a leading European manufacturer of cartonboard for packaging.

Advisers to MM Group:
SKW Schwarz, Munich: Dr. Stephan Morsch (lead), Marion Anzinger, Dr. Thomas Hausbeck, Dr. Angela Poschenrieder (Associated Partner; all Corporate/M&A), Michael Wahl, Sabrina Hochbrückner (Counsel; both Employment Law, Frankfurt), Dr. Klaus Jankowski (Public Law/Real Estate), Maria Rothämel (Counsel; Public Law; both Berlin); Associate: Christine Wärl (Corporate/M&A)

08/27/2026, Dr. Stephan Morsch, Marion Anzinger, Dr. Thomas Hausbeck, Dr. Angela Poschenrieder, Michael Wahl, Sabrina Hochbrückner, Dr. Klaus Jankowski, Maria Rothämel, Christine Wärl

SKW Schwarz advises OverDrive Europe on the acquisition of divibib

SKW Schwarz has advised OverDrive Europe GmbH, the European subsidiary of the leading U.S. digital library platform OverDrive,Inc., on the acquisition of divibib GmbH, the company behind the German digital lending service Onleihe, from ekz.bibliotheksservice GmbH.

Onleihe will be gradually migrated to the Libbyplatform, bringing together the digital catalogs of OverDrive and divibib for libraries and patrons across the DACH region. All other divisions of the ekz Group will not be affected by the transaction.

The acquisition deepens OverDrive’s commitment to libraries and readers in the DACH region.

OverDrive, Inc. is the company behind Libby, Sora, and Kanopy, the leading digital reading, learning, and entertainment apps for libraries and schools. OverDrive serves more than 600 public libraries, schools, and academic partners across Germany, Austria, and Switzerland.

divibib, a subsidiary of ekz.bibliotheksservice based in Reutlingen, has been operating the digital lending platform Onleihe since 2007, serving public libraries across Germany, Austria, Switzerland, and other European markets. ekz Group is a long-standing provider of services and technology for public libraries in the German-speaking countries.

The SKW Schwarz team advising OverDrive was led by Stephan Morsch (Corporate/M&A) and Stefan Peintinger (IT & Digital Business/IP), and included partner Alexander Möller (Employment), associated partner Matthias Pajunk (Procurement), counsel Eva Bonacker (Corporate/M&A), as well as associates Christine Wärl (Corporate/M&A) and Tamara Ulm (Employment).

08/21/2026, Dr. Stephan Morsch, Dr. Stefan Peintinger, Alexander Möller, Dr. Mathias Pajunk, Eva Bonacker, Christine Wärl, Tamara Ulm

Federal Labour Court: No Entitlement to the Full Disclosure or Copies of Compliance Reports

With its judgment of 16 April 2026 (8 AZR 169/25), the Eighth Senate of the German Federal Labour Court (Bundesarbeitsgericht – BAG) handed down a decision of considerable practical relevance for employers: Pursuant to Art. 15 GDPR, employees generally have no right to receive copies of complete compliance investigation reports. This is because the data subject’s right of access under data protection law relates to personal data – and generally not to the document as such.

From a corporate perspective, the judgment provides important clarification regarding the limits of data protection access requests, which employees are increasingly using to challenge internal investigations. It strengthens employers’ position against attempts to use data protection law as a gateway into internal corporate decision-making processes.

What was the case about?

The case concerned a senior employee whose conduct as a manager had been reported to the company’s ombudsperson on several occasions. The company commissioned a compliance report documenting, among other things, the allegations against the manager, statements made by whistleblowers and witnesses, assessments of their credibility, as well as legal assessments by the law firm instructed by the company. The senior employee requested copies of the compliance reports pursuant to Art. 15(1) in conjunction with Art. 15(3) GDPR.

The right to a copy of personal data does not necessarily cover complete documents

In line with the case law of the Court of Justice of the European Union (CJEU), the BAG clarified that Art. 15(1) in conjunction with Art. 15(3) GDPR does not give employees a right to receive a copy of an entire compliance report, even where the report contains personal data.

The “right to a copy” under Art. 15(3) GDPR does not constitute an independent right to obtain a document “as such”. Rather, it governs the manner in which the right of access under Art. 15(1) GDPR is to be exercised. The subject matter of that right is only personal data. Art. 15(3) GDPR, in turn, does not also confer a right to receive the entire document containing such personal data.

Under the GDPR, a right to receive copies of excerpts from documents or even complete documents may arise only where this is “essential” to enable the data subject to effectively exercise their rights. This may be the case, for example, where the processing of the data can only be understood by the employee in its context. As a general rule, the employee concerned bears the burden of demonstrating this necessity.

In the case at hand, the BAG rejected such a necessity, at least with regard to the legal assessments and client-related information contained in the compliance report. In order to understand the personal data stored in relation to the senior employee, she did not need to have access to this content. Consequently, in the BAG’s view, there was no entitlement to a copy of the complete document.

No right to copies of complete documents based on the right of access to personnel files either

The BAG also held that the right of access to personnel files (§ 26(2) SprAuG, § 83(1) BetrVG) does not give rise to a right to receive copies of complete documents.

These provisions grant employees the right to inspect their personnel files, i.e. all documents relating to their personal or professional circumstances that have an internal connection with the employment relationship. While this generally gives rise to a right to make copies to a reasonable extent, that right ends where personnel records are to be copied and disclosed “as a whole”. According to the BAG, extensive documents such as a complete compliance investigation report therefore cannot be requested solely on the basis of the right to inspect personnel files.

Of particular practical relevance is the BAG’s observation that the legal assessments and client-related information contained in such a compliance report may not even form part of the “personnel file”. This means that even if the report is stored in the personnel file, this does not automatically mean that all of its contents – in particular, internal legal assessments and strategic considerations – must be provided in copy.

Practical considerations

The BAG’s decision is consistent with the fundamental principles of data protection law that have already been confirmed by several supreme courts. Art. 15 GDPR does not establish a general right of access to files. Nor can it generally be assumed that the disclosure of documents is necessary to enable data subjects to effectively exercise their rights.

Employers can and should take a restrictive approach to requests for the disclosure of documents contained in compliance files. The obligation to provide copies is generally limited to the context of personal data. From an employer’s perspective, it is therefore advisable to take a closer look at the way personnel files and compliance processes are structured: personal factual information should be clearly separated from legal, internal and business-related content. Accordingly, compliance investigation reports should be structured separately and stored independently.

Standardised processes should also be established for responding to access requests under Art. 15 GDPR in a way that ensures employees receive their personal data completely and in an intelligible form, without requiring the employer to disclose entire compliance reports or its internal legal strategy.

 

 

08/14/2026, Tamara Ulm, Dr. Stefan Peintinger, Ferdinand Schwarz

KI-Flash: GEMA v. Suno – German Court Assesses AI Training not to be Fair Use Under US Law

On 31 July 2026, the 42nd Civil Chamber of the Munich Regional Court (Landgericht München I) issued its final judgment largely upholding GEMA's claims against the AI music generator Suno (case no. 42 O 763/25; oral hearing held on 9 March 2026). We previously reported on this on LinkedIn. The full, 137-page grounds for judgment are now available and go significantly beyond the press release issued the previous week. Below, we set out the central passages of the decision: from the memorization and adaptation of the works in Germany, to the application of US law to the reproduction during training, to the legal consequences ordered by the court.

Stream-Ripping and Open-Ended Prompts

The proceedings concerned six musical works: "Atemlos durch die Nacht" (Kristina Bach), "Rasputin" (Frank Farian, Fred Jay, George Reyam), "Big in Japan" and "Forever Young" (Marian Gold, Bernhard Lloyd, Frank Mertens), the chorus of "Mambo No. 5 A Little Bit of…" (David Lubega, Christian Pletschacher), and "Daddy Cool" (Frank Farian). The dispute did not concern the lyrics, but rather the melody, harmony, rhythm, and arrangement of the compositions. Suno had obtained access to the works by stream-ripping them from YouTube, in the process circumventing the platform's technical copy protection, the so-called Rolling Cipher. To generate the outputs at issue, the claimant used between four and 176 prompts per work, each limited to the original lyrics, the desired musical style, and the title of the work, without any further musical instructions.

Copyright Protection as a Preliminary Question

Before turning to the actual question of infringement, the chamber had to establish, for each of the six works individually, that it met the threshold for copyright protection. The chamber listened to the tracks during the hearing and evaluated the private expert opinions submitted by both parties; it rejected the defendant's request for a court-appointed expert opinion, on the grounds that the members of the chamber themselves belonged to the relevant public familiar with musical matters. For the remainder of the judgment, this examination is more of a preliminary question than the actual focus: the heart of the decision lies in what happened to the protected works during AI training and in the outputs.

Reproduction and Adaptation in Germany

On the question of whether a reproduction occurred in Germany, the chamber relied on the concept of memorization: the works were reproducibly contained within model versions v3.5 and v4, which goes beyond the mere learning of statistical patterns. The court found that both the memorization within the model (Section 16 UrhG) and the public communication of the outputs (Section 15(1), (2) UrhG) constituted an infringement, for which the defendant, not the users, was responsible, because the simple, open-ended prompts did not control the specific content of the outputs. In the chamber's view, the text and data mining exception under Section 44b UrhG did not apply. For outputs that were not identical reproductions but recognizable adaptations of the original works, the chamber additionally relied on Section 23 UrhG: a distinction between reproduction and adaptation was in any event unnecessary, since any adaptation fixed in material form simultaneously constitutes a reproduction.

No Making Available to the Public

Not every claim brought by GEMA succeeded. The claimant had also based its claims regarding public communication, in the alternative, on the right of making available to the public under Section 19a UrhG. The chamber dismissed this part of the claim: making a work available to the public requires that the public can access the work from a place and at a time individually chosen by them. Because retrieving some outputs required up to 176 identical prompts, the chamber did not consider access "at a time of the user's choosing" to have been sufficiently established. GEMA was, however, able to successfully base its claim instead on the right of public communication under Section 15(2) UrhG.

Jurisdiction of German Courts Over AI Training in the US

On the basis of the concentration rule in Section 131(2) VGG, the claimant, as a collecting society, was also able to bring the claims arising from the purely US-based training activities before the same court. This provision allows a collecting society to bundle all claims against the same infringer before a single court with jurisdiction under Section 131(1) VGG, even where different courts would otherwise have jurisdiction over individual infringing acts; the sole requirement is that the infringer is identical, not that the individual infringing acts are identical.

The Path to US Law: Article 8 Rome II and the Court's Own Research

For the reproduction occurring during training in the US, US law applied under Article 8(1) of the Rome II Regulation. The chamber highlights a private international law point that extends beyond the resolution of this particular case: the Rome II Regulation applies as a so-called loi uniforme and therefore refers not only to the law of EU member states, but also to the law of third countries such as the US. The chamber then determined the applicable US law itself, ex officio, under Section 293 ZPO, expressly declining to obtain an expert opinion: it did so on the basis of the text of the U.S. Copyright Act and relevant case law, drawing, among other things, on the library of the Max Planck Institute for Innovation and Competition in Munich. The chamber also had to close a conflict-of-laws gap with respect to the claim for information asserted in this context: while US law addresses requests for information procedurally, through pre-trial discovery, German procedural law has no equivalent instrument. The chamber addressed this by applying Section 242 BGB by analogy, to close the resulting gap in the applicable rules.

Fair Use – The Four Factors Under Warhol

The chamber examined all four factors under 17 U.S.C. § 107 in light of the Supreme Court's decision in Warhol (Andy Warhol Foundation for the Visual Arts, Inc. v. Goldsmith, 598 U.S. 508 (2023)), and found that each individual factor weighed against the defendant.

On the first factor, the purpose and character of the use, the chamber found that Suno had not created new musical works with the outputs at issue, but had instead generated recordings that closely resembled the originals, and had therefore not transformed the works. In addition, the chamber weighed the circumvention of the Rolling Cipher as a violation of the DMCA's anti-circumvention provision (17 U.S.C. § 1201(a)(1)(A)), which it treated as evidence of bad faith conduct feeding into the assessment. The chamber expressly draws a parallel to Bartz v. Anthropic, where the fact that the works originated from pirated copies already weighed against a finding of transformative use, and cites that court's statement that the outcome would have been different had the outputs at issue there been infringing. That was precisely the case with Suno.

The second factor, the nature of the work used, likewise weighed against Suno in the chamber's view, because the outputs drew not merely on facts or ideas but on the creative elements of the works, a parallel the court also drew in Kadrey v. Meta. On the third factor, the amount and substantiality of the portion used, the chamber noted that this did not involve non-public intermediate copies of the kind recognized as fair use in software reverse engineering, but rather works that became publicly accessible through the outputs. On the fourth factor, market effect, the chamber relied on actual market substitution, pointing even to publicly available YouTube tutorials showing users how to create cover versions of well-known songs using Suno. The burden of proving the absence of market harm lay with the defendant, which, in the chamber's view, had not discharged that burden.

Legal Consequences: Information, Damages, and Publication of the Judgment

In addition to the injunctive relief, the chamber awarded GEMA a claim for information regarding the acts of use undertaken since 1 July 2023, as well as a declaration of liability for damages, the latter based on 17 U.S.C. § 504(a) for the reproduction during training in the US. There is also a claim rarely seen in German copyright proceedings: GEMA may publish the operative part of the judgment, at the defendant's expense, in the Süddeutsche Zeitung within six weeks of the judgment becoming final. The defendant was further ordered to pay pre-litigation legal fees of EUR 5,049.70. The chamber rejected the defendant's request to stay the proceedings and refer the matter to the CJEU under Article 267(2) TFEU, holding that the EU law questions concerning reproduction and public communication had already been sufficiently clarified by existing CJEU case law.

Assessment and Outlook

The judgment was issued at first instance and is not yet final. As to timing: the Bartz v. Anthropic proceedings, to which the chamber repeatedly refers, were concluded on 20 July 2026 through a court-approved settlement covering roughly 482,000 books at approximately USD 3,000 each. For providers of AI-based content generators, the new judgment now provides a clear direction: in the Munich Regional Court's view, it is not the abstract transformativeness of a training method that determines the availability of a fair use defense, but the actual similarity between the specific outputs generated and the protected original works. The extent to which German courts will engage substantively with foreign law in future cases where training takes place outside the EU is likely to matter well beyond this individual case.

If you have questions regarding the copyright assessment of AI training data, we would be glad to discuss the concrete implications of this decision for your practice.

08/13/2026, Moritz Mehner, Maximilian Moll de Alba

The E-Evidence Regulation Is Coming: What Service Providers Need to Know Now – Part 2

Part 2: EEVO – Obligations, Deadlines, and Sanctions in Practice

The first part of this publication set out the basic structure of the EEVO: the two new instruments, EPOC and EPOC-PR, the range of service providers concerned, and the conditions under which a connection to the EU within the meaning of the Regulation exists. This second part now turns to the practical implementation that becomes directly relevant to service providers in an actual case: the applicable deadlines for production and preservation, the scope of the review required before execution, and the sanctions and liability consequences of non-compliance.

 

Deadlines: Production and Preservation Compared

The most striking feature is the deadlines, which are considerably shorter than those familiar from classic mutual legal assistance proceedings. For the European Production Order, the standard deadline is ten days from receipt, shortened to eight hours in emergencies (Article 10(2) and (4) EEVO). The logic underlying the European Preservation Order is different: the focus here is not on rapid production, but on freezing the status quo. The obligation to preserve the data concerned arises immediately upon receipt; the preservation itself must be maintained for 60 days and may be extended once, by 30 days, by the issuing authority (Article 11(1) EEVO). If a production order subsequently follows, the preservation obligation continues until the data is actually produced (Article 11(2) EEVO) – the two instruments can therefore be combined.

 

What Review Is Required Before Execution?

How extensive a review a service provider must carry out before execution depends largely on the category of data concerned. For an EPOC: subscriber data and traffic data used solely for user identification must be produced without further review (Article 5(3) EEVO). The position is different for anything going beyond this – for further traffic data and for content data, it must be examined whether the underlying offence falls within the catalogue of serious offences set out in Article 5(4) EEVO. For the EPOC-PR, the scope is deliberately drawn more broadly: it may be issued for any offence for which a corresponding order would be possible in a comparable domestic case under the same conditions (Article 6(3) EEVO), and it covers all categories of data.

Irrespective of the data category, the same formal review applies in both cases: is the person concerned identifiable from the information provided, and is the certificate complete and free of errors? Where there is doubt on this point, this must be indicated using the form set out in Annex III; the issuing authority must then provide clarification within five days – if it fails to do so, the obligation to execute or preserve, as applicable, lapses.

 

When May or Must Execution Be Refused?

Not every order received must actually be executed. The addressee does not have a general power to refuse – the EEVO is too heavily geared towards rapid effectiveness for that. In four narrowly defined cases, however, the addressee may, or must, refuse execution and must notify the issuing authority of this without delay: where the order is formally deficient (Article 10(6), Article 11(5) EEVO); where execution is factually impossible, for example because the person concerned is not a customer of the service provider or the data has already been lawfully deleted (Article 10(7), Article 11(6) EEVO); where there are indications of immunities, privileges, or rules on liability under press law (Article 10(5), Article 11(4) EEVO); and where there is a conflict with an obligation under the law of a third country, such as the United States or the United Kingdom (Article 17 EEVO).

The last case is likely to be the most complex in practice: the objection may be raised within ten days of receipt, and enforcement is then suspended until this procedure has concluded – the data must, however, continue to be preserved in the meantime. In the immunity and press-law cases, by contrast, the addressee does not make its own decision to refuse, but merely triggers a review by the competent authorities.

 

Sanctions and Liability: Who Bears Which Risk?

A service provider that fails, without a valid reason, to comply with an order in breach of its obligations risks fines of up to 2% of total worldwide annual turnover for the preceding financial year (Article 16(1) EEVO) – a framework that companies are likely to find familiar from other pieces of European legislation.

In practice, what is likely to matter most is whether, and how actively, a company communicates with the issuing authority: a company that promptly reports any obstacles is likely to be in a better position to rely on a recognized justification within the meaning of the provision, whereas unexplained silence increases the risk of sanctions.

The picture on liability is somewhat more reassuring: service providers are not liable to their users or third parties for damage arising solely from good-faith compliance with an EPOC or EPOC-PR (Article 15(2) EEVO) – responsibility for the lawfulness of the order remains with the issuing authority. Nor does the service provider necessarily have to bear the costs of responding to an order alone: under certain conditions, reimbursement may be claimed, to the extent that the national law of the issuing state provides for this in respect of comparable domestic orders (Article 14 EEVO).

 

What Companies Need to Do Now

All of this results in a scope of action for affected service providers that is manageable, but time critical. A point of contact ready to receive orders must be designated or appointed, internal workflows for receipt, review, preservation, transmission, and documentation must be established, and the relevant personnel should be familiar with the tight deadlines before an actual case arises. To provide a quick overview, we have summarized the key deadlines and review steps for EPOC and EPOC-PR in this one-pager.

This outlines the practical obligations arising from the EEVO. Service providers falling within the scope of the Regulation should have incorporated the deadlines, review obligations, and response duties described above into their internal processes by 18 August 2026 at the latest, in order to be able to respond in a timely and legally compliant manner in the event of an EPOC or EPOC-PR.

Would you like support in setting up or reviewing your internal processes? We would be glad to assist you in developing workflows that work in practice and to support you in preparing for 18 August 2026.

08/10/2026, Moritz Mehner

The E-Evidence Regulation Is Coming: What Service Providers Need to Know Now - Part 1

What Does the E-Evidence Regulation Cover – And Who Does It Apply To?

From 18 August 2026, Regulation (EU) 2023/1543 on European Production Orders and European Preservation Orders for electronic evidence in criminal proceedings – the e-Evidence Regulation, or EEVO for short – will become directly applicable in all Member States, including Germany, following a three-year transitional period. This date is no longer a distant prospect: in Germany, the implementing legislation, the Electronic Evidence Implementation and Enforcement Act (Elektronische-Beweismittel-Umsetzungs- und Durchführungsgesetz, EBewMG), was promulgated in March 2026; the Federal Office of Justice (Bundesamt für Justiz) has been designated as the central authority, while the Federal Network Agency (Bundesnetzagentur) is responsible for technical regulation.

Before turning to the EEVO itself, a look at the position under the law as it currently stands helps put matters into context. With the EEVO, the legislator responds to a state of affairs that has proven increasingly “very difficult” over the years. Cross-border access to electronic evidence has so far been governed by the classic mutual legal assistance procedure: a foreign authority had to submit a request to the competent German authority, which would then examine it and, where appropriate, issue its own order – only at that point was a service provider under any obligation to produce data. Depending on the case, this route could take weeks or months, while the request itself remained without consequence for the service provider in the meantime. A foreign request received directly by a service provider did not, on its own, give rise to any obligation to review or respond – it could, and generally had to, remain unanswered as long as no German order had been issued. 

In this two-part publication, we now present the EEVO, which addresses precisely this point. The first part covers its basic structure – the new instruments EPOC and EPOC-PR, the range of service providers concerned, and the scope of application. The second part will then set out the applicable deadlines, the review obligations that apply, and the sanctions that may follow non-compliance. 

In addition to these two articles, we have created a cheat-sheet that provides a quick overview of the key deadlines and review steps.
>> Read cheat-sheet <<

 

Two New Instruments: EPOC and EPOC-PR

At the heart of the EEVO are two new types of order that allow law enforcement authorities in one Member State to address service providers in another Member State directly in future – without the previously customary detour via mutual legal assistance proceedings. The European Production Order (EPOC) requires a service provider to produce specified electronic evidence, such as content, traffic, or subscriber data. The European Preservation Order (EPOC-PR) operates a step earlier: it merely requires the service provider to preserve data for a specified period so that it is not deleted before a production order, where applicable, follows.

For affected companies, this means one thing above all: both types of order take immediate effect. Unlike before, no separate involvement of a German authority is required – an order issued by another Member State becomes binding as soon as it reaches the designated point of contact within the company. What was previously described as a passive role thus becomes an active obligation to act. Whereas a service provider was previously permitted to leave a foreign request unanswered without consequence, it is now directly obligated in its own right from the moment an EPOC or EPOC-PR is received.

 

Who Is Subject to the EEVO?

The EEVO addresses service providers with a connection to the EU under Article 2(1) EEVO, irrespective of whether they are established in the EU at all. This marks an important difference from many other pieces of European legislation: a cloud provider without any European establishment can be just as affected as a German company. Under Article 3(3) EEVO, this covers in particular providers of electronic communications services (such as messaging or VoIP services), domain name registries and registrars, as well as other information society services – a category under which the Regulation expressly includes platform operators such as social networks and file-hosting services, as well as hosting providers and cloud services.

The addressee of an order is, as a general rule, the controller within the meaning of Article 4(7) GDPR, i.e. whoever determines the purposes and means of the processing. Only exceptionally may an EPOC be addressed directly to a processor: where the controller cannot be identified by the issuing authority despite reasonable efforts, or where the investigation would otherwise be jeopardized (Article 5(6) EEVO).

 

When Is There a “Connection to the EU”?

The Regulation first requires that the services be accessible to persons in a Member State – identifiable, for example, by language, currency, or targeted marketing. That alone, however, is not sufficient. In addition, there must be a substantial connection to one or more Member States, such as an establishment carrying out genuine economic activity, a significant number of users, or activity that is clearly directed at the relevant Member State. Mere technical accessibility of a website is expressly not sufficient for this purpose under Recital 29 EEVO – a service that happens to also be accessible from Germany does not thereby automatically fall within the scope of the Regulation.

 

Who Receives the Orders?

Once the question of whether a provider is covered has been resolved, the practical question remains of where an order is actually to be sent. Under Article 3(1) of Directive (EU) 2023/1544, every service provider must designate an establishment or a legal representative for the receipt of EPOCs and EPOC-PRs – by 18 August 2026 at the latest, or within six months of commencing service provision in the EU. Orders are, as a general rule, addressed exclusively to this designated point of contact (Article 7(1) EEVO). If it fails to respond in time in an emergency, or if no point of contact has yet been designated, the authority may exceptionally address another establishment of the company (Article 7(2) EEVO).

In practice, it is therefore advisable for the function internally responsible for EPOC/EPOC-PR matters – such as Legal or Compliance – to correspond to the externally designated point of contact and to be genuinely reachable. Otherwise, there is a risk that an emergency order with a particularly short deadline ends up with a group entity that is unprepared and consequently unable to respond in time.

This sets out the legal framework. What this looks like in practice – which specific deadlines apply, when an order may be refused, and what consequences follow non-compliance – is the subject of the second and final part of this series.

Would you like to assess whether, and to what extent, your company is subject to the EEVO, or do you need support in designating a point of contact for receiving orders? We would be glad to assist you with the legal assessment and with preparing for 18 August 2026.

08/06/2026, Moritz Mehner

Cyber Resilience Act: The Five Key Takeaways from the European Commission's Guidelines

The Cyber Resilience Act (CRA) introduces extensive new cybersecurity requirements for manufacturers of software, connected devices, and other products with digital elements. While most obligations will apply from 11 December 2027, manufacturers will already be required, from 11 September 2026, to report actively exploited vulnerabilities and severe security incidents.

As companies prepare for the CRA, numerous practical questions arise: When is a new software version considered a new product? What are the consequences of a substantial update? How long must security updates be provided? And do products that have already been developed need to be redesigned to comply with the CRA?

The European Commission has now published guidelines on the application of the CRA. Using practical examples, the Commission explains how it interprets key concepts and obligations under the Regulation. Although the guidelines are not legally binding, they provide important guidance for companies and, likely, for the competent authorities responsible for enforcing the CRA.

Below, we summarize the aspects of the guidelines that are particularly relevant in practice.

 

1. The 24-hour reporting deadline does not start with the first suspicion

From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents. The guidelines explain when these short reporting deadlines begin to run.

An unconfirmed indication alone does not trigger the reporting deadline. However, the manufacturer must assess it without undue delay. The reporting period begins once this initial assessment establishes with sufficient certainty that:

  • a vulnerability contained in the product is being actively exploited; or
  • a severe security incident has occurred and has affected the security of the product.

From that point onward, an initial early warning report must generally be submitted within 24 hours. A follow-up notification must be submitted within 72 hours.

For an actively exploited vulnerability, the complete report must generally be submitted within 14 days after a corrective or mitigating measure becomes available. For a severe security incident, the deadline is one month after the 72-hour notification.

Companies therefore need not only a technical reporting mechanism but also clear responsibilities for the initial assessment and escalation of potential incidents. The process should cover both external reports and findings from internal security testing. The guidelines emphasize that the initial assessment must be carried out without undue delay, particularly where the potential vulnerability poses a significant risk. These procedures should be tested in practice before 11 September 2026.

 

2. A software version is generally placed on the market only once

According to the European Commission, software that is offered as a standalone product is placed on the market when the completed version is first made available on the EU market. This applies regardless of when individual customers purchase or download the software.

The guidelines illustrate this with an example: If software version 1.0.0 is first made available for download on 1 January 2028, it is considered to have been placed on the market on that date-even if some customers download it only at a later stage. A later version, such as 1.0.1, is not considered to have been newly placed on the market unless the changes are substantial. Consequently, the original placement-on-the-market date remains decisive.

The situation may differ for different variants of the same software, for example, builds for different operating systems or packages with different functionalities. Such variants may qualify as separate products. A new software version is also considered to be placed on the market again if it has undergone a substantial modification.

This distinction is particularly important for the CRA's transitional provisions. Manufacturers should document when individual versions were first made available, which variants they treat as separate products, and what changes were introduced subsequently.

 

3. Products that have already been developed do not automatically need to be redesigned

Many products that will only be placed on the market after 11 December 2027 are already under development today or have even been fully developed. According to the guidelines, the CRA does not automatically require these products to be redesigned.

However, manufacturers must assess the cybersecurity risks of the product. Based on the technical documentation, they must be able to demonstrate that the product achieves an appropriate level of cybersecurity and complies with the CRA requirements. The required conformity assessment, the EU Declaration of Conformity, and CE marking also remain mandatory.

However, the Commission does not require manufacturers to retrospectively recreate all evidence and testing from earlier development phases. If it is no longer possible to demonstrate how cybersecurity risks were addressed during the original development process, the manufacturer may instead carry out a current risk assessment and explain how the existing product design and security measures mitigate the identified risks.

This clarification is particularly relevant for industrial products with long development cycles. Companies should review which evidence is already available for ongoing product developments and identify any documentation gaps that still need to be closed.

 

4. For software updates, the decisive factor is the cybersecurity risk-not the scope of the update

Not every major update constitutes a "substantial modification" within the meaning of the CRA. Conversely, even a small change may qualify as substantial. The decisive factor is whether the intended use of the product changes or whether new or increased cybersecurity risks arise that were not previously considered.

The Commission provides the example of a system that initially only displays operational data from machines. If the system is later updated to allow it to control those machines, its intended use changes. The update must therefore be regarded as a substantial modification.

The guidelines also set out a non-exhaustive list of assessment criteria. In particular, it should be examined whether the update:

  • introduces additional interfaces, communication channels, execution environments, or external dependencies;
  • enables new attack scenarios; or
  • significantly changes the likelihood or potential impact of attack scenarios that have already been considered.

By contrast, a significant functional enhancement does not necessarily constitute a substantial modification if it was already planned during the original development and taken into account in the risk assessment. Updates that merely remediate vulnerabilities or strengthen existing security measures generally do not constitute a substantial modification, provided that they neither change the intended purpose of the product nor introduce new or increased cybersecurity risks.

Companies should therefore align their product roadmaps with their cybersecurity risk assessments at an early stage. A technical classification as a major or minor release is not sufficient for the legal assessment. It is advisable to establish a documented process for evaluating security-relevant updates against the CRA criteria.

 

5. Five years is not a standard support period

As a general rule, the CRA requires a support period of at least five years. If a product is expected to be used for a shorter period, the support period may also be shorter. Conversely, where a product has a longer expected service life, five years will not automatically be sufficient.

This is particularly relevant for industrial installations, control systems, and other long-life products. For such products, the support period must reflect the realistically expected service life. The guidelines expressly clarify that five years should not be regarded as a universal standard for all products.

A substantial modification also does not automatically trigger a new five-year support period. The decisive question is whether the modification also affects the product's expected service life. For example, if a software update merely introduces new functionalities without extending the lifetime of the hardware or changing users' expectations, the remaining original support period generally continues to apply.

For continuously evolving software, manufacturers may, under certain conditions, limit vulnerability remediation to the most recently placed-on-the-market version. Users must be able to upgrade to that version free of charge and without additional costs. Normal efforts such as testing or configuration changes are generally not regarded as additional costs. However, if users are required to purchase new hardware or fundamentally rebuild their system environment, the manufacturer cannot rely on this simplification.

 

Practical Tip

The guidelines do not create any additional legal obligations. However, they provide important clarification on key issues that companies must address when implementing the CRA.

Manufacturers should, in particular, review whether software versions and updates are documented in a traceable manner, whether the cybersecurity risk assessment is integrated with product planning, whether support periods have been determined realistically, and whether the reporting process will be operational by September 2026.

The guidelines also address, among other topics, free and open-source software, cloud-based functionalities, spare parts, and the interaction of the CRA with vehicle regulation, the Radio Equipment Directive, and the Machinery Regulation.

 

Discover Our CRA Compliance Suite

Our CRA Compliance Suite provides modular, fixed-fee consulting services to help manufacturers, importers, and distributors of digital products implement the requirements of the Cyber Resilience Act (CRA). Contact us for more information.

07/30/2026, Dr. Daniel Meßmer, Martin Schweinoch

Protection of Trade Secrets in Employment Relationships: New Article Published in RüSiR

How can companies effectively protect their trade secrets in employment relationships?

This question is explored by our partners Dr. Rembert Niebel and Alexander Möller in their article "Trade Secret Protection in Employment Relationships", published in the latest issue of RüSiR – Journal for Defence, Homeland Security, Cyber & Space.

Trade secrets are among a company's most valuable assets. This is particularly true in the security and defence sector, where employees regularly have access to sensitive information and technical know-how. The article examines the legal framework governing trade secret protection in employment relationships and explains the safeguards already provided by the German Trade Secrets Act (Geschäftsgeheimnisgesetz – GeschGehG), as well as how these can be effectively complemented through employment contract provisions.

The authors also discuss recent case law of the German Federal Labour Court (Bundesarbeitsgericht – BAG) on confidentiality agreements. They explain why broad, generic confidentiality clauses are often insufficient and outline alternative contractual approaches available to employers. Particular attention is given to tiered confidentiality agreements for employees with access to particularly sensitive information, as well as additional legal instruments for protecting confidential business information.

While the article is primarily aimed at companies operating in the security and defence industry, it also provides valuable guidance for employers across all sectors seeking to align their trade secret protection strategies with the latest legal developments.

You can download the full article as a PDF here.

 

07/28/2026, Dr. Rembert Niebel, Alexander Möller

European Commission Publishes Guidance on the Cyber Resilience Act

The European Commission has published guidance on the implementation of the Cyber Resilience Act (CRA). The guidance is intended to support companies in the practical application of the regulation and provides clarification on a wide range of interpretative questions.

Among other topics, it addresses the scope of the Cyber Resilience Act, the classification of remote data processing solutions and open source software, substantial modifications to products, the determination of support periods, cybersecurity risk assessments, and the new reporting obligations. In addition, it includes numerous practical examples and decision-making aids, particularly for small and medium-sized enterprises (SMEs). The guidance therefore provides valuable support for the practical implementation of the new regulatory requirements.

The guidance is not legally binding. Nevertheless, it is expected to play a significant role in the interpretation and application of the Cyber Resilience Act in practice and provides companies with important guidance as they prepare for the new regulatory requirements.

The publication comes at an important point in time. As of 11 September 2026, the reporting obligations under the Cyber Resilience Act will apply. The product-specific requirements will apply to products placed on the market from 11 December 2027 onwards. Companies should use the remaining time to align their products, processes, and compliance structures with the new requirements at an early stage.

Further Information:

07/27/2026, Dr. Daniel Meßmer

Protection of Military Inventions: New Expert Article Published in RüSiR

How can military inventions be effectively protected without disclosing security-sensitive information? Our partner Markus von Fuchs addresses this question in his expert article, “The Protection of Military Inventions through Secrecy During Development, Commercialization and Infringement Proceedings”, published in the latest issue of RüSiR – Journal for Defence, Homeland Security, Cyber & Space.

Against the backdrop of an evolving security landscape and the growing importance of dual-use technologies, the article examines the challenges of protecting military innovations. It explains why traditional patent strategies do not always provide adequate protection in the defence sector and explores the role of secret patents and trade secret protection. The article also discusses how technological developments – particularly in the fields of drone and cyber technologies – influence the choice of appropriate protection strategies.

Another key focus is the legal framework governing secret patents under German law. The article outlines the requirements for classifying an invention as a secret patent, the procedures before the German Patent and Trade Mark Office (DPMA), and the legal implications of secrecy orders. It also examines the impact on patent infringement proceedings, security clearance requirements, and the commercial exploitation and licensing of security-relevant technologies.

Finally, the article demonstrates that the choice between patent protection and confidentiality has become an increasingly strategic decision. Particularly for technologies with short innovation cycles or significant security relevance, a multi-layered protection strategy – combining technical intellectual property rights with a robust confidentiality framework consisting of technical, organisational and contractual measures – may provide the most effective means of safeguarding innovation over the long term.

You can download the full article as a PDF here.

07/27/2026, Markus von Fuchs

CJEU Judgment on Geoblocking: The Limits of the Borderless Internet

While information on the internet is accessible worldwide at any time, its legal regulations and intellectual property rights are always subject to strict territorial limits. Anyone who publishes content online must therefore be aware of the risk of infringing third-party rights abroad. The Court of Justice of the European Union (CJEU) has now ruled that effective geoblocking can prevent such infringements in other countries (judgment of 9 July 2026, Case C-788/24 – Anne Frank Fonds).

 

The Anne Frank Case: Geoblocking as Protection Against Copyright Claims

The legal proceedings involved a dispute between the Anne Frank Fonds and the Anne Frank Stichting regarding the online publication of the diaries of the world-famous Jewish teenager. While the works are already in the public domain in Belgium, they remain partially protected by copyright in the Netherlands until 2037. The defendants published a scientific edition on a Belgian website but blocked access for users from the Netherlands using geoblocking. The Anne Frank Fonds nevertheless considered this an infringement of its copyrights, arguing that users could bypass the restriction via standard VPN services.

The CJEU ruled that an unauthorized "communication to the public" — and thus an infringement of the copyrights still existing in the Netherlands — does not occur, provided that the geographical restriction is effective. To achieve this, the block must primarily correspond to the latest state of the art. Absolute security is not required. A user-side circumvention by means of VPN services does not automatically render the restriction ineffective.

 

Relevance Beyond Copyright Law

At the same time, the CJEU emphasizes conversely that an active duty applies to anyone who knows or ought to know about existing intellectual property rights abroad. Anyone who, with knowledge of such rights, fails to implement effective geoblocking measures is deemed to be targeting their content at the entire global audience (para. 42 of the judgment). The CJEU left open when such knowledge (the duty to know) can be assumed. Previous business relationships or the existence of delimitation agreements could already be sufficient.

This duty by no means affects copyright law alone. Geoblocking is also playing an increasingly important role in trademark law. An infringement of a national trademark on the internet requires that the use of the trademark actually takes place within the domestic territory. In this context, courts examine whether the use of the sign produces a noticeable economic effect in the domestic market—the so-called "commercial effect".

Whether such a domestic nexus exists must generally be assessed based on the specific circumstances of each case. Relevant factors include, among others, the language of the website, the top-level domain, information provided on the website, or—if available—specific delivery options, as well as other circumstances such as economic activity in the country. Now confirmed by the CJEU, the absence of geoblocking measures is at least a strong, if not decisive, indication that the website in question is (also) directed at the domestic public. This is likely to be particularly relevant for global websites.

 

Liability of the Website Operator, Not the VPN Provider

According to the CJEU, it is solely the website operator who is liable for ineffective technical measures — not the VPN provider whose service is used to circumvent them. This applies even if the VPN provider is aware that its service can be used to access protected content without the rights holders’ consent.

 

Conclusion

The CJEU judgment provides much-needed clarity for online business practices. Geoblocking has become a central tool for legally secure market segmentation in intellectual property law. At the same time, the lack of geoblocking measures can indicate that accessing the content from abroad is intentionally desired. Conversely, anyone who deliberately restricts their online activities to specific countries and implements this technically soundly via geoblocking can effectively eliminate liability risks abroad.
 

07/20/2026, Sandra Sophia Redeker, Dr. Thomas Hohendorf

SKW Schwarz Advises IQM Quantum Computers on the Acquisition of Assets from Quantistry GmbH

SKW Schwarz has advised the Finnish quantum computing company IQM Quantum Computers on the acquisition of selected assets from Berlin-based Quantistry GmbH. The transaction strengthens IQM’s software and simulation capabilities and further expands its technology platform for industrial applications of quantum computing.

Through the transaction, IQM is acquiring proprietary software applications, algorithms, and intellectual property from Quantistry. In addition, Quantistry’s core technical and quantum chemistry team will join IQM. The acquisition enhances IQM’s capabilities, particularly for applications in the automotive, aerospace, chemicals, materials science, and pharmaceutical industries.

The transaction was completed shortly after IQM’s business combination with Real Asset Acquisition Corp., through which IQM became Europe’s first publicly listed quantum computing company and is now listed on Nasdaq.

IQM Quantum Computers (Nasdaq: IQMX), headquartered in Espoo, Finland, is a global leader in superconducting full-stack quantum computers. IQM employs more than 400 people and operates across Europe, Asia, and North America.

Quantistry is a Berlin-based developer of a cloud-native simulation workflow platform for chemistry and materials. The company develops software solutions for research and development applications in industries including automotive, aerospace, energy storage, and pharmaceuticals.

With this transaction, SKW Schwarz further strengthens its practice advising companies in the quantum computing sector. SKW Schwarz regularly advises companies in the quantum computing and deep tech sectors on M&A transactions as well as technology and regulatory matters. The firm works closely with an international network of specialized law firms on cross-border mandates.

 

Advisors to IQM Quantum Computers
SKW Schwarz, Munich: Tobias Rodehau (Lead Partner), Dr. Alexander Karst, Eva Bonacker (Counsel; all Corporate/M&A), Dr. Matthias Orthwein (IT & Digital Business), Maria Rothämel (Counsel, Public Law, Berlin), Alexander Möller (Employment, Frankfurt), Tamara Ulm (Associate, Employment)

07/20/2026, Tobias Rodehau, Dr. Alexander Karst, Eva Bonacker, Dr. Matthias Orthwein, Maria Rothämel, Alexander Möller, Tamara Ulm

CJEU: Consumers Cannot Waive Their 14-Day Right of Withdrawal When Signing Up for a Streaming Subscription

Is the supply of a streaming service to be classified as an offer of ‘digital content’ or of a ‘digital service’ within the meaning of Articles 2(11) and (16) of the Consumer Rights Directive 2011/83/EU (hereinafter the ‘CRD’)? With regard to this question, whether a waiver of the right of withdrawal is possible (digital content) or not (digital services), opinions differ sharply.

Austria's Supreme Court sought clarity and referred this question – which ultimately determines when consumers' right of withdrawal lapses and thus goes well beyond a mere semantic distinction – to the Court of Justice of the European Union (CJEU). On July 9, the CJEU ruled in favor of stronger consumer protection (Judgment of 9 July 2026, Case C-234/25).

 

Personalized Streaming Services Constitute ‘Digital Services’

Consumers who wish to access films, series, or live sports on Sky or other streaming platforms before the expiration of the 14-day withdrawal period are typically required to waive their right of withdrawal when concluding the contract. Article 16(1)(m) in conjunction with Article 2(11) CRD provides such an exception to the right of withdrawal laid down in Article 9(1) – but only for ‘digital content’.

Following the view of the European Commission and the Advocate General, which the CJEU has adopted, streaming subscriptions generally do not constitute ‘digital content’, but rather ‘digital services’, to which this exception does not apply. Instead, the consumer's right of withdrawal expires only once the streaming provider has fully performed the contractual service (Article 16(1)(a) in conjunction with Article 2(16) CRD).

Unlike the supply of ‘digital content’, the supply of a ‘digital service’ is ‘necessarily defined by the dynamic nature of the offering proposed by the trader concerned, which goes beyond the mere stable and, as the case may be, continuous provision of specific content.’ According to the CJEU, this is the case, in particular, where ‘the offering is designed to adapt to the consumer’s individual behaviour or expectations, or to influence the manner in which the consumer uses the services concerned, for example by recommending specific content to the consumer.’ Such recommendation systems are an integral part of virtually all modern streaming services, helping users navigate an overwhelming volume of available content.

 

No Risk of Abuse Due to Appropriate Compensation

Sky Österreich Fernsehen GmbH (hereinafter ‘Sky Austria’) was unsuccessful in arguing that such an interpretation would open the door to abuse. Sky Austria pointed out that subscription numbers typically spike when a popular series’ first or final season is released, or when decisive matches in football championships take place. If customers were able to cancel their subscription immediately after viewing such content, they could effectively receive this premium programming for free.

The CJEU held that the legislature had already addressed this concern in Article 14(3) CRD, which entitles the trader to compensation proportionate ‘to what has been provided until the time the consumer has informed the trader of the exercise of the right of withdrawal, in comparison with the full coverage of the contract.’ In this regard, the trader is not required to calculate this compensation purely on a time‑proportionate basis (pro rata temporis); it may instead take the market value of the service provided as a starting point in order to reflect the differences in economic value between the offered content (for example, the final stage of a sporting competition compared with a daily television series). In plain terms, this means the compensation a consumer owes could actually exceed the monthly subscription fee; either way, charging at least a pro-rata (time-proportional) fee remains permissible. Seen in this light, the CJEU ruling is likely to be a theoretical victory for consumers – in practice, not much is likely to change, and probably rightly so.

 

Applicability to German Law

Since the Austrian provision at the centre of this request, Section 18(1)(1) and (11) of the Distance and Off‑Premises Contracts Act (Fern‑ und Auswärtsgeschäfte‑Gesetz), essentially corresponds to Sections 356(5) and (6) of the German Civil Code (Bürgerliches Gesetzbuch), the decision can readily be transposed to German law. In addition, the CRD does not expressly refer to the law of the Member States for the interpretation of the term ‘digital content’, which is why that term must be interpreted autonomously and uniformly under EU law.

 

Outlook

With this decision, the CJEU is significantly shaking up the existing landscape of streaming subscriptions, particularly since, on the one hand, the architecture of streaming services in the form of recommendation systems is affected, and on the other hand, claims for compensation in the event of withdrawal following prior streaming consumption are likely to meet with little acceptance at first.

Indirectly, the decision is also likely to have repercussions for other streaming models – whether the streaming of music tracks and podcasts via Spotify, audiobooks via Audible, or the magazine subscription with the Süddeutsche Zeitung – wherever the provider's performance goes beyond the mere provision of a single digital item. The CJEU has thus cut a dogmatic swath that points far beyond the specific question referred. In economic terms, this swath will be less significant, since compensation fees will become established for the usage that occurred prior to withdrawal.

07/17/2026, Dr. Andreas Peschel-Mehner

KI-Flash: EDPB Publishes Guidelines on Web Scraping in the Context of Generative AI

Web scraping is practically indispensable for training large AI models – and, from a data protection perspective, one of the biggest open questions: who is liable if personal data ends up in a training dataset through the automated harvesting of the open internet? On 7 July 2026, the European Data Protection Board (EDPB) addressed this question in Guidelines 03/2026, presenting a concrete assessment framework for the first time. Having already reported on the EDPB's Opinion 28/2024 on AI models in an earlier KI-Flash, we now turn to this second major development from the same plenary session. We reported separately on the Guidelines on the Anonymization of Personal Data adopted at the same time. The new web scraping guidelines are likewise open for public consultation until 30 October 2026.

 

Web Scraping for AI Training Purposes

More precisely, web scraping refers to the automated extraction of large volumes of data from publicly accessible internet sources – one of the central methods for sourcing training data for generative AI models. Until now, there was no specific, EU-wide guidance on how this practice can be reconciled with the requirements of the GDPR. The new guidelines close this gap and build on the Opinion 28/2024 mentioned above, as well as on Guidelines 1/2024 on Article 6(1)(f) GDPR. They are addressed to private entities that scrape data themselves, engage third parties to do so, or use already-scraped datasets for training or fine-tuning.

 

Controllership: Who Is Responsible for the Scraping Process?

A key question in practice concerns the allocation of roles under data protection law: the EDPB clarifies that the entity carrying out the scraping is not automatically a controller within the meaning of the GDPR. What matters instead is who determines the purposes and means of the processing. If an AI developer engages a service provider to carry out scraping under documented instructions, that provider will generally qualify as a processor, while the developer is treated as the controller. Where an already-scraped dataset is reused by a third party, the scraper and the reusing AI developer are, in principle, separately responsible for their own respective processing. Only where both parties jointly determine the purposes and means does joint controllership come into consideration.

 

Transparency: When Does the Individual Duty to Inform Not Apply?

With controllership clarified, this also raises the question of adequate transparency: the information obligations under Articles 13 and 14 GDPR pose practical difficulties for controllers engaged in web scraping, since data subjects are often not individually identifiable where data is collected indirectly. The EDPB acknowledges that individual information may be dispensed with where it proves impossible or would involve disproportionate effort (Article 14(5)(b) GDPR). This exception, however, does not apply across the board; it requires weighing the effort involved against the impact on the data subjects concerned, considering the volume and age of the data and the safeguards already in place. As a minimum measure, the EDPB requires controllers in such cases to make the information publicly available, for instance through a privacy notice specifying the categories of data, the sources and, where possible, the characteristics of the crawler used.

 

Data Minimisation: Measures Before, During and After Collection

The principle does not rule out training on large volumes of data as such, but it does require that personal data not needed for the purpose should not be collected in the first place. The EDPB proposes a multi-layered set of measures to this end. Before collection, controllers should, among other things, consider using synthetic data, define precise selection criteria, and exclude websites that structurally contain particularly sensitive data or that technically oppose scraping, for example through robots.txt, ai.txt or CAPTCHA. During and after collection, syntax-based filtering, pseudonymization and anonymization come into consideration as well. In addition, the EDPB requires controllers to ensure data quality by relying on reliable sources, timestamping the data and carrying out sample checks, to meet the principle of accuracy.

 

Legitimate Interest as the Key Legal Basis

The question of which legal basis could justify any of this in the first place usually leads, in practice, to Article 6(1)(f) GDPR: consent is practically impossible to obtain in the case of indirect, large-scale collection, which is why web scraping for generative AI is regularly based on legitimate interest instead. The EDPB applies the familiar three-step test: the existence of a legitimate interest, the necessity of the processing, and a balancing of interests. As examples of legitimate interests, it cites the development of chatbots or improvements to threat detection. In the balancing exercise, particular weight is given to data subjects' ability to control their own data, possible chilling effects arising from a sense of being under surveillance, and data subjects' reasonable expectations, for example whether a website technically excludes scraping or whether the data was made recognizably and publicly available.

Where the balancing test comes out against the data subjects, mitigating measures such as opt-out lists, shortened retention periods or enhanced transparency measures can restore the lawfulness of the processing.

 

 

Special Categories of Personal Data

Handling sensitive data also poses a particular challenge: special categories of personal data under Article 9 GDPR are, in principle, subject to a prohibition on processing that can only be lifted where one of the exceptions under Article 9(2) GDPR applies. Because it is difficult to reliably rule out in advance that sensitive data will also be captured when scraping large volumes of data, the EDPB transposes the CJEU's reasoning in GC and Others (C-136/17), concerning the responsibility of search engine operators, to the web scraping context: the prohibition under Article 9(1) GDPR then applies only within the framework of the controller's responsibilities, powers and capabilities, provided the controller takes appropriate measures to prevent and delete such data before, during and after AI development. This transposition is subject to narrow conditions: it applies only where the activity is structurally comparable to that of a search engine, and only to the incidental, unintended capture of sensitive data.

 

Practical Note

Even though the guidelines have not yet been finally adopted, they already provide clear guidance that national supervisory authorities are likely to apply when reviewing existing and future training data pipelines. Companies that scrape data themselves, commission scraping, or purchase already-scraped datasets should promptly review their own documentation on the balancing of interests, data minimization measures and the handling of special categories of data against the criteria set out in the guidelines. The ongoing consultation also offers an opportunity to feed practical experience and concerns directly into the final text.

We would be glad to assist you in reviewing your training data pipelines for compliance with the new EDPB guidelines, as well as in preparing or updating your data protection documentation for AI training processes.

07/16/2026, Moritz Mehner, Marius Drabiniok, Dr. Oliver Hornung

Guidelines on the Anonymisation of Personal Data – European Data Protection Board (EDPB) Launches Public Consultation

On 7 July 2026, the EDPB published its long-awaited Guidelines on the anonymisation of personal data (“Guidelines”). These Guidelines are currently in draft form and are expected to be adopted following the public consultation process, which is open until 30 October 2026.

 

What is this about?

The key criterion for the application of the General Data Protection Regulation (“GDPR”) is the processing of personal data (“PD”). This concept is defined broadly in Article 4(1) GDPR. According to Recital 26, sentence 5 GDPR, the principles of data protection do not apply to anonymous information. Consequently, the GDPR does not apply to information that does not relate to an identified or identifiable natural person. Existing links between information and an identifiable individual can be removed through anonymisation.

Although this fundamental distinction in data protection law already existed before the GDPR came into force, determining when information has been anonymised to a legally sufficient standard remains both a technical and legal challenge in practice.

The former Article 29 Working Party had already addressed this issue in its respective Opinion from 2014. Over the past ten years, the Court of Justice of the European Union (CJEU) has also issued several judgments on the subject (see, for example, most recently the SRB decision).

 

Key Content of the Guidelines

The EDPB aims to provide greater clarity in distinguishing between anonymous information and personal data by establishing a practical assessment framework.

According to the EDPB, the three key criteria are No Record Isolation, No Linkage, and No Inference (see paragraphs 52 et seq. of the Guidelines).

The first criterion, No Record Isolation, requires that a dataset does not contain any attributes capable of identifying an individual. Considered on its own, the data must not constitute personal data.

The second criterion, No Linkage, builds on the first. It requires that the dataset cannot be linked to another dataset in a way that would enable the identification of a natural person.

The third criterion, No Inference, requires that no conclusions about a specific individual can be drawn from the available data. Such conclusions or inferences must also not be possible through the combination of the data with reasonably available additional information. In practical terms, it must not be possible to re-identify a natural person through analysis, linkage, or statistical inference.

These three criteria interact with one another and may be satisfied to varying degrees. What matters is that, when assessed as a whole, the information has been effectively anonymised (see paragraph 53 of the Guidelines).

 

What Happens Next?

The EDPB invites all interested stakeholders to participate in the public consultation until 30 October 2026. As discussions are currently ongoing at EU level regarding the GDPR-related provisions of the Digital Omnibus Act-which also focus (or have focused) on the concept of personal data-we expect a significant number of submissions.

In our view, the Guidelines represent an important step towards making the GDPR's requirements and the relevant case law on anonymisation more practical and easier to apply.

We will also publish an analysis once the final version of the Guidelines has been adopted.

07/15/2026, Dr. Stefan Peintinger, Martin Schweinoch

Youth Protection in Digital Services in the EU: The Commission’s Regulatory Push and What Providers Need to Know

Reddit Shows What Regulation Looks Like in Practice

On 24 June 2026, Reddit announced that it would automatically switch teen accounts in the EU to the most restrictive privacy settings – permanently locked in for 13- to 15-year-olds, set as a changeable default for 16- and 17-year-olds – and tie access to NSFW content to age verification going forward. The announcement came immediately after the European Commission’s third and final meeting of the “Special Panel on child safety online” on 16 June 2026, and coincided with ongoing DSA enforcement proceedings against several adult-content providers.

Reddit is responding to regulatory pressure coming from several directions at once. The European Commission is currently advancing youth protection in digital services not only through legislation and guidelines, but also through active enforcement. This article looks at the role the Digital Services Act (DSA) plays in this, who Article 28 DSA actually applies to, where matters are headed next, and which other rules apply alongside it.

The DSA at a Glance: A Tiered System of Obligations

The Digital Services Act (Regulation (EU) 2022/2065) has been fully applicable since 17 February 2024 and sets out the obligations of intermediary service providers in the EU. Its tiered system of obligations imposes requirements of varying scope depending on the type and size of the service – from basic transparency and reporting rules for all intermediary services, through additional obligations for hosting services and online platforms, up to the strictest requirements for very large online platforms and search engines (VLOPs/VLOSEs).

This tiering matters for correctly gauging the reach of individual provisions, such as Article 28 DSA discussed here: not every obligation applies to every service provider in the same way.

Who Does Article 28 DSA Actually Apply To?

Article 28 DSA is specifically addressed to providers of online platforms that are accessible to minors. What matters is not whether a service is expressly aimed at minors, but whether minors can access and use it at all. This covers, in particular, social networks, video and sharing platforms, and comparable services with user-generated content, such as Reddit. Under Article 19 DSA, micro and small enterprises within the meaning of EU Recommendation 2003/361/EC are exempt from the additional obligations for online platforms (Articles 19–28 DSA) and therefore also from Article 28 DSA. Purely B2B services and platforms without any meaningful accessibility to minors likewise fall outside the scope of the provision.

Nevertheless, this classification is not limited to traditional social networks. Even services that do not primarily function as social-media platforms could be covered, based on specific features typical of such platforms. 

If one or more of these features are present, services that are not traditional social media platforms may also be affected. Not least, this could include online games with public chat features or marketplaces for virtual goods, messaging services with public channels or groups, AI chatbots and virtual companions with personalized interaction, learning platforms with forums or social profiles, livestreaming services with viewer chat, as well as marketplaces and classifieds portals with user-generated listings. 

Whether an obligation under Article 28 DSA actually applies in a given case depends on an overall assessment. The decisive factors are, in particular, the wording of the terms and conditions as well as the actual user structure known to the provider—and not the service’s original target audience alone.

What the Guidelines Specifically Require from Providers

Article 28(1) DSA requires covered platforms to take appropriate and proportionate measures to ensure a high level of privacy, safety and security for minor users. The wording was deliberately left open and required further specification by the Commission.

That specification followed on 14 July 2025 in the form of guidelines containing a non-exhaustive list of risk-appropriate measures against grooming, harmful content, addictive design and cyberbullying. Key recommendations include:

  • Accounts of minors set to private by default, to guard against unwanted contact and data access;
  • Age verification for access to adult content (e.g. pornography, gambling), and age estimation where contractual minimum ages differ;
  • A risk-based approach that takes account of the platform’s nature, size, purpose and user base.

For platform operators, this may mean adjusting default settings, implementing technical age verification or estimation procedures, and documenting a risk assessment of their own service functions – the kind of measures Reddit has now put in place.

Digital Age Verification Is Coming: The EU Wallet on Its Way

In practice, the guidelines are complemented by the age-verification solution developed by the Commission (the “mini wallet”), which allows users to prove their age without disclosing any further personal data. It is technically compatible with the forthcoming EU Digital Identity Wallet and has been “feature ready” since 15 April 2026, meaning Member States and market participants can now build on it. The Commission is aiming for a Union-wide rollout of both solutions by the end of 2026. For platform operators, this points toward a single, EU-wide standard for age verification that is set to replace the patchwork of approaches used by providers so far.

How Old Is Old Enough? The Current EU Debate on Fixed Age Limits

At the same time, a fixed minimum age is under discussion. In a resolution of 26 November 2025, the European Parliament called for an EU-wide age limit of 16 for social media, video platforms and AI companions that pose risks to minors, subject to parental consent, together with a general access ban for children under 13. At national level, the expert commission “Child and Youth Protection in the Digital World,” set up by Federal Minister Karin Prien in September 2025, presented a total of 56 recommendations on 24 June 2026. According to press reports, these are said to include two alternative approaches: a statutory age limit of 13 combined with effective age verification, or service- and function-specific restrictions based on risk assessment. The ministry does not plan to publish the full recommendations until mid-July 2026. Minister Prien herself has already spoken out in favor of the first alternative. Neither approach has yet been implemented into binding law, but both signal that platform operators should prepare for stricter requirements.

Youth Protection: A Regulatory Patchwork

Depending on the specific service, other rules can apply alongside Article 28 DSA, including the German Youth Protection Act (Jugendschutzgesetz, JuSchG) for carrier media and certain gaming platforms, the Interstate Treaty on the Protection of Minors in the Media (Jugendmedienschutz-Staatsvertrag, JMStV) for telemedia with content that may impair development, the Audiovisual Media Services Directive (AVMSD) for video-sharing platforms, and the Unfair Commercial Practices Directive (UCPD) for issues such as loot boxes and manipulative in-game purchases. Which of these provisions apply alongside the DSA in a given case again depends on the specific service and its content.

Finding Your Way Through the Regulatory Jungle

As the example of Reddit shows, youth protection in the digital space is evolving dynamically across several levels at once. For providers, this adds up to an increasingly complex web of DSA rules, national law and consumer-protection requirements. We would be glad to help you navigate this regulatory environment and identify the obligations that specifically apply to your service.

07/09/2026, Moritz Mehner

Events

30

Focus topics

22

Expertise

30

Mixed

30

Further insights

Explore the latest legal developments, insights, publications and news from our firm.