Search results for

Lawyers

44

Dr. Dorothee Altenburg represents clients in all aspects of intellectual property law. She is particularly experienced in the area of trademark law. Operating in Germany as well as internationally, Dr. Altenburg devises legal strategies to establish and defend trademarks, design rights, and patents. She represents clients before the relevant authorities in Germany, in the European Union, and in WIPO proceedings. She conducts trademark registrations worldwide. She has substantial experience in drafting licensing agreements. She is acquainted with the litigation issues that arise in the environs of intellectual property and (unfair) competition law. She represents clients before customs authorities counterfeiting cases. She also coordinates EU-wide customs seizure proceedings against counterfeit products.

Dr. Altenburg further represents publishers, media companies, and artists in matters to do with copyright, publishing law, and personality rights. 

Nikolaus Bertermann has been a lawyer for a Europe-wide leading internet service provider for ten years and can therefore rely on in-depth technical expertise, a sound knowledge of the IT industry, and many years of experience as a company lawyer.

He provides comprehensive advice on all forms of classic and agile software creation and IT project contracts, the use and adaptation of open source software, and cloud computing within and outside the EU.

Mr. Bertermann conducts data protection audits, advises companies on the legally compliant design of data processing procedures within and outside corporate structures, and accompanies clients in projects to implement the requirements of the EU General Data Protection Regulation. He commented on the central provisions of the GDPR for publishing house C.H.Beck.

Eva Bonacker advises German and international clients on diverse matters of competition, M&A, corporate and general commercial law, with a special focus on European and German antitrust and competition law.

Eva Bonacker has advised clients from various industries including media, IT and software, e-commerce, publishing, information and business intelligence, energy, climate technology, and consumer goods.

Dr. Mathias Pajunk advises on all issues of public commercial law. The main focus of his work lies on advising public authorities on the award of public contracts and service concessions. This includes the monitoring of awards at all stages, including the drafting of contracts. At the same time, Dr. Mathias Pajunk represents both public authorities and bidders in the context of review proceedings. His other fields of activity include dealing with complex issues in the areas of state aid and antitrust law.

Dr. Brock specializes in IP law (trademarks, patents, designs, copyright law, etc.), unfair competition law (including advertising law), IT law, data protection law as well as distribution and contract law.

He advises comprehensively on IP matters, including the filing of national and international intellectual property rights as well as licensing and enforcement in disputes in and out of court. He further advises on innovation and know-how protection (including trade secrets), on cross-border research and development projects, on employees’ inventions law, and on standard essential patents (SEP). Furthermore, his advice includes the development of brand-based labeling and quality seal systems.

While his client base covers a wide selection of industries (for instance health care & life sciences, information technology and consumer goods), he focuses on technology-driven and innovative companies, ranging from start-ups to mid-sized companies to globally operating corporations.

Dr. Oliver M. Bühr has been advising on IT matters for many years. This includes software, hardware, projects, and outsourcing. He frequently supports his clients in all matters relating to data protection, especially in the implementation of the GDPR. He also has extensive experience in e-business and advises companies on designing their offerings on the internet. Innovative topics such as cloud computing or the advising of FinTechs are also a key part of his work. Many of the projects on which he advises have an international dimension, and he works closely with lawyers from foreign legal systems.

As a notary, he works particularly in the areas of property law, corporate law, and inheritance law.

Markus von Fuchs advises in intellectual property law, in particular in competition, patent, and trademark law as well as on the protection of know-how. He advises companies on protecting and commercially exploiting intellectual property, for example through licensing, sales, R&D, and cooperation agreements. He also focuses on the judicial and extrajudicial defense of intellectual property rights in interim injunction and principal proceedings. He further advises on border seizing procedures, initiates and advises on criminal measures relating to product and brand piracy, and on the infringement of business and business secrets. Markus von Fuchs also advises many companies on developing and introducing new technologies and business models. He has particular expertise in the optical and medical technology sectors.

Christoph Haesner’s work comprises the entire range of media law, copyright law, and entertainment law. He advises clients in the fields of film and TV, and in sales and licensing on legal issues at all stages of development, production, distribution, and evaluation of audiovisual productions, both nationally and internationally.

His work focuses on all matters pertaining to movie financing, not only for purely national projects, but also for those with major international connections.

He also advises on transactions (M&A) in the media sector. Christoph Haesner regularly supports companies throughout the transaction phase and advises on all matters arising from M&A transactions, under corporate law, contract law, copyright law, and media law.

Dr. Johann Heyde provides comprehensive legal advisory throughout media and entertainment law, in which film and television compose a main focus of his practice. Mr. Heyde advises on all aspects of national and international film and TV productions from film financing and subsidization, right clearance particularly in terms of copyright and privacy law, as well as licensing and exploitation of such productions.

Moreover, Dr. Johann Heyde’s advisory work spans all levels of digital commerce and business with a particular emphasis on improving internet portals, online services and other digital media (including on- demand platforms) and counseling on all relevant legal issues in e-commerce, some of which include terms and conditions, consumer protection, advertising and competition law, licensing and the dissemination of all forms of content over the internet.

Dr. Johann Heyde’s expertise includes his command of music law and especially collecting societies law in particular with respect to digital media.

Dr. Magnus Hirsch advises both German and international clients on a wide variety of matters which fall within the area of trademarks, designs, copyrights, patents, and unfair competition – in both preventative and contentious situations.

He also has more than 25 years of intellectual property litigation experience, having worked on numerous litigation matters regarding all kinds of IP issues and has appeared in many Federal District Courts, as well as Courts of Appeal, throughout Germany, and has represented several clients in proceedings up to the Federal Court of Justice.

In particular, his specialization comprises portfolio management as well as enforcing clients’ rights against counterfeiters, parallel importers and domain name pirates, both through court proceedings, as well as international dispute systems. Mr. Hirsch also represents clients before the German Patent and Trademark Office and the European Union Intellectual Property Office (EUIPO) registering or opposing German national trademarks and Community Trade Marks, respectively. He also has significant experience in drafting IP-related agreements, such as trademark license agreements, priority agreements and agreements with publicity agencies.

A further focus lies in the field of trademark and competition infringements on the Internet, in particular in the conduct of litigation in and out of court, also in connection with Internet domains, as well as the litigation of patent infringements.

Dr. Magnus Hirsch spent several months practicing at the Hong Kong office of an international law firm where he focused on Asian IP law, especially the enforcement of intellectual property rights in and out of court and the prosecution of product piracy and trademark counterfeiting in Southeast Asia.

Dr. Oliver Hornung advises national and international IT service providers and users in the legal structuring and negotiation of IT, project, and outsourcing contracts, as well as in matters of copyright and licensing. He is also regularly involved in distressed projects (dispute management) and advises clients in conciliation and arbitration proceedings and, where necessary, in litigation.

The regulatory environment for the use of data and corresponding technologies is complex and new legal acts are constantly being added by the European Commission. In this dynamic environment, Dr. Oliver Hornung advises his clients on all legal issues, in particular with a focus on AI compliance, Data Act, NIS-2, cyber security, cloud computing and data law.

Another focus of his legal advice is data protection with a focus on digital health and the EU's Digital Decade. If necessary, Dr. Oliver Hornung and his team defend the rights of his clients before supervisory authorities or in court.

Finally, Dr. Oliver Hornung advises start-ups on all questions relating to IT law and data protection law. In addition to his extensive practical work, Dr. Oliver Hornung is also a frequently requested lecturer in IT law and data protection law.

Klaus Jankowski advises on complex investment projects and company settlements, with a focus on public building and planning law.

For several years, he has also been advising the public sector on legislative projects and sensitive infrastructure projects.

He plays a leading role in the international network of lawyers First Law International and has excellent contacts to law firms worldwide.

Dr. Bernd Joch advises on corporate restructuring in employment law and corporate law, conducts balancing of interests and social plan negotiations, and represents his clients in arbitration proceedings.

He has many years of experience in advising companies, executive board members, general managers, and employees, in particular also in the field of dismissal protection matters.

In the area of commercial law, he advises and represents companies, in particular, in the areas pertaining to agencies and representatives.

René M. Kieselmann specializes in EU public procurement law and associated legal fields. Among others he is a member of SKW Schwarz’s IT & Digital Business and Life Sciences & Health Practice Group and has wide-ranging technical expertise in various areas. In addition to IT law, he advises on state aid law, subsidy law/grant law, and on rescue services and civil protection, i.e. the prevention of health hazards. Jointly with his team he is designing complex public procurement projects. René Kieselmann ensures adequate communication between bidders and clients, constructively conducting negotiations. SKW Schwarz advises on major bidding projects, including in the housing, in healthcare/pharmaceuticals and IT/banking sectors. He is also familiar with the structures of rescue services, civil protection, and disaster control as well as the regulatory context (SGB). Here he constructively designs award procedures on a long-term basis (“planning model”). In this connection, he also deals with issues of medical law ranging from emergency physicians to paramedics. While he is not litigating in court or before the Public Procurement Tribunal frequently, he has nevertheless gained considerable forensic experience since 2009, including at the Court of Justice of the European Union.

Norbert Klingner specializes in national and international movie/TV and advertising film production, financing, insurance, and distribution. He represents well-known producers, distributors, global distributors, and movie financing entities. His expertise ranges from negotiating and drafting contracts from the beginning of the material development to all matters related to production and financing up to the strategically correct exploitation and licensing. A selection of the film productions in which Mr. Klingner was involved can be found on the Internet Movie Database IMDb.

Margret Knitter advises her clients in all matters of intellectual property and competition law. This includes not only strategic advice, but also legal disputes. Her practice focuses on the development and defense of trademark and design portfolios, border seizure proceedings and advice on developing marketing campaigns. She advises on labelling obligations, packaging design, marketing strategies and regulatory questions, in particular for cosmetics, detergents, toys, foodstuffs and Cannabis. She represents her clients vis-à-vis authorities, courts and the public prosecutor's office.

In the field of media and entertainment, she mainly advises on questions of advertising law, in particular product placement, branded entertainment and influencer marketing. She is a member of the board of the Branded Content Marketing Association (BCMA) for the DACH region and member of the INTA Non-Traditional Marks Committee.

Dr. Olaf Kreißl is a notary and lawyer specialising in real estate, corporate and inheritance law. He provides support in real estate transactions, property development projects, land and residential property purchase agreements, corporate transactions (M&A) and all corporate law matters (corporate housekeeping, capital increases, conversion and restructuring measures, etc.). In the area of asset management and succession planning or anticipated succession, he drafts and certifies gifts, wills, marriage contracts, divorce agreements, and powers of attorney for precautionary and special purposes.

He also has many years of legal expertise in the field of real estate management and private construction and architectural law.  The focus here is also on advising on legal issues in connection with the management of real estate (commercial leasing, asset management, etc.), the realisation of construction projects and the drafting and negotiation of the corresponding real estate-specific contracts. 

Stefan Kridlo regularly advises national and international companies on all material issues of business law, commercial law, and corporate law, in particular also on corporate acquisitions.

The main focus of his many years of work is the support of real estate investors pertaining to real estate transactions and real estate portfolios, their structuring and administration. Stefan Kridlo worked as a notary until April 2025 in the areas of corporate law, real estate law and inheritance law. He also works as an executor.

Sabine Kröger is a Certified Expert for Commercial and Corporate Law as well as for Banking and Capital Markets Law and advises and represents national and international companies, executives and shareholders comprehensively in the field of corporate law and banking law.

As an experienced litigator, she also comprehensively represents her clients in court (corporate litigation / banking litigation).

Ms. Kröger's activities focus in particular on:

  • advising and representing mid-sized enterprises (SMEs) or their managing directors or shareholders in shareholder disputes and internal company disputes;
  • the assumption of committee representation for shareholders;
  • advising and representing financial investors and credit institutions in the field of credit law and collateral security law and in defending claims of clients/investors, including the representation in mass claim proceedings.

Eberhard Kromer’s traditional focus in media law is entertainment and music. He counsels artists, publishers, labels, internet service providers, managements, as well as tour promoters. He has been active and well-versed in digital commerce issues since the inception of the internet. Eberhard’s practice is constantly affected by rapidly changing e-commerce models, social media platforms and ongoing digitization (Web 4.0, Internet of Things).

Dr. Kromer’s many years of experience as General Counsel and VP Business Affairs for a global media corporation give him the insight to recognize a corporation’s operational strengths and weaknesses. This enables him to find the best solution together with and for the client.

Franziska Ladiges advises clients on all questions of IT and data protection law. Thanks to secondments and many years of experience, she has in-depth knowledge of data protection. In this area, she supports companies (from small businesses to listed companies) from various industries with the implementation of data protection compliance. In addition, she advises on various individual data protection issues, including order processing, data subject rights and international data transfer. Finally, she regularly carries out data protection quick checks for companies on site.

In addition, Franziska Ladiges has experience in drafting contracts regulating the creation, use or transfer of software. She also drafts and reviews general terms and conditions (both purchasing and sales and internet platforms) and advises on the development of online shops and internet platforms. She often represents her clients before state courts in contract disputes or data protection matters.

In the area of private clients, Christoph Meyer has special expertise in establishing and managing family foundations, the creation of succession rules for medium-sized companies and high-net-worth individuals, as well as in all matters pertaining to family law, with a focus on more complex asset situations. The drafting of wills, powers of attorney, and marriage contracts also play an important role, with a considerable proportion of cases having international relevance. Should amicable solutions not be achievable, Mr. Meyer advises the clients, with careful strategic and tactical planning, but also with the required readiness to resolve disputes, through possible legal proceedings before civil and financial courts.

Dr. Ulrich Muth advises companies, in particular banks and financial service providers.

In particular, he specializes in consulting for creditors of loan claims secured by real estate, in the monitoring of credit and reorganization negotiations, in the prevention of damage claims on account of alleged breaches of the duty of disclosure and consultation as well as in the enforcement of creditor interests in the event of the insolvency of the debtor. Based on many years of experience of proceedings in the fields of banking, commercial and company law, as well as in disputes involving competition law, Dr. Muth works together with the clients to develop economic solutions for avoiding legal disputes as well as efficient trial strategies.

Dr. Matthias Nordmann advises international groups, mid cap companies, investors and entrepreneurs on company, commercial and corporate law in particular on structuring and mergers & acquisitions. He has a special focus on transactions in IP/IT driven industries as well as real estate.

Dr. Orthwein was admitted to the bar in 2003 and became a partner at SKW Schwarz in 2011. He received his Master of Laws (LL.M.) in American Law from Boston University (USA) in 2000 and his doctorate from the University Muenster in 2003 with a topic in telecommunications law.

He advises his clients in all areas of IT law, in particular cloud and software contract law using new agile software developing and contract methods, the commercial use of data and artificial intelligence (AI) as well as digital transformation projects. Together with his clients, he develops and brings to life new digital platforms and business models. He is an experienced expert in national and international data protection law issues in particular with regard to the use of cloud services.

The Lexology Index Germany 2025 lists him as a “world's leading practitioner” in the data category. In 2025, Handelsblatt / Best Lawyers again recommends him as a lawyer in the categories “IT law” and “data protection law.” He is once again listed in the JUVE Handbook 2025 as a “frequently recommended lawyer” for IT and data protection law.


Dr. Orthwein is a lecturer for IT and data protection law in applied AI at the Technical University of Rosenheim.

Dr. Orthwein is member of the German Society for Law and Informatics, the International Association of Privacy Professionals, the German Outsourcing Association and the German-American Lawyers Association. He is Senior Vice Chairman of the Technology Law Committee of the International Bar Association.

Dr. Andreas Peschel-Mehner has provided legal counsel to all forms of digital business since the inception of the world wide web. His advisory spans start-ups, multi-channel offerings and international internet companies and focuses on all applicable legal fields with a particular emphasis on data protection and usage, terms and conditions, consumer protection, compliance, advertising, gaming and competition law, among numerous others. Dr. Andreas Peschel-Mehner also commands broad expertise in media and entertainment law, in particular issues touching on the film and television industry and those related to media production finance and the global exploitation thereof, with digital media advisory on changes to utilization models, revenue streams and video on demand platforms composing a significant part of his counsel. 

An excerpt of the projects Dr. Andreas Peschel-Mehner has accompanied can be found on the Internet Movie Database IMDb. His advisory expertise is augmented by decades of involvement with and counsel of national and international computer game publishers and studios. Finally, developments and use of KI technologies across all his expert areas has become a strategic element of his practice.

Ulrich Reber is a certified expert in international business law. Mr. Reber advises and represents German and foreign companies in civil and commercial matters with an emphasis on corporate litigation, for example in commercial and corporate disputes before civil courts and arbitration tribunals. He commands particular expertise in cross-border debt enforcement cases in and out of court. His clients include leading European and non-European companies requiring legal assistance in Germany, to whom he provides corporate legal advice with a special focus on insolvency law. Numerous clients come from the media, entertainment and IT sectors.

Legal expertise – digitally sophisticated

Stefan Schicker has been advising clients at the intersection of law, technology, and innovation for over 20 years. As an experienced and award-winning lawyer specializing in IT and IP law, he assists national and international companies in the legally compliant design of digital business models – from the design of complex internet platforms to the protection of intellectual property.

One of Stefan Schicker's special areas of expertise is the legal structuring of corporate influencer initiatives: with specially developed workshops, he supports companies in setting up corporate LinkedIn communication in a legally compliant and effective manner – in accordance with copyright, personality rights, competition law, etc. – More information.
 

Legal tech & law firm development – with leadership experience

In parallel to his legal practice, Stefan Schicker is one of the most prominent legal tech experts in the German-speaking world. As former COO and CEO of SKW Schwarz, he played a key role in shaping the digital transformation of the law firm – from strategy to operational implementation.

Today, he supports law firms and legal departments in establishing and expanding modern structures:

  • Development and introduction of AI-supported tools
  • Establishing internal teams of experts and training concepts
  • Change processes for the sustainable anchoring of digital working methods
  • Organization of law firms as companies

Stefan Schicker brings a unique combination of legal depth, technological experience, and operational law firm management to the table – recognized, among other things, as one of the “Top 3 Legal Leaders of the Year” (Best of Legal Awards).
 


For companies and law firms that don't want to wait for the future

Whether companies with digital business models or law firms undergoing change: Stefan Schicker combines legal certainty with entrepreneurial foresight – and makes complex transformations understandable, feasible, and effective – More information.

Dr. Tatjana Schroeder has extensive experience in stock corporation law and also accompanies the development of this very specific legal field through regular publications. Stock corporation law also always depends on trends in the capital market and is subject to continuous change.

Mathias Schwarz advises on movie and TV productions, copyright and personality rights, licensing, and media financing. His clients are financial institutions, private investors, movie and TV producers, as well as broadcasting and publishing companies. He also represents a number of renowned individuals in the German media industry. In addition, he has been advising a number of family offices and private clients for a long time.

Marketing Manager
HR assistance
Head of Controlling
Head of IT
Head of Marketing & Communication
Head of Business Development
Head of HR
HR Manager
Management Accounting
Senior Legal Tech Advisor
Legal Tech & Innovation Manager

News

30

The E-Evidence Regulation Is Coming: What Service Providers Need to Know Now - Part 1

What Does the E-Evidence Regulation Cover – And Who Does It Apply To?

From 18 August 2026, Regulation (EU) 2023/1543 on European Production Orders and European Preservation Orders for electronic evidence in criminal proceedings – the e-Evidence Regulation, or EEVO for short – will become directly applicable in all Member States, including Germany, following a three-year transitional period. This date is no longer a distant prospect: in Germany, the implementing legislation, the Electronic Evidence Implementation and Enforcement Act (Elektronische-Beweismittel-Umsetzungs- und Durchführungsgesetz, EBewMG), was promulgated in March 2026; the Federal Office of Justice (Bundesamt für Justiz) has been designated as the central authority, while the Federal Network Agency (Bundesnetzagentur) is responsible for technical regulation.

Before turning to the EEVO itself, a look at the position under the law as it currently stands helps put matters into context. With the EEVO, the legislator responds to a state of affairs that has proven increasingly “very difficult” over the years. Cross-border access to electronic evidence has so far been governed by the classic mutual legal assistance procedure: a foreign authority had to submit a request to the competent German authority, which would then examine it and, where appropriate, issue its own order – only at that point was a service provider under any obligation to produce data. Depending on the case, this route could take weeks or months, while the request itself remained without consequence for the service provider in the meantime. A foreign request received directly by a service provider did not, on its own, give rise to any obligation to review or respond – it could, and generally had to, remain unanswered as long as no German order had been issued. 

In this two-part publication, we now present the EEVO, which addresses precisely this point. The first part covers its basic structure – the new instruments EPOC and EPOC-PR, the range of service providers concerned, and the scope of application. The second part will then set out the applicable deadlines, the review obligations that apply, and the sanctions that may follow non-compliance. 

In addition to these two articles, we have created a cheat-sheet that provides a quick overview of the key deadlines and review steps.
>> Read cheat-sheet <<

 

Two New Instruments: EPOC and EPOC-PR

At the heart of the EEVO are two new types of order that allow law enforcement authorities in one Member State to address service providers in another Member State directly in future – without the previously customary detour via mutual legal assistance proceedings. The European Production Order (EPOC) requires a service provider to produce specified electronic evidence, such as content, traffic, or subscriber data. The European Preservation Order (EPOC-PR) operates a step earlier: it merely requires the service provider to preserve data for a specified period so that it is not deleted before a production order, where applicable, follows.

For affected companies, this means one thing above all: both types of order take immediate effect. Unlike before, no separate involvement of a German authority is required – an order issued by another Member State becomes binding as soon as it reaches the designated point of contact within the company. What was previously described as a passive role thus becomes an active obligation to act. Whereas a service provider was previously permitted to leave a foreign request unanswered without consequence, it is now directly obligated in its own right from the moment an EPOC or EPOC-PR is received.

 

Who Is Subject to the EEVO?

The EEVO addresses service providers with a connection to the EU under Article 2(1) EEVO, irrespective of whether they are established in the EU at all. This marks an important difference from many other pieces of European legislation: a cloud provider without any European establishment can be just as affected as a German company. Under Article 3(3) EEVO, this covers in particular providers of electronic communications services (such as messaging or VoIP services), domain name registries and registrars, as well as other information society services – a category under which the Regulation expressly includes platform operators such as social networks and file-hosting services, as well as hosting providers and cloud services.

The addressee of an order is, as a general rule, the controller within the meaning of Article 4(7) GDPR, i.e. whoever determines the purposes and means of the processing. Only exceptionally may an EPOC be addressed directly to a processor: where the controller cannot be identified by the issuing authority despite reasonable efforts, or where the investigation would otherwise be jeopardized (Article 5(6) EEVO).

 

When Is There a “Connection to the EU”?

The Regulation first requires that the services be accessible to persons in a Member State – identifiable, for example, by language, currency, or targeted marketing. That alone, however, is not sufficient. In addition, there must be a substantial connection to one or more Member States, such as an establishment carrying out genuine economic activity, a significant number of users, or activity that is clearly directed at the relevant Member State. Mere technical accessibility of a website is expressly not sufficient for this purpose under Recital 29 EEVO – a service that happens to also be accessible from Germany does not thereby automatically fall within the scope of the Regulation.

 

Who Receives the Orders?

Once the question of whether a provider is covered has been resolved, the practical question remains of where an order is actually to be sent. Under Article 3(1) of Directive (EU) 2023/1544, every service provider must designate an establishment or a legal representative for the receipt of EPOCs and EPOC-PRs – by 18 August 2026 at the latest, or within six months of commencing service provision in the EU. Orders are, as a general rule, addressed exclusively to this designated point of contact (Article 7(1) EEVO). If it fails to respond in time in an emergency, or if no point of contact has yet been designated, the authority may exceptionally address another establishment of the company (Article 7(2) EEVO).

In practice, it is therefore advisable for the function internally responsible for EPOC/EPOC-PR matters – such as Legal or Compliance – to correspond to the externally designated point of contact and to be genuinely reachable. Otherwise, there is a risk that an emergency order with a particularly short deadline ends up with a group entity that is unprepared and consequently unable to respond in time.

This sets out the legal framework. What this looks like in practice – which specific deadlines apply, when an order may be refused, and what consequences follow non-compliance – is the subject of the second and final part of this series.

Would you like to assess whether, and to what extent, your company is subject to the EEVO, or do you need support in designating a point of contact for receiving orders? We would be glad to assist you with the legal assessment and with preparing for 18 August 2026.

08/06/2026, Moritz Mehner

Cyber Resilience Act: The Five Key Takeaways from the European Commission's Guidelines

The Cyber Resilience Act (CRA) introduces extensive new cybersecurity requirements for manufacturers of software, connected devices, and other products with digital elements. While most obligations will apply from 11 December 2027, manufacturers will already be required, from 11 September 2026, to report actively exploited vulnerabilities and severe security incidents.

As companies prepare for the CRA, numerous practical questions arise: When is a new software version considered a new product? What are the consequences of a substantial update? How long must security updates be provided? And do products that have already been developed need to be redesigned to comply with the CRA?

The European Commission has now published guidelines on the application of the CRA. Using practical examples, the Commission explains how it interprets key concepts and obligations under the Regulation. Although the guidelines are not legally binding, they provide important guidance for companies and, likely, for the competent authorities responsible for enforcing the CRA.

Below, we summarize the aspects of the guidelines that are particularly relevant in practice.

 

1. The 24-hour reporting deadline does not start with the first suspicion

From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents. The guidelines explain when these short reporting deadlines begin to run.

An unconfirmed indication alone does not trigger the reporting deadline. However, the manufacturer must assess it without undue delay. The reporting period begins once this initial assessment establishes with sufficient certainty that:

  • a vulnerability contained in the product is being actively exploited; or
  • a severe security incident has occurred and has affected the security of the product.

From that point onward, an initial early warning report must generally be submitted within 24 hours. A follow-up notification must be submitted within 72 hours.

For an actively exploited vulnerability, the complete report must generally be submitted within 14 days after a corrective or mitigating measure becomes available. For a severe security incident, the deadline is one month after the 72-hour notification.

Companies therefore need not only a technical reporting mechanism but also clear responsibilities for the initial assessment and escalation of potential incidents. The process should cover both external reports and findings from internal security testing. The guidelines emphasize that the initial assessment must be carried out without undue delay, particularly where the potential vulnerability poses a significant risk. These procedures should be tested in practice before 11 September 2026.

 

2. A software version is generally placed on the market only once

According to the European Commission, software that is offered as a standalone product is placed on the market when the completed version is first made available on the EU market. This applies regardless of when individual customers purchase or download the software.

The guidelines illustrate this with an example: If software version 1.0.0 is first made available for download on 1 January 2028, it is considered to have been placed on the market on that date-even if some customers download it only at a later stage. A later version, such as 1.0.1, is not considered to have been newly placed on the market unless the changes are substantial. Consequently, the original placement-on-the-market date remains decisive.

The situation may differ for different variants of the same software, for example, builds for different operating systems or packages with different functionalities. Such variants may qualify as separate products. A new software version is also considered to be placed on the market again if it has undergone a substantial modification.

This distinction is particularly important for the CRA's transitional provisions. Manufacturers should document when individual versions were first made available, which variants they treat as separate products, and what changes were introduced subsequently.

 

3. Products that have already been developed do not automatically need to be redesigned

Many products that will only be placed on the market after 11 December 2027 are already under development today or have even been fully developed. According to the guidelines, the CRA does not automatically require these products to be redesigned.

However, manufacturers must assess the cybersecurity risks of the product. Based on the technical documentation, they must be able to demonstrate that the product achieves an appropriate level of cybersecurity and complies with the CRA requirements. The required conformity assessment, the EU Declaration of Conformity, and CE marking also remain mandatory.

However, the Commission does not require manufacturers to retrospectively recreate all evidence and testing from earlier development phases. If it is no longer possible to demonstrate how cybersecurity risks were addressed during the original development process, the manufacturer may instead carry out a current risk assessment and explain how the existing product design and security measures mitigate the identified risks.

This clarification is particularly relevant for industrial products with long development cycles. Companies should review which evidence is already available for ongoing product developments and identify any documentation gaps that still need to be closed.

 

4. For software updates, the decisive factor is the cybersecurity risk-not the scope of the update

Not every major update constitutes a "substantial modification" within the meaning of the CRA. Conversely, even a small change may qualify as substantial. The decisive factor is whether the intended use of the product changes or whether new or increased cybersecurity risks arise that were not previously considered.

The Commission provides the example of a system that initially only displays operational data from machines. If the system is later updated to allow it to control those machines, its intended use changes. The update must therefore be regarded as a substantial modification.

The guidelines also set out a non-exhaustive list of assessment criteria. In particular, it should be examined whether the update:

  • introduces additional interfaces, communication channels, execution environments, or external dependencies;
  • enables new attack scenarios; or
  • significantly changes the likelihood or potential impact of attack scenarios that have already been considered.

By contrast, a significant functional enhancement does not necessarily constitute a substantial modification if it was already planned during the original development and taken into account in the risk assessment. Updates that merely remediate vulnerabilities or strengthen existing security measures generally do not constitute a substantial modification, provided that they neither change the intended purpose of the product nor introduce new or increased cybersecurity risks.

Companies should therefore align their product roadmaps with their cybersecurity risk assessments at an early stage. A technical classification as a major or minor release is not sufficient for the legal assessment. It is advisable to establish a documented process for evaluating security-relevant updates against the CRA criteria.

 

5. Five years is not a standard support period

As a general rule, the CRA requires a support period of at least five years. If a product is expected to be used for a shorter period, the support period may also be shorter. Conversely, where a product has a longer expected service life, five years will not automatically be sufficient.

This is particularly relevant for industrial installations, control systems, and other long-life products. For such products, the support period must reflect the realistically expected service life. The guidelines expressly clarify that five years should not be regarded as a universal standard for all products.

A substantial modification also does not automatically trigger a new five-year support period. The decisive question is whether the modification also affects the product's expected service life. For example, if a software update merely introduces new functionalities without extending the lifetime of the hardware or changing users' expectations, the remaining original support period generally continues to apply.

For continuously evolving software, manufacturers may, under certain conditions, limit vulnerability remediation to the most recently placed-on-the-market version. Users must be able to upgrade to that version free of charge and without additional costs. Normal efforts such as testing or configuration changes are generally not regarded as additional costs. However, if users are required to purchase new hardware or fundamentally rebuild their system environment, the manufacturer cannot rely on this simplification.

 

Practical Tip

The guidelines do not create any additional legal obligations. However, they provide important clarification on key issues that companies must address when implementing the CRA.

Manufacturers should, in particular, review whether software versions and updates are documented in a traceable manner, whether the cybersecurity risk assessment is integrated with product planning, whether support periods have been determined realistically, and whether the reporting process will be operational by September 2026.

The guidelines also address, among other topics, free and open-source software, cloud-based functionalities, spare parts, and the interaction of the CRA with vehicle regulation, the Radio Equipment Directive, and the Machinery Regulation.

 

Discover Our CRA Compliance Suite

Our CRA Compliance Suite provides modular, fixed-fee consulting services to help manufacturers, importers, and distributors of digital products implement the requirements of the Cyber Resilience Act (CRA). Contact us for more information.

07/30/2026, Dr. Daniel Meßmer, Martin Schweinoch

Protection of Trade Secrets in Employment Relationships: New Article Published in RüSiR

How can companies effectively protect their trade secrets in employment relationships?

This question is explored by our partners Dr. Rembert Niebel and Alexander Möller in their article "Trade Secret Protection in Employment Relationships", published in the latest issue of RüSiR – Journal for Defence, Homeland Security, Cyber & Space.

Trade secrets are among a company's most valuable assets. This is particularly true in the security and defence sector, where employees regularly have access to sensitive information and technical know-how. The article examines the legal framework governing trade secret protection in employment relationships and explains the safeguards already provided by the German Trade Secrets Act (Geschäftsgeheimnisgesetz – GeschGehG), as well as how these can be effectively complemented through employment contract provisions.

The authors also discuss recent case law of the German Federal Labour Court (Bundesarbeitsgericht – BAG) on confidentiality agreements. They explain why broad, generic confidentiality clauses are often insufficient and outline alternative contractual approaches available to employers. Particular attention is given to tiered confidentiality agreements for employees with access to particularly sensitive information, as well as additional legal instruments for protecting confidential business information.

While the article is primarily aimed at companies operating in the security and defence industry, it also provides valuable guidance for employers across all sectors seeking to align their trade secret protection strategies with the latest legal developments.

You can download the full article as a PDF here.

 

07/28/2026, Dr. Rembert Niebel, Alexander Möller

European Commission Publishes Guidance on the Cyber Resilience Act

The European Commission has published guidance on the implementation of the Cyber Resilience Act (CRA). The guidance is intended to support companies in the practical application of the regulation and provides clarification on a wide range of interpretative questions.

Among other topics, it addresses the scope of the Cyber Resilience Act, the classification of remote data processing solutions and open source software, substantial modifications to products, the determination of support periods, cybersecurity risk assessments, and the new reporting obligations. In addition, it includes numerous practical examples and decision-making aids, particularly for small and medium-sized enterprises (SMEs). The guidance therefore provides valuable support for the practical implementation of the new regulatory requirements.

The guidance is not legally binding. Nevertheless, it is expected to play a significant role in the interpretation and application of the Cyber Resilience Act in practice and provides companies with important guidance as they prepare for the new regulatory requirements.

The publication comes at an important point in time. As of 11 September 2026, the reporting obligations under the Cyber Resilience Act will apply. The product-specific requirements will apply to products placed on the market from 11 December 2027 onwards. Companies should use the remaining time to align their products, processes, and compliance structures with the new requirements at an early stage.

Further Information:

07/27/2026, Dr. Daniel Meßmer

Protection of Military Inventions: New Expert Article Published in RüSiR

How can military inventions be effectively protected without disclosing security-sensitive information? Our partner Markus von Fuchs addresses this question in his expert article, “The Protection of Military Inventions through Secrecy During Development, Commercialization and Infringement Proceedings”, published in the latest issue of RüSiR – Journal for Defence, Homeland Security, Cyber & Space.

Against the backdrop of an evolving security landscape and the growing importance of dual-use technologies, the article examines the challenges of protecting military innovations. It explains why traditional patent strategies do not always provide adequate protection in the defence sector and explores the role of secret patents and trade secret protection. The article also discusses how technological developments – particularly in the fields of drone and cyber technologies – influence the choice of appropriate protection strategies.

Another key focus is the legal framework governing secret patents under German law. The article outlines the requirements for classifying an invention as a secret patent, the procedures before the German Patent and Trade Mark Office (DPMA), and the legal implications of secrecy orders. It also examines the impact on patent infringement proceedings, security clearance requirements, and the commercial exploitation and licensing of security-relevant technologies.

Finally, the article demonstrates that the choice between patent protection and confidentiality has become an increasingly strategic decision. Particularly for technologies with short innovation cycles or significant security relevance, a multi-layered protection strategy – combining technical intellectual property rights with a robust confidentiality framework consisting of technical, organisational and contractual measures – may provide the most effective means of safeguarding innovation over the long term.

You can download the full article as a PDF here.

07/27/2026, Markus von Fuchs

CJEU Judgment on Geoblocking: The Limits of the Borderless Internet

While information on the internet is accessible worldwide at any time, its legal regulations and intellectual property rights are always subject to strict territorial limits. Anyone who publishes content online must therefore be aware of the risk of infringing third-party rights abroad. The Court of Justice of the European Union (CJEU) has now ruled that effective geoblocking can prevent such infringements in other countries (judgment of 9 July 2026, Case C-788/24 – Anne Frank Fonds).

 

The Anne Frank Case: Geoblocking as Protection Against Copyright Claims

The legal proceedings involved a dispute between the Anne Frank Fonds and the Anne Frank Stichting regarding the online publication of the diaries of the world-famous Jewish teenager. While the works are already in the public domain in Belgium, they remain partially protected by copyright in the Netherlands until 2037. The defendants published a scientific edition on a Belgian website but blocked access for users from the Netherlands using geoblocking. The Anne Frank Fonds nevertheless considered this an infringement of its copyrights, arguing that users could bypass the restriction via standard VPN services.

The CJEU ruled that an unauthorized "communication to the public" — and thus an infringement of the copyrights still existing in the Netherlands — does not occur, provided that the geographical restriction is effective. To achieve this, the block must primarily correspond to the latest state of the art. Absolute security is not required. A user-side circumvention by means of VPN services does not automatically render the restriction ineffective.

 

Relevance Beyond Copyright Law

At the same time, the CJEU emphasizes conversely that an active duty applies to anyone who knows or ought to know about existing intellectual property rights abroad. Anyone who, with knowledge of such rights, fails to implement effective geoblocking measures is deemed to be targeting their content at the entire global audience (para. 42 of the judgment). The CJEU left open when such knowledge (the duty to know) can be assumed. Previous business relationships or the existence of delimitation agreements could already be sufficient.

This duty by no means affects copyright law alone. Geoblocking is also playing an increasingly important role in trademark law. An infringement of a national trademark on the internet requires that the use of the trademark actually takes place within the domestic territory. In this context, courts examine whether the use of the sign produces a noticeable economic effect in the domestic market—the so-called "commercial effect".

Whether such a domestic nexus exists must generally be assessed based on the specific circumstances of each case. Relevant factors include, among others, the language of the website, the top-level domain, information provided on the website, or—if available—specific delivery options, as well as other circumstances such as economic activity in the country. Now confirmed by the CJEU, the absence of geoblocking measures is at least a strong, if not decisive, indication that the website in question is (also) directed at the domestic public. This is likely to be particularly relevant for global websites.

 

Liability of the Website Operator, Not the VPN Provider

According to the CJEU, it is solely the website operator who is liable for ineffective technical measures — not the VPN provider whose service is used to circumvent them. This applies even if the VPN provider is aware that its service can be used to access protected content without the rights holders’ consent.

 

Conclusion

The CJEU judgment provides much-needed clarity for online business practices. Geoblocking has become a central tool for legally secure market segmentation in intellectual property law. At the same time, the lack of geoblocking measures can indicate that accessing the content from abroad is intentionally desired. Conversely, anyone who deliberately restricts their online activities to specific countries and implements this technically soundly via geoblocking can effectively eliminate liability risks abroad.
 

07/20/2026, Sandra Sophia Redeker, Dr. Thomas Hohendorf

SKW Schwarz Advises IQM Quantum Computers on the Acquisition of Assets from Quantistry GmbH

SKW Schwarz has advised the Finnish quantum computing company IQM Quantum Computers on the acquisition of selected assets from Berlin-based Quantistry GmbH. The transaction strengthens IQM’s software and simulation capabilities and further expands its technology platform for industrial applications of quantum computing.

Through the transaction, IQM is acquiring proprietary software applications, algorithms, and intellectual property from Quantistry. In addition, Quantistry’s core technical and quantum chemistry team will join IQM. The acquisition enhances IQM’s capabilities, particularly for applications in the automotive, aerospace, chemicals, materials science, and pharmaceutical industries.

The transaction was completed shortly after IQM’s business combination with Real Asset Acquisition Corp., through which IQM became Europe’s first publicly listed quantum computing company and is now listed on Nasdaq.

IQM Quantum Computers (Nasdaq: IQMX), headquartered in Espoo, Finland, is a global leader in superconducting full-stack quantum computers. IQM employs more than 400 people and operates across Europe, Asia, and North America.

Quantistry is a Berlin-based developer of a cloud-native simulation workflow platform for chemistry and materials. The company develops software solutions for research and development applications in industries including automotive, aerospace, energy storage, and pharmaceuticals.

With this transaction, SKW Schwarz further strengthens its practice advising companies in the quantum computing sector. SKW Schwarz regularly advises companies in the quantum computing and deep tech sectors on M&A transactions as well as technology and regulatory matters. The firm works closely with an international network of specialized law firms on cross-border mandates.

 

Advisors to IQM Quantum Computers
SKW Schwarz, Munich: Tobias Rodehau (Lead Partner), Dr. Alexander Karst, Eva Bonacker (Counsel; all Corporate/M&A), Dr. Matthias Orthwein (IT & Digital Business), Maria Rothämel (Counsel, Public Law, Berlin), Alexander Möller (Employment, Frankfurt), Tamara Ulm (Associate, Employment)

07/20/2026, Tobias Rodehau, Dr. Alexander Karst, Eva Bonacker, Dr. Matthias Orthwein, Maria Rothämel, Alexander Möller, Tamara Ulm

CJEU: Consumers Cannot Waive Their 14-Day Right of Withdrawal When Signing Up for a Streaming Subscription

Is the supply of a streaming service to be classified as an offer of ‘digital content’ or of a ‘digital service’ within the meaning of Articles 2(11) and (16) of the Consumer Rights Directive 2011/83/EU (hereinafter the ‘CRD’)? With regard to this question, whether a waiver of the right of withdrawal is possible (digital content) or not (digital services), opinions differ sharply.

Austria's Supreme Court sought clarity and referred this question – which ultimately determines when consumers' right of withdrawal lapses and thus goes well beyond a mere semantic distinction – to the Court of Justice of the European Union (CJEU). On July 9, the CJEU ruled in favor of stronger consumer protection (Judgment of 9 July 2026, Case C-234/25).

 

Personalized Streaming Services Constitute ‘Digital Services’

Consumers who wish to access films, series, or live sports on Sky or other streaming platforms before the expiration of the 14-day withdrawal period are typically required to waive their right of withdrawal when concluding the contract. Article 16(1)(m) in conjunction with Article 2(11) CRD provides such an exception to the right of withdrawal laid down in Article 9(1) – but only for ‘digital content’.

Following the view of the European Commission and the Advocate General, which the CJEU has adopted, streaming subscriptions generally do not constitute ‘digital content’, but rather ‘digital services’, to which this exception does not apply. Instead, the consumer's right of withdrawal expires only once the streaming provider has fully performed the contractual service (Article 16(1)(a) in conjunction with Article 2(16) CRD).

Unlike the supply of ‘digital content’, the supply of a ‘digital service’ is ‘necessarily defined by the dynamic nature of the offering proposed by the trader concerned, which goes beyond the mere stable and, as the case may be, continuous provision of specific content.’ According to the CJEU, this is the case, in particular, where ‘the offering is designed to adapt to the consumer’s individual behaviour or expectations, or to influence the manner in which the consumer uses the services concerned, for example by recommending specific content to the consumer.’ Such recommendation systems are an integral part of virtually all modern streaming services, helping users navigate an overwhelming volume of available content.

 

No Risk of Abuse Due to Appropriate Compensation

Sky Österreich Fernsehen GmbH (hereinafter ‘Sky Austria’) was unsuccessful in arguing that such an interpretation would open the door to abuse. Sky Austria pointed out that subscription numbers typically spike when a popular series’ first or final season is released, or when decisive matches in football championships take place. If customers were able to cancel their subscription immediately after viewing such content, they could effectively receive this premium programming for free.

The CJEU held that the legislature had already addressed this concern in Article 14(3) CRD, which entitles the trader to compensation proportionate ‘to what has been provided until the time the consumer has informed the trader of the exercise of the right of withdrawal, in comparison with the full coverage of the contract.’ In this regard, the trader is not required to calculate this compensation purely on a time‑proportionate basis (pro rata temporis); it may instead take the market value of the service provided as a starting point in order to reflect the differences in economic value between the offered content (for example, the final stage of a sporting competition compared with a daily television series). In plain terms, this means the compensation a consumer owes could actually exceed the monthly subscription fee; either way, charging at least a pro-rata (time-proportional) fee remains permissible. Seen in this light, the CJEU ruling is likely to be a theoretical victory for consumers – in practice, not much is likely to change, and probably rightly so.

 

Applicability to German Law

Since the Austrian provision at the centre of this request, Section 18(1)(1) and (11) of the Distance and Off‑Premises Contracts Act (Fern‑ und Auswärtsgeschäfte‑Gesetz), essentially corresponds to Sections 356(5) and (6) of the German Civil Code (Bürgerliches Gesetzbuch), the decision can readily be transposed to German law. In addition, the CRD does not expressly refer to the law of the Member States for the interpretation of the term ‘digital content’, which is why that term must be interpreted autonomously and uniformly under EU law.

 

Outlook

With this decision, the CJEU is significantly shaking up the existing landscape of streaming subscriptions, particularly since, on the one hand, the architecture of streaming services in the form of recommendation systems is affected, and on the other hand, claims for compensation in the event of withdrawal following prior streaming consumption are likely to meet with little acceptance at first.

Indirectly, the decision is also likely to have repercussions for other streaming models – whether the streaming of music tracks and podcasts via Spotify, audiobooks via Audible, or the magazine subscription with the Süddeutsche Zeitung – wherever the provider's performance goes beyond the mere provision of a single digital item. The CJEU has thus cut a dogmatic swath that points far beyond the specific question referred. In economic terms, this swath will be less significant, since compensation fees will become established for the usage that occurred prior to withdrawal.

07/17/2026, Dr. Andreas Peschel-Mehner

KI-Flash: EDPB Publishes Guidelines on Web Scraping in the Context of Generative AI

Web scraping is practically indispensable for training large AI models – and, from a data protection perspective, one of the biggest open questions: who is liable if personal data ends up in a training dataset through the automated harvesting of the open internet? On 7 July 2026, the European Data Protection Board (EDPB) addressed this question in Guidelines 03/2026, presenting a concrete assessment framework for the first time. Having already reported on the EDPB's Opinion 28/2024 on AI models in an earlier KI-Flash, we now turn to this second major development from the same plenary session. We reported separately on the Guidelines on the Anonymization of Personal Data adopted at the same time. The new web scraping guidelines are likewise open for public consultation until 30 October 2026.

 

Web Scraping for AI Training Purposes

More precisely, web scraping refers to the automated extraction of large volumes of data from publicly accessible internet sources – one of the central methods for sourcing training data for generative AI models. Until now, there was no specific, EU-wide guidance on how this practice can be reconciled with the requirements of the GDPR. The new guidelines close this gap and build on the Opinion 28/2024 mentioned above, as well as on Guidelines 1/2024 on Article 6(1)(f) GDPR. They are addressed to private entities that scrape data themselves, engage third parties to do so, or use already-scraped datasets for training or fine-tuning.

 

Controllership: Who Is Responsible for the Scraping Process?

A key question in practice concerns the allocation of roles under data protection law: the EDPB clarifies that the entity carrying out the scraping is not automatically a controller within the meaning of the GDPR. What matters instead is who determines the purposes and means of the processing. If an AI developer engages a service provider to carry out scraping under documented instructions, that provider will generally qualify as a processor, while the developer is treated as the controller. Where an already-scraped dataset is reused by a third party, the scraper and the reusing AI developer are, in principle, separately responsible for their own respective processing. Only where both parties jointly determine the purposes and means does joint controllership come into consideration.

 

Transparency: When Does the Individual Duty to Inform Not Apply?

With controllership clarified, this also raises the question of adequate transparency: the information obligations under Articles 13 and 14 GDPR pose practical difficulties for controllers engaged in web scraping, since data subjects are often not individually identifiable where data is collected indirectly. The EDPB acknowledges that individual information may be dispensed with where it proves impossible or would involve disproportionate effort (Article 14(5)(b) GDPR). This exception, however, does not apply across the board; it requires weighing the effort involved against the impact on the data subjects concerned, considering the volume and age of the data and the safeguards already in place. As a minimum measure, the EDPB requires controllers in such cases to make the information publicly available, for instance through a privacy notice specifying the categories of data, the sources and, where possible, the characteristics of the crawler used.

 

Data Minimisation: Measures Before, During and After Collection

The principle does not rule out training on large volumes of data as such, but it does require that personal data not needed for the purpose should not be collected in the first place. The EDPB proposes a multi-layered set of measures to this end. Before collection, controllers should, among other things, consider using synthetic data, define precise selection criteria, and exclude websites that structurally contain particularly sensitive data or that technically oppose scraping, for example through robots.txt, ai.txt or CAPTCHA. During and after collection, syntax-based filtering, pseudonymization and anonymization come into consideration as well. In addition, the EDPB requires controllers to ensure data quality by relying on reliable sources, timestamping the data and carrying out sample checks, to meet the principle of accuracy.

 

Legitimate Interest as the Key Legal Basis

The question of which legal basis could justify any of this in the first place usually leads, in practice, to Article 6(1)(f) GDPR: consent is practically impossible to obtain in the case of indirect, large-scale collection, which is why web scraping for generative AI is regularly based on legitimate interest instead. The EDPB applies the familiar three-step test: the existence of a legitimate interest, the necessity of the processing, and a balancing of interests. As examples of legitimate interests, it cites the development of chatbots or improvements to threat detection. In the balancing exercise, particular weight is given to data subjects' ability to control their own data, possible chilling effects arising from a sense of being under surveillance, and data subjects' reasonable expectations, for example whether a website technically excludes scraping or whether the data was made recognizably and publicly available.

Where the balancing test comes out against the data subjects, mitigating measures such as opt-out lists, shortened retention periods or enhanced transparency measures can restore the lawfulness of the processing.

 

 

Special Categories of Personal Data

Handling sensitive data also poses a particular challenge: special categories of personal data under Article 9 GDPR are, in principle, subject to a prohibition on processing that can only be lifted where one of the exceptions under Article 9(2) GDPR applies. Because it is difficult to reliably rule out in advance that sensitive data will also be captured when scraping large volumes of data, the EDPB transposes the CJEU's reasoning in GC and Others (C-136/17), concerning the responsibility of search engine operators, to the web scraping context: the prohibition under Article 9(1) GDPR then applies only within the framework of the controller's responsibilities, powers and capabilities, provided the controller takes appropriate measures to prevent and delete such data before, during and after AI development. This transposition is subject to narrow conditions: it applies only where the activity is structurally comparable to that of a search engine, and only to the incidental, unintended capture of sensitive data.

 

Practical Note

Even though the guidelines have not yet been finally adopted, they already provide clear guidance that national supervisory authorities are likely to apply when reviewing existing and future training data pipelines. Companies that scrape data themselves, commission scraping, or purchase already-scraped datasets should promptly review their own documentation on the balancing of interests, data minimization measures and the handling of special categories of data against the criteria set out in the guidelines. The ongoing consultation also offers an opportunity to feed practical experience and concerns directly into the final text.

We would be glad to assist you in reviewing your training data pipelines for compliance with the new EDPB guidelines, as well as in preparing or updating your data protection documentation for AI training processes.

07/16/2026, Moritz Mehner, Marius Drabiniok, Dr. Oliver Hornung

Guidelines on the Anonymisation of Personal Data – European Data Protection Board (EDPB) Launches Public Consultation

On 7 July 2026, the EDPB published its long-awaited Guidelines on the anonymisation of personal data (“Guidelines”). These Guidelines are currently in draft form and are expected to be adopted following the public consultation process, which is open until 30 October 2026.

 

What is this about?

The key criterion for the application of the General Data Protection Regulation (“GDPR”) is the processing of personal data (“PD”). This concept is defined broadly in Article 4(1) GDPR. According to Recital 26, sentence 5 GDPR, the principles of data protection do not apply to anonymous information. Consequently, the GDPR does not apply to information that does not relate to an identified or identifiable natural person. Existing links between information and an identifiable individual can be removed through anonymisation.

Although this fundamental distinction in data protection law already existed before the GDPR came into force, determining when information has been anonymised to a legally sufficient standard remains both a technical and legal challenge in practice.

The former Article 29 Working Party had already addressed this issue in its respective Opinion from 2014. Over the past ten years, the Court of Justice of the European Union (CJEU) has also issued several judgments on the subject (see, for example, most recently the SRB decision).

 

Key Content of the Guidelines

The EDPB aims to provide greater clarity in distinguishing between anonymous information and personal data by establishing a practical assessment framework.

According to the EDPB, the three key criteria are No Record Isolation, No Linkage, and No Inference (see paragraphs 52 et seq. of the Guidelines).

The first criterion, No Record Isolation, requires that a dataset does not contain any attributes capable of identifying an individual. Considered on its own, the data must not constitute personal data.

The second criterion, No Linkage, builds on the first. It requires that the dataset cannot be linked to another dataset in a way that would enable the identification of a natural person.

The third criterion, No Inference, requires that no conclusions about a specific individual can be drawn from the available data. Such conclusions or inferences must also not be possible through the combination of the data with reasonably available additional information. In practical terms, it must not be possible to re-identify a natural person through analysis, linkage, or statistical inference.

These three criteria interact with one another and may be satisfied to varying degrees. What matters is that, when assessed as a whole, the information has been effectively anonymised (see paragraph 53 of the Guidelines).

 

What Happens Next?

The EDPB invites all interested stakeholders to participate in the public consultation until 30 October 2026. As discussions are currently ongoing at EU level regarding the GDPR-related provisions of the Digital Omnibus Act-which also focus (or have focused) on the concept of personal data-we expect a significant number of submissions.

In our view, the Guidelines represent an important step towards making the GDPR's requirements and the relevant case law on anonymisation more practical and easier to apply.

We will also publish an analysis once the final version of the Guidelines has been adopted.

07/15/2026, Dr. Stefan Peintinger, Martin Schweinoch

Youth Protection in Digital Services in the EU: The Commission’s Regulatory Push and What Providers Need to Know

Reddit Shows What Regulation Looks Like in Practice

On 24 June 2026, Reddit announced that it would automatically switch teen accounts in the EU to the most restrictive privacy settings – permanently locked in for 13- to 15-year-olds, set as a changeable default for 16- and 17-year-olds – and tie access to NSFW content to age verification going forward. The announcement came immediately after the European Commission’s third and final meeting of the “Special Panel on child safety online” on 16 June 2026, and coincided with ongoing DSA enforcement proceedings against several adult-content providers.

Reddit is responding to regulatory pressure coming from several directions at once. The European Commission is currently advancing youth protection in digital services not only through legislation and guidelines, but also through active enforcement. This article looks at the role the Digital Services Act (DSA) plays in this, who Article 28 DSA actually applies to, where matters are headed next, and which other rules apply alongside it.

The DSA at a Glance: A Tiered System of Obligations

The Digital Services Act (Regulation (EU) 2022/2065) has been fully applicable since 17 February 2024 and sets out the obligations of intermediary service providers in the EU. Its tiered system of obligations imposes requirements of varying scope depending on the type and size of the service – from basic transparency and reporting rules for all intermediary services, through additional obligations for hosting services and online platforms, up to the strictest requirements for very large online platforms and search engines (VLOPs/VLOSEs).

This tiering matters for correctly gauging the reach of individual provisions, such as Article 28 DSA discussed here: not every obligation applies to every service provider in the same way.

Who Does Article 28 DSA Actually Apply To?

Article 28 DSA is specifically addressed to providers of online platforms that are accessible to minors. What matters is not whether a service is expressly aimed at minors, but whether minors can access and use it at all. This covers, in particular, social networks, video and sharing platforms, and comparable services with user-generated content, such as Reddit. Under Article 19 DSA, micro and small enterprises within the meaning of EU Recommendation 2003/361/EC are exempt from the additional obligations for online platforms (Articles 19–28 DSA) and therefore also from Article 28 DSA. Purely B2B services and platforms without any meaningful accessibility to minors likewise fall outside the scope of the provision.

Nevertheless, this classification is not limited to traditional social networks. Even services that do not primarily function as social-media platforms could be covered, based on specific features typical of such platforms. 

If one or more of these features are present, services that are not traditional social media platforms may also be affected. Not least, this could include online games with public chat features or marketplaces for virtual goods, messaging services with public channels or groups, AI chatbots and virtual companions with personalized interaction, learning platforms with forums or social profiles, livestreaming services with viewer chat, as well as marketplaces and classifieds portals with user-generated listings. 

Whether an obligation under Article 28 DSA actually applies in a given case depends on an overall assessment. The decisive factors are, in particular, the wording of the terms and conditions as well as the actual user structure known to the provider—and not the service’s original target audience alone.

What the Guidelines Specifically Require from Providers

Article 28(1) DSA requires covered platforms to take appropriate and proportionate measures to ensure a high level of privacy, safety and security for minor users. The wording was deliberately left open and required further specification by the Commission.

That specification followed on 14 July 2025 in the form of guidelines containing a non-exhaustive list of risk-appropriate measures against grooming, harmful content, addictive design and cyberbullying. Key recommendations include:

  • Accounts of minors set to private by default, to guard against unwanted contact and data access;
  • Age verification for access to adult content (e.g. pornography, gambling), and age estimation where contractual minimum ages differ;
  • A risk-based approach that takes account of the platform’s nature, size, purpose and user base.

For platform operators, this may mean adjusting default settings, implementing technical age verification or estimation procedures, and documenting a risk assessment of their own service functions – the kind of measures Reddit has now put in place.

Digital Age Verification Is Coming: The EU Wallet on Its Way

In practice, the guidelines are complemented by the age-verification solution developed by the Commission (the “mini wallet”), which allows users to prove their age without disclosing any further personal data. It is technically compatible with the forthcoming EU Digital Identity Wallet and has been “feature ready” since 15 April 2026, meaning Member States and market participants can now build on it. The Commission is aiming for a Union-wide rollout of both solutions by the end of 2026. For platform operators, this points toward a single, EU-wide standard for age verification that is set to replace the patchwork of approaches used by providers so far.

How Old Is Old Enough? The Current EU Debate on Fixed Age Limits

At the same time, a fixed minimum age is under discussion. In a resolution of 26 November 2025, the European Parliament called for an EU-wide age limit of 16 for social media, video platforms and AI companions that pose risks to minors, subject to parental consent, together with a general access ban for children under 13. At national level, the expert commission “Child and Youth Protection in the Digital World,” set up by Federal Minister Karin Prien in September 2025, presented a total of 56 recommendations on 24 June 2026. According to press reports, these are said to include two alternative approaches: a statutory age limit of 13 combined with effective age verification, or service- and function-specific restrictions based on risk assessment. The ministry does not plan to publish the full recommendations until mid-July 2026. Minister Prien herself has already spoken out in favor of the first alternative. Neither approach has yet been implemented into binding law, but both signal that platform operators should prepare for stricter requirements.

Youth Protection: A Regulatory Patchwork

Depending on the specific service, other rules can apply alongside Article 28 DSA, including the German Youth Protection Act (Jugendschutzgesetz, JuSchG) for carrier media and certain gaming platforms, the Interstate Treaty on the Protection of Minors in the Media (Jugendmedienschutz-Staatsvertrag, JMStV) for telemedia with content that may impair development, the Audiovisual Media Services Directive (AVMSD) for video-sharing platforms, and the Unfair Commercial Practices Directive (UCPD) for issues such as loot boxes and manipulative in-game purchases. Which of these provisions apply alongside the DSA in a given case again depends on the specific service and its content.

Finding Your Way Through the Regulatory Jungle

As the example of Reddit shows, youth protection in the digital space is evolving dynamically across several levels at once. For providers, this adds up to an increasingly complex web of DSA rules, national law and consumer-protection requirements. We would be glad to help you navigate this regulatory environment and identify the obligations that specifically apply to your service.

07/09/2026, Moritz Mehner

SKW Schwarz Among the Top 10 Mid-Sized Employers for Career Starters

07/08/2026

Acquisition of Historical Monuments: Understanding the Associated Obligations

Purchasing a historical monument entails not only acquiring a valuable building but also assuming the legal obligations tied to its preservation. This is particularly true when the buyer is aware of the monument's status and the need for restoration - essentially, when the acquisition is made "with open eyes." Recent case law imposes stringent requirements in such instances, emphasizing that preservation, structural alterations, or even demolition of the monument should only be permitted under exceptional circumstances. The ruling by the Administrative Court of Würzburg on April 17, 2026 (Case No. W 5 K 25.782) illustrates that buyers in these situations face significantly heightened obligations to demonstrate compliance and provide evidence.

Historical monuments shape the character of German cities and towns more than any other element of the built environment. Historic town halls, late 19th-century villas, industrial facilities, and half-timbered houses contribute to the unique identity of local centers while documenting the social, economic, and architectural developments of past eras. They serve as vital testimonies to local history and often possess considerable scientific, artisanal, or artistic value. Visitors from countries with relatively young architectural histories may find it surprising that modern office spaces or hotels can be found within buildings several hundred years old. However, the continued use of historical structures is crucial for their preservation.

Under Article 70 of the German Basic Law (GG), monument protection law falls within the legislative competence of the federal states. Consequently, there are 16 state monument protection laws, each with varying regulations but all aimed at the protection and preservation of cultural monuments as witnesses to history, art, and culture. The core principle of all state laws is the obligation to preserve. Owners are required to maintain their monuments within reasonable limits and protect them from harm. This protection typically extends beyond the building itself to include its surroundings, provided they contribute to the monument's overall impact.

For owners, developers, and investors looking to alter or repurpose a monument, this often presents significant temporal, financial, and organizational challenges. Unlike standard building permit procedures, monument protection authorities frequently demand extensive documentation, restoration assessments, conservation concepts, and detailed plans and photographic documentation. Additionally, there are often repeated requests for further information, consultations with various specialized authorities, and lengthy approval processes. The implementation of economically viable repurposing concepts frequently encounters substantial resistance from monument protection authorities. Investors may feel that the principle of "everything remains as it is" is given undue weight over innovative and economically sensible solutions - even when prolonged vacancy threatens.

Particularly stringent requirements apply when an owner acquires a monument with full knowledge of its status and often significant restoration needs. In such cases, they cannot claim that the legal burdens of monument protection were unexpected. Rather, the courts expect that the buyer considers the specific requirements of monument protection law in their investment decision at the time of purchase. The more conscious the acquisition, the higher the demands for later proof of economic unfeasibility.

The extent of these heightened evidentiary obligations is exemplified by the ruling of the Administrative Court of Würzburg on April 17, 2026.

The case involved a former sanatorium built between 1906 and 1913 in Bad Kissingen, classified as a historical monument. The owner purchased the property with knowledge of its status and later applied for a permit to demolish the building. After the relevant monument protection authority denied the application, she filed a lawsuit with the Administrative Court.

The monument protection authority argued that the owner had knowingly acquired the property as a historical monument, thereby assuming the associated preservation obligations. Merely citing substantial renovation costs or failed negotiations with potential operators was insufficient to demonstrate economic unfeasibility. The plaintiff was required to substantiate that a monument-compliant use was permanently excluded and that serious marketing efforts had been unsuccessful over an extended period. However, she failed to provide such evidence.

The Administrative Court upheld this view. The claim of economic unfeasibility was rejected. The court found that the submitted economic viability assessment did not meet the high standards required for such proof. The focus was not on the individual financial situation of the owner but rather on the perspective of a property owner open to monument concerns. The critical question was whether the monument could, considering its unique characteristics, be economically self-sustaining.

This assessment was based on a comprehensible economic viability calculation, where renovation costs - adjusted for deferred maintenance and necessary building code measures - were compared against achievable revenues, potential funding, and tax benefits. A mere comparison of renovation costs with those of new construction was deemed insufficient, as this would typically lead to the economically most attractive solution being the demolition of protected buildings. Furthermore, the court required a usage and restoration concept coordinated with the State Office for Monument Preservation, along with a robust economic forecast covering approximately 15 years. Only the owner could develop realistic usage alternatives and provide the authority with a solid decision-making basis.

This ruling underscores that acquiring a monument "with open eyes" carries significant legal consequences. Those who consciously choose a restoration-needy historical monument also assume the risks associated with the preservation obligations tied to the property. Consequently, the requirements for demonstrating economic unfeasibility increase. Simple assertions of lack of profitability or failed marketing attempts are typically insufficient. Comprehensive documentation of marketing efforts, clear usage analyses, serious consideration of monument-compatible alternatives, and reliable economic calculations - ideally coordinated early with monument authorities - are essential.

For owners and developers, this leads to a clear course of action: the success of a monument protection approval process is often determined long before the actual application is submitted. A thorough inventory, meaningful plans and photographic documentation, robust usage and restoration concepts, and a meticulously documented examination of all monument-compatible alternatives are necessary. Only on this basis can the required economic assessment meet the high standards set by the courts.

However, this ruling is not only directed at owners and investors. Monument authorities are also called upon to support viable and economically feasible usage concepts and to engage constructively in dialogue with project developers. The long-term preservation of historical monuments is typically achievable only when monument protection and economic viability are not viewed as opposing forces. Historical structures can only be sustainably preserved if they can continue to be used meaningfully in the future. Therefore, the preservation of monuments is not a one-way street; it requires the willingness of all parties involved to develop practical and monument-compatible solutions.

07/06/2026, Maria Rothämel

SKW Schwarz recognised in multiple Leaders League Germany 2026 rankings

SKW Schwarz has been recognised in the latest Leaders League Germany 2026 rankings across four practice areas:
 

Germany – Best Law Firms for Data Protection – 2026
Recommended
Matthias Orthwein

Germany – Best Law Firms for IT & Outsourcing – 2026
Excellent
Oliver Hornung, Daniel Meßmer and Matthias Orthwein

Germany – Best Law Firms for Media, Sports & Entertainment – 2026
Highly recommended
Norbert Klingner and Andreas Peschel-Mehner

Germany – Best Law Firms for Trademark Litigation – 2026
Highly recommended
Dorothee Altenburg, Magnus Hirsch, Margret Knitter and Rembert Niebel
 

These rankings reflect SKW Schwarz's expertise in data protection, IT & outsourcing, media law and trademark litigation, and underline the firm's strength in advising clients at the intersection of technology, digital business, intellectual property and media.

We are delighted by this recognition and would like to thank our clients for their continued trust and confidence, as well as all our colleagues whose commitment and expertise contributed to this achievement.

About Leaders League
Leaders League is one of the internationally established legal directories, publishing annual rankings across numerous jurisdictions and practice areas. Its research is based on an independent assessment of market information, references and law firm submissions.

07/03/2026

KI Flash: When AI Answers Are No Longer Privileged

With two recent decisions, the Regional Courts of Munich I and Berlin II have, for the first time, taken a closer look at AI‑supported search and answer formats. Both cases concerned Google’s “AI Overview”.

Although the underlying facts differ, the core legal question in both decisions is essentially the same:

When does a platform have to treat the output of an AI feature as its own statement?

 

Search engines and many platform models typically act as aggregators and “technical tools” for finding third‑party content. As a rule, they benefit from liability privileges: they are usually only liable for third‑party content once they have actual knowledge of a legal violation and then fail to remove or block it (“notice and take‑down”). By contrast, they are generally directly liable for unlawful content that they themselves publish. This is precisely where the courts step in. 

Once platforms “adopt” third‑party content as their own, they are generally treated as if they had published it themselves.

The courts essentially apply this principle to AI‑generated outputs in these two decisions as well: if an AI output is understood as the provider’s own statement, courts no longer treat the service as a neutral intermediary. The special liability privileges enjoyed by classic search engines and host providers then apply only in a limited way, if at all. The provider is, in principle, liable as if it had authored the content itself. The two decisions take different approaches, but together they offer initial guidance on when courts tend in one direction or the other.

 

LG Munich I: “AI Overview” as the Provider’s Own Statement

In the case before the Regional Court of Munich I (judgment of 28 May 2026 – 26 O 869/26), a publishing company brought an action against Google in relation to the “Übersicht mit KI” (AI Overview) feature. When the company name is entered into the Google search bar, the autocomplete function already suggests, among other things, the term “Betrugsmasche” (“scam”). Once this suggestion is selected, an AI Overview appears above the conventional search results.

This overview consists of a continuous text in which the company is explicitly linked to allegations such as “unseriöse Geschäftspraktiken” (“untrustworthy business practices”), “Betrugsmasche” (“scam”) and “Abo‑Fallen” (“subscription traps”). The text is structured into several sections, includes links to third‑party websites, rephrases statements from sources in its own words and even contains concrete recommendations (“If you are dealing with …, be extremely cautious”, “If you have a subscription, try to cancel it in due time”, “If you receive unjustified demands, do not pay”). The overview also contains statements and conclusions that cannot be found in this form in the underlying sources.

The Munich court considers this AI Overview to be Google’s own substantive statement, not merely a technical display of third‑party content (paras. 33 et seq.). In particular, it stresses that:

  • the AI generates a self‑contained narrative text that summarizes, structures and evaluates search results in its own words,
  • it produces statements and links between pieces of information that are not contained in the underlying third‑party sources at all (so‑called “hallucinations”),
  • from the perspective of a reasonable average user, the AI overview appears as an answer provided by Google to the search query, not as a neutral list of results; the advisory elements reinforce this impression.

On this basis, the court assumes that Google has “adopted” the AI content as its own. Google is therefore liable for unlawful AI overviews, in particular for untrue, reputation‑damaging factual allegations about the claimant.

In addition, the court finds that it is not sufficient simply to switch off the specific AI answer. Due to the AI’s “black box” character, similar content may be generated again at any time; in the court’s view, the risk of repetition remains. Overall, the decision shows that for newly generated, chat‑like answers, there is a relatively low threshold for assuming “appropriation” (“Zu‑Eigen‑Machen”) at least where the text does not merely summarize search results, but goes beyond them by creating its own content, giving concrete recommendations and, as in this case, partly relying on technical errors (hallucinations).

 

LG Berlin II: AI Answers as Search/Information Format in Trademark Law

In the case before the Regional Court of Berlin II (judgment of 1 June 2026 – 52 O 62/26), the focus was on AI‑generated texts that mention the claimant’s branded perfumes and at the same time highlight so‑called “scent twins” (“Duftzwillinge”) as cheaper alternatives, including links to the respective sellers. The AI texts described which vendors offer scent twins to the claimant’s branded perfumes and guided users via links straight to the websites of these vendors. In terms of substance, they largely stayed within what was reflected in the regular search results displayed below. The claimant regarded this as use of its trademarks by Google to promote knockoff products.

The court, however, denies that Google used the marks in its own right in the sense of trademark law (Art. 9 UMV). The starting point is the basic trademark use requirement: use only occurs where the sign is employed in the context of the user’s own commercial communication, i.e. to designate or promote that party’s own goods or services.

The court relies again on the user’s perspective: a “reasonably well‑informed and reasonably observant user” perceives the AI texts as a search and information format, not as advertising or Google’s own product communication. Such a user recognizes that the content is based on third‑party websites, that Google operates a search engine aggregating such content, and that Google itself does not sell perfumes. The court further emphasizes that the AI texts merely reflect the actual search results and that each statement in the “Übersicht mit KI” is backed by a link to the corresponding search result; there is no evidence of targeted selection or steering in favor of specific sellers.

Against this background, the court concludes that, although Google does display the marks within the AI answer, this display does not amount to trademark use by Google as part of its own commercial communication. In this context, the court therefore rejects an “appropriation” of the AI outputs.

 

Common Approach and Practical Takeaways

At first glance, the two decisions lead to different outcomes, but they are not necessarily contradictory. Both courts ultimately pose the same question: does the AI output still look like a search/result format that merely improves the user experience, or does it appear as an independent statement by the provider?

The answer depends mainly on the format, structure and content of the respective output. Taken together, these decisions draw an initial, soft line: it is not only “purely fictional” AI content that can trigger direct liability. Even a genuinely independent substantive processing of search results – going beyond a neutral presentation of sources – can already lead courts to treat the content as the provider’s own.

For all providers of AI‑supported search and answer systems, the concept of “appropriation” thus remains a central risk factor: the more an AI output appears as a distinct, evaluative statement and the further it moves beyond the underlying sources, the more likely it is that the provider will be treated as if it had authored the content itself.

Which concrete adjustments are advisable in any given case – whether in product design, answer logic, disclaimers or notice‑and‑action processes – depends on the specific architecture of the system. We would be pleased to support you in assessing existing AI functionalities from a legal perspective and in developing appropriate safeguards.

07/02/2026, Moritz Mehner

IP Stars 2026: SKW Schwarz maintains top rankings in trade mark and copyright

We are delighted about the publication of the IP Stars rankings 2026 and the renewed recognition of our expertise in intellectual property.

We have successfully maintained our firm rankings compared to last year:

  • Trade mark - law firms – Tier 2
  • Copyright & related rights – Tier 1 

In addition, numerous colleagues have been recognised for their outstanding work in trade mark and IP law:

Trade mark stars 2026
Dr. Dorothee Altenburg, Dr. Markus Brock, Margret Knitter, LL.M., Dr. Rembert Niebel and Dr. Oliver Stöckel

Notable practitioners 2026
Dr. Daniel Kendziur, Sandra Sophia Redeker, Dr. Magnus Hirsch and Dr. Andreas Peschel-Mehner

Rising star 2026
Lara Guyot

We warmly congratulate all recognised colleagues on these excellent results.

Our special thanks also go to our clients and business partners for their trust, close cooperation and continued support. These recognitions are the result of a joint effort.

About IP Stars
The IP Stars rankings by Managing IP are among the world’s leading directories for law firms and lawyers specialising in intellectual property. The rankings are based, among other things, on extensive research, market feedback, client references and an analysis of significant matters, and are regarded as an important benchmark for excellence in IP law.

We are delighted with this renewed confirmation of our work and will continue to do everything we can to support our clients with first-class advice in trade mark, copyright and IP law.

06/25/2026, Dr. Dorothee Altenburg, Dr. Markus Brock, Margret Knitter, Dr. Rembert Niebel, Dr. Oliver Stöckel, Dr. Daniel Kendziur, Sandra Sophia Redeker, Dr. Magnus Hirsch, Dr. Andreas Peschel-Mehner, Lara Guyot

Cologne Regional Court Tightens Requirements for Advertising Disclosures in Social Media Grids

The Cologne Regional Court (Judgment of May 12, 2026 – 88 O 1/26) ruled against an event and cultural recommendation account for insufficient advertising disclosure on a social media platform. The court objected to video posts that were labeled as “Advertisement” in the caption but whose preview images in the profile grid - the post overview, i.e., the visual arrangement of all posts in a multi-column layout displayed when accessing a profile - contained no indication that they were advertisements. Users viewing the tile overview could not distinguish between promotional and editorial content.

The event and cultural recommendation account argued, among other things, that most users consume content through the feed or reels, that the grid itself was therefore not subject to disclosure requirements, and that the business profile already made the commercial nature of the account sufficiently apparent. The court rejected these arguments.

 

Thumbnail in the Grid as an Independent Commercial Practice

According to the Cologne Regional Court, the content constituted commercial communication because the account promoted third parties (including a cinema operator and a spirits manufacturer) and failed to substantiate that it had received no consideration in return. Consequently, the presumption under Section 5a(4) of the German Unfair Competition Act (UWG) applied.

A key aspect of the decision is the classification of the preview image in the grid: the thumbnail represents the post or reel and is itself part of the commercial practice. Therefore, the commercial purpose must already be disclosed at that stage; a disclosure solely in the caption of the post or video comes too late. Neither the use of a business profile nor the general expectation that media offerings are financed through advertising (which the court ultimately questioned) was sufficient, in the court’s view, to make the advertising character “immediately apparent from the circumstances.”

As a result, promotional content must be labeled in such a way that its advertising nature is clearly and unambiguously recognizable “at first glance” within the grid. The court considered labeling the thumbnail itself both possible and reasonable. In addition, other legal provisions (including Section 6 DDG and Section 22 MStV) impose transparency obligations that lead to the same outcome. Notably, in an earlier decision, the German Federal Court of Justice (BGH) had assumed that Section 22 MStV took precedence.

 

Conclusion and Outlook: More Disclosure, More Pressure on Platforms and Creators

If the Cologne Regional Court’s decision gains broader acceptance, it could significantly change social media advertising practices:

  • Advertising disclosures in grids: Creators and recommendation accounts will need to adapt their disclosure practices. Promotional posts will likely have to be designed so that their advertising nature is clearly identifiable as advertising already on overview and search pages—particularly within the profile grid. A disclosure only in the caption or after opening the post will generally no longer be sufficient.
  • Platform obligations under Article 26 DSA: Social media platforms face stricter requirements regarding their disclosure tools. Article 26 of the Digital Services Act (DSA) requires commercial communication to be clear, unambiguous, and identifiable by users in real time. These requirements are likely to increasingly extend to grids, feeds, and search views.
  • Potential wave of warning letters: A new wave of cease-and-desist letters directed at creators and brands cannot be ruled out—similar to the influencer cease-and-desist letter wave seen several years ago, but this time focusing on thumbnails, grids, and overview pages.

Creators should therefore review and, where necessary, promptly adjust their profiles, thumbnails, and disclosure practices. Social media platforms would be well advised to critically reassess their implementation of Article 26 DSA and strengthen their disclosure functionalities accordingly.

06/25/2026, Johannes Schäufele, Corinna Schneiderbauer

Handelsblatt "Germany's Best Lawyers 2026"

Today, the new edition of the ‘Germany's Best Lawyers 2026’ rating was published by Handelsblatt in cooperation with the US publisher Best Lawyers:

The title ‘Lawyer of the Year for Intellectual Property Law’ goes to Dr. Rembert Niebel.

In the ‘Ones to watch’ section, Dr. Frithjof Roschlaub was listed in the ‘Corporate Law’ category and Dr. Thomas Hohendorf, Hannah Mugler and Dr. Christoph Wiegand. in the ‘Intellectual Property Law’ category. Hannah Mugler was also named in the ‘Data Security and Privacy Law’ category and, together with Helena Kasper, Marius Drabiniok and Dr. Elisabeth von Finckenstein, in the ‘IT Law’ category. Maria Rothämel is listed in the category ‘Public Commercial Law’, Dr. Alexander Tegge in the ‘Trusts and Succession Planning’ category and Afra Nickl in the category ‘Biotechnology Law and Life Sciences Practice’.Anna-Sophia Leitner, Maximilian König, Dr. Max-Niklas Blome and Dr. Frithjof Roschlaub are named in the category ‘Litigation’.

66 lawyers from the firm are also recommended in 24 areas of law.

  • Dr. Dorothee Altenburg (Art Law, Entertainment Law, Intellectual Property Law)
  • Stephan Altenburg (Employee Benefits Law, Labor and Employment Law)
  • Fabian Bauer, LL.M. (Information Technology Law)
  • Nikolaus Bertermann (Data Security and Privacy Law, Information Technology Law, Technology Law)
  • Eva Bonacker (Corporate Law)
  • Dr. Markus Brock (Intellectual Property Law)
  • Dr. Oliver M. Bühr (Information Technology Law, Intellectual Property Law, Technology Law)
  • Christoph Conrad (Public Law)
  • Markus von Fuchs (Intellectual Property Law, Media Law)
  • Dr. Christoph Haesner (Entertainment Law, Media Law)
  • Dr. Thomas Hausbeck (Tax Law)
  • Dr. Johann Heyde (Advertising Law, Information Technology Law)
  • Dr. Magnus Hirsch (Intellectual Property Law)
  • Dr. Oliver Hornung (Data Security and Privacy Law, Information Technology Law, Technology Law)
  • Dr. Klaus Jankowski (Construction Law)
  • Dr. Bernd Joch (Labor and Employment Law)
  • Dr. Wulf Kamlah (Information Technology Law)
  • Dr. Daniel Kendziur (Information Technology Law)
  • René Kieselmann (Public Law, Public Private Partnership)
  • Norbert Klingner (Gaming Law, Media Law, Restructuring and Insolvency Law)
  • Margret Knitter (Art Law, Intellectual Property Law)
  • Dr. Olaf Kreißl (Real Estate Law)
  • Franziska Ladiges (Data Security and Privacy Law, Information Technology Law)
  • Dr. Martin Liebernickel (Tax Law, Trusts and Succession Planning)
  • Moritz Mehner (Data Security and Privacy Law, Information Technology Law)
  • Dr. Daniel Meßmer (Data Security and Privacy Law, Information Technology Law)
  • Alexander Möller (Labor and Employment Law)
  • Dr. Stephan Morsch (Corporate Law, Mergers and Acquisitions Law)
  • Dr. Rembert Niebel (Intellectual Property Law, Litigation)
  • Dr. Matthias Nordmann (Information Technology Law)
  • Dr. Matthias Orthwein (Data Security and Privacy Law, Information Technology Law, Technology Law)
  • Dr. Mathias Pajunk (Public Private Partnership)
  • Dr. Stefan Peintinger (Data Security and Privacy Law, Information Technology Law, Intellectual Property Law)
  • Dr. Andreas Peschel-Mehner (Data Security and Privacy Law, Information Technology Law, Media Law, Entertainment Law)
  • Dr. Kolja Petrovicki (Mergers and Acquisitions Law)
  • Dr. Christoph Philipp (Family Law, Tax Law, Trusts and Succession Planning)
  • Sandra Sophia Redeker (Intellectual Property Law)
  • Dr. Johannes Schäufele (Data Security and Privacy Law)
  • Stefan C. Schicker (Information Technology Law, Intellectual Property Law, Technology Law)
  • Corinna Schneiderbauer (Information Technology Law)
  • Götz Schneider-Rothhaar (Entertainment Law, Media Law)
  • Dr. Tatjana Schroeder (Mergers and Acquisitions Law)
  • Prof. Dr. Mathias Schwarz (Entertainment Law, Media Law)
  • Martin Schweinoch (Information Technology Law)
  • Dr. Gerd Seeliger (Tax Law)
  • Stefan Skulesch (Tax Law)
  • Dr. Oliver Stöckel (Advertising Law, Health Care Law, Intellectual Property Law, Litigation)
  • Michael Wahl (Labor and Employment Law)
  • Georg Wallraf (Media Law)
  • Dr. Sebastian Graf von Wallwitz (Mergers and Acquisitions Law)
  • Konstantin Wegner (Media Law)
  • Johanna Weiß (Media Law)
  • Julian Westpfahl (Information Technology Law)

The list of recommendations is compiled annually by the US specialist publisher Best Lawyers; in Germany, it is published in an exclusive cooperation with the Handelsblatt newspaper. The ‘Best Lawyers’ nominations are based on a peer-to-peer survey in which commercial lawyers are asked which competitors they recommend.

06/18/2026

NIS2 – LAST CALL: New Registration Deadline!

NIS2 is a European directive under which significantly more companies than before will be required to implement IT security measures within their operations, including many organizations that likely never expected to be classified as important entities for Germany’s critical infrastructure. The requirements of the EU directive have already been incorporated into the German BSI Act and are directly applicable without any transitional periods.

Among the obligations of affected entities is the registration with the German Federal Office for Information Security (BSI). The deadline for this registration, which is subject to administrative fines, officially expired on March 6, 2026.

So far, however, the BSI has shown some leniency despite the low number of registrations received. According to statements by the authority, fines (of up to €500,000) were not expected to be imposed at this stage (as we reported here).

 

Is that changing now? It appears so!

The BSI has now sent a letter to business associations in which the authority has noticeably tightened its tone.

Affected entities are expected to complete their registration no later than July 31, 2026. According to the BSI, these registrations are overdue. Even in difficult cases involving uncertainty about whether an entity falls within the scope of the regulation, the authority is showing increasingly little tolerance for further delays. Such entities are requested to submit their consolidated questions to the BSI and, if they are found to be within scope, complete their registration within six weeks after receiving the authority’s response.

In other words: “Last Call” for anyone who has not yet devoted sufficient attention to this issue.

The scope of the new IT security requirements is broad and by no means limited to traditional “critical infrastructure” operators. We have previously reported here on examples of rather unexpected cases falling within the scope of the regulation.

Our NIS2 applicability assessment tool (here) provides a free and easy starting point for companies that now need to determine whether they are affected.

 

06/18/2026, Henrik Hofmeister, Fabian Bauer, Dr. Matthias Orthwein

SKW Schwarz advises German-based CPQ provider SAE on sale to Norwegian Xait

SKW Schwarz advised the shareholders of German-based SAE GmbH on the sale of a majority stake in the company to Main Capital Partners-backed Xait, a global provider of document collaboration and proposal software.

With this first add-on acquisition since the start of its partnership with Main Capital, Xait is strengthening its position within the CPQ segment.

Based in Weng, Germany, SAE provides a modular CPQ and variant management platform that enables manufacturers of complex, highly configurable products to automate configuration, pricing and quotation processes. The platform is primarily used by industrial and manufacturing companies especially in the machinery, plant engineering, industrial equipment and automotive-related industries.

Xait, headquartered in Stavanger, Norway, is a global provider of software for collaborative document editing and quotation preparation. The company serves more than 300 clients, primarily in the renewable energy, capital goods and business services sectors.

The SKW Schwarz team was led by partner Marion Anzinger and included partners Dr Stephan Morsch (both Corporate/M&A), Dr Daniel Meßmer (IT), Alexander Möller (Employment), Dr Stefan Peintinger (Data Protection) and Nicole Wolf-Thomann (Tax), counsel Eva Bonacker (M&A) and Niklas Bolten (Real Estate), as well as Raluca-Ramona Calin (Paralegal).

06/15/2026, Marion Anzinger, Dr. Stephan Morsch, Dr. Daniel Meßmer, Dr. Stefan Peintinger, Nicole Wolf-Thomann, Alexander Möller, Eva Bonacker, Peer Niklas Bolten

SKW Schwarz at the Bitkom Social Media Roundtable

06/12/2026, Johannes Schäufele, Fabian Bauer

EmpCo Directive: Important Clarifications from the European Commission on “Green” Trademarks

The European Commission has issued welcome clarifications for trademark owners in its updated Frequently Asked Questions (FAQs) on the EmpCo Directive. The guidance addresses trademarks that contain elements such as “green” or “blue” and provides greater legal certainty for businesses using such branding. The previous version of the FAQs, published on 27 November 2025, suggested that trademark owners might no longer be able to use these terms because they could be regarded as general environmental claims. As a result, many companies considered rebranding initiatives in order to reduce the risk of regulatory or enforcement action against their brands.

 

Updated FAQs Provide Greater Legal Certainty

Following concerns raised by businesses, including representatives of German industry, the European Commission has now published a revised version of the FAQs (dated 18 May 2026). The updated guidance makes clear that branding featuring the colours green or blue, or similar elements, is not automatically prohibited. This applies where it is unlikely that the average consumer would understand the relevant term or element, in its specific commercial context, as an environmental claim.

 

No General Ban on “Green” Trademarks

The revised FAQs therefore reject the interpretation that trademarks containing terms such as “green” are subject to a general or automatic prohibition. Although the FAQs are not legally binding and do not have the force of law, they provide important insight into the European Commission’s interpretation of the EmpCo Directive. As such, they are likely to be given significant consideration by national authorities and courts across the EU.

 

Case-by-Case Assessment Remains Necessary

At the same time, the Commission emphasises that each case must still be assessed individually. A restriction may still be justified where consumers are likely to perceive a trademark as making a general environmental claim. Businesses and their advisers should therefore continue to assess carefully how a particular trademark is likely to be understood by the relevant public.

 

Conclusion

The updated FAQs provide welcome clarification and greater legal certainty for trademark owners. The use of terms such as “green”, “blue”, or similar elements in trademarks and branding remains permissible and does not automatically violate the requirements of the EmpCo Directive. However, companies should continue to evaluate their branding on a case-by-case basis, as consumer perception remains the key factor in determining compliance.

06/12/2026, Dr. Rembert Niebel

Influencer Advertising on Platforms Under Scrutiny: Bamberg Regional Court Clarifies Labeling Obligations for Platform Providers

The Regional Court of Bamberg (Landgericht Bamberg) has further specified the requirements for labeling of sponsored content provided by influencers on online platforms (judgment of March 11, 2026 – 1 HK O 19/25). According to the court, a clear indication of the commercial nature of influencer content, which is at least partially financed by third parties must be visible throughout the entire duration of the content. As a consequence, platform providers may be required to revise and enhance their existing advertising disclosure tools, in particular by implementing prominent and continuous notices as well as clear identification of the influencers’ commercial partners.

 

Dispute Concerning Existing Advertising Disclosure

The decision arose from two influencer contributions published on a video-sharing platform. The first case concerned a so-called "Finfluencer" (an influencer focusing on financial topics) who presented financial products while simultaneously promoting a broker app he personally used, including affiliate links generating commission payments. In the second case, the court addressed an influencer featuring products from an online retailer in an unboxing video, displaying the retailers logos and including tracking links. In both instances, the platform provider displayed a brief notice stating "Contains paid promotion" for approximately ten seconds at the beginning of the video. The notice subsequently disappeared with no further disclosure provided. No further labeling or clarification indicating that the companies mentioned had co-financed the posts was provided. Only abstract references to the influencers' videos being advertising-funded were found elsewhere, such as under the video itself. The platform provider also offered various means for labeling.

The plaintiff considered these measures insufficient, arguing that it misled users and filed a lawsuit against the online platform provider, citing Article 26 of the Digital Services Act (DSA).

 

Key Point: Real-Time Disclosure Required

The court ruled in favor of the plaintiff. While the platform provider had indeed provided influencers with a function to declare whether their content constitutes commercial communication, as required by Article 26(2) sentence 1 DSA, the court found that the disclosure displayed within the video was inadequate.

According to Article 26(2) sentence 2 DSA, platform providers must ensure that other users can clearly and unequivocally identify in real-time - through highlighted labels - that the content provided by the influencer represents or contains commercial communication. From the court's perspective, "in real-time" means that the notice must be visible throughout at least the predominant portion of the duration of the video. A brief notice at the beginning is insufficient. Furthermore, the labeling must be visually prominent. The court considered factors such as the relationship to the promotional statement, size, color, and placement of the notice, but emphasized that the exact requirements must be assessed based on the circumstances of each individual case.

The primary responsibility for labeling lies with the influencer. In this regard, the court deemed it insufficient for one of the influencers to merely provide an abstract reference to advertising content beneath the video. Such a reference does not clearly indicate the connection to the specific related commercial content. However, if the influencer utilizes the function under Article 26(2) sentence 1 DSA and labels their content as advertising or content with advertising, the court also holds the platform provider accountable.

Additionally, the cooperation partner of the influencer - i.e., the actual advertiser - must be disclosed in accordance with Section 6(1) No. 2 of the German Digital Service Act (DDG). Here, the influencer is initially responsible. However, without the need to consider a potential liability exemption under Article 6(1) DSA, injunction claims under German law, particularly the Act Against Unfair Competition (UWG), could also be asserted against the platform provider.

 

Conclusion and Practical Guidance

If the interpretation of the Regional Court of Bamberg prevails, platform providers will have no choice but to ensure that influencer posts are prominently labeled as advertising or partially advertising for their entire duration. This extensive obligation raises practical concerns regarding posts containing advertising only intermittently, e.g. when influencers insert their own advertising segments into otherwise editorial content. A clear assignment of the notice to the advertising content would be impossible in such cases. Moreover, the influencer would be compelled to provide continuous notices even for non-advertising content. Whether this is reasonable remains questionable. Additionally, whether the liability exemption under Article 6(1) DSA is indeed circumvented, as assumed by the court, requires further clarification. Nevertheless, platform providers are advised to proactively revise their tools, despite the unresolved questions and the lack of finality of the ruling.

 

06/11/2026, Yves Heuser

High-Risk AI Systems under the AI Act: Timeline Extensions and Initial Clarifications

After discussing liability for misleading statements made by an AI chatbot in our last AI Flash, we would like to continue providing you with regular legal insights on AI-related developments.

In today’s AI Flash, we would like to take a closer look at high-risk AI systems in light of recent developments at the European level. On 19 May 2026, the European Commission launched a consultation process and published three draft guidelines on the classification of high-risk AI systems. For the first time, these drafts provide detailed clarification on what is arguably the most consequential question under the AI Act (AIA): When does an AI system qualify as high-risk—and when does it not?

Given the complexity of the topic, particularly considering the different categories of high-risk AI systems, we will divide our comments on the draft guidelines into several AI Flash publications. This contribution is intended to provide an initial overview, enabling us to address specific aspects in greater detail in future editions.

 

Timeline: What the AI Omnibus Has Changed

Before addressing the substantive classification question, it is important to understand the applicable timeline. With the provisional trilogue agreement on the so-called “Digital Omnibus on AI” of 7 May 2026, the European Parliament and the Council substantially postponed the application deadlines for high-risk AI systems:

  • AI systems serving as safety components in regulated products under Annex I of the AI Act (including AI used in medical devices, lifts, and toys)
    Postponement: 2 August 2027 → 2 August 2028 (+12 months)
  • Standalone high-risk AI systems under Annex III of the AI Act (including AI used in human resources and critical infrastructure)
    Postponement: 2 August 2026 → 2 December 2027 (+16 months)

Although the trilogue agreement has not yet been formally adopted and the original deadlines technically remain applicable until adoption, formal enactment within the relevant timeframe is considered highly likely.

Against this backdrop, the newly published draft guidelines constitute an important tool for companies. They provide an opportunity to use the additional preparation time in a structured and substantive manner and, for the first time on an official basis, assess whether and to what extent AI systems may be subject to high-risk classification in the future.

 

The Two Classification Pathways under Article 6 AI Act

Article 6 AI Act provides for two independent pathways leading to a high-risk classification.

 

Annex I (Product Safety)
An AI system qualifies as high-risk if it is itself a regulated product or serves as a safety component of such a product falling within specific EU harmonisation legislation and the product is subject to a third-party conformity assessment.

This pathway is particularly relevant for AI used in medical devices, toys, vehicles, and lifts.

The Commission appears to interpret the key concept of a “safety component” rather broadly. Even a system not expressly intended to perform a safety function may qualify as a safety component if its failure or malfunction could create a health or safety risk. Purely efficiency-, comfort-, or performance-related functions without safety relevance do not fall within this category.

 

Annex III (Use Case-Based Classification)
For most businesses, the practically more relevant pathway is Annex III of the AI Act. Here, the legislator identifies eight areas of application (with further subdivisions) in which the use of AI systems is generally considered high-risk:

  • Biometrics
  • Critical infrastructure
  • Education and vocational training
  • Employment and worker management
  • Access to essential private and public services
  • Law enforcement
  • Migration, asylum and border control
  • Administration of justice and democratic processes

This category will be the primary focus of the present contribution.

 

Intended Purpose as the Key to Classification
A central theme throughout the draft guidelines is the concept of the intended purpose of an AI system.

The decisive factor is how the intended purpose is presented externally in instructions for use, technical documentation, marketing materials, and other statements made by the provider.

The Commission makes it clear that providers cannot avoid a high-risk classification through disclaimers or exclusions in their terms of use if the system’s design, marketing, or overall positioning suggests a high-risk use case. Any limitation of the intended purpose must be communicated clearly, specifically, and consistently across all materials.

 

HR Example: Where Does the High-Risk Zone Begin?

Annex III, Section 4 of the AI Act expressly covers AI systems used in the fields of employment, worker management, and access to self-employment.

Specifically, this includes:

  • “AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, analyse or filter applications, and evaluate candidates.”
  • “AI systems intended to be used for decisions affecting the terms of employment relationships, promotions and termination of contractual employment relationships, for task allocation based on individual behaviour or personal traits or characteristics, or for monitoring and evaluating the performance and behaviour of persons in such relationships.”

According to the draft guidelines, the specific use case and, subsequently, the degree to which the system influences a human decision are of particular importance.

The mere existence of human oversight is not sufficient to avoid classification as a high-risk AI system. Given the significant practical relevance of HR applications, we intend to address this topic in greater detail in a dedicated future AI Flash.

 

The Article 6(3) Filter: An Exception for Annex III Systems

For AI systems that fall within one of the Annex III areas but whose functions are comparatively limited, Article 6(3) AI Act provides a filter that may prevent classification as a high-risk system.

This filter applies exclusively to Annex III systems and not to product safety-related AI systems under Annex I.

The Commission explicitly emphasises that the conditions for applying the filter must be interpreted narrowly, as Article 6(3) constitutes an exception to rules primarily designed to protect fundamental rights.

The filter applies only where one of the following criteria is met:

  • Narrow Procedural Task: The system performs only a clearly limited procedural task, such as sorting application documents into predefined categories. Systems that evaluate data or make qualitative assessments do not fall within this category.
  • Improvement of a Completed Human Activity: The system improves the result of a previously completed human action but neither replaces nor revises it. Example: Highlighting inconsistencies in a decision already made by a human.
  • Detection of Decision-Making Patterns without Influence: The system identifies patterns or deviations in decision-making processes but neither influences nor replaces human judgment.
  • Preparatory Task with Limited Influence on Outcomes: The system prepares a decision without substantively steering it, for example by providing relevant guidelines without directing the outcome of the decision.

The operational key question therefore becomes: Does the system merely structure a process, or does it influence human judgment?

Systems that sort, convert, or detect duplicates may fall within the filter. Systems that rank, assess, score, or make clear recommendations will generally be classified as high-risk.

Furthermore, the filter is entirely unavailable where the AI system performs profiling, i.e., automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person.

This limitation is highly relevant in practice because many AI tools used in HR inherently involve profiling functionalities. Thorough assessment is therefore essential.

Providers seeking to rely on the filter must, prior to placing the system on the market, prepare a written self-assessment documenting:

  • the intended purpose;
  • the basis for the high-risk classification under Article 6(2) AI Act;
  • the applicable filter condition; and
  • the reasons why no profiling is involved.

The system must subsequently be registered in an EU database.

 

A Potential Pitfall for AI Deployers

As a first step, it is the provider of the AI system who is responsible for defining its intended purpose and, consequently, determining its risk classification.

From the deployer’s perspective, however, Article 25(1) AI Act is particularly important. It provides, among other things, that a deployer may effectively become a provider where the intended purpose of an AI system that was not originally classified as high-risk and has already been placed on the market or put into service is modified in such a way that the AI system subsequently becomes a high-risk AI system within the meaning of Article 6 AI Act.

Put simply:
A company that uses a generative AI system—which will often not qualify as high-risk—for candidate selection purposes may alter the system’s risk classification and simultaneously assume a different regulatory role.

 

Practical Recommendation: Participate in the Consultation

The draft guidelines are open for public consultation until 23 June 2026. Formal adoption by the Commission is expected thereafter, although no specific timeline has yet been announced. Under the current framework, the guidelines are not legally binding; authoritative interpretation remains the responsibility of the Court of Justice of the European Union (CJEU). Nevertheless, they represent the clearest indication to date of how the Commission—and, in practice, national market surveillance authorities—are likely to approach the classification question.

The additional preparation time resulting from the AI Omnibus should therefore not be viewed as a reason to delay action, but rather as an opportunity for structured preparation. The key classification question—Is my system high-risk, and if so, does the Article 6(3) filter apply?—should be addressed, or at least prepared, as early as possible.

Our experience shows that delayed engagement with these issues, or a late change of course, often results in considerable additional effort. We would therefore be pleased to support you with an initial assessment of your AI systems and with establishing a practical framework for documenting and routinely reviewing your compliance documentation.

06/10/2026, Marius Drabiniok, Dr. Oliver Hornung

The Obligation to Install Photovoltaic Systems on Buildings in Germany

The obligation to install photovoltaic (PV) systems on buildings now affects virtually every owner of residential property in Germany, as it no longer applies only to newly constructed buildings but also to existing buildings.

The following article therefore provides an initial overview of the PV installation obligation. For an assessment of whether the PV installation obligation applies to your project, or for questions regarding your specific case, please contact your SKW Schwarz advisor.

Where Is the PV Installation Obligation Regulated by Law?

The central federal law governing energy requirements for buildings is the German Building Energy Act (Gebäudeenergiegesetz – GEG), which entered into force on November 1, 2020. The GEG itself does not establish a nationwide obligation to install PV systems. Instead, Section 9a GEG authorizes the federal states (Länder) to adopt more extensive regulations.

Section 9a GEG therefore provides:

“The federal states may, by state law, impose more extensive requirements regarding the generation and use of electricity, heat, and cooling from renewable energy sources in connection with buildings, as well as further requirements or restrictions concerning direct electric heating systems.”

Whether a PV installation obligation exists therefore depends on the specific state regulations in the federal state where your project is to be carried out.

 

Overview of the PV Installation Obligations in the German Federal States

The following table (as of May 17, 2026) provides an overview of whether a PV installation obligation exists in each federal state and the legal provisions on which it is based:

 

PV anlagen liste 2.png

 

Due to the large number of state-specific regulations, this table can only provide a general overview. A legal assessment of each individual case remains necessary. Even in federal states where no statutory state-level PV obligation exists, an obligation may exceptionally arise from a local development plan or municipal regulations.

Exceptions and Exemptions from the PV Installation Obligation – The Example of Lower Saxony

Even if a PV installation obligation generally exists in your federal state, this does not mean that it always applies. The following examples from the Lower Saxony Building Code (NBauO) illustrate this.

1. Cases in Which No PV Obligation Exists Under Section 32a(2) NBauO

According to the wording of Section 32a(2) NBauO, the obligation to equip 50% of the roof area with a solar energy installation for electricity generation applies only if the newly constructed or renovated roof area amounts to at least 50 m².

As an additional requirement, Section 32a(2) No. 3 NBauO requires “replacement of the roof covering down to the waterproofing layer.” If a roof is re-covered without such a “major roof renovation,” no PV obligation is likely to arise.

Accordingly, it is always necessary to examine and document whether the project reaches the relevant size threshold and scope. Similar considerations apply in other federal states with PV obligations.

2. Statutory Exceptions to the PV Obligation Under Section 32a(4) NBauO

Section 32a(4) sentence 1 NBauO provides several exceptions to the PV installation obligation. It should be noted that the provision uses the term “insofar as,” meaning that the obligation may be reduced only partially rather than waived entirely.

a) The PV Obligation Conflicts with Other Public-Law Requirements (Section 32a(4) Sentence 1 No. 1 NBauO)

Conflicts with other public-law requirements are likely to be exceptional and may arise, for example, from provisions in a development plan (e.g., requirements regarding green roofs) or from heritage protection regulations. Comparable provisions exist in other federal states.

b) The PV Obligation Is Technically Impossible (Section 32a(4) Sentence 1 No. 2 NBauO)

Technical impossibility may exist, for example, where the roof or building structure lacks sufficient load-bearing capacity, structural stability, or connection possibilities, or where there are no sufficiently large flat roof surfaces due to numerous small roof sections.

Buildings with predominantly north-, northwest-, or northeast-facing roofs, or roofs subject to significant shading, may also fall under this exception. Comparable provisions exist in other federal states.

c) The PV Obligation Is Not Economically Reasonable (Section 32a(4) Sentence 1 No. 3 NBauO)

In Lower Saxony, a PV obligation is generally considered economically unreasonable if an optimized solar energy installation would not pay for itself within 20 years, meaning that the investment costs could not be offset through revenues or savings (in the case of self-consumption systems) during that period, or if the building has an expected remaining useful life of less than 20 years.

The obligation is also considered economically unreasonable if the requirement to install a solar energy system would render the construction project economically unfeasible. Other federal states may apply different standards.

d) Solar Thermal Systems Have Been or Will Be Installed on the Roof Area (Section 32a(4) Sentence 1 No. 4 NBauO)

The roof area required for such a solar thermal installation may be deducted proportionally from the available roof area and the minimum occupancy requirement.

If the remaining available roof area is less than 50 m², or if 50% of the roof area is already occupied, the PV installation obligation no longer applies.

e) Exception Under Section 32a(4) Sentence 2 NBauO

Under this provision, the obligations under Section 32a(2) No. 3 and Section 32a(3) Sentence 2 NBauO may also be waived where the construction measure is urgently required due to special external circumstances, particularly to remedy unforeseen damage caused by environmental events.

For example, this exception may apply where a roof has sustained damage (e.g., as a result of environmental events) that necessitates involuntary roof replacement within the meaning of Section 32a(2) No. 3 NBauO.

Conclusion

As PV installation obligations now exist in almost all German federal states, they should be taken into account at an early stage when constructing new buildings and when planning roof renovations, vertical extensions, or alterations to existing buildings.

Even where property owners are convinced that no obligation applies in their specific case, thorough documentation of the relevant facts is strongly recommended.

We would be pleased to advise you on whether your construction project is subject to the PV installation obligation or whether a statutory exception may apply in your particular circumstances.

 

06/10/2026, Janina Schortz

Regulated on the Road: Why In‑Car Entertainment Triggers Media Platform Regulation under the German Interstate Media Treaty

Automakers are turning their cars into rolling media hubs – and German regulators have already set important precedents: in 2024, the state media authorities classified the in‑car entertainment systems of several automakers as user interfaces, and the “Tesla Media Player” is additionally treated as a media platform. This makes clear that access to and discoverability of media services in cars are subject to media regulation.

The German Interstate Media Treaty (MStV) defines media platforms as services that combine broadcasting, broadcast-like or journalistic-editorial telemedia into a comprehensive offering determined by the provider (e.g. the OEM curates and controls an overall line‑up of third‑party radio, streaming and video apps such as Spotify, YouTube). 

User interfaces, on the other hand, are the textual or acoustic overview of offerings or content on media platforms.

 

Providers of media platforms are required to 

  • notify the state media authorities one month before going live. 
  • ensure non-discriminatory access by guaranteeing equal access conditions for all content providers. 
  • Changes to media offerings may not be made without the consent of the content providers. 
  • Platforms that reach a certain minimum size must meet certain transparency requirements. For example, media platform providers must be transparent to their users about the principles according to which offerings are granted access to their platform. This includes, among other things, information about the criteria used to sort, arrange, and present content on their platform.

 

If an in‑car entertainment system qualifies as a user interface, the following requirements must generally be met:

  • No preference for own offers or offers of third parties against payment 
  • Sorting of apps in the offering must be easily customizable by users on a permanent basis
  • Broadcasting must be accessible at the first selection level with one click
  • Publicly financed and public value broadcasting must be easy to find (if included on the platform)

 

In other words: the way you design and organize your in‑car media offering is no longer just a UX decision, it is a regulated activity. OEMs should therefore assess now whether their current and planned infotainment systems qualify as a media platform and/or user interface under the MStV, and if so, implement compliant product, UX and contractual setups early on and take the necessary legal compliance steps – for example, fulfilling the notification obligation vis‑à‑vis the competent state media authority. Doing this proactively reduces regulatory risk, avoids costly redesigns after launch and gives legal certainty for future, media‑rich vehicle generations.

06/01/2026, Johannes Schäufele, Corinna Schneiderbauer

Cease-and-Desist Tsunami in the Guitar Industry: Fender, the Stratocaster, and the Limits of Copyright Law

Relying on a default judgment issued by the Regional Court of Düsseldorf, Fender claims copyright protection for the body shape of the “Stratocaster” and is sending cease-and-desist letters to numerous guitar manufacturers and dealers using Strat-style shapes in Germany. SKW Schwarz is representing Maybach Guitars in this dispute. The case illustrates how far copyright protection for iconic product shapes may actually extend.

In a default judgment dated December 22, 2025 (Case No. 14c O 64/25), the Regional Court of Düsseldorf ruled solely on the basis of Fender’s submissions and without any opposing arguments that the body shape of the Fender “Stratocaster” constituted a copyright-protected work of applied art. Fender is now using this decision as the basis for a huge wave of cease-and-desist actions against numerous manufacturers of guitars with Strat-style shapes — including Maybach Guitars.

 

What Fender Is Demanding

  • Cessation of the manufacture, distribution, and promotion of certain guitar models,
  • Execution of a cease-and-desist declaration subject to contractual penalties,
  • Destruction and recall of the affected guitars,
  • Comprehensive disclosure of information, as well as damages and reimbursement of legal fees.

For affected manufacturers, far more than just a single product line is at stake.

 

The Counterposition: Iconic, Yes — Monopoly, No

Maybach Guitars is defending itself with the support of an international legal team, including SKW Schwarz (Dr. Magnus Hirsch). The response focuses, among other things, on:

  • the limits of relying on a default judgment against an entire industry,
  • the decades-long tolerated use of the Strat shape by hundreds of manufacturers worldwide,
  • international precedents in which the Strat body shape was classified as generic, as well as
  • specific design differences between Maybach guitars and the examples cited by Fender, and also
  • the protection of everyday items, so-called works of applied art, under copyright law, which is virtually unlimited in duration, alongside design protection, which is limited to 25 years.


 

What Does This Mean for the Industry?

The Stratocaster case demonstrates that copyright protection for iconic shapes might be possible — but not unlimited. Companies receiving cease-and-desist letters should neither panic nor sign anything prematurely, but instead carefully examine their legal options. This is especially relevant because not only could Fender assert similar claims regarding other models, but other well-known guitar manufacturers may also follow Fender’s example.

Our partner and attorney Dr. Magnus Hirsch will be pleased to assist you with any questions or advisory needs.

05/26/2026, Dr. Magnus Hirsch

Events

30

Focus topics

22

Expertise

30

Mixed

30

Further insights

Explore the latest legal developments, insights, publications and news from our firm.

noResults