Search results for
Lawyers
Markus von Fuchs advises in intellectual property law, in particular in competition, patent, and trademark law as well as on the protection of know-how. He advises companies on protecting and commercially exploiting intellectual property, for example through licensing, sales, R&D, and cooperation agreements. He also focuses on the judicial and extrajudicial defense of intellectual property rights in interim injunction and principal proceedings. He further advises on border seizing procedures, initiates and advises on criminal measures relating to product and brand piracy, and on the infringement of business and business secrets. Markus von Fuchs also advises many companies on developing and introducing new technologies and business models. He has particular expertise in the optical and medical technology sectors.
Norbert Klingner specializes in national and international movie/TV and advertising film production, financing, insurance, and distribution. He represents well-known producers, distributors, global distributors, and movie financing entities. His expertise ranges from negotiating and drafting contracts from the beginning of the material development to all matters related to production and financing up to the strategically correct exploitation and licensing. A selection of the film productions in which Mr. Klingner was involved can be found on the Internet Movie Database IMDb.
Margret Knitter advises her clients in all matters of intellectual property and competition law. This includes not only strategic advice, but also legal disputes. Her practice focuses on the development and defense of trademark and design portfolios, border seizure proceedings and advice on developing marketing campaigns. She advises on labelling obligations, packaging design, marketing strategies and regulatory questions, in particular for cosmetics, detergents, toys, foodstuffs and Cannabis. She represents her clients vis-à-vis authorities, courts and the public prosecutor's office.
In the field of media and entertainment, she mainly advises on questions of advertising law, in particular product placement, branded entertainment and influencer marketing. She is a member of the board of the Branded Content Marketing Association (BCMA) for the DACH region and member of the INTA Non-Traditional Marks Committee.
Dr. Matthias Nordmann advises international groups, mid cap companies, investors and entrepreneurs on company, commercial and corporate law in particular on structuring and mergers & acquisitions. He has a special focus on transactions in IP/IT driven industries as well as real estate.
Dr. Andreas Peschel-Mehner has provided legal counsel to all forms of digital business since the inception of the world wide web. His advisory spans start-ups, multi-channel offerings and international internet companies and focuses on all applicable legal fields with a particular emphasis on data protection and usage, terms and conditions, consumer protection, compliance, advertising, gaming and competition law, among numerous others. Dr. Andreas Peschel-Mehner also commands broad expertise in media and entertainment law, in particular issues touching on the film and television industry and those related to media production finance and the global exploitation thereof, with digital media advisory on changes to utilization models, revenue streams and video on demand platforms composing a significant part of his counsel.
An excerpt of the projects Dr. Andreas Peschel-Mehner has accompanied can be found on the Internet Movie Database IMDb. His advisory expertise is augmented by decades of involvement with and counsel of national and international computer game publishers and studios. Finally, developments and use of KI technologies across all his expert areas has become a strategic element of his practice.
Legal expertise – digitally sophisticated
Stefan Schicker has been advising clients at the intersection of law, technology, and innovation for over 20 years. As an experienced and award-winning lawyer specializing in IT and IP law, he assists national and international companies in the legally compliant design of digital business models – from the design of complex internet platforms to the protection of intellectual property.
One of Stefan Schicker's special areas of expertise is the legal structuring of corporate influencer initiatives: with specially developed workshops, he supports companies in setting up corporate LinkedIn communication in a legally compliant and effective manner – in accordance with copyright, personality rights, competition law, etc. – More information.
Legal tech & law firm development – with leadership experience
In parallel to his legal practice, Stefan Schicker is one of the most prominent legal tech experts in the German-speaking world. As former COO and CEO of SKW Schwarz, he played a key role in shaping the digital transformation of the law firm – from strategy to operational implementation.
Today, he supports law firms and legal departments in establishing and expanding modern structures:
- Development and introduction of AI-supported tools
- Establishing internal teams of experts and training concepts
- Change processes for the sustainable anchoring of digital working methods
- Organization of law firms as companies
Stefan Schicker brings a unique combination of legal depth, technological experience, and operational law firm management to the table – recognized, among other things, as one of the “Top 3 Legal Leaders of the Year” (Best of Legal Awards).
For companies and law firms that don't want to wait for the future
Whether companies with digital business models or law firms undergoing change: Stefan Schicker combines legal certainty with entrepreneurial foresight – and makes complex transformations understandable, feasible, and effective – More information.
News
EmpCo: Special rule planned in Germany for certain existing stock – what companies need to know now
Just days before the new EmpCo rules take effect, an important amendment to the German Act Against Unfair Competition (UWG) is taking shape. A special rule is planned for certain goods that were placed on the market before 27 September 2026. However, the proposed amendment would not introduce a general sell-through or grace period. For companies, the key priorities now are to document, prioritise and prepare for potential disputes.
On 27 September 2026, the new rules implementing the Empowering Consumers Directive (EmpCo) will take effect under the German Act Against Unfair Competition (UWG). From that date, environmental and sustainability communications will have to comply with stricter requirements.
One question is particularly pressing for companies: What happens to goods that are already on the market where the packaging contains environmental or sustainability claims that may no longer comply with the new requirements?
So far, the UWG does not provide for a general transition, grace or sell-through period for such goods. Just days before the deadline, however, an important amendment is now taking shape.
Proposed Section 15b UWG: proportionality test for claims for injunctive relief
According to a draft legislative resolution currently available, a new Section 15b UWG is to be introduced into German law.
Under the proposed provision, claims for injunctive relief based on certain EmpCo infringements relating to goods placed on the market before 27 September 2026 would have to be asserted in good faith and in accordance with the principle of proportionality.
As part of a comprehensive balancing of interests, four factors in particular would have to be taken into account:
- the seriousness of the infringement;
- the efforts made by the company to remedy the infringement;
- the costs associated with remedying the infringement; and
- the environmental impact associated with remedying the infringement.
The German Bundestag is expected to vote on the Act to Modernise Design Law on 24 September 2026, in the context of which the amendment to the UWG is, according to the information currently available, expected to be introduced. The proposed new provision has not yet been adopted.
No general sell-through or grace period
For companies, it is important to understand what the proposed rule would not do: based on the wording currently available, it would not introduce a general transition, grace or sell-through period.
Section 15b UWG-E would not automatically make an EmpCo infringement lawful. Instead, the provision is intended to make the enforcement of claims for injunctive relief in relation to certain goods already placed on the market subject to a proportionality test.
In a specific dispute, it could therefore be relevant, for example, whether a contested claim can be corrected by applying stickers or relabelling, what costs this would entail, or whether an immediate stop to distribution would result in the destruction of significant quantities of goods and the associated environmental impact.
Depending on the individual case, this balancing of interests may affect the nature and scope of injunctive relief. How the provision will be applied in practice, however, is likely to become clear only over time and, potentially, through case law.
Key distinction: “placed on the market” does not mean “produced”
One detail of the proposed wording is particularly important.
The special rule would not apply across the board to all goods produced before the deadline. Instead, it expressly refers to goods that were already placed on the market before 27 September 2026.
Companies holding significant quantities of goods or packaging should therefore carefully assess which inventory may fall within the scope of the proposed provision.
In particular, companies should now ensure that they can document when the relevant goods were placed on the market.
What companies should document now
The proposed rule makes documentation even more important. The information companies record today may later prove crucial when assessing whether injunctive relief is proportionate.
Companies should document in particular:
- Which goods are affected? Which products or packaging contain potentially problematic environmental or sustainability claims?
- When were they placed on the market? Delivery records, inventory management data and other relevant evidence should be secured without delay.
- What measures have already been taken? For example, changes to future packaging, relabelling, stickers or information provided to retailers and other distribution partners.
- What further adjustments are possible? And what organisational and economic effort would they require?
- What costs would arise? For example, from relabelling, product recalls, changes to production or, where applicable, destruction of goods.
- What would the environmental impact be? This may be particularly relevant where significant quantities of goods or packaging would otherwise have to be destroyed.
The latter four aspects in particular directly reflect the criteria that, according to the draft currently available, are to be considered as part of the proportionality assessment.
No extension for websites, online shops or social media
The proposed special rule should not be understood as a general extension of the EmpCo implementation deadline.
Based on the wording currently available, Section 15b UWG-E expressly refers to goods placed on the market before the deadline. Other forms of environmental and sustainability communication would not generally benefit from the proposed rule.
Companies should therefore continue to review and, where necessary, adapt websites, online shops, social media communications, digital campaigns and other communications that can be changed at short notice by 27 September.
EmpCo remains a litigation issue
The proposed amendment does not eliminate the risk of legal disputes.
Competitors, associations and qualified entities can take action against unlawful environmental and sustainability communications. The new provision would instead add another question to potential disputes: Is the claim for injunctive relief sought proportionate in the circumstances of the individual case?
In addition to the legal assessment of the claim itself, it may therefore become crucial how well a company has documented its existing inventory, the remedial measures already taken and the associated costs and environmental impact.
Companies should use the remaining days to focus on two areas:
1. Compliance:
Prioritise communications that can still be changed, review claims and secure the necessary supporting evidence.
2. Litigation readiness:
Document affected inventory and when it was placed on the market, assess potential remedial measures and record their economic and environmental impact.
What happens next?
The German Bundestag is expected to vote on the Act to Modernise Design Law on 24 September 2026. It remains to be seen whether the proposed Section 15b UWG will be adopted and, if so, in what final form.
For companies, the message is clear: Monitor developments – but do not wait for them.
The EmpCo deadline remains 27 September 2026. The proposed special rule could provide new arguments in the defence against claims for injunctive relief in relation to certain goods already placed on the market. However, it does not replace the need to review existing claims or to prepare for potential legal disputes.
Prioritise claims. Secure evidence. Document existing stock. Prepare for potential disputes.
EmpCo Compliance & Litigation
SKW Schwarz supports companies in implementing the new EmpCo requirements – from our EmpCo Quick Check and the legal review of environmental and sustainability claims to dealing with packaging and existing stock, as well as defending against cease-and-desist demands, claims for injunctive relief and regulatory fine proceedings.
Find out more about our EmpCo Compliance & Litigation services Click here
KI-Flash: Advertising Law and Data Protection as Ads Launch in ChatGPT
Since August 24, 2026, German ChatGPT users have also been seeing ads.
OpenAI has opened the advertising channel for 31 European markets. For users on the free Free and Go plans, ChatGPT’s functions are now available only with ads, while the Plus, Pro, Business, Enterprise and Edu plans remain ad-free according to the provider’s announcement of 18 August 2026. Ads are also shown only to logged-in users who have reached the age of majority.
One week later, on 31 August 2026, OpenAI opened self-service access through the Ads Manager for the same markets in a beta version. Advertisers based in Germany have since been able to book ads without an agency or technology partner. Booking through the provider’s ads solutions team and through agency and technology partners remains available alongside this.
Ad-funded generative AI is therefore no longer an announced plan in the German market but live operation. This article sets out the standards of review under advertising and data protection law. It is addressed to companies that advertise in this environment or deploy AI assistants in their own operations; the provider’s own obligations are described only to the extent that they matter from that perspective. No statements by the competent authorities on this advertising model are available so far.
This article opens a three-part series on current developments around AI assistants. The second part deals with the designation of ChatGPT as a very large online search engine under the Digital Services Act and the obligations attached to it. The third part asks to what extent advertisers and agencies are responsible for the content of ads placed in AI assistants and liable for the statements they make. The question of when a provider must have AI answers attributed to it as its own content was already covered in our KI-Flash of 2 July 2026.
No personalised advertising in the EEA so far
For ads on online platforms, a distinction is drawn between personalised and non-personalised advertising. The legal requirements for the two differ considerably.
In the first phase, currently implemented in the European Economic Area, ads are selected without personalisation in the sense of profiling. What is used is the topic of the ongoing conversation together with limited contextual information such as approximate location, language, time of day and device type. Earlier chats and stored information are expressly excluded according to the provider. Advertisers receive aggregated performance data only, and no conversation content, no real names and no precise location data.
Personalised advertising requires separate consent. Only then do chat history, stored information and a user’s behaviour in response to earlier ads feed into the selection. Users’ consent is required for this, as OpenAI also expressly describes in the version of its European privacy policy of 2 June 2026. This personalised advertising option has not yet been activated in the EEA.
One point that has largely gone unnoticed deserves attention here: behaviour in response to earlier ads can only feed into the selection if it has been collected beforehand, and, at least according to the provider, that does not happen in the first phase. The change therefore does not consist solely in evaluating existing data but first of all in building up a new set of data. Consent would have to cover that step as well.
How must advertising in an AI assistant be labelled?
The provider describes the ads as clearly labelled and visually separated from the answer. Under advertising law, the question is usually discussed under Section 5a(4) UWG. No. 11 of the Annex to Section 3(3) UWG may also apply, which covers the use of editorial content financed by a trader and disguised as information. That provision presupposes, however, that editorial content exists at all, and whether an AI-generated answer qualifies is an open question. For comparison portals and search engines, editorial content is in part affirmed even though there is no editorial team in the traditional sense. What speaks against that classification is precisely the position taken by the ZAK, the joint commission of the German state media authorities, according to which AI answers are the provider’s own content and therefore do not appear as neutral reporting. Added to this are Section 6(1) DDG for commercial communication in digital services and, where the service qualifies as a media intermediary or a media-like offering, Section 22 MStV. Classification as a media intermediary depends on whether the service aggregates third-party content, selects it and determines how easily it can be found. That is exactly what the ZAK relied on in relation to source citations and link lists. A service that generates only its own answers does not meet that test.
The structural risk, however, lies not in the design of the ad block but in the selection logic. An ad selected on the basis of the topic of the ongoing conversation appears at a moment when the user has just articulated a specific concern. In functional terms it works like native advertising, even where it is presented as “formally separated”. Whether a visual separation is enough to address this problem of contextual proximity is a question of the specific implementation.
Are AI answers the provider’s own content?
Against the labelling obligations under Section 22 MStV and Section 6 DDG it could be argued that a chat interface has no editorial part from which advertising would have to be distinguished in the first place. On the line that has emerged so far, that defence does not hold: in its judgment of 28 May 2026 (26 O 869/26), the Regional Court of Munich I treated a search engine’s “AI Overview” function as the provider’s own substantive statement and found that the provider had adopted the content as its own (paras. 33 f.). Three aspects were decisive: the function produces a self-contained running text that summarises, structures and evaluates search results; it forms statements that are not contained in the sources relied on; and, from the perspective of a reasonably informed average user, it appears as an answer for which the provider is responsible rather than as a neutral list of results. On 14 July 2026, in proceedings of the Hamburg/Schleswig-Holstein and Berlin-Brandenburg state media authorities, the ZAK issued its first orders against AI services operated by Google and Perplexity, holding that AI answers are the providers’ own content and that the liability exemption under the DSA does not apply. Neither decision is final and binding yet, and appeals have been announced. For Section 5a(4) UWG this preliminary question is irrelevant. For No. 11 of the Annex it matters, because editorial content is a constituent element there.
The promise about the answers
OpenAI promotes the principle that advertising does not influence the answers. Beyond being a product description, this also appears to be a statement about a material characteristic of the service within the meaning of Section 5 UWG. If the actual design departs from it – for instance through influence on ordering, product mentions or shopping integration – a misleading commercial practice would come into consideration. In practice the question of evidence arises immediately: how does a competitor prove a distortion in the model’s behaviour? How the model works lies solely within the provider’s sphere, which speaks in favour of a secondary burden of substantiation: the competitor puts forward tangible indications and the provider then has to respond in substantiated form. It can be countered that a secondary burden of substantiation is ruled out to the extent that the competitor can test the answering behaviour itself. Starting points are offered by the audit obligations under Art. 37, the ad repository under Art. 39 and researcher access under Art. 40 DSA – provisions that now apply as a result of the designation as a very large online search engine of 31 August 2026. More on this in the next article.
Who is subject to the consent requirement?
Section 25 TDDDG applies to access to information on terminal equipment through cookies. The OpenAI measurement pixel sets a first-party cookie on the advertiser’s domain. The consent requirement therefore falls not on the platform operator but on the booking party. The provider also makes a server-side interface for conversion measurement available; its use, too, is processing carried out by the booking party itself.
Section 25 TDDDG does not apply to server-side transmission, because no access to terminal equipment takes place there. The only benchmark in that respect is the GDPR.
May chat histories be used to select ads?
This is where the real point of examination lies. Chats are shared for the purpose of completing a task, not for optimising advertising. Drawing on the history for ad selection must therefore be measured against Art. 5(1)(b) and Art. 6(4) GDPR, regardless of whether consent is obtained.
Art. 9 GDPR also comes into play. Conversation histories regularly reveal health data, religious or philosophical beliefs, sexual orientation or political opinions. In Cases C-252/21 and C-446/21 the CJEU applied a broad standard for when special categories of data are involved and set strict requirements for the validity of consent. In Case C-446/21 it also found a breach of the data minimisation principle because personal data had been processed for targeted advertising purposes without any distinction according to their nature. Irrespective of this, Art. 21(2) GDPR provides an unconditional right to object to direct marketing, which is not open to any balancing exercise. The right attaches solely to the purpose of the processing and not to the legal basis. It therefore also covers the delivery of non-personalised ads to the extent that these constitute direct marketing.
Self-commitment does not replace a legal basis
The provider has set category exclusions for physical health, mental health and politics; political advertising is currently not permitted at all. Exclusions of this kind are contractual self-commitments. They replace neither a legal basis under Art. 9 GDPR nor an assessment of sector-specific advertising bans. How a prohibition under the law on advertising for medicinal products is to be enforced in an interface in which users are describing their symptoms is an open question.
The reverse case also arises. Under the provider’s advertising policies, regulated industries, among them legal, health and financial services, are excluded from booking outside the United States. For companies in these sectors, the first question is therefore not one of admissibility but one of access.
The protection of minors, too, operates through a technical self-commitment: ads are not served where the user is presumed to be a minor, as determined by age estimation. That protective measure is itself processing that calls for justification. Section 6 JMStV and No. 28 of the Annex to Section 3(3) UWG have to be taken into account in addition. Section 6 JMStV is a rule governing market conduct within the meaning of Section 3a UWG and can therefore also be enforced under unfair competition law. No. 28 of the Annex covers direct exhortations to children to buy, that is to persons under the age of fourteen. Art. 6(1)(f) GDPR comes into consideration as the legal basis for age estimation. It cannot be based on Art. 6(1)(c) GDPR to the extent that it rests on a voluntary self-commitment rather than on a specific legal obligation.
Transparency and labelling
The information obligations under Art. 12 to 14 GDPR are under particular scrutiny in 2026: on 19 March 2026 the EDPB launched a coordinated enforcement action on precisely these provisions, with 25 supervisory authorities taking part. A privacy policy revised shortly beforehand, which for the first time includes advertising as a processing purpose, therefore falls within an ongoing year of review.
Art. 50 AI Act has applied since 2 August 2026 in addition. Digital Omnibus Regulation (EU) 2026/1744 postponed only the machine-readable marking under Art. 50(2) AI Act for systems placed on the market before that date, namely to 2 December 2026. As regards competence, a distinction has to be drawn in Germany: under the KI-MIG, the Federal Network Agency is the central market surveillance authority, but for media services used for journalistic or advertising purposes competence remains, pursuant to Section 2(8) KI-MIG, with the authorities designated under state law.
What remains open for the booking party
What remains unresolved above all is which labelling obligations apply to the booking party itself, independently of how the platform operator implements them, and who is the controller under data protection law once the booking party deploys its own measurement tools. The third article in this series addresses both questions. For companies whose staff use ad-funded plans in their day-to-day work, there is the added point that conversation content feeds into ad selection there. What this means for trade secrets and for professionals bound by professional secrecy has barely been examined so far.
We would be glad to support you in reviewing your campaigns in the AI environment, in designing labelling and measurement, and in assessing the allocation of roles under data protection law.
The manufacture of medicines in a pharmacy
Federal Administrative Court on the Compounding of Medicinal Products in Pharmacies
In its judgment of 12 March 2026, the German Federal Administrative Court (BVerwG) clarified important issues concerning the compounding of medicinal products in pharmacies.
Dr. Oliver Stöckel analyses the decision in his latest article for GRUR-Prax. The article focuses on the requirements for prescriptions for medical practice supplies, the need to identify specific patients, and the limitation of stock preparations to a maximum of 100 patients or patient portions per day.
The decision is likely to significantly restrict the practical scope for compounding medicinal products for medical practice supplies.
Beck-Online subscribers can read the full article here (in German).
AI Flash: AI literacy Under Article 4 of the AI Act: A Look at the New (Old) Questions
Following our report on the GEMA v. Suno case in our last AI Flash, we would like to continue providing you with regular legal insights into current developments in AI law.
Today’s topic: AI literacy under Article 4 of the AI Act
Hardly any provision of the AI Regulation affects as many companies in practice as Article 4 of the AI Act on so-called “AI literacy.” It applies regardless of risk class or industry and thus to anyone who offers or operates AI systems. This is already relevant simply when using ChatGPT, Copilot, or comparable tools in everyday work. The provision has now been amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744 of July 8, 2026, in effect since July 27, 2026). This is reason enough to take another detailed look at the regulation.
I. What Has Changed?
In its original version, Article 4 of the Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (AI Act) required providers and operators to ensure, to the best of their ability, that their personnel possessed a sufficient level of AI literacy. This wording faced criticism for implying a success that companies could hardly guarantee reliably.
The Digital Omnibus on AI has made adjustments. Article 4 AI Act now states:
(1) Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.
(2) The Commission and the Member States shall support and facilitate the efforts of providers and deployers of AI systems, in particular SMEs, in fulfilling their obligation under paragraph 1 of this Article. For that purpose, the Commission shall publish practical examples of how to comply with that obligation on the single information platform referred to in Article 62(3), point (b).
(3) The Board shall adopt recommendations, taking into account European competence frameworks, to support the Commission and Member States in the promotion of AI literacy required under paragraph 1, including by setting out common objectives.
Thus, the obligation has shifted from "ensuring" a level of competence to supporting the development of AI literacy through appropriate measures - explicitly without guaranteeing a specific individual competence level.
Notably, what was not included in the new version of the regulation is significant: the original Commission proposal aimed to largely shift the responsibility for promoting AI literacy to the EU and the Member States. This fundamental realignment did not prevail in the trilogue. The obligation remains-albeit mitigated-with the providers and operators themselves. The only new aspect is the accompanying support from the Commission, Member States, and the AI Committee (paragraphs 2 and 3).
II. What Does "AI literacy" Actually Mean?
The term "AI literacy" is not defined in Article 4 AI Act but is elaborated in the definition provided in Article 3 No. 56 AI Act. According to this, AI literacy refers to the "skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations in the context of this Regulation, to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and possible harm it can cause."
Thus, AI literacy is not merely technical niche knowledge but a bundle of technical understanding, risk awareness, and legal and ethical basic understanding. It addresses all actors along the AI value chain - from developers and operational staff to individuals who use AI systems on behalf of the company, such as external service providers.
Importantly for practice: Article 4 AI Act does not prescribe a specific training format, certification, or a dedicated "AI Officer." Internal training, e-learning, workshops, or external training are all permissible-what matters is that the measures fit the technical knowledge level, experience, context of use, and risk profile of the respective target group. Both the Federal Network Agency and the AI Service Center Austria of the RTR explicitly recommend documenting the measures taken (type of training, content, timing, affected groups) to demonstrate compliance with Article 4 AI Act if necessary, even though no legally mandated proof standard currently exists.
III. The (Highly Problematic) Question of Sanctions
The question remains, particularly contentious in practice: What happens if a company fails to promote AI literacy?
1. No Immediate Fine Under Article 99 AI Act
First, the good news: Article 99 AI Act lists the provisions subject to fines exhaustively. Article 4 AI Act is not mentioned there. Therefore, the regulation does not provide for an immediate fine specifically for violations of the AI literacy obligation - this is confirmed by both the Austrian AI Service Center of the RTR and the Federal Network Agency.
However, a violation is not without consequences. Some literature suggests that national market surveillance authorities - in Germany, the Federal Network Agency - can address violations of Article 4 AI Act based on national regulations with other enforcement measures. Moreover, and practically more significant, Article 4 AI Act exerts its effect mainly indirectly, through general civil and corporate law.
2. Employer Liability Under § 278 BGB
If a company uses AI systems, it bears the entrepreneurial risk as an operator and is responsible for the proper organization of operations and work equipment. If damage occurs to customers or business partners - due to incorrect operation of an AI system, unverified adoption of erroneous AI outputs, or inputting business secrets into an external AI system - the employer is liable under § 278 BGB for the fault of its employees as vicarious agents. Article 4 AI Act reinforces an existing duty of care and effectively becomes the benchmark against which the appropriateness of the organizational measures taken is assessed. If there is a complete lack of a traceable training and governance structure, the assumption of a breach of duty of care is likely.
3. Recourse Against Employees
Conversely, a company that suffers damage can seek recourse from responsible employees under the principles of internal damage compensation. Here, an interesting interaction emerges: in cases of slight negligence, the employee is typically not liable; in cases of moderate negligence, only partially; full liability generally only arises in cases of gross negligence or intent. Literature suggests that the success of a recourse claim may depend on whether the employer has fulfilled its training obligation under Article 4 AI Act. A company without a robust training concept may find itself at a disadvantage in a serious case - even with potentially gross negligence on the part of employees.
4. Liability of Management and Board
Finally, the question also concerns the management level itself. Managing directors of a GmbH (§ 43 Abs. 1 GmbHG) and board members of an AG (§§ 76, 93 Abs. 1 AktG) are obliged to take the necessary organizational measures to ensure compliance with legal behavior within the company - such as through a compliance management system that also incorporates the AI literacy obligation. If they violate this obligation culpably and the company suffers damage as a result, internal liability under § 43 Abs. 2 GmbHG or § 93 Abs. 2 S. 1 AktG may apply. The recognized business judgment rule in German law provides only limited assistance here: whether or not to establish a compliance system with a training concept is not a matter of entrepreneurial discretion but is legally mandated. Entrepreneurial discretion exists only regarding the specific design - as long as an appropriate minimum standard is maintained.
Interim Conclusion: While Article 4 AI Act is not subject to fines, it is by no means without consequences. The actual "sanctioning" occurs through the backdoor of general liability law - and this makes the norm more relevant for business practice than the absence of a fine might initially suggest.
IV. Looking Beyond the Obligation: Added Value in Practice
While the legal discussion of liability risks is certainly justified, our consulting practice with numerous in-house training sessions and workshops on AI literacy reveals another often underestimated effect: the real value does not arise only in disputes but already in the training room itself. In almost every format we have facilitated, most of the staff's open questions - from responsibility for AI outputs to handling confidential data and copyright issues - could be clarified through direct exchange.
Practical uncertainties in daily interactions with AI tools can often be resolved easily before they become actual problems. Moreover, through shared exchange, a collective awareness within the company is created. AI literacy is then not perceived as an abstract compliance requirement but as a jointly developed standard that the staff supports.
V. Conclusion and Outlook
The Digital Omnibus on AI has made Article 4 AI Act more practical without abandoning the obligation itself. The absence of a fine does not change the fact that deficiencies in AI literacy can become relevant under general civil, labor, and corporate law - for the company, for employees in recourse cases, and for the management level alike. Those who take this framework seriously and simultaneously leverage the practical value of training and workshops not only create legal certainty but also foster a sense of shared sovereignty in dealing with AI within the company.
SKW Schwarz is happy to assist you in designing suitable training programs and accompanying you in conducting initial workshops on AI literacy in your company. Please feel free to contact us so that we can jointly create the greatest possible value for your business.
The E-Evidence Regulation Is Coming: What Service Providers Need to Know Now – Part 2
Part 2: EEVO – Obligations, Deadlines, and Sanctions in Practice
The first part of this publication set out the basic structure of the EEVO: the two new instruments, EPOC and EPOC-PR, the range of service providers concerned, and the conditions under which a connection to the EU within the meaning of the Regulation exists. This second part now turns to the practical implementation that becomes directly relevant to service providers in an actual case: the applicable deadlines for production and preservation, the scope of the review required before execution, and the sanctions and liability consequences of non-compliance.
Deadlines: Production and Preservation Compared
The most striking feature is the deadlines, which are considerably shorter than those familiar from classic mutual legal assistance proceedings. For the European Production Order, the standard deadline is ten days from receipt, shortened to eight hours in emergencies (Article 10(2) and (4) EEVO). The logic underlying the European Preservation Order is different: the focus here is not on rapid production, but on freezing the status quo. The obligation to preserve the data concerned arises immediately upon receipt; the preservation itself must be maintained for 60 days and may be extended once, by 30 days, by the issuing authority (Article 11(1) EEVO). If a production order subsequently follows, the preservation obligation continues until the data is actually produced (Article 11(2) EEVO) – the two instruments can therefore be combined.
What Review Is Required Before Execution?
How extensive a review a service provider must carry out before execution depends largely on the category of data concerned. For an EPOC: subscriber data and traffic data used solely for user identification must be produced without further review (Article 5(3) EEVO). The position is different for anything going beyond this – for further traffic data and for content data, it must be examined whether the underlying offence falls within the catalogue of serious offences set out in Article 5(4) EEVO. For the EPOC-PR, the scope is deliberately drawn more broadly: it may be issued for any offence for which a corresponding order would be possible in a comparable domestic case under the same conditions (Article 6(3) EEVO), and it covers all categories of data.
Irrespective of the data category, the same formal review applies in both cases: is the person concerned identifiable from the information provided, and is the certificate complete and free of errors? Where there is doubt on this point, this must be indicated using the form set out in Annex III; the issuing authority must then provide clarification within five days – if it fails to do so, the obligation to execute or preserve, as applicable, lapses.
When May or Must Execution Be Refused?
Not every order received must actually be executed. The addressee does not have a general power to refuse – the EEVO is too heavily geared towards rapid effectiveness for that. In four narrowly defined cases, however, the addressee may, or must, refuse execution and must notify the issuing authority of this without delay: where the order is formally deficient (Article 10(6), Article 11(5) EEVO); where execution is factually impossible, for example because the person concerned is not a customer of the service provider or the data has already been lawfully deleted (Article 10(7), Article 11(6) EEVO); where there are indications of immunities, privileges, or rules on liability under press law (Article 10(5), Article 11(4) EEVO); and where there is a conflict with an obligation under the law of a third country, such as the United States or the United Kingdom (Article 17 EEVO).
The last case is likely to be the most complex in practice: the objection may be raised within ten days of receipt, and enforcement is then suspended until this procedure has concluded – the data must, however, continue to be preserved in the meantime. In the immunity and press-law cases, by contrast, the addressee does not make its own decision to refuse, but merely triggers a review by the competent authorities.
Sanctions and Liability: Who Bears Which Risk?
A service provider that fails, without a valid reason, to comply with an order in breach of its obligations risks fines of up to 2% of total worldwide annual turnover for the preceding financial year (Article 16(1) EEVO) – a framework that companies are likely to find familiar from other pieces of European legislation.
In practice, what is likely to matter most is whether, and how actively, a company communicates with the issuing authority: a company that promptly reports any obstacles is likely to be in a better position to rely on a recognized justification within the meaning of the provision, whereas unexplained silence increases the risk of sanctions.
The picture on liability is somewhat more reassuring: service providers are not liable to their users or third parties for damage arising solely from good-faith compliance with an EPOC or EPOC-PR (Article 15(2) EEVO) – responsibility for the lawfulness of the order remains with the issuing authority. Nor does the service provider necessarily have to bear the costs of responding to an order alone: under certain conditions, reimbursement may be claimed, to the extent that the national law of the issuing state provides for this in respect of comparable domestic orders (Article 14 EEVO).
What Companies Need to Do Now
All of this results in a scope of action for affected service providers that is manageable, but time critical. A point of contact ready to receive orders must be designated or appointed, internal workflows for receipt, review, preservation, transmission, and documentation must be established, and the relevant personnel should be familiar with the tight deadlines before an actual case arises. To provide a quick overview, we have summarized the key deadlines and review steps for EPOC and EPOC-PR in this one-pager.
This outlines the practical obligations arising from the EEVO. Service providers falling within the scope of the Regulation should have incorporated the deadlines, review obligations, and response duties described above into their internal processes by 18 August 2026 at the latest, in order to be able to respond in a timely and legally compliant manner in the event of an EPOC or EPOC-PR.
Would you like support in setting up or reviewing your internal processes? We would be glad to assist you in developing workflows that work in practice and to support you in preparing for 18 August 2026.
The E-Evidence Regulation Is Coming: What Service Providers Need to Know Now - Part 1
What Does the E-Evidence Regulation Cover – And Who Does It Apply To?
From 18 August 2026, Regulation (EU) 2023/1543 on European Production Orders and European Preservation Orders for electronic evidence in criminal proceedings – the e-Evidence Regulation, or EEVO for short – will become directly applicable in all Member States, including Germany, following a three-year transitional period. This date is no longer a distant prospect: in Germany, the implementing legislation, the Electronic Evidence Implementation and Enforcement Act (Elektronische-Beweismittel-Umsetzungs- und Durchführungsgesetz, EBewMG), was promulgated in March 2026; the Federal Office of Justice (Bundesamt für Justiz) has been designated as the central authority, while the Federal Network Agency (Bundesnetzagentur) is responsible for technical regulation.
Before turning to the EEVO itself, a look at the position under the law as it currently stands helps put matters into context. With the EEVO, the legislator responds to a state of affairs that has proven increasingly “very difficult” over the years. Cross-border access to electronic evidence has so far been governed by the classic mutual legal assistance procedure: a foreign authority had to submit a request to the competent German authority, which would then examine it and, where appropriate, issue its own order – only at that point was a service provider under any obligation to produce data. Depending on the case, this route could take weeks or months, while the request itself remained without consequence for the service provider in the meantime. A foreign request received directly by a service provider did not, on its own, give rise to any obligation to review or respond – it could, and generally had to, remain unanswered as long as no German order had been issued.
In this two-part publication, we now present the EEVO, which addresses precisely this point. The first part covers its basic structure – the new instruments EPOC and EPOC-PR, the range of service providers concerned, and the scope of application. The second part will then set out the applicable deadlines, the review obligations that apply, and the sanctions that may follow non-compliance.
In addition to these two articles, we have created a cheat-sheet that provides a quick overview of the key deadlines and review steps.
>> Read cheat-sheet <<
Two New Instruments: EPOC and EPOC-PR
At the heart of the EEVO are two new types of order that allow law enforcement authorities in one Member State to address service providers in another Member State directly in future – without the previously customary detour via mutual legal assistance proceedings. The European Production Order (EPOC) requires a service provider to produce specified electronic evidence, such as content, traffic, or subscriber data. The European Preservation Order (EPOC-PR) operates a step earlier: it merely requires the service provider to preserve data for a specified period so that it is not deleted before a production order, where applicable, follows.
For affected companies, this means one thing above all: both types of order take immediate effect. Unlike before, no separate involvement of a German authority is required – an order issued by another Member State becomes binding as soon as it reaches the designated point of contact within the company. What was previously described as a passive role thus becomes an active obligation to act. Whereas a service provider was previously permitted to leave a foreign request unanswered without consequence, it is now directly obligated in its own right from the moment an EPOC or EPOC-PR is received.
Who Is Subject to the EEVO?
The EEVO addresses service providers with a connection to the EU under Article 2(1) EEVO, irrespective of whether they are established in the EU at all. This marks an important difference from many other pieces of European legislation: a cloud provider without any European establishment can be just as affected as a German company. Under Article 3(3) EEVO, this covers in particular providers of electronic communications services (such as messaging or VoIP services), domain name registries and registrars, as well as other information society services – a category under which the Regulation expressly includes platform operators such as social networks and file-hosting services, as well as hosting providers and cloud services.
The addressee of an order is, as a general rule, the controller within the meaning of Article 4(7) GDPR, i.e. whoever determines the purposes and means of the processing. Only exceptionally may an EPOC be addressed directly to a processor: where the controller cannot be identified by the issuing authority despite reasonable efforts, or where the investigation would otherwise be jeopardized (Article 5(6) EEVO).
When Is There a “Connection to the EU”?
The Regulation first requires that the services be accessible to persons in a Member State – identifiable, for example, by language, currency, or targeted marketing. That alone, however, is not sufficient. In addition, there must be a substantial connection to one or more Member States, such as an establishment carrying out genuine economic activity, a significant number of users, or activity that is clearly directed at the relevant Member State. Mere technical accessibility of a website is expressly not sufficient for this purpose under Recital 29 EEVO – a service that happens to also be accessible from Germany does not thereby automatically fall within the scope of the Regulation.
Who Receives the Orders?
Once the question of whether a provider is covered has been resolved, the practical question remains of where an order is actually to be sent. Under Article 3(1) of Directive (EU) 2023/1544, every service provider must designate an establishment or a legal representative for the receipt of EPOCs and EPOC-PRs – by 18 August 2026 at the latest, or within six months of commencing service provision in the EU. Orders are, as a general rule, addressed exclusively to this designated point of contact (Article 7(1) EEVO). If it fails to respond in time in an emergency, or if no point of contact has yet been designated, the authority may exceptionally address another establishment of the company (Article 7(2) EEVO).
In practice, it is therefore advisable for the function internally responsible for EPOC/EPOC-PR matters – such as Legal or Compliance – to correspond to the externally designated point of contact and to be genuinely reachable. Otherwise, there is a risk that an emergency order with a particularly short deadline ends up with a group entity that is unprepared and consequently unable to respond in time.
This sets out the legal framework. What this looks like in practice – which specific deadlines apply, when an order may be refused, and what consequences follow non-compliance – is the subject of the second and final part of this series.
Would you like to assess whether, and to what extent, your company is subject to the EEVO, or do you need support in designating a point of contact for receiving orders? We would be glad to assist you with the legal assessment and with preparing for 18 August 2026.
Cyber Resilience Act: The Five Key Takeaways from the European Commission's Guidelines
The Cyber Resilience Act (CRA) introduces extensive new cybersecurity requirements for manufacturers of software, connected devices, and other products with digital elements. While most obligations will apply from 11 December 2027, manufacturers will already be required, from 11 September 2026, to report actively exploited vulnerabilities and severe security incidents.
As companies prepare for the CRA, numerous practical questions arise: When is a new software version considered a new product? What are the consequences of a substantial update? How long must security updates be provided? And do products that have already been developed need to be redesigned to comply with the CRA?
The European Commission has now published guidelines on the application of the CRA. Using practical examples, the Commission explains how it interprets key concepts and obligations under the Regulation. Although the guidelines are not legally binding, they provide important guidance for companies and, likely, for the competent authorities responsible for enforcing the CRA.
Below, we summarize the aspects of the guidelines that are particularly relevant in practice.
1. The 24-hour reporting deadline does not start with the first suspicion
From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents. The guidelines explain when these short reporting deadlines begin to run.
An unconfirmed indication alone does not trigger the reporting deadline. However, the manufacturer must assess it without undue delay. The reporting period begins once this initial assessment establishes with sufficient certainty that:
- a vulnerability contained in the product is being actively exploited; or
- a severe security incident has occurred and has affected the security of the product.
From that point onward, an initial early warning report must generally be submitted within 24 hours. A follow-up notification must be submitted within 72 hours.
For an actively exploited vulnerability, the complete report must generally be submitted within 14 days after a corrective or mitigating measure becomes available. For a severe security incident, the deadline is one month after the 72-hour notification.
Companies therefore need not only a technical reporting mechanism but also clear responsibilities for the initial assessment and escalation of potential incidents. The process should cover both external reports and findings from internal security testing. The guidelines emphasize that the initial assessment must be carried out without undue delay, particularly where the potential vulnerability poses a significant risk. These procedures should be tested in practice before 11 September 2026.
2. A software version is generally placed on the market only once
According to the European Commission, software that is offered as a standalone product is placed on the market when the completed version is first made available on the EU market. This applies regardless of when individual customers purchase or download the software.
The guidelines illustrate this with an example: If software version 1.0.0 is first made available for download on 1 January 2028, it is considered to have been placed on the market on that date-even if some customers download it only at a later stage. A later version, such as 1.0.1, is not considered to have been newly placed on the market unless the changes are substantial. Consequently, the original placement-on-the-market date remains decisive.
The situation may differ for different variants of the same software, for example, builds for different operating systems or packages with different functionalities. Such variants may qualify as separate products. A new software version is also considered to be placed on the market again if it has undergone a substantial modification.
This distinction is particularly important for the CRA's transitional provisions. Manufacturers should document when individual versions were first made available, which variants they treat as separate products, and what changes were introduced subsequently.
3. Products that have already been developed do not automatically need to be redesigned
Many products that will only be placed on the market after 11 December 2027 are already under development today or have even been fully developed. According to the guidelines, the CRA does not automatically require these products to be redesigned.
However, manufacturers must assess the cybersecurity risks of the product. Based on the technical documentation, they must be able to demonstrate that the product achieves an appropriate level of cybersecurity and complies with the CRA requirements. The required conformity assessment, the EU Declaration of Conformity, and CE marking also remain mandatory.
However, the Commission does not require manufacturers to retrospectively recreate all evidence and testing from earlier development phases. If it is no longer possible to demonstrate how cybersecurity risks were addressed during the original development process, the manufacturer may instead carry out a current risk assessment and explain how the existing product design and security measures mitigate the identified risks.
This clarification is particularly relevant for industrial products with long development cycles. Companies should review which evidence is already available for ongoing product developments and identify any documentation gaps that still need to be closed.
4. For software updates, the decisive factor is the cybersecurity risk-not the scope of the update
Not every major update constitutes a "substantial modification" within the meaning of the CRA. Conversely, even a small change may qualify as substantial. The decisive factor is whether the intended use of the product changes or whether new or increased cybersecurity risks arise that were not previously considered.
The Commission provides the example of a system that initially only displays operational data from machines. If the system is later updated to allow it to control those machines, its intended use changes. The update must therefore be regarded as a substantial modification.
The guidelines also set out a non-exhaustive list of assessment criteria. In particular, it should be examined whether the update:
- introduces additional interfaces, communication channels, execution environments, or external dependencies;
- enables new attack scenarios; or
- significantly changes the likelihood or potential impact of attack scenarios that have already been considered.
By contrast, a significant functional enhancement does not necessarily constitute a substantial modification if it was already planned during the original development and taken into account in the risk assessment. Updates that merely remediate vulnerabilities or strengthen existing security measures generally do not constitute a substantial modification, provided that they neither change the intended purpose of the product nor introduce new or increased cybersecurity risks.
Companies should therefore align their product roadmaps with their cybersecurity risk assessments at an early stage. A technical classification as a major or minor release is not sufficient for the legal assessment. It is advisable to establish a documented process for evaluating security-relevant updates against the CRA criteria.
5. Five years is not a standard support period
As a general rule, the CRA requires a support period of at least five years. If a product is expected to be used for a shorter period, the support period may also be shorter. Conversely, where a product has a longer expected service life, five years will not automatically be sufficient.
This is particularly relevant for industrial installations, control systems, and other long-life products. For such products, the support period must reflect the realistically expected service life. The guidelines expressly clarify that five years should not be regarded as a universal standard for all products.
A substantial modification also does not automatically trigger a new five-year support period. The decisive question is whether the modification also affects the product's expected service life. For example, if a software update merely introduces new functionalities without extending the lifetime of the hardware or changing users' expectations, the remaining original support period generally continues to apply.
For continuously evolving software, manufacturers may, under certain conditions, limit vulnerability remediation to the most recently placed-on-the-market version. Users must be able to upgrade to that version free of charge and without additional costs. Normal efforts such as testing or configuration changes are generally not regarded as additional costs. However, if users are required to purchase new hardware or fundamentally rebuild their system environment, the manufacturer cannot rely on this simplification.
Practical Tip
The guidelines do not create any additional legal obligations. However, they provide important clarification on key issues that companies must address when implementing the CRA.
Manufacturers should, in particular, review whether software versions and updates are documented in a traceable manner, whether the cybersecurity risk assessment is integrated with product planning, whether support periods have been determined realistically, and whether the reporting process will be operational by September 2026.
The guidelines also address, among other topics, free and open-source software, cloud-based functionalities, spare parts, and the interaction of the CRA with vehicle regulation, the Radio Equipment Directive, and the Machinery Regulation.
Discover Our CRA Compliance Suite
Our CRA Compliance Suite provides modular, fixed-fee consulting services to help manufacturers, importers, and distributors of digital products implement the requirements of the Cyber Resilience Act (CRA). Contact us for more information.
Protection of Trade Secrets in Employment Relationships: New Article Published in RüSiR
How can companies effectively protect their trade secrets in employment relationships?
This question is explored by our partners Dr. Rembert Niebel and Alexander Möller in their article "Trade Secret Protection in Employment Relationships", published in the latest issue of RüSiR – Journal for Defence, Homeland Security, Cyber & Space.
Trade secrets are among a company's most valuable assets. This is particularly true in the security and defence sector, where employees regularly have access to sensitive information and technical know-how. The article examines the legal framework governing trade secret protection in employment relationships and explains the safeguards already provided by the German Trade Secrets Act (Geschäftsgeheimnisgesetz – GeschGehG), as well as how these can be effectively complemented through employment contract provisions.
The authors also discuss recent case law of the German Federal Labour Court (Bundesarbeitsgericht – BAG) on confidentiality agreements. They explain why broad, generic confidentiality clauses are often insufficient and outline alternative contractual approaches available to employers. Particular attention is given to tiered confidentiality agreements for employees with access to particularly sensitive information, as well as additional legal instruments for protecting confidential business information.
While the article is primarily aimed at companies operating in the security and defence industry, it also provides valuable guidance for employers across all sectors seeking to align their trade secret protection strategies with the latest legal developments.
You can download the full article as a PDF here.
Protection of Military Inventions: New Expert Article Published in RüSiR
How can military inventions be effectively protected without disclosing security-sensitive information? Our partner Markus von Fuchs addresses this question in his expert article, “The Protection of Military Inventions through Secrecy During Development, Commercialization and Infringement Proceedings”, published in the latest issue of RüSiR – Journal for Defence, Homeland Security, Cyber & Space.
Against the backdrop of an evolving security landscape and the growing importance of dual-use technologies, the article examines the challenges of protecting military innovations. It explains why traditional patent strategies do not always provide adequate protection in the defence sector and explores the role of secret patents and trade secret protection. The article also discusses how technological developments – particularly in the fields of drone and cyber technologies – influence the choice of appropriate protection strategies.
Another key focus is the legal framework governing secret patents under German law. The article outlines the requirements for classifying an invention as a secret patent, the procedures before the German Patent and Trade Mark Office (DPMA), and the legal implications of secrecy orders. It also examines the impact on patent infringement proceedings, security clearance requirements, and the commercial exploitation and licensing of security-relevant technologies.
Finally, the article demonstrates that the choice between patent protection and confidentiality has become an increasingly strategic decision. Particularly for technologies with short innovation cycles or significant security relevance, a multi-layered protection strategy – combining technical intellectual property rights with a robust confidentiality framework consisting of technical, organisational and contractual measures – may provide the most effective means of safeguarding innovation over the long term.
You can download the full article as a PDF here.
CJEU Judgment on Geoblocking: The Limits of the Borderless Internet
While information on the internet is accessible worldwide at any time, its legal regulations and intellectual property rights are always subject to strict territorial limits. Anyone who publishes content online must therefore be aware of the risk of infringing third-party rights abroad. The Court of Justice of the European Union (CJEU) has now ruled that effective geoblocking can prevent such infringements in other countries (judgment of 9 July 2026, Case C-788/24 – Anne Frank Fonds).
The Anne Frank Case: Geoblocking as Protection Against Copyright Claims
The legal proceedings involved a dispute between the Anne Frank Fonds and the Anne Frank Stichting regarding the online publication of the diaries of the world-famous Jewish teenager. While the works are already in the public domain in Belgium, they remain partially protected by copyright in the Netherlands until 2037. The defendants published a scientific edition on a Belgian website but blocked access for users from the Netherlands using geoblocking. The Anne Frank Fonds nevertheless considered this an infringement of its copyrights, arguing that users could bypass the restriction via standard VPN services.
The CJEU ruled that an unauthorized "communication to the public" — and thus an infringement of the copyrights still existing in the Netherlands — does not occur, provided that the geographical restriction is effective. To achieve this, the block must primarily correspond to the latest state of the art. Absolute security is not required. A user-side circumvention by means of VPN services does not automatically render the restriction ineffective.
Relevance Beyond Copyright Law
At the same time, the CJEU emphasizes conversely that an active duty applies to anyone who knows or ought to know about existing intellectual property rights abroad. Anyone who, with knowledge of such rights, fails to implement effective geoblocking measures is deemed to be targeting their content at the entire global audience (para. 42 of the judgment). The CJEU left open when such knowledge (the duty to know) can be assumed. Previous business relationships or the existence of delimitation agreements could already be sufficient.
This duty by no means affects copyright law alone. Geoblocking is also playing an increasingly important role in trademark law. An infringement of a national trademark on the internet requires that the use of the trademark actually takes place within the domestic territory. In this context, courts examine whether the use of the sign produces a noticeable economic effect in the domestic market—the so-called "commercial effect".
Whether such a domestic nexus exists must generally be assessed based on the specific circumstances of each case. Relevant factors include, among others, the language of the website, the top-level domain, information provided on the website, or—if available—specific delivery options, as well as other circumstances such as economic activity in the country. Now confirmed by the CJEU, the absence of geoblocking measures is at least a strong, if not decisive, indication that the website in question is (also) directed at the domestic public. This is likely to be particularly relevant for global websites.
Liability of the Website Operator, Not the VPN Provider
According to the CJEU, it is solely the website operator who is liable for ineffective technical measures — not the VPN provider whose service is used to circumvent them. This applies even if the VPN provider is aware that its service can be used to access protected content without the rights holders’ consent.
Conclusion
The CJEU judgment provides much-needed clarity for online business practices. Geoblocking has become a central tool for legally secure market segmentation in intellectual property law. At the same time, the lack of geoblocking measures can indicate that accessing the content from abroad is intentionally desired. Conversely, anyone who deliberately restricts their online activities to specific countries and implements this technically soundly via geoblocking can effectively eliminate liability risks abroad.
CJEU: Consumers Cannot Waive Their 14-Day Right of Withdrawal When Signing Up for a Streaming Subscription
Is the supply of a streaming service to be classified as an offer of ‘digital content’ or of a ‘digital service’ within the meaning of Articles 2(11) and (16) of the Consumer Rights Directive 2011/83/EU (hereinafter the ‘CRD’)? With regard to this question, whether a waiver of the right of withdrawal is possible (digital content) or not (digital services), opinions differ sharply.
Austria's Supreme Court sought clarity and referred this question – which ultimately determines when consumers' right of withdrawal lapses and thus goes well beyond a mere semantic distinction – to the Court of Justice of the European Union (CJEU). On July 9, the CJEU ruled in favor of stronger consumer protection (Judgment of 9 July 2026, Case C-234/25).
Personalized Streaming Services Constitute ‘Digital Services’
Consumers who wish to access films, series, or live sports on Sky or other streaming platforms before the expiration of the 14-day withdrawal period are typically required to waive their right of withdrawal when concluding the contract. Article 16(1)(m) in conjunction with Article 2(11) CRD provides such an exception to the right of withdrawal laid down in Article 9(1) – but only for ‘digital content’.
Following the view of the European Commission and the Advocate General, which the CJEU has adopted, streaming subscriptions generally do not constitute ‘digital content’, but rather ‘digital services’, to which this exception does not apply. Instead, the consumer's right of withdrawal expires only once the streaming provider has fully performed the contractual service (Article 16(1)(a) in conjunction with Article 2(16) CRD).
Unlike the supply of ‘digital content’, the supply of a ‘digital service’ is ‘necessarily defined by the dynamic nature of the offering proposed by the trader concerned, which goes beyond the mere stable and, as the case may be, continuous provision of specific content.’ According to the CJEU, this is the case, in particular, where ‘the offering is designed to adapt to the consumer’s individual behaviour or expectations, or to influence the manner in which the consumer uses the services concerned, for example by recommending specific content to the consumer.’ Such recommendation systems are an integral part of virtually all modern streaming services, helping users navigate an overwhelming volume of available content.
No Risk of Abuse Due to Appropriate Compensation
Sky Österreich Fernsehen GmbH (hereinafter ‘Sky Austria’) was unsuccessful in arguing that such an interpretation would open the door to abuse. Sky Austria pointed out that subscription numbers typically spike when a popular series’ first or final season is released, or when decisive matches in football championships take place. If customers were able to cancel their subscription immediately after viewing such content, they could effectively receive this premium programming for free.
The CJEU held that the legislature had already addressed this concern in Article 14(3) CRD, which entitles the trader to compensation proportionate ‘to what has been provided until the time the consumer has informed the trader of the exercise of the right of withdrawal, in comparison with the full coverage of the contract.’ In this regard, the trader is not required to calculate this compensation purely on a time‑proportionate basis (pro rata temporis); it may instead take the market value of the service provided as a starting point in order to reflect the differences in economic value between the offered content (for example, the final stage of a sporting competition compared with a daily television series). In plain terms, this means the compensation a consumer owes could actually exceed the monthly subscription fee; either way, charging at least a pro-rata (time-proportional) fee remains permissible. Seen in this light, the CJEU ruling is likely to be a theoretical victory for consumers – in practice, not much is likely to change, and probably rightly so.
Applicability to German Law
Since the Austrian provision at the centre of this request, Section 18(1)(1) and (11) of the Distance and Off‑Premises Contracts Act (Fern‑ und Auswärtsgeschäfte‑Gesetz), essentially corresponds to Sections 356(5) and (6) of the German Civil Code (Bürgerliches Gesetzbuch), the decision can readily be transposed to German law. In addition, the CRD does not expressly refer to the law of the Member States for the interpretation of the term ‘digital content’, which is why that term must be interpreted autonomously and uniformly under EU law.
Outlook
With this decision, the CJEU is significantly shaking up the existing landscape of streaming subscriptions, particularly since, on the one hand, the architecture of streaming services in the form of recommendation systems is affected, and on the other hand, claims for compensation in the event of withdrawal following prior streaming consumption are likely to meet with little acceptance at first.
Indirectly, the decision is also likely to have repercussions for other streaming models – whether the streaming of music tracks and podcasts via Spotify, audiobooks via Audible, or the magazine subscription with the Süddeutsche Zeitung – wherever the provider's performance goes beyond the mere provision of a single digital item. The CJEU has thus cut a dogmatic swath that points far beyond the specific question referred. In economic terms, this swath will be less significant, since compensation fees will become established for the usage that occurred prior to withdrawal.
KI-Flash: EDPB Publishes Guidelines on Web Scraping in the Context of Generative AI
Web scraping is practically indispensable for training large AI models – and, from a data protection perspective, one of the biggest open questions: who is liable if personal data ends up in a training dataset through the automated harvesting of the open internet? On 7 July 2026, the European Data Protection Board (EDPB) addressed this question in Guidelines 03/2026, presenting a concrete assessment framework for the first time. Having already reported on the EDPB's Opinion 28/2024 on AI models in an earlier KI-Flash, we now turn to this second major development from the same plenary session. We reported separately on the Guidelines on the Anonymization of Personal Data adopted at the same time. The new web scraping guidelines are likewise open for public consultation until 30 October 2026.
Web Scraping for AI Training Purposes
More precisely, web scraping refers to the automated extraction of large volumes of data from publicly accessible internet sources – one of the central methods for sourcing training data for generative AI models. Until now, there was no specific, EU-wide guidance on how this practice can be reconciled with the requirements of the GDPR. The new guidelines close this gap and build on the Opinion 28/2024 mentioned above, as well as on Guidelines 1/2024 on Article 6(1)(f) GDPR. They are addressed to private entities that scrape data themselves, engage third parties to do so, or use already-scraped datasets for training or fine-tuning.
Controllership: Who Is Responsible for the Scraping Process?
A key question in practice concerns the allocation of roles under data protection law: the EDPB clarifies that the entity carrying out the scraping is not automatically a controller within the meaning of the GDPR. What matters instead is who determines the purposes and means of the processing. If an AI developer engages a service provider to carry out scraping under documented instructions, that provider will generally qualify as a processor, while the developer is treated as the controller. Where an already-scraped dataset is reused by a third party, the scraper and the reusing AI developer are, in principle, separately responsible for their own respective processing. Only where both parties jointly determine the purposes and means does joint controllership come into consideration.
Transparency: When Does the Individual Duty to Inform Not Apply?
With controllership clarified, this also raises the question of adequate transparency: the information obligations under Articles 13 and 14 GDPR pose practical difficulties for controllers engaged in web scraping, since data subjects are often not individually identifiable where data is collected indirectly. The EDPB acknowledges that individual information may be dispensed with where it proves impossible or would involve disproportionate effort (Article 14(5)(b) GDPR). This exception, however, does not apply across the board; it requires weighing the effort involved against the impact on the data subjects concerned, considering the volume and age of the data and the safeguards already in place. As a minimum measure, the EDPB requires controllers in such cases to make the information publicly available, for instance through a privacy notice specifying the categories of data, the sources and, where possible, the characteristics of the crawler used.
Data Minimisation: Measures Before, During and After Collection
The principle does not rule out training on large volumes of data as such, but it does require that personal data not needed for the purpose should not be collected in the first place. The EDPB proposes a multi-layered set of measures to this end. Before collection, controllers should, among other things, consider using synthetic data, define precise selection criteria, and exclude websites that structurally contain particularly sensitive data or that technically oppose scraping, for example through robots.txt, ai.txt or CAPTCHA. During and after collection, syntax-based filtering, pseudonymization and anonymization come into consideration as well. In addition, the EDPB requires controllers to ensure data quality by relying on reliable sources, timestamping the data and carrying out sample checks, to meet the principle of accuracy.
Legitimate Interest as the Key Legal Basis
The question of which legal basis could justify any of this in the first place usually leads, in practice, to Article 6(1)(f) GDPR: consent is practically impossible to obtain in the case of indirect, large-scale collection, which is why web scraping for generative AI is regularly based on legitimate interest instead. The EDPB applies the familiar three-step test: the existence of a legitimate interest, the necessity of the processing, and a balancing of interests. As examples of legitimate interests, it cites the development of chatbots or improvements to threat detection. In the balancing exercise, particular weight is given to data subjects' ability to control their own data, possible chilling effects arising from a sense of being under surveillance, and data subjects' reasonable expectations, for example whether a website technically excludes scraping or whether the data was made recognizably and publicly available.
Where the balancing test comes out against the data subjects, mitigating measures such as opt-out lists, shortened retention periods or enhanced transparency measures can restore the lawfulness of the processing.
Special Categories of Personal Data
Handling sensitive data also poses a particular challenge: special categories of personal data under Article 9 GDPR are, in principle, subject to a prohibition on processing that can only be lifted where one of the exceptions under Article 9(2) GDPR applies. Because it is difficult to reliably rule out in advance that sensitive data will also be captured when scraping large volumes of data, the EDPB transposes the CJEU's reasoning in GC and Others (C-136/17), concerning the responsibility of search engine operators, to the web scraping context: the prohibition under Article 9(1) GDPR then applies only within the framework of the controller's responsibilities, powers and capabilities, provided the controller takes appropriate measures to prevent and delete such data before, during and after AI development. This transposition is subject to narrow conditions: it applies only where the activity is structurally comparable to that of a search engine, and only to the incidental, unintended capture of sensitive data.
Practical Note
Even though the guidelines have not yet been finally adopted, they already provide clear guidance that national supervisory authorities are likely to apply when reviewing existing and future training data pipelines. Companies that scrape data themselves, commission scraping, or purchase already-scraped datasets should promptly review their own documentation on the balancing of interests, data minimization measures and the handling of special categories of data against the criteria set out in the guidelines. The ongoing consultation also offers an opportunity to feed practical experience and concerns directly into the final text.
We would be glad to assist you in reviewing your training data pipelines for compliance with the new EDPB guidelines, as well as in preparing or updating your data protection documentation for AI training processes.
Margret Knitter named once again among the “Top 250 Women in IP”
Managing IP has published the latest edition of its “Top 250 Women in IP” ranking, once again recognising our partner Margret Knitter among the world's leading women in intellectual property.
Published annually since 2013, the “Top 250 Women in IP” ranking highlights outstanding female IP practitioners from more than 30 jurisdictions who have distinguished themselves through exceptional work for clients and their firms. The selection is based on extensive research conducted by the IP STARS editorial team.
Margret Knitter’s continued inclusion in this list reflects her longstanding expertise in trademark, design and unfair competition law, as well as her strong reputation within the international intellectual property community.
This recognition complements SKW Schwarz's excellent performance in the IP STARS 2026 rankings, where the firm was once again recognised among the leading firms for trademark and copyright law, with several of its practitioners receiving individual distinctions.
Congratulations to Margret Knitter on this well-deserved international recognition.
Guidelines on the Anonymisation of Personal Data – European Data Protection Board (EDPB) Launches Public Consultation
On 7 July 2026, the EDPB published its long-awaited Guidelines on the anonymisation of personal data (“Guidelines”). These Guidelines are currently in draft form and are expected to be adopted following the public consultation process, which is open until 30 October 2026.
What is this about?
The key criterion for the application of the General Data Protection Regulation (“GDPR”) is the processing of personal data (“PD”). This concept is defined broadly in Article 4(1) GDPR. According to Recital 26, sentence 5 GDPR, the principles of data protection do not apply to anonymous information. Consequently, the GDPR does not apply to information that does not relate to an identified or identifiable natural person. Existing links between information and an identifiable individual can be removed through anonymisation.
Although this fundamental distinction in data protection law already existed before the GDPR came into force, determining when information has been anonymised to a legally sufficient standard remains both a technical and legal challenge in practice.
The former Article 29 Working Party had already addressed this issue in its respective Opinion from 2014. Over the past ten years, the Court of Justice of the European Union (CJEU) has also issued several judgments on the subject (see, for example, most recently the SRB decision).
Key Content of the Guidelines
The EDPB aims to provide greater clarity in distinguishing between anonymous information and personal data by establishing a practical assessment framework.
According to the EDPB, the three key criteria are No Record Isolation, No Linkage, and No Inference (see paragraphs 52 et seq. of the Guidelines).
The first criterion, No Record Isolation, requires that a dataset does not contain any attributes capable of identifying an individual. Considered on its own, the data must not constitute personal data.
The second criterion, No Linkage, builds on the first. It requires that the dataset cannot be linked to another dataset in a way that would enable the identification of a natural person.
The third criterion, No Inference, requires that no conclusions about a specific individual can be drawn from the available data. Such conclusions or inferences must also not be possible through the combination of the data with reasonably available additional information. In practical terms, it must not be possible to re-identify a natural person through analysis, linkage, or statistical inference.
These three criteria interact with one another and may be satisfied to varying degrees. What matters is that, when assessed as a whole, the information has been effectively anonymised (see paragraph 53 of the Guidelines).
What Happens Next?
The EDPB invites all interested stakeholders to participate in the public consultation until 30 October 2026. As discussions are currently ongoing at EU level regarding the GDPR-related provisions of the Digital Omnibus Act-which also focus (or have focused) on the concept of personal data-we expect a significant number of submissions.
In our view, the Guidelines represent an important step towards making the GDPR's requirements and the relevant case law on anonymisation more practical and easier to apply.
We will also publish an analysis once the final version of the Guidelines has been adopted.
SKW Schwarz Among the Top 10 Mid-Sized Employers for Career Starters
SKW Schwarz has been ranked among the Top 10 mid-sized employers for early career lawyers and has been nominated for the iurratio awards 2027.
The nomination recognizes the firm's commitment to providing outstanding training and attractive career opportunities for young legal professionals. In the category "Best Employers for Career Starters – Best Mid-Sized Law Firm," SKW Schwarz is one of the ten nominated firms.
The iurratio awards are presented annually based on a comprehensive employer survey and a nationwide talent survey of law students, trainee lawyers (Referendare), research assistants, and fully qualified lawyers. The evaluation covers a range of criteria, including training and professional development, working models and career prospects, health and well-being initiatives, work-life balance, diversity and social responsibility, as well as legal tech and digitalization.
This nomination reflects our commitment to providing aspiring lawyers with an outstanding environment to launch their careers—offering challenging mandates, personalized development, and a wide range of opportunities for professional growth. We are delighted to receive this recognition and would like to thank all of our colleagues whose dedication has made this achievement possible.
You can find the full list of nominated law firms here:
https://iurratio.de/die-besten-arbeitgeber-fuer-referendariat-berufseinstieg-2027
The winners of the iurratio awards 2027 will be announced in November 2026.
Events
Focus topics
Expertise
Mixed
Further insights
Explore the latest legal developments, insights, publications and news from our firm.
- Legal insights
- Whitepaper
- Law firm update
- In the Media
- Upcoming Events
09/22/2026
How the Digital Interstate Media Treaty regulates media, platforms and AI
09/22/2026
EmpCo: Special rule planned in Germany for certain existing stock – what companies need to know now
09/21/2026
KI-Flash: Advertising Law and Data Protection as Ads Launch in ChatGPT
09/21/2026
The New EU FDI Screening Regulation – What Companies Should Consider Now
















































