<?xml version="1.0" encoding="utf-8"?>







    <rss version="2.0"
         xmlns:content="http://purl.org/rss/1.0/modules/content/"
         xmlns:atom="http://www.w3.org/2005/Atom">
        <channel>
            <title>ADVANTLAW -&gt; News</title>
            <link>https://www.advantlaw.com/</link>
            <description></description>
            <language>it-it</language>
            <copyright>RYZE Digital</copyright>
            
            <pubDate>Mon, 17 Aug 2026 17:22:01 +0200</pubDate>
            <lastBuildDate>Mon, 17 Aug 2026 17:22:01 +0200</lastBuildDate>
            
            <atom:link href="https://www.advant-beiten.com/en/news/feed.xml" rel="self" type="application/rss+xml" />
            
                
                    <item>
                        <guid isPermaLink="false">news-8314</guid>
                        <pubDate>Fri, 03 Jan 2025 16:44:17 +0100</pubDate>
                        <title>Tattoos in video games - and what the German Federal Court of Justice&#039;s “photo wallpaper ruling” might have to do with it</title>
                        <link>https://www.advant-beiten.com/en/news/tattoos-in-videospielen-und-was-das-fototapeten-urteil-des-bgh-damit-zu-tun-haben-koennte</link>
                        <description>The depiction of tattoos of real people, mostly athletes, in video games is a recurring issue in US courts. In Germany, no such cases are known so far. The decision that has already gone down in the history of the Federal Court of Justice as the &quot;photo wallpaper ruling&quot; at least gives an idea of how such a dispute would end in Germany.</description>
                        <content:encoded><![CDATA[<p></p><h3>The Hayden vs. Take-Two Case: When Tattoo Art Goes Digital</h3><p>Jimmy Hayden is a renowned tattoo artist from Cleveland. He counts several NBA stars among his clients, including Shaquille O'Neal, Kyrie Irving and, relevant to this case, LeBron James. His tattoos have been the subject of a long-running legal battle with video game publisher Take-Two Interactive, the company behind the popular "NBA 2K" series of video games.</p><p>Hayden filed a lawsuit in 2017. In his lawsuit, which was revised in 2019, he argued that the detailed reproduction of the tattoos he had engraved in several titles in the "NBA 2K" series infringed on his copyrights.&nbsp;</p><p>The key legal question was: Does a video game company need the tattoo artist's permission to display the tattoos as part of a licensed likeness of the athlete? Take-Two argued that the license to use James' likeness included the right to display his tattoos. The Ohio federal jury agreed with this argument. It ruled that Take-Two's agreement to use James' likeness impliedly granted it the right to display his tattoos.</p><p>But this is not the only case of its kind. Take-Two won a similar lawsuit in a New York federal court in 2020. The case concerned the depiction of tattoos of the late basketball player Kobe Bryant and other NBA players.&nbsp;</p><p>However, another case shows that the law in this area is not yet fully established: In 2022, an Illinois jury ordered Take-Two to pay damages to a tattoo artist whose work was featured on the body of wrestler Randy Orton in the "WWE 2K" game series, even though the damages amounted to only $3,750.</p><p>These differing decisions illustrate that the legal assessment of tattoos in another medium is still evolving, as tattoo artist Hayden is said to have already appealed the most recent decision.</p><h3>What the "photo wallpaper rulings” of the German Federal Court of Justice have to do with it</h3><p>Although there has not yet been a comparable decision in Germany regarding the depiction of tattoos in video games, the recent rulings of the German Federal Court of Justice (BGH, rulings of September 11, 2024 - I ZR 139/23; I ZR 140/23; I ZR 141/23) regarding so-called photo wallpapers could provide an indication of how such a decision would turn out in German courts.</p><p>The BGH had to deal with a number of cases concerning the display of photo wallpapers on the Internet. The cases before the BGH revolved around a company founded by a professional photographer that marketed photo wallpapers featuring his photographs. In three different constellations, these wallpapers were placed on the Internet as images by the respective defendants: A private user showed the wallpaper as a background in Facebook videos, a media agency presented a client project in which the wallpaper could be seen, and a hotel operator advertised with photos of its decorated rooms. In each case, the photographer's company took legal action against the use, seeking damages and reimbursement for the cost of the warning.</p><p>However, the BGH clearly rejected these claims and assumed "clear consent". The core consideration of the court: Anyone who places a copyrighted work such as a photo wallpaper on the market without special restrictions must expect certain usual uses. Today, this includes the fact that the wallpaper can be seen in photos or videos posted on the Internet - not only in a private context, but also in a commercial context.</p><p>It is particularly interesting that the BGH did not limit these considerations to the direct purchaser of the wallpaper. Third parties, such as the media agency in this case, may also rely on implied consent if their use is considered customary. The court emphasized that the author is, of course, free to prohibit certain uses - but he must then also make such restrictions clear, for example through corresponding contractual agreements or clearly visible reservations of rights.</p><p>These considerations should also apply to celebrity tattoos in video games. A tattoo artist also takes his or her work "out into the world" without any particular restrictions - moreover, he or she applies it to the skin of a person who naturally moves around in public and is photographed or filmed doing so. In the case of prominent sports stars such as LeBron James, this media presence is even an essential part of their professional activity. Following the logic of the BGH, a tattoo artist would therefore have to expect that his work would be depicted together with its "wearer" - be it in traditional media, on social networks, or even in video games.</p><p>It is up to the authors of the tattoos to regulate their works in explicit agreements with their "objects", the tattooed persons. The extent to which such regulations would then be effective, particularly with regard to the personal rights of the tattooed person, offers potential for further decisions by the BGH.</p><p>Fabian Eckstein</p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital Compliance</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/8/f/csm_AdobeStock_295160836_9862a8b6b6.jpeg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-7972</guid>
                        <pubDate>Mon, 09 Sep 2024 16:40:04 +0200</pubDate>
                        <title>Consent Management Regulation - Goodbye cookie banner?</title>
                        <link>https://www.advant-beiten.com/en/news/einwilligungsverwaltungsverordnung-cookie-banner-ade</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>According to a recent <a href="https://www.bitkom.org/Presse/Presseinformation/Drei-Viertel-von-Cookie-Bannern-genervt" target="_blank" rel="noreferrer">study by Bitkom</a>, 76% of internet users feel annoyed by cookie banners. The German government therefore passed the so-called Consent Management Regulation (EinwV) last week, which is intended to reduce the number of cookie banners and improve the user experience on the internet.</p><p>Section 26 of the German Telecommunications Digital Services Data Protection Act (TDDDG), which was introduced in December 2021 as the "TTDSG", provides the Federal Government with the power to issue regulations to govern so-called consent management services.</p><p>The original idea of such services, which are also discussed under the keyword of "Personal Information Management System (PIMS)", was that the internet user would submit their personal cookie preferences once to the PIMS and the providers of digital services would be able to request these preferences from the PIMS. Users would have the option of agreeing to all cookies, generally accepting or rejecting individual categories of cookies across the board (e.g. statistics cookies or marketing cookies) or rejecting all unnecessary cookies.</p><h3>(In)permissibility of general consents</h3><p>The problem with such blanket consent to the use of cookies, even if it is only given for certain categories of cookies, is that the internet user cannot really give informed consent in this case. Even though providers of digital services often use similar cookies and tools, they are not exactly the same. Each provider uses different cookies in some cases and therefore also transmits information from internet users to different recipients. Internet users would thus never know exactly what processing they are consenting to at the time of giving their consent, let alone to whom their data is being transmitted. For this reason, the German government has also decided against blanket default settings and comments on this in the explanatory memorandum to the regulation:</p><blockquote><p><i>“General default settings for possible consent requests from the provider of digital services, which are made by the end user without reference to the specific use of a digital service, do not meet the requirements for the management of consent.”</i></p></blockquote><p>However, this also means that the desired effect of PIMS, namely, to reduce the number of cookie banners, is lost.&nbsp;</p><h3>Solution through the EinwV?</h3><p>Section 3 (1) of the now adopted Consent Regulation (EinwV) stipulates that the approved consent management service (i.e. the PIMS) stores the end user's cookie settings when they use a digital service for the first time. According to its wording, internet users will still have to see a cookie banner every time they visit a website for the first time.<br>The approved service must also be user-friendly, i.e. transparent and comprehensible, and a request to review the end user's settings may only be made after one year at the earliest (Section 4 EinwV). It must also be possible to switch to another approved consent management service at any time (Section 5 EinwV). Furthermore, in accordance with Section 6, a competition-compliant procedure is required for providers of digital services. Finally, integration into so-called retrieval and display software (usually presumably Internet browsers) should be made possible (Section 7 EinwV).</p><p>As the name "<i><u>approved</u> consent management service</i>" makes clear, the service must be approved. This is done in accordance with the procedure described in Part 3 of the Regulation. The competent body for this is the Federal Commissioner for Data Protection and Freedom of Information (Section 8 EinwV).</p><p>Part 4, the last part of the regulation, defines technical and organizational measures for providers of digital services as well as manufacturers and providers of retrieval and display software. Particular attention should be paid to Section 18 (1) of the Consent Regulation, which declares the integration of approved consent management services by digital service providers to be voluntary. This provision has been criticized by consumer advocates as the requirements of the regulation can easily be circumvented in this way. Moreover, the fact that the use of consent management services is voluntary will probably result in them rarely being used, especially in practice. In light of the study cited at the beginning, the proportion of those who use such a service to generally reject non-optional cookies is likely to be very high. The providers of digital services will also assume this and therefore have no interest in using such services. They will be inclined to continue to use cookie banners to access the data of at least those users who click on "accept all" because they actually want to give their consent, do not really care or simply like to press green buttons.</p><h3>Conclusion</h3><p>There are major doubts as to whether the adopted regulation can really reduce the number of cookie banners on the internet. It can also only regulate consent in accordance with Section 25 (2) TDDDG. In practice, however, consent is often also obtained via cookie banners in accordance with the GDPR (in particular also in accordance with Article 49 para. 1 a) GDPR). Strictly speaking, these cannot then be obtained through the consent management service, which would probably entail that the previous cookie banners would have to remain in place for these consents in any case.</p><p>However, another argument against the regulation is that the use of the consent management service does not appear to have any added value for either users or service providers. Users would still have to make a setting at least for every new website and even several times if the website uses new cookies or other tools, because no blanket default setting for different providers of digital services is to be legally permissible. Service providers, on the other hand, are presumably not interested in participating in consent management, which will probably result in more refusals of optional cookies.</p><p>Ultimately, though, the relevance of the services for consent management will depend on the specific technical design. If this is kept as easy to install and low-threshold as possible, it could perhaps be attractive for some digital service providers. With a well-functioning solution that actually makes things easier for the user, these service providers could then advertise particularly user-friendly cookie handling.</p><p><a href="https://www.advant-beiten.com/experten/cv-professional/fabian-eckstein" target="_blank">Fabian Eckstein</a></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital Compliance</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/b/f/csm_Digital_Media_Header_Scott_99bf6e4dc6.jpeg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-6820</guid>
                        <pubDate>Thu, 02 May 2024 08:23:00 +0200</pubDate>
                        <title>Update AI Act - the ten most important questions for users of AI systems</title>
                        <link>https://www.advant-beiten.com/en/news/update-ai-act-die-zehn-wichtigsten-fragen-fuer-anwender-von-ki-systemen</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>After the political agreement on the AI Act was effectively announced in the media in December 2023, the now provisionally final version was adopted on 13 March 2024. The AI Act was approved by the European Parliament with an overwhelming majority of 523 votes to 46. All that now remains is for the legal and linguistic experts to review it and for the Council to formally adopt the Regulation. This is expected to happen before the end of the current legislature (or by July 2024).</p><p>There is no doubt that manufacturers of AI systems will have to comply with the provisions of the AI Act and will therefore certainly be keeping a close eye on this European Regulation. However, companies that "only" use AI should do the same. In the following, we have compiled the ten practical questions that companies should ask themselves if they are using or planning to use AI.</p><h3>1. Which companies must comply with the provisions of the AI Act?</h3><p>Most of the provisions of the AI Act deal with prohibited and high-risk AI systems and the resulting obligations for providers, as well as for importers and distributors of such AI systems. However, this does not mean that users of an AI system can now sit back and relax. On the contrary: users (referred to as "deployers" in the AI Act) of AI systems are also covered by the AI Act and must comply with extensive obligations.</p><p>The AI Act applies not only to companies based in the EU, but also to providers and deployers based outside the EU, provided that the output generated by the AI systems is used in the EU.</p><h3>2. Excluded areas of application</h3><p>First, the AI Act excludes from ist scope the use of AI by natural persons for purely personal, non-professional purposes from the scope of application. AI systems that are developed and used exclusively in the field of scientific research and development are also excluded from the scope of application.</p><p>The provision that the AI Act does not apply to certain AI with free and open source licenses (open source) may become significant in the future. The AI Act provides for another significant exception for the use of AI systems in the military, defense and national security sectors. In addition, Member States have the option to provide for further exceptions in specific areas. For example, they can provide for further legal and administrative provisions on the use of AI systems by employers to provide further protection for employees.</p><h3>3. Prohibited AI systems</h3><p>AI systems that pose an unacceptable risk are completely prohibited under Art. 5 AI Act. This includes AI systems in the following eight areas:</p><ul><li>Techniques of subliminal influence beyond human consciousness to significantly distorting or harm a person's behaviour</li><li>Targeted exploitation of the vulnerabilities of certain groups of people due to their age or disability</li><li>Social scoring</li><li>The use of profiling systems to assess or predict the risk of an individual committing a criminal offense</li><li>Non-targeted collection (scraping) of facial images from the Internet or from video surveillance systems to create facial recognition databases</li><li>The use of emotion recognition systems in the workplace and in educational institutions</li><li>The use of biometric categorisation systems</li><li>The use of 'real-time' remote biometric identification systems in public spaces for purposes of law enforcement (although this is declared permissible within narrow limits).</li></ul><p></p><h3>4. Which systems are high-risk AI systems?</h3><p>The core of the AI Act are the regulations on so-called high-risk AI systems. In principle, AI systems are considered high-risk AI systems if they pose a significant threat to fundamental rights.</p><p>A high-risk AI system exists if an AI system is used as a safety component for a product that falls under the EU harmonisation legislation listed in Annex I or is itself such a product. This includes, for example, machinery, toys and medical devices.</p><p>An AI system is also considered to be a high-risk AI system if it falls into one of the following areas of Annex III:</p><ul><li>Remote biometric identification systems and AI systems for biometric categorisation and emotion recognition</li><li>Critical infrastructure: This includes AI systems that are intended to be uses as safety components in the management and operation of critical digital infrastructure, road traffic or in the supply of water, gas, heating and electricity.</li><li>Education and vocational training: AI systems are covered if they are used to make decisions on the access of natural persons to educational and vocational training institutions.</li><li>Employment, workers management and access to self-employment: AI systems used for analyzing, filtering and evaluating applicants are covered.</li><li>Certain essential private and essential public services and benefits: This includes, for example, AI systems that are used to evaluate the creditworthiness and credit score of natural persons.</li><li>Law enforcement</li><li>Migration, asylum and border control management</li><li>Administration of justice and democratic processes</li></ul><p>However, the AI Act provides for an important exception: AI systems from the aforementioned Annex III categories can be exempted from classification as high-risk AI systems under certain conditions. The prerequisite is that there is no significant risk of harm to the health, safety or fundamental rights of natural persons. Examples include AI systems that ae intended to perform a narrow prcedural task. The same applies if the AI system is used to improve an activity previously carried out by humans. The assessment of whether such an exemption applies must be carried out by the company itself as part of a risk evaluation and documented accordingly.</p><h3>5. What regulations apply to deployers of high-risk AI systems?</h3><p>Companies that use high-risk AI systems as deployers must fulfill a comprehensive catalog of obligations. These include the following, for example:</p><ul><li>They shall take appropriate technical and organizational measures to ensure that the high-risk AI systems are used in accordance with the instructions for use.</li><li>They transfer human supervision to natural persons.</li><li>They ensure that input data is relevant and sufficiently representative with regard to the purpose of the AI system.</li><li>They monitor the operation of the high-risk AI system on the basis of the instructions for use and, if necessary, inform the suppliers or, in the event of serious incidents, the importer, distributor and the relevant authorities.</li><li>You keep automatically generated logs for at least six months.</li><li>If they are also employers, they must inform the employees concerned and the employee representatives about the use of a high-risk AI system in the workplace.</li><li>They are subject to an obligation to cooperate with the authorities.</li></ul><p>The fundamental rights impact assessment for high-risk AI systems, which was originally required for all deployers, is now only foreseen in the current text of the Regulation for state institutions and private companies performing public services, as well as for those high-risk AI systems where public services, credit assessment or risk-based pricing of life and health insurance are affected, Art. 27 AI Act.</p><p>Under certain conditions, deployers may also become providers of a high-risk AI system themselves and then be subject to the stricter provider obligations, such as the establishment of a risk management system, the implementation of a conformity assessment procedure and registration in an EU database. Such a change of responsibility comes into effect if a high-risk AI system is placed on the market or put into operation under its own name or brand, or if a significant change is made to a high-risk AI system.</p><h3>6. What obligations apply to deployers of AI systems that are not high-risk AI systems?</h3><p>While the comprehensive list of obligations outlined above applies to deployers of high-risk AI systems, deployers of low-risk AI systems are generally only subject to certain transparency obligations, Article 50 AI Act. For example, they must disclose if content such as images, videos or audio content constituting a deep fake has been artificially generated or modified by an AI. The same obligation applies when an AI generates or manipulates text that is published with the purpose of informing the public on matters of public interest.</p><h3>7. What applies to SMEs?</h3><p>The declared aim of the AI Act is to create an innovation-friendly regulatory framework. Accordingly, the legislator has introduced regulatory relief for micro, small and medium-sized enterprises (SMEs) - including start-ups - based in the EU. For example, SMEs can benefit from non-material and financial support. Finally, under certain conditions, SMEs are to be given priority and free access to so-called regulatory sandboxes. Finally, fines can be capped.</p><h3>8. When does the AI Act apply?</h3><p>Exact dates cannot yet be given, as the final text oft he AI Act needs to be published in the Official Journal of the EU before it can enter into force. The ban on AI systems will take effect six months after the Regulation comes into force. The majority of the provisions of the AI Act will apply 24 months after entry into force. However, the obligations stipulated for high-risk AI systems will only apply after 36 months.</p><h3>9. How are violations of the AI Act sanctioned?</h3><p>Non-compliance with the requirements of the AI Act can result in exorbitant fines. These vary depending on the violation and the size of the company. While violations of prohibited AI systems can result in fines of up to EUR 35 million or 7% of global annual turnover, other violations of obligations under the AI Act can result in fines of up to EUR 15 million or 3% of annual global turnover. Fines of up to EUR 7.5 million or 1% of turnover may be imposed for providing of false information.</p><p>Several national and EU-wide authorities are involved in enforcement, resulting in a complex structure of responsibilities and coordination procedures. In Germany, it is not yet clear which authority will ensure compliance with the requirements of the AI Act. The Federal Network Agency and the Federal Office for Information Security are being discussed.</p><h3>10. ToDos for companies</h3><p>First of all, each company should determine and classify the risk class to which the AI systems used belong. The requirements for their proper use are then derived from this categorisation. Especially for future projects, it is important to involve the departments responsible for AI in the company at an early stage to ensure sufficient testing and compliance with the regulations. This is highly recommended, especially in view of the high fines.</p><p><a href="https://www.advant-beiten.com/en/experts/dr-peggy-muller" target="_blank">Dr Peggy Müller</a></p><p>Another article on this topic can be found under this <a href="https://www.advant-beiten.com/en/blogs/iim/kuenstliche-intelligenz-was-wichtiger-ist-als-das-ki-gesetz" target="_blank">link</a>.</p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital Compliance</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-1700</guid>
                        <pubDate>Tue, 09 Apr 2024 18:00:00 +0200</pubDate>
                        <title>Artificial intelligence: what is more important than the AI Act?</title>
                        <link>https://www.advant-beiten.com/en/news/kuenstliche-intelligenz-was-wichtiger-ist-als-das-ki-gesetz</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>The EU recently passed the EU Artificial Intelligence Act (AI Act) with much fanfare.</p><p>The Act is a milestone (see our blog post for more details). It is really relevant for providers and deployers of AI systems, especially those with high risks. However, most of the practical and legal issues associated with the use of AI are not regulated or even addressed in the law. They remain to be negotiated between the parties.</p><h3>1. Internal: Clear rules</h3><p>Wherever employees have access to the Internet, they use to at least experiment with AI, in particular to see what ChatGPT, Copilot, Claude, Dall-E, Midjourney and others can do. It has also become widely known that there can be risks for the company in using them. This has already cost some people their jobs. It is therefore all the more surprising that many companies still do not have internal guidelines on the correct use of artificial intelligence in the workplace. It is essential to regulate the handling of sensitive information and the use of the results of AI work, but ideally also responsibilities, accountability, and documentation requirements. One thing is certain: these systems will be used. A total ban would be impossible to enforce and would also hamper productivity.</p><h3>2. Reliable contracts</h3><p>Many organizations buy AI solutions from third parties or license software that includes AI. This should be governed using contracts that take into account the specific issues associated with the use of AI - not just outdated standard IT terms and conditions that are still silent on the subject of AI. Of course, there is nothing wrong with adapting outdated IT standard terms and conditions to the many new practical and legal requirements.</p><p><strong>Some important challenges:</strong></p><p>No licensee or user should rely on the legal compliance of generative AI systems (such as Chat GPT, etc.). In particular, it is questionable whether the data used for training has been obtained and used legally, especially with regard to data protection, personal rights and third party copyrights. This does not mean that a company should generally refrain from using such systems. But the distribution of risk must be properly regulated.</p><p>Artificial intelligence also sometimes produces undesirable results or exhibits strange behavior. For example, the results of AI generated work can infringe the rights of third parties. Rights clearance can be much more difficult here than with human-generated work, because the AI does not or cannot disclose which authors it has used in the first place (a particular problem: this makes proper disclosure of the use of open source code almost impossible and the use therefore inadmissible). There have also been reports of chatbots used on company websites that have literally fallen flat on their faces - because the chatbot gave customers rights that they would not have had under the contract. Finally, AI also makes mistakes, which can have unexpected consequences: With this in mind, some systems regularly accept a certain level of error tolerance. However, if the settings of an AI system, for example for fraud prevention, are so strict that it only approves a transaction if fraud can be ruled out 100%, it is unlikely to ever approve a transaction. At the same time, however, a more “tolerant” setting means a conscious acceptance of wrong decisions, which can, for example, invalidate the insurance cover that would exist for wrong human decisions. </p><p>In general, the point is that AI is effective but often operates in an opaque way and will sooner or later produce errors. It is therefore necessary to regulate contractually how the lack of transparency is dealt with and who bears the risk if it is not possible to determine where the error was made - and also what level of error probability is still acceptable.</p><p>The usual standards of intent and gross negligence found in most standard contracts are not useful here: both parties know that errors can occur. It is therefore necessary to regulate which errors are attributable to which party. This can be done, for example, in provisions on data quality, service levels and indemnity clauses. Of course, there is no boilerplate solution for every use of AI. However, it is important that the issue is considered and regulated appropriately.</p><p>It is also important to regulate the extent to which the AI can be 'trained' using the licensee's data, and whether other customers can also benefit from what the AI learns in this way. In the worst case, the data used for training could be disclosed to other customers or their end users of the AI, which could constitute a violation of privacy rights, intellectual property rights or trade secrets. If the licensee's dataset includes personal data, it generally must not be used to train the AI for other customers anyway.</p><p>In connection with the AI Act, the European Commission has also presented draft standard contractual clauses for the procurement of AI systems by public authorities (AI SCC). The requirements set out in the AI SCCs are intended to ensure that the contract terms comply with the requirements of the AI Act, with one version of the AI SCCs published for high-risk AI systems and one for non-high-risk AI systems.;</p><p>The AI SCCs cannot be used as the sole contractual basis for the use of AI, as many issues relevant to contract law (e.g. liability, intellectual property) are not addressed or are inadequately addressed. Nevertheless, the AI SCCs can provide useful points of reference for negotiating contractual terms, even between private companies.</p><h3>3. HR software</h3><p>As mentioned above, EU legislation on artificial intelligence will not apply across the board, but will impose specific obligations on providers and deployers of AI systems. However, there is one area of application that deserves special mention: Software in the HR sector is often considered a high-risk system, in particular recruitment tools (for the recruitment and selection of candidates or the placement of targeted job advertisements) and personnel management tools. High risk systems are subject to particularly strict requirements.</p><p><a href="https://www.advant-beiten.com/en/experts/dr-andreas-lober" target="_blank">Dr Andreas Lober</a><br><a href="https://www.advant-beiten.com/en/experts/lennart-kriebel" target="_blank">Lennart Kriebel</a></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital Compliance</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-1692</guid>
                        <pubDate>Thu, 21 Mar 2024 17:00:00 +0100</pubDate>
                        <title>The Cyber Resilience Act: What You Should Know Now</title>
                        <link>https://www.advant-beiten.com/en/news/der-cyber-resilience-act-was-sie-schon-jetzt-wissen-sollten</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>Almost unnoticed in the shadow of the AI Regulation, the so-called Cyber Resilience Act ("CRA") was passed by the European Parliament on March 12, 2024. This comprehensive law introduces extensive security requirements for manufacturers, importers, and distributors of hardware and software products intended for the European Union market. The goal of the CRA is to improve cybersecurity and combat widespread vulnerabilities that can have far-reaching consequences due to, among other things, inconsistent provision of security updates and lack of user understanding. In this way, the law complements the NIS-2 Directive, which focuses primarily on corporate cybersecurity.</p><h3>What does the Cyber Resilience Act cover?</h3><p>The scope of the CRA is very broad, covering all types of hardware and software, from low to high risk. The CRA initially distinguishes between three categories of products:</p><ul><li>"Basic" products with digital elements</li><li>Class I and II important products with digital elements, and</li><li>Critical products with digital elements.</li></ul><p>The requirements for the products vary depending on the category.</p><p>Class I important products include:</p><ul><li>Identity management systems</li><li>Stand-alone and embedded browsers</li><li>Password managers</li><li>Anti-malware</li><li>Network management systems</li><li>Security information and event management systems</li><li>Boot managers</li><li>Public key infrastructures and digital certificates issuance software</li><li>Physical and virtual network interfaces</li><li>Operating systems</li><li>Routers, modems, and switches</li><li>Microprocessors</li><li>Microcontrollers</li><li>Application-specific integrated circuits and field-programmable gate arrays</li><li>Smart home general purpose virtual assistants</li><li>Smart home products with security features</li><li>Internet connected toys</li><li>Wearables for health monitoring</li></ul><p>Class II important products include:</p><ul><li>Hypervisors</li><li>Container runtime systems</li><li>Firewalls</li><li>Intrusion detection and/or prevention systems</li><li>Tamper-resistant microprocessors and microcontrollers</li></ul><p>The annex of critical products currently includes hardware devices with security boxes, smart meter gateways in intelligent metering systems, and smartcards or similar devices. Both lists are to be expanded and specified by the EU Commission through delegated acts in the future.</p><h3><strong>Essential Cybersecurity Requirements:</strong></h3><p>In order to make a product with digital elements available in the EU, it must meet some essential requirements. First, the manufacturer must assess and document the cybersecurity risks of the product, taking into account the results during planning, production, and the expected lifetime of the product. Based on this assessment, the products must, in particular</p><ul><li>be free of known exploitable vulnerabilities,</li><li>have secure configurations enabled by default, and</li><li>enable free security updates automatically.</li></ul><p>They must</p><ul><li>protect against unauthorized access,</li><li>maintain the confidentiality and integrity of data,</li><li>minimize data processing, and</li><li>ensure core functionality even after disruptions.</li></ul><p>Product design must minimize attacks, limit impact, and provide transparent security information. This includes an obligation to identify and document exploitable vulnerabilities, regularly review product security, and take precautionary measures, including a coordinated vulnerability disclosure policy. The support period for products with digital elements, during which security updates must be provided and technical documentation must be produced, shall generally be at least five years. The end of the support period shall be clearly and conspicuously disclosed at the time of purchase.</p><p>Importers and distributors of products are also required to ensure that the products comply with the requirements of the Regulation.</p><h3>Conformity Assessment and CE Marking:</h3><p>For products with digital components, an EU declaration of conformity from the manufacturer is required, ensuring compliance with the requirements set out in the CRA or further regulations. The corresponding CE Marking must be visibly, legibly, and permanently affixed to the product. For software products, the software must be indicated either on the conformity declaration or on the accompanying website.</p><p>The intended conformity assessment procedure can be conducted by the manufacturer on their own responsibility for products not classified as important or critical. The involvement of an independent notified body is voluntary for important products of Class I but mandatory for Class II.</p><h3>Point of Contact:</h3><p>Manufacturers shall designate a single point of contact where users can report vulnerabilities and obtain information. The single point of contact should not only be automated but also enable contact with a human employee.</p><h3>Reporting Obligations:</h3><p>Manufacturers must report security breaches by malicious actors and cybersecurity incidents that pose an increased risk to users or other individuals. The European Union Agency for Cybersecurity (ENISA) will set up a uniform reporting platform for these reports, which must generally be made immediately but can be delayed for a necessary period for security reasons in individual cases. Addressed vulnerabilities will be recorded in a European vulnerability database in agreement with the manufacturer.</p><h3>Monitoring and Enforcement:</h3><p>Monitoring and enforcement are primarily carried out by market surveillance authorities, which must now be designated in each Member State. These can also demand access to internal data from manufacturers to assess product conformity.</p><p>In case of violations, as with other EU legislation, depending on the nature and severity, substantial fines can be imposed. In the case of the Cyber Resilience Act, they can amount to up to 15 million euros or 2,5% of the company's total worldwide annual turnover in the preceding financial year. The specific rules are left to the EU Member States.</p><h3>Timeline</h3><p>The CRA must now be formally adopted by the Council of the European Union. This is expected to take place in April 2024. In line with other EU legislation, the CRA will then enter into force on the twentieth day following its publication in the Official Journal of the European Union. The Regulation will be fully applicable 36 months after its entry into force, although some aspects, including the obligation to report security incidents, will apply earlier.</p><p>Products with digital elements placed on the market before the full entry into force of the Regulation will not be subject to the requirements, provided they are not significantly modified after that date. However, this does not apply to the obligation to report security incidents</p><h3>Assessment</h3><p>The Cyber Resilience Act obliges economic operators to exercise particular care in the context of cybersecurity. On the one hand, this leads to considerable additional efforts, but on the other hand, it provides a certain degree of legal certainty, as the CRA applies throughout the European Union. Thus, products that comply with the requirements of the Regulation can, in principle, be marketed in any other EU Member State without stricter cybersecurity requirements hindering economic activity. Although the requirements of the Cyber Resilience Act will not be fully applicable for approximately 36 months, they need to be considered early for products with long development cycles and long-term contracts.</p><p><span lang="EN-US"><span><span>From a legal perspective, in addition to compliance with mandatory disclosures, new aspects will play a critical role in the negotiation of IT contracts. For example, manufacturers who obtain components for their products from third parties should require assurances that these components are compliant with the CRA.</span></span></span></p><p><strong><a href="https://www.advant-beiten.com/en/experts/daniel-trunk" target="_blank">Daniel Trunk</a></strong></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital Compliance</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-1685</guid>
                        <pubDate>Sun, 17 Mar 2024 17:00:00 +0100</pubDate>
                        <title>Cloud, SaaS and edge business models under fire</title>
                        <link>https://www.advant-beiten.com/en/news/cloud-saas-und-edge-geschaeftsmodelle-unter-feuer</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>The EU Data Act came into force on January 11, 2024. Up to now, connected products have been the main focus of public interest.</p><p>However, providers of cloud, SaaS, edge and similar services are also affected. The Data Act dedicates a separate chapter to them. This Chapter VI contains regulations for so-called data processing services and primarily aims to make it easier to switch between different services, i.e. to remove existing barriers to switching.</p><p>In particular, if providers work with long term-contracts or the export of customer data is complex, the business model must be reviewed- ideally immediately.</p><p>The main reasons for this are as follows:</p><p><strong>Long contract terms are obsolete.</strong> The customer can initiate a switch to another provider at any time with a notice period of two months. As a rule, the switch should be successfully completed after a further 30 days. After a successful switch, the previous contract is general-ly deemed to be terminated. The previous practice of refinancing providers' initial investments via certain minimum contract terms will therefore no longer work without further ado. Set-up fees, which have become less important in recent years as a result of SaaS services becoming more popular, could be considered as an alternative, as could payments in the event of premature contract termination (e.g., termination fees).</p><p><strong>Exit support can be very costly, but must generally be provided free of charge in the future.</strong> Since January 11, 2024, only reduced switching fees may be charged; from January 12, 2027, switching must be free of charge. At the same time, however, the Data Act provides for comprehensive support obligations that the source provider cannot evade.</p><p><strong>The provider is – to a certain extent – responsible for interoperability with the new provider's system.</strong></p><p>These issues should be addressed immediately, as they will force many providers to adapt their business model. As soon as the Data Act will fully come into force on September 12, 2025, a whole range of other obligations will be added, in particular</p><ul><li>Adaptation of contracts (the Data Act specifies mandatory contract clauses)</li><li>Abolition of technical and organizational barriers to change</li><li>Extensive information obligations</li></ul><p>In addition to civil litigation with customers, breaches of the Data Act can also result in sanctions being imposed by the regulatory authorities; the maximum amount of fines has not yet been determined. Particularly juicy: The provisions on data processing services are likely classified as market conduct rules and thus subject to competition law. Breaches could be subject to warnings from competitors.</p><p>Providers of data processing services must also implement safeguards against unauthorized access from public bodies in third countries.</p><p>Our <a href="https://www.advant-beiten.com/en/blogs/iim/eu-data-act-relevance-companies-iot-and-beyond" target="_blank">blog post</a> provides an overview of the provisions of the Data Act, including those relating to networked products.</p><p><a href="https://www.advant-beiten.com/en/experts/dr-andreas-lober" target="_blank">Dr Andreas Lober</a><br><a href="https://www.advant-beiten.com/en/experts/lennart-kriebel" target="_blank">Lennart Kriebel</a></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital Compliance</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-1639</guid>
                        <pubDate>Wed, 20 Dec 2023 17:00:00 +0100</pubDate>
                        <title>The AI Act - The Agreement and What It Means</title>
                        <link>https://www.advant-beiten.com/en/news/der-ai-act-die-einigung-und-was-sie-bedeutet</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><span><span><span>As Ursula von der Leyen, President of the European Commission, put it: This is a historic moment. On 8 December 2023, after a three-day-marathon of negotiating, the European regulation efforts were awarded with a preliminary political agreement on the first comprehensive European act on artificial intelligence: the AI Act. It is not, as from time to time even the EU itself claims, the first regulation on AI worldwide. With an executive order in the United States and an Act on Automated Decision-Making in China, corresponding regulations already exist in other parts of the world. </span></span></span></p><p><span lang="EN-GB"><span><span>The AI Act aims to ensure that only AI systems which are both safe and respect the fundamental rights and values of the EU are brought onto the European market and are used in the EU. Still, even though an agreement has been reached, the outcome of the negotiations was announced although there is not yet a consolidated text to present. The political agreement will be put into a final text over the coming months. To this end, a number of technical negotiation meetings have been scheduled until the end of February. As some of the information currently available varies widely , we will have to wait until the final text will be published in the first quarter of 2024. The overview below presents the most significant known regulations.</span></span></span></p><h3><span><span><span>Definition of an AI System</span></span></span></h3><p><span><span><span>The new AI Act will include an amended definition of AI systems compared to the European Parliament's last proposals, which is close to the OECD's definition. The OECD's definition is as follows:</span></span></span></p><p><span><span><span>“<em>An AI system is a machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. Different AI systems vary in their levels of autonomy and adaptiveness after deployment</em>.” </span></span></span></p><p><span lang="EN-GB"><span><span>This definition is particularly criticised because it is extremely broad and therefore even includes simple auto-correction or Excel functions, for example. In this respect, the final wording of the Act including its recitals which, as we know, may often be used to fine-tune certain terms must be awaited.</span></span></span><span><span><span> </span></span></span></p><h3><span><span><span>Risk-based Approach</span></span></span></h3><p><span><span><span>The Regulation, which is based on a proposal by the EU Commission in April 2021 and is part of the EU's digital strategy, follows a risk-based approach. It categorises AI systems into different groups depending on the risk they pose: from minimal risk to high-risk and even banned AI systems. </span></span></span></p><p><span lang="EN-GB"><span><span>According to this approach, six principles apply to all AI systems. AI systems should (1) enable human agency and oversight, (2) be technically robust and safe, (3) comply with privacy and data protection regulations, (4) be transparent, (5) ensure diversity, non-discrimination and fairness and (6) ensure social and environmental well-being.</span></span></span><span><span><span> </span></span></span></p><h3><span><span><span>Banned AI Systems</span></span></span></h3><p><span><span><span>AI systems involving an unacceptable risk will be banned in the EU. These include, for example, systems using manipulative techniques, systems that exploit weaknesses or vulnerabilities, social scoring and databases based on mass facial recognition. </span></span></span></p><p><span><span><span>Until the very end there was an intense debate as to whether AI for facial recognition should be permitted or not. While individual countries, such as France, supported the use of AI for facial recognition, arguing that it could be used to ensure security around major events such as the 2024 Olympic Games, most remained sceptic. Despite a tough battle over several days of negotiations, a complete ban on real-time biometric identification could not be achieved against the massive resistance of the member states. After lengthy discussions, the bans involving the recognition of emotions and remote biometric identification were adjusted. </span></span></span></p><p><span><span><span>The ban on AI systems for emotion recognition now only applies in the workplace and in education. It will however still be permissible to use such systems for medical or safety reasons, for example to monitor pilot fatigue. </span></span></span></p><p><span lang="EN-GB"><span><span>The regulations on remote biometric identification have also been amended. Both 'real time' and 'post' identification will remain banned. Exceptions are expected for the prosecution of criminal offences in clearly defined cases. The AI Act also includes a catalogue of protective measures to prevent potential misuse.</span></span></span></p><h3><span><span><span>High-risk Systems</span></span></span></h3><p><span><span><span>A large part of AI systems will be categorised as high-risk AI systems. These are, for example, AI based medical devices or autonomous vehicles. In general, education, critical infrastructure, migration, asylum, or border controls are considered critical high-risk areas. </span></span></span></p><p><span><span><span>High-risk AI systems will have to comply with a number of requirements and obligations to be approved in the EU. For example, conformity assessments must be carried out and a quality and risk-mitigation system must be integrated. High-risk AI systems will also have to be registered in the corresponding EU database. The requirement to carry out an impact assessment for fundamental rights remains unchanged, although this will now only apply to public organisations and private bodies that provide essential public services, such as hospitals or banks. Further changes have been made to the responsibilities and the roles of the various players.</span></span></span></p><p><span lang="EN-GB"><span><span>Further, a filter system has been introduced. An AI system can lose its classification as a high-risk system if it fulfils one of a total of four conditions, for example if it (1) is intended to monitor or improve a human activity or (2) is only used to recognise decision-making patterns or deviations from previous decision-making patterns, (3) is only used to carry out preparatory tasks for a human activity relevant for critical applications or (4) is only intended to carry out procedural tasks.</span></span></span><span><span><span> </span></span></span></p><h3><span><span><span>AI Systems with Limited Risk</span></span></span></h3><p><span lang="EN-GB"><span><span>Specific transparency obligations will apply to AI systems with limited risk. These will, above all, include the information that a certain content has been generated by AI. The aim is to ensure that users can make informed decisions about further use.</span></span></span></p><h3><span><span><span>Generative AI</span></span></span></h3><p><span><span><span>Also in the field of generative AI there will be some changes, unsurprisingly, as these provisions were the most controversial. While the European Parliament ‑ not least in view of ChatGPT - supported a regulation of generative AI systems, the Commission had recently been of the opinion that these AI systems did not require a regulation. It was instead sufficient if manufacturers submit to voluntary commitments. </span></span></span></p><p><span><span><span>These AI systems are now called 'general purpose AI' instead of 'foundation models'. The definition of general purpose AI was amended so that it now only includes large generative AI systems.</span></span></span></p><p><span><span><span><em>“‘General purpose AI model’ means an AI model, including when trained with a large amount of data using self-supervision at scale, that is capable to competently perform a wide range of distinct tasks regardless of the way the model is released on the market.”</em></span></span></span></p><p><span><span><span>Developers of general purpose AI models will have to comply with certain minimum requirements, such as creating technical documentation, providing information for downstream providers and providing information about training and testing procedures. They must also comply with copyright regulations and the products generated must be labelled with a watermark. </span></span></span></p><p><span><span><span>Large AI systems posing systemic risks, so-called 'systemic risk AI' or top tier models that exceed a certain computing power (1025 FLOPs) during training, must fulfil additional obligations. These include, for example, setting up a risk-mitigation system and maintaining an appropriate level of cyber security. Details of this have not yet been finalised. Still, it is assumed that OpenAI's GPT4 and Google's Gemini will be considered to be systems with systemic risk. Models of the European developers Aleph Alpha and Mistral on the other hand will most likely not be categorised as AI models with systemic risk based on their computing power. <span><span><span><span><span>Honi soit qui mal y pense.</span></span></span></span></span> </span></span></span></p><p><span lang="EN-GB"><span><span>Linking transparency requirements to computing power is heavily criticised, as the capability alone says little about the risks of an AI system. In order to be able to make adjustments as technology develops, the Commission will be able to adjust the current threshold and also define additional criteria.</span></span></span><span><span><span> </span></span></span></p><h3><span><span><span>Open Source Models</span></span></span></h3><p><span lang="EN-GB"><span><span>The previous proposal also excluded models based on open source licences from the AI Act. According to the recent agreement, only those open source generative purpose AI systems that are categorised as systemic risk AI systems are to fall within the scope of the AI Act. They are also not exempt from the requirements for high-risk AI systems. This is to be welcomed, as the mere fact that an AI model is based on open source licences or not says little about the risk it poses.</span></span></span></p><h3><span><span><span>Copyright Requirements</span></span></span></h3><p><span lang="EN-GB"><span><span>According to the regulation, AI developers will have to disseminate a copyright policy and a detailed summary of the content they have used to train their generative purpose AI models. This transparency requirement is intended to let authors determine whether their work has been used. It has not been specified yet what exactly 'detailed' means. If the information provided so far is to be believed, the text and data mining limitation for generative AI is explicitly recognised. This had been controversial. The background: Interference with copyright exploitation rights is only permitted if the rights are exempted by limitation provisions. The limitations for text and data mining, i.e. the automated analytical technique of works to obtain information about patterns, trends and correlations, are relevant for the multiplication which happens in the training of AI. According to the text and data mining limitation, the reservations of rights holders in particular must be observed.</span></span></span></p><h3><span><span><span>Penalties</span></span></span></h3><p><span lang="EN-GB"><span><span>The penalties under the AI Act have been amended again, but remain differentiated in proportion to the seriousness of the irregularity. For example, a breach of the ban on certain systems and non-compliance with data requirements may be penalised with up to 7% of the company's global annual turnover or EUR 35 million.</span></span></span></p><h3><span><span><span>Enforcement and Authorities</span></span></span></h3><p><span lang="EN-GB"><span><span>An AI Office is (already) being set up in the European Commission to enforce the regulation of generative purpose AI systems. All other AI systems will be monitored by the competent national authorities. In order to ensure the uniform application of legislation, they will meet regularly in a European Committee on Artificial Intelligence.</span></span></span></p><h3><span><span><span>Right to Lodge a Complaint</span></span></span></h3><p><span lang="EN-GB"><span><span>Another new addition is the possibility for natural and legal persons to lodge a complaint with the competent national authority about non-compliance with the requirements of the AI Act.</span></span></span></p><h3><span><span><span>Entry into Force of the AI Act</span></span></span></h3><p><span><span><span>In principle, the majority of the AI Act's catalogue of obligations will apply 24 months after its entry into force. However, the current draft of the AI Act provides for certain obligations to apply earlier. For example, the ban on certain systems will take effect just six months after the Act comes into force, which means it is expected to apply as early as over the course of 2024. The requirements for generative purpose AI systems will apply just 12 months after the AI Act comes into force. </span></span></span></p><p><span lang="EN-GB"><span><span>It is therefore highly advisable to review the provisions of the AI Act at an early stage, not least in view of the fact that the conversion of any systems may well take some time.</span></span></span><span><span><span> </span></span></span></p><h3><span><span><span>Next Steps </span></span></span></h3><p><span lang="EN-GB"><span><span>As mentioned at the beginning of this post, the AI Act is not yet final - and it may still be a while. Although the recently announced political agreement on the key points has been reached, the technical aspects of the legal text still have to be negotiated in detail over the next few weeks. It may take a while for the bits and pieces to be divided and negotiated, with a lot of the details being figured out later. Finally, the EU bodies must then approve the final text of the regulation. As it is a regulation, it applies directly in all Member States and does not need to be transposed into national law.</span></span></span></p><h3><span><span><span>Conclusion</span></span></span></h3><p><span lang="EN-GB"><span><span>With the AI Act, the EU intends to keep what it calls an 'extremely delicate balance' between boosting innovation and uptake of AI in Europe on the one hand and respecting the fundamental rights of EU citizens on the other. However, the final document which contains more than 250 pages comes across as a bureaucratic nightmare, imposing high documentation requirements on many companies. Due to the vagueness of many regulations, there will be a range of grey areas that could lead to uncertainties and, in the worst case, to considerations as to whether the use of AI should initially be avoided against this background until a uniform application practice of the competent authorities emerges. Nonetheless, the EU's attempt to address this major contemporary issue and to take account of dynamic developments by continuously adapting the provisions, as explicitly envisaged, is to be welcomed in principle.</span></span></span></p><p><a href="https://www.advant-beiten.com/en/experts/dr-peggy-muller" target="_blank"><span><span><span>Dr Peggy Müller</span></span></span></a></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital Compliance</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-1564</guid>
                        <pubDate>Thu, 09 Nov 2023 17:00:00 +0100</pubDate>
                        <title>EU Data Act: Action required for Connected Products, Related Services and Cloud Computing </title>
                        <link>https://www.advant-beiten.com/en/news/eu-data-act-relevance-companies-iot-and-beyond</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><em>You would like to hear from us personally about the <strong>new obligations under the Data Act</strong>? Then register for our webinar: <a href="https://events.teams.microsoft.com/event/5a3a01a1-3fea-4a19-9f4e-d80e7f5f8f5f@fefb03b4-cfed-4293-bd9c-32a29868fe16" target="_blank" rel="noreferrer">Registration</a></em></p><p>On 27 November 2023, the EU Council adopted the Data Act, which was the final requirement after the the text had been adopted by the European Parliament on 9 November 2023. Following the formal adoption by the Council, the new regulation will be published in the EU’s official journal in the coming weeks and will enter into force 20 days after this publication.</p><p>The Data Act - an EU regulation and as such directly applicable in all EU member states - provides for harmonized rules for "fair access to and use of data". Unlike the GDPR it is not limited to personal data. The aim is to make this data commercially usable.</p><p>It is clear already that the Act will go well beyond regulating the „Internet of Things“ (IoT). It relates in particular to "connected products" and cloud services.</p><p>Below we provide an initial overview.</p><p><strong>Data Sharing:</strong> Far-reaching obligations are imposed on data holders, in particular provision and access obligations in relation to user data.</p><p>Data from connected products or related services may have to be shared with the user or a third party (data recipient). This is intended to strengthen the rights of users in relation to the data holder. It is also intended to encourage new players to invest in the data economy.</p><p>Connected products and related services must be designed in accordance with the requirements of the Data Act ("access by design"). Moreover, the Act requires data holders to make data from connected products or related services accessible free of charge and, where applicable, continuously in realtime.<br>To date, many connected products and related services have not been designed with this in mind, which is why the Data Act and its obligations must be considered from the very beginning of product development in future.</p><p>Vice versa, data holders are no longer allowed to freely share non-personal data with other players - for advertising purposes, for instance. In this respect, the right to share data is generally restricted to the extent necessary to fulfil the user contract. Any further sharing of non-personal data may in future require a data licence agreement. This is also likely to affect existing data records.</p><p>With a few exceptions , small and certain medium-sized enterprises are exempt from the obligation to share data (less than 50 employees or EUR 10 million annual turnover).</p><p><strong>UNFAIR CONTRACTUAL CLAUSES:</strong> The provisions on unfair contractual terms (Chapter IV) are meant to prevent the abuse of contractual imbalances. The law introduces a ban on unilaterally imposed unfair terms in B2B contracts and is based on the law on general terms and conditions. In addition to a general clause, the Data Act also contains (non-exhaustive) examples of unfair terms. These include, for instance, provisions that limit liability for the quality of the data provided. Furthermore, exclusive rights of use to data that are imposed unilaterally can be problematic. To support this, the European Commission is to publish model contract clauses that companies can use use for orientation.</p><p><strong>DATA FOR THE PUBLIC SECTOR:</strong> In emergencies, such as natural catastrophes, public sector bodies must be provided with data that is required to deal with the emergency.</p><p><strong>REGULATING DATA PROCESSING SERVICES, ESPECIALLY CLOUD SERVICES:</strong> The Data Act is intended to facilitate switching between similar "data processing services" (Chapter VI). The generic term "data processing services" includes, inter alia, Software as a Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS). These provisions are intended to break up the EU cloud market and facilitate the portability of data between cloud providers. The regulations are very detailed and primarily cover technical and organisational measures, but also contractual details. For instance, a maximum limit for cancellation periods is provided for. Furthermore, interfaces must be created for data transfer when exporting data between different cloud service providers. In addition to these very detailed requirements in individual cases, however, there is also a seemingly endless ban on obstacles to switching ("In particular, providers of data processing services may not impose any pre-commercial, commercial, technical, contractual or organizational obstacles and must remove such obstacles"). Exceptions apply to "custom-built“ data processing services.</p><p><strong>INTERNATIONAL DATA TRANSFER AND INTEROPERABILITY:</strong> International data transfer is also specifically regulated to prevent unlawful access to non-personal data by foreign state authorities (Chapter VII). However, the requirements are not identical to the provisions of the GDPR on data transfers to third countries. Additionally, regulations on interoperability are provided for (Chapter VIII).</p><h3>Late Changes to Definitions</h3><p>The law-making process for the Act started in early 2022. There were still significant changes in the legislative process, even in provisions such as the definitions of "connected product" and "related services". These are, however, fundamental to the area of application of the Act, specifically for determining who is considered a "data holder" and is thus affected by numerous obligations. The European Commission’s initial draft still excluded devices such as PCs, Smartphones, and game consoles. In the text which has been adopted now, they are no longer excluded.<br>The definition of the term "connected product" now reads as follows:<br>‘connected product’ means an item that obtains, generates or collects data concerning its use or environment and that is able to communicate product data via an electronic communications service, physical connection or on-device access, and whose primary function is not the storing, processing or transmission of data on behalf of any party other than the user;</p><p>‘related service’ means a digital service, other than an electronic communications service, including software, which is connected with the product at the time of the purchase, rent or lease in such a way that its absence would prevent the connected product from performing one or more of its functions, or which is subsequently connected to the product by the manufacturer or a third party to add to, update or adapt the functions of the connected product;</p><h3>Trade Secrets still little protected</h3><p>The obligation to share data may even extend to trade secrets, although there have also been some changes in the course of the legislative process. It is striking to see that the protection of trade secrets appears to be weaker than under the GDPR. In principle, the protection of trade secrets comprises a multi-level mechanism: the relevant data must first be identified as a trade secret by the data holder or trade secret holder. The parties involved in the data transfer must then agree on contractual, technical and organizational measures to ensure the confidentiality of the trade secrets to be transferred. Model contractual terms will also be available for this purpose in future. Once protective measures have been agreed, trade secrets must also be disclosed. It remains unclear how a data holder should enforce these protective measures in practice vis-à-vis the recipients of the data, i.e. typically their own users or authorized third parties. Basically, the disclosure of trade secrets can only be suspended if no agreement can be reached on the protective measures to be taken or if these are insufficiently implemented by the recipient of the data. However, the latter will often be accompanied by the compromising of trade secrets. Any decision to suspend the transfer of data must be justified by the data holder and reported to the competent authority.</p><p>The data holder may also refuse to disclose trade secrets ex ante in individual cases under exceptional circumstances if he can prove that the disclosure of the trade secret is very likely to cause him serious harm - in this case, too, the data holder must inform not only the user of the refusal, but also the competent national authority. The threshold for the right to refuse ("highly likely to suffer serious economic damage") has been somewhat weakened as of late, but is still very high. This is regrettable from the perspective of the data holder or trade secret holder, as this ex ante right could in many cases be the most effective way of preventing the disclosure of trade secrets from the outset.</p><h3>What about the GDPR?</h3><p>Unlike the GDPR, the Data Act applies to both non-personal data and personal data. The GDPR primarily serves to protect natural persons and creates a legal basis for the processing of personal data. The Data Act, in contrast, primarily aims to realize the free movement of data. The Data Act does not affect the GDPR, i.e. in cases where a connected product or a related service is used and personal data is also generated, both laws apply in parallel.<br>In particular, the Data Act is not intended to reduce the protection offered by the GDPR for personal data and therefore cannot serve as a legal basis for data processing under the GDPR. In practice, this will probably cause more difficulties than it seems at first glance, especially if a connected product or a related service collects personal and non-personal data - in this case, the latter may have to be passed on, but the former may not (as far as persons other than the user are concerned) or not easily: In any case, the question then arises as to whether a legal basis within the meaning of the GDPR would allow a transfer. This may create difficult situations for data holders in the future. They must now decide more conclusively than before which data is actually personal data: Disclosure may not be mandatory for this data, but it is for data without a personal reference. This is not made any easier by the fact that data from connected products will often have a "relative" personal reference - and the question of relative personal reference is currently before the ECJ.<br>There may also be discussions on the question of whether owners of trade secrets can rely on the fact that the GDPR appears to weigh their interests more heavily than the Data Act.</p><h3>Timeline</h3><p>Following the adoption by the Council and the publication in the official journal, the Data Act will be directly applicable in all EU member states after a transitional period of 20 months, without the need for member state implementation of the regulations. The so-called "access by design" obligation, i.e. the requirement to design (new) connected products and related services, only applies after a further 12 months. Apart from this "access by design" obligation, however, the Data Act not only affects new connected products and related services, but also - at least in principle - those already on the market. This means that owners of existing data records or existing data silos could potentially also be subject to the new rules, in particular the data provision obligations and the restrictions on data use (such as the requirement of a data licence agreement). For such potential data holders in particular, the period of 20 months could be quite short to adequately prepare for the obligations of the Data Act.</p><p><a href="https://www.advant-beiten.com/en/experts/dr-andreas-lober" target="_blank">Dr Andreas Lober</a><br><a href="https://www.advant-beiten.com/en/experts/lennart-kriebel" target="_blank">Lennart Kriebel</a></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital Compliance</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                    </item>
                
            
        </channel>
    </rss>


