<?xml version="1.0" encoding="utf-8"?>







    <rss version="2.0"
         xmlns:content="http://purl.org/rss/1.0/modules/content/"
         xmlns:atom="http://www.w3.org/2005/Atom">
        <channel>
            <title>ADVANTLAW -&gt; News</title>
            <link>https://www.advantlaw.com/</link>
            <description></description>
            <language>it-it</language>
            <copyright>RYZE Digital</copyright>
            
            <pubDate>Sat, 15 Aug 2026 09:19:21 +0200</pubDate>
            <lastBuildDate>Sat, 15 Aug 2026 09:19:21 +0200</lastBuildDate>
            
            <atom:link href="https://www.advant-beiten.com/en/news/feed.xml" rel="self" type="application/rss+xml" />
            
                
                    <item>
                        <guid isPermaLink="false">news-10507</guid>
                        <pubDate>Wed, 01 Jul 2026 16:33:00 +0200</pubDate>
                        <title>ADVANT Beiten Advises Banyan Software on the Acquisition of tec4U-Solutions GmbH</title>
                        <link>https://www.advant-beiten.com/en/news/advant-beiten-beraet-beraet-banyan-software-beim-erwerb-der-tec4u-solutions-gmbh</link>
                        <description></description>
                        <content:encoded><![CDATA[<p class="text-justify"><strong>Berlin/Freiburg, 1&nbsp;July&nbsp;2026 -&nbsp;</strong>The international law firm ADVANT Beiten has provided comprehensive legal advice to Banyan Software on its acquisition of tec4U-Solutions GmbH.&nbsp;</p><p class="text-justify">Founded in 2013 and headquartered in Saarbrücken, Germany, tec4U-Solutions GmbH develops software solutions and data services for material and product compliance management. Through its "DataCross" platform, the company supports manufacturers, distributors and importers in complying with international regulatory requirements, including REACH, PFAS and the EU Deforestation Regulation (EUDR).</p><p class="text-justify">Banyan Software is a global acquirer of specialized software businesses pursuing a long-term buy-and-hold strategy. With the acquisition, the company further strengthens its presence in the European vertical market software sector. tec4U-Solutions GmbH will continue to operate independently from its Saarbrücken headquarters.</p><p class="text-justify">ADVANT Beiten regularly advises Banyan Software on acquisitions in the German-speaking region and continues to support the company in executing its long-term growth strategy. This latest mandate highlights the firm's extensive expertise in cross-border M&amp;A transactions in the technology sector and its longstanding experience in advising international software and technology companies.</p><p><strong>Advisors to Banyan Software:</strong><br><strong>ADVANT Beiten:</strong> Christian Burmeister (Berlin and Freiburg, lead, Corporate/ M&amp;A), Damien Heinrich (Freiburg, Corporate/M&amp;A), Mathias Zimmer-Goertz, Christian Döpke (both Dusseldorf, IP/IT), Michael Riedel (Berlin, Employment Law).</p><p><strong>Public Relations</strong><br>Frauke Reuther<br>Manager Kommunikation<br>ADVANT Beiten<br>+49 (69) 75 60 95 - 570<br><a href="file:///C:/Users/fmannott/AppData/Local/Microsoft/Windows/Temporary%20Internet%20Files/Content.Outlook/99IBPS14/frauke.reuther@advant-beiten.com" target="_blank">frauke.reuther@advant-beiten.com</a></p>]]></content:encoded>
                        
                            
                                <category>Labour Law</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/7/4/csm_IT_Data_Abstract_6_R_d817e32c96.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10394</guid>
                        <pubDate>Fri, 05 Jun 2026 08:19:31 +0200</pubDate>
                        <title>ADVANT Advises Pidigi S.p.A. on the Acquisition of Key Assets of Sympatex Technologies GmbH from Insolvency Proceedings</title>
                        <link>https://www.advant-beiten.com/en/news/advant-beiten-beraet-pidigi-spa-beim-erwerb-wesentlicher-vermoegenswerte-der-sympatex-technologies-gmbh-aus-der-insolvenz</link>
                        <description></description>
                        <content:encoded><![CDATA[<p class="text-justify"><strong>Munich, 5&nbsp;May 2026</strong>&nbsp;– ADVANT Beiten has assisted the Italian firm Pidigi S.p.A. with the acquisition of key assets of Sympatex Technologies GmbH following its insolvency. The transaction took place as part of a restructuring by way of transfer.</p><p class="text-justify">The transaction involved the acquisition of essentially all of Sympatex Technologies GmbH’s assets, in particular its trademark rights and other key intangible assets. With this acquisition, Pidigi ensures the continuation of the day-to-day operations of the long-established trademark Sympatex.</p><p class="text-justify">ADVANT Beiten provided Pidigi with comprehensive advice on all legal aspects of the transaction, including the structuring and execution of the asset deal, as well as matters relating to corporate law, intellectual property law and labour &amp; employment law.</p><p class="text-justify">Advice on the Italian legal aspects was provided by Stefano Dindo, a lawyer at the law firm Dindo, Zorzi e Associati in Verona which referred the matter to ADVANT Beiten.</p><p class="text-justify">Since 1986, Sympatex Technologies GmbH has been developing innovative, PFAS-free membrane technologies for functional clothing, footwear, protective clothing and technical applications. Pidigi S.p.A. has been operating internationally since 1953 as a supplier of materials to the footwear, leather goods and sportswear industries.</p><p><strong>Advisor to Pidigi S.p.A.:</strong><br><strong>ADVANT Beiten:&nbsp;</strong>Matthias W. Stecher (in charge, IP/IT), Virginia Mäurer, Maike Pflästerer (both Labour &amp; Employment), Christoph Heinrich (Antitrust), Tanja Hogh Holub and Christian Hess (both IP/IT), Mario Weichel (Corporate/M&amp;A).</p><p><strong>Dindo, Zorzi e Associati:&nbsp;</strong>Stefano Dindo</p><p><strong>Public Relations</strong><br>Frauke Reuther<br>Manager Kommunikation<br>ADVANT Beiten<br>+49 (69) 75 60 95 - 570<br><a href="file:///C:/Users/fmannott/AppData/Local/Microsoft/Windows/Temporary%20Internet%20Files/Content.Outlook/99IBPS14/frauke.reuther@advant-beiten.com" target="_blank">frauke.reuther@advant-beiten.com</a></p>]]></content:encoded>
                        
                            
                                <category>Labour Law</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                                <category>Intellectual Property</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Antitrust Law</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/b/d/csm_Capital_Markets_Sport_6_R_cd084570f9.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10325</guid>
                        <pubDate>Wed, 20 May 2026 13:22:56 +0200</pubDate>
                        <title>Covert Advertising Is the Devil – or: What Meryl Streep Has to Do with Media Law</title>
                        <link>https://www.advant-beiten.com/en/news/der-teufel-ist-schleichwerbung-oder-was-meryl-streep-mit-dem-medienrecht-zu-tun-hat</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>Fashionistas are speculating whether “The Devil Wears Prada 2” can help Valentino's riveted “Rockstud” make a comeback. They discuss Chanel's garments, Dior's design, and Dolce &amp; Gabbana's fashion show. People are downing Starbucks coffee nonstop, with the occasional Diet Coke thrown in. Maybach sedans are the cars of choice: You would probably have to watch the film scene by scene to determine whether there’s even a single shot in which no well-known brand is shown. Of course, this fits into the film’s story sometimes better than others.</p><p>But wait, what was that again about covert advertising, product placement, and all that? Shouldn't the film perhaps be labelled as a continuous infomercial—or, at worst, from start to finish? Older readers may still remember this sort of thing from Stefan Raab's shows.&nbsp;</p><p>In fact, more than 30 years ago, the Federal Court of Justice addressed the question of how product placement should be assessed from a legal perspective.&nbsp;</p><p>The initial question is always whether an action 'is intended to promote the business of the company in question' - that is, to boost sales of a specific product. The situation is straightforward when the brand owner pays for the product placement. However, this is often difficult to detect from the outside. This is why courts rely on the following reasoning: Based on common sense, a commercial act (and an intent to promote competition) is presumed to exist when a product appears conspicuously often and without any apparent editorial, artistic, or dramatic justification.&nbsp;</p><p>At any rate, when it comes to the fashion brands in “The Devil Wears Prada 2”, it’s hard to deny that there is a 'dramatic reason' for featuring them. Incidentally, if reports in the marketing media are to be believed, no money was spent on this; the brands simply promoted the film themselves (Maybach, for instance, with a co-branded campaign titled “The Art of Arrival”). However, this should still be a significant consideration. In that respect, we can conclude as an interim finding that this is probably a case of product placement.</p><p>The standards that apply to product placement, however, vary depending on the medium. In the broadcasting sector (which includes television), this issue is specifically regulated by the State Media Treaty. Under the treaty, covert advertising is prohibited but product placement is permitted under certain conditions and within certain limits. In particular, it must be clearly indicated – on television, for example, at the beginning and end of a programme, as well as when the programme resumes after a commercial break.</p><p>The producers of “The Devil Wears Prada 2” can breathe a sigh of relief, as feature films tend to be subject to less stringent requirements. Nevertheless, drawing the line is not easy: simply having a car manufacturer pay for the main character to drive one of its vehicles in a film does not automatically make it inadmissible. It should also be noted that this vehicle is often depicted in a conspicuous manner that is not called for by the plot. Just how much of a balancing act this can be is demonstrated almost perfectly by Meryl Streep and Anne Hathaway (not only) in their conversation toward the end of the film.</p><p>Any publication—such as Runway—that evolves from a pure glossy magazine into a hybrid world of social media and strategic partnerships must also bear in mind that the legal framework for advertising and product placement varies depending on the type of media. Different laws may even apply. For instance, the State Media Treaty has separate chapters for broadcasting on the one hand and telemedia on the other (which also differ in content); it does not apply to movie theatres or newsstands. The press code applies only to the press while competition law applies to everyone. Complicated? Yes. Product placement and cross-promotions are not light entertainment.</p><p>Even German female influencers have already tested the limits of what is permissible: Cathy Hummels, for example, was able to convince the Federal Court of Justice that she has a genuine personal interest in fashion. Posts for which she receives no consideration as a result do not have to be labelled as advertising, even if they promote her commercial social media profile. The situation was different for influencers who had received something in return. This naturally raises the question of whether it counts as 'consideration' if the production company does not have to pay for the Coke – or if Anne alias Andy is allowed to keep the dress worn in the Hamptons after filming. For the record, media regulators draw the line at a product value of 100 euros, though this is open to discussion on a case-by-case basis.</p><p>And that’s not all: the guidelines are even stricter when the target audience is primarily children.</p><p>As is so often the case with legal matters, the tried-and-tested saying applies: The devil is in the details (not in Prada).</p><p><a href="https://www.advant-beiten.com/en/experts/cv-professional/dr-andreas-lober" target="_blank">Dr. Andreas Lober</a><br><a href="https://www.advant-beiten.com/en/experts/cv-professional/dr-peggy-mueller" target="_blank">Dr. Peggy Müller</a></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/c/b/csm_Corporate_MA_Sport_2_R_bc58183217.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10106</guid>
                        <pubDate>Fri, 13 Mar 2026 10:44:27 +0100</pubDate>
                        <title>New Withdrawal Button Requirement for Online Businesses</title>
                        <link>https://www.advant-beiten.com/en/news/der-widerrufs-button-kommt-neue-pflicht-fuer-den-online-handel-ab-19-juni-2026</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>New legal requirements are coming for online vendors this summer. In the B2C sector, most businesses will be required to implement a so-called ‘withdrawal button’ that allows customers to withdraw from a purchase directly through the online store. This requirement results from Directive (EU) 2023/2673. The goal? Make it even simpler for consumers to withdraw from contracts, although his is already pretty straightforward (and not subject to any burdensome formal requirements). And this has nothing to do with the cancellation button we’re already familiar with; the withdrawal button is actually mandatory for many more companies.</p><p>In Germany, this will be part of the updated German Civil Code (Section 356a) and take effect on 19 June 2026.</p><h3><span>To whom does the obligation apply?</span></h3><p>The withdrawal button requirement covers almost all online sales to consumers. The obligation applies regardless of whether the consumer purchases goods, digital content or services (including financial services). Exceptions apply only in cases where there is no right of withdrawal. Smaller businesses are not granted any special exemptions.</p><h3><span>What are the requirements for the withdrawal button?</span></h3><p>The legal requirements for the withdrawal button (or, as the lawmaker puts it, the withdrawal function) are quite specific:</p><p>First, there must be a clearly visible button labeled "Withdraw from contract here" (or equivalent wording). (The German law does not require the word “here”, contrary to the underlying EU directive). The button must be easily accessible, and available throughout the entire withdrawal period.</p><p>In a next step, the consumer must provide essential information to identify the contract:</p><ol><li data-list-item-id="eb77d1bc159e629993de34c2d855406da"><span>The consumer's name,</span></li><li data-list-item-id="e49de5086435a7df6e56ac81e19a51664"><span>Details identifying the contract (or specific part) they want to withdraw from,</span></li><li data-list-item-id="e1565609bd02379dbc20cdd2f012c4bfa"><span>Details regarding confirmation of receipt.</span></li></ol><p>Then, there must be a ‘confirmation button’ clearly labeled "Confirm withdrawal" or similar and equally clear.</p><p>Finally, businesses must immediately send the consumer a confirmation of receipt via e-mail (or other permanent record).</p><h3><span>EU Withdrawal Button vs. German Cancellation Button (</span><i><span>Kündigungsbutton</span></i><span>)</span></h3><p>Companies offering subscriptions or ongoing services online in Germany might think this sounds familiar. You're right – it's similar to the cancellation button that's been required in Germany since July 2022 (Section 312k German Civil Code). However, unlike the withdrawal button, the cancellation button is not a requirement under EU law but German-specific. Even if a cancellation button has already been implemented, the requirement to provide a withdrawal button still applies. The legal consequences are also different: Cancellation (for instance, via the cancellation button) terminates the contract for the future, whereas in the case of withdrawal, the services already provided must (in principle, at least) be reversed.</p><h3><span><strong>Practical Information</strong></span></h3><p>19&nbsp;June&nbsp;2026 is less than three months away. Companies should move quickly to implement the withdrawal button if they haven't already initiated the process. Beyond the technical requirements, you'll also need to update your withdrawal policy and possibly your privacy policy. Non-compliance will almost certainly trigger warnings from competitors or consumer protection associations. Experience with the cancellation button (and other consumer laws) shows that consumer protection associations send out warnings shortly after new policies take effect and sometimes even provide consumers with ready-made reporting forms.&nbsp;</p><p>If you don't respond to such warnings within a few days, this can lead to interim injunctions or other legal action. Additionally, incorrect withdrawal policy information can prevent the withdrawal period from starting, meaning it won't expire until 12 months and 14 days have passed. Fines may also be imposed in some cases, though experience shows the risk of monetary fines is low in the beginning after a new regulation takes effect.</p><p>Beyond that, e-commerce law is constantly evolving. Businesses should monitor other regulatory developments: additional information requirements (such as durability guarantees) and legally required warranty labels. The Digital Fairness Act also promises to further strengthen consumer protection.</p><p>Daniel Trunk</p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/1/d/csm_Digital_Media_Tech_4_R_0a17bb27a6.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10022</guid>
                        <pubDate>Tue, 17 Feb 2026 10:18:49 +0100</pubDate>
                        <title>What&#039;s New in Arbitration in 2026 – A Perspective</title>
                        <link>https://www.advant-beiten.com/en/news/whats-new-in-arbitration-in-2026-a-perspective</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>Although the year is already well underway, it is worthwhile to think about which significant developments in arbitration lie ahead in 2026. Beyond the German arbitration reform and current initiatives in France, notable changes are also expected across Asia this year. A common thread underlying many of these developments is the effort to modernize frameworks and to adopt international standards. At the same time, the use of artificial intelligence (AI) is set to play an increasingly prominent role in arbitration, both legislatively and in practice.&nbsp;</p><h3><span><strong>Reform of the German Arbitration Law</strong></span></h3><p>On 27 January 2026, the German Federal Ministry of Justice presented a revised draft bill to modernize Germany's arbitration framework. While the 2026 version introduces two material modifications compared to the 2024 draft – notably with respect to Sections 55 and 1031 of the German Code of Civil Procedure (ZPO) (<a href="https://www.advant-beiten.com/en/news/modernisation-of-german-arbitration-law-key-changes-in-the-january-2026-draft" target="_blank">Modernisation of German Arbitration Law: Key Changes in the January 2026 Draft | ADVANT Beiten</a>) – it retains the broader reform agenda already set out in 2024.<br>The overall objective of the reform remains unchanged: to strengthen Germany's position as a competitive place for arbitration, to further harmonize domestic arbitration law with prevailing international standards, and to enhance procedural efficiency in practice. To that end, the draft continues to provide for a number of structural adjustments, including the facilitation of digital proceedings, expressly permitting electronic awards and video hearings, and clearer rules on the publication of arbitral awards (subject to party consent). It also establishes a narrowly tailored retrial mechanism beyond the ordinary set-aside period and clarifies key issues such as multi-party arbitrator appointments, enforcement of foreign interim measures, judicial review of jurisdictional decisions, and the admissibility of dissenting opinions. Collectively, these measures reflect the legislator's intention to modernize German arbitration law in light of international developments and technological process.&nbsp;<br><br>Within this broader framework, the 2026 draft introduces targeted refinements. The revised version of Sec. 55 ZPO now permits reliance on the principle of <i>lex fori</i> and habitual residence of the party concerned, rather than requiring recourse to foreign nationality‑based capacity rules. This approach aligns procedural capacity with modern principles of private international law.&nbsp;<br>A further improvement concerns the revised wording of Sec. 1031, Subsection 1 ZPO. Under the draft, arbitration agreements shall be concluded or documented in writing or by any other means of communication that allows the information to be stored. This amendment brings German Law more closely into line with international legal standards while preserving the flexibility required in contemporary commercial practice.&nbsp;<br>Taken together, the reform – both in its unchanged core elements and its 2026 refinements – signals a clear policy direction: Germany aims not merely to update its arbitration law, but to position itself proactively within an increasingly competitive global arbitration landscape.</p><h3><span><strong>Court of Arbitration for Nazi-Looted Cultural Property: First Cases Underway</strong></span></h3><p>The newly established Court of Arbitration for Nazi-Looted Cultural Property began its work in December 2025. It serves as an alternative dispute resolution mechanism for addressing disagreements regarding the restitution of cultural property confiscated as a result of Nazi persecution. Claimants can trigger arbitration unilaterally if public institutions in Germany refuse to return items, utilizing a "standing offer" system. It handles cases of cultural property lost between 30 January 1933 and 8 May 1945 due to persecution on racial, political, religious, or ideological grounds. The court is administered by the German Lost Art Foundation (Deutsches Zentrum Kulturgutverluste) in Magdeburg, with the arbitration office located in Berlin. The panel consists of 36 arbitrators. Its framework was negotiated with the Jewish Claims Conference and the Central Council of Jews in Germany. This institution represents a major shift in Germany's approach to restitution, aimed at providing legal certainty for both claimants and public holders of art. Something which is obviously well appreciated, given that as of February 18, 2026, already two cases have been brought before this institution.</p><h3><span><strong>Germany's Commercial Courts</strong></span></h3><p>The recent introduction of Commercial Courts in Germany, as part of the broader reform efforts surrounding German arbitration law, cannot be viewed in isolation from developments in arbitration. For decades, arbitration has been the preferred mechanism for resolving complex cross-border commercial or M&amp;A disputes, largely due to its flexibility, international enforceability, specialized decision-makers, and the possibility of conducting proceedings in English. These advantages have increasingly shaped the expectations of multinational companies regarding dispute resolution.<br>Against this backdrop, the establishment of Commercial Courts represents a deliberate legislative response. By incorporating features traditionally associated with arbitration – such as English-language proceedings, procedural flexibility, specialized senates, and virtual hearings – the German legislator has sought to enhance the competitiveness of its state court system. In doing so, Germany positions its Commercial Courts not as a replacement for arbitration, but as a complementary and, in some cases, competitive alternative within the broader dispute resolution landscape.<br>Proceedings before Commercial Courts may be conducted in English at the level of certain Higher Regional Courts – a notable innovation within the German judicial system.&nbsp;<br>The courts operate through specialized senates, with subject-matter expertise varying by federal state. For instance, two senates at the Hanseatic Higher Regional Court hear commercial disputes with an amount in dispute of EUR 500,000.00 or more, covering areas such as corporate law, post-M&amp;A, banking and insurance law, transport, and shipping. Proceedings may be conducted virtually and offer enhanced confidentiality as well as verbatim transcripts – features traditionally associated with arbitration.<br>It is therefore unsurprising that the new Commercial Courts have been well received and are widely regarded as a success. Initial experiences suggest that both the Commercial Court and the Commercial Chambers established at certain Regional Courts, such as the Regional Court of Frankfurt am Main, are committed to conducting proceedings efficiently and resolving disputes significantly faster than is typically the case before state courts.&nbsp;</p><h3><span><strong>AI-bitration</strong></span></h3><p>The rapid advancement of artificial intelligence has also reached the field of arbitration, bringing significant new developments. AI is increasingly influencing arbitral proceedings by offering transformative tools that promise greater efficiency and enhanced analytical capabilities. While it remains widely accepted that decision-making must rest with human arbitrators, AI's expanding capacity for analysis, interpretation, and drafting raises complex legal, ethical, and practical questions.&nbsp;<br>A central issue for arbitral tribunals is whether, and to what extent, arbitration rules permit the use of AI – particularly given that neither international treaties nor most national arbitration laws expressly regulate its deployment. In the absence of legal provisions, parties and tribunals frequently look to institutional guidance. However, such guidance remains in an early stage of development. Examples include the 2024 Guidelines of the Silicon Valley Arbitration &amp; Mediation Center, the SCC's 2024 Guide, and the CIArb's 2025 Guideline. Most recently the American Arbitration Association published its AI Arbitrator focusing on documents-only construction disputes. However, a real arbitrator remains involved and decisive in this procedure.<br>These initiatives seek to promote the responsible and effective use of AI in arbitration. Yet the existing guidelines remain deliberately broad and preliminary, while technological innovation continues to evolve at remarkable speed. Looking ahead to 2026, the growing relevance of AI in dispute resolution is likely to prompt further institutional guidelines and frameworks. As practical experience accumulates, existing guidelines will be tested, adjusted, and developed further to ensure that arbitral proceedings remain both technologically advanced and firmly anchored in fundamental principles of due process and fairness.</p><h3><span><strong>New Arbitration Laws and Rules</strong></span></h3><p>Across Asia, 2026, marks a year of significant regulatory reforms. China has introduced comprehensive amendments to its Arbitration Law, effective 1 March 2026. The reform constitutes a strategic step toward modernizing the domestic arbitration framework and further aligning the regime for foreign-related arbitration with international practice. Notable innovations include the nationwide introduction of ad-hoc arbitration, improvements to the recognition and enforcement of foreign arbitral awards, and the incorporation of additional internationally recognized key concepts, including a clearer statutory recognition of the separability of arbitration agreements and enhanced tribunal authority to rule on its own jurisdiction (<i>Kompetenz-Kompetenz</i>) – widely regarded as meaningful progress.<br>Pursuing a comparable objective of strengthening procedural governance and aligning its framework with internationally recognized best practices, the Asian International Arbitration Centre (AIAC) has introduced the AIAC Suite of Rules 2026. Effective from 1 January 2026, the suite comprises six new or revised sets of rules and guidelines. Key changes include an expanded scope of application, a clarification of party obligations, adjustments to procedural requirements, mandatory disclosure of third-party funding, and revisions concerning arbitrator conduct and tribunal powers.<br>In Korea, the 2026 version of the KCAB Rules has entered into force. Among the most notable developments are the establishment of the KCAB International Arbitration Court, the introduction of differentiated procedural tracks designed to enhance efficiency, the expansion of virtual proceedings, and the formal recognition of remote hearings.<br>From a European perspective, the ongoing reform of French arbitration law also merits close attention. The reform, expected to be finalized by autumn 2026, envisaged the codification of a unified and modern Arbitration Code aimed at harmonizing the legal framework and further consolidating France's position as a leading place of arbitration.</p><p><br><a href="https://www.advant-beiten.com/en/experts/cv-professional/dr-ralf-hafner" target="_blank">Dr. Ralf Hafner</a><br><a href="https://www.advant-beiten.com/en/experts/cv-professional/oliver-korte" target="_blank">Oliver Korte</a><br><a href="https://www.advant-beiten.com/en/experts/cv-professional/dr-tobias-poernbacher" target="_blank">Dr. Tobias Pörnbacher</a></p>]]></content:encoded>
                        
                            
                                <category>China Desk</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Dispute Resolution</category>
                            
                                <category>Contract &amp; Commercial Law</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/4/4/csm_ADV-print_litigation-and-arbitration_web_8bbaafadf9.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10017</guid>
                        <pubDate>Mon, 16 Feb 2026 10:17:12 +0100</pubDate>
                        <title>ADVANT Beiten Advises Banyan Software on Acquisition of Gini</title>
                        <link>https://www.advant-beiten.com/en/news/advant-beiten-beraet-banyan-software-bei-uebernahme-von-gini</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>Berlin/Freiburg, 16 February 2026 -&nbsp;</strong>The international law firm ADVANT Beiten has provided comprehensive legal and tax advice to Banyan Software on the acquisition of Gini GmbH. The transaction marks another significant milestone in Banyan's international growth strategy and underscores the attractiveness of German software companies for long-term global investors.</p><p class="text-justify">Banyan Software was founded in 2016 and regularly acquires growing software companies with the aim of developing them over the long term as part of a buy-and-hold strategy. Banyan Software has locations in Canada, the United Kingdom and the DACH region.&nbsp;</p><p class="text-justify">Gini was founded in 2011 and has established itself over more than a decade as a trusted provider of document and payment AI platforms. Among other things, its solutions simplify invoice payments, automate data capture and are firmly anchored in the work processes of leading financial institutions. Under Banyan's new ownership, Gini will continue to expand its market presence, particularly in the banking sector, private health insurance and e-commerce.&nbsp;</p><p class="text-justify">Following the transaction, the company's location and product development will continue.</p><p class="text-justify">ADVANT Beiten regularly advises Banyan Software on the implementation of its growth strategy in the DACH region, most recently in June 2025 on the acquisition of star/trac.</p><p class="text-justify"><strong>Advisor Banyan Software:</strong></p><p class="text-justify"><strong>ADVANT Beiten:</strong> Christian Burmeister (Lead), Damien Heinrich, Julius Bauer (all Corporate/M&amp;A), Heiko Wunderlich, Fabian Moser (both Tax), Mathias Zimmer-Goertz, Christian Döpke (both IP/IT), Michael Riedel (Employment Law).</p><p><strong>Public Relations</strong><br>Frauke Reuther<br>Manager Communications<br>ADVANT Beiten<br>+49 (69) 75 60 95 - 570<br><a href="mailto:frauke.reuther@advant-beiten.com">frauke.reuther@advant-beiten.com</a></p>]]></content:encoded>
                        
                            
                                <category>Labour Law</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Tax Law</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/a/0/csm_IP_Header_Scott_3f0bc7d17d.jpeg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9970</guid>
                        <pubDate>Thu, 29 Jan 2026 09:31:00 +0100</pubDate>
                        <title>NIS-2 Implementation Act Entered into Force: New Cyber Security Obligations for Companies</title>
                        <link>https://www.advant-beiten.com/en/news/nis-2-umsetzungsgesetz-in-kraft-neue-cybersicherheitspflichten-fuer-unternehmen</link>
                        <description>The NIS-2 Directive which has been transposed into German law by the NIS-2 Implementation Act, which came into force on 6 December 2025, tightens the cyber security obligations. This also applies to companies whose business models are neither digital nor data intensive. IT security is thus becoming a compliance issue and an obligation for many companies.</description>
                        <content:encoded><![CDATA[<p>The German Federal Parliament (Bundestag) has adopted the law on the implementation of the NIS-2 Directive and on the regulation of essential principles of information security management in the federal administration (in short: "NIS-2 Implementation Act"). After approval by the German Federal Council (Bundesrat) and promulgation in the Federal Law Gazette, it has been in force since 6&nbsp;December&nbsp;2025.&nbsp;</p><p>The NIS-2 Implementation Act changes the Act on the German Federal Office for Information Security (<i>Gesetz über das Bundesamt für Sicherheit in der Informationstechnik</i>, BSIG) and introduces new, stricter cyber security obligations. The group of companies that must implement cyber security measures will be significantly expanded compared to the previous group of addressees.</p><p>After the legislative process had been interrupted by the new elections in spring 2025, it went faster than expected. As the transposition deadline of 17&nbsp;October&nbsp;2024 had long since expired and the European Commission had already initiated infringement proceedings against the Federal Republic of Germany, the German legislator adopted the NIS-2 Implementation Act in an accelerated manner towards the end of the year 2025. It is therefore not surprising that the Act already entered into force one day after its promulgation in the Federal Law Gazette and without any transitional periods. For the companies concerned, this means that they must now implement the new cyber security obligations at very short notice. They are obliged to take suitable and proportionate technical, operative and organisational measures to ensure IT security in the company.</p><p>The NIS-2 Directive (NIS = Network Information Security), which was passed by the European Parliament on 10&nbsp;November&nbsp;2022, belongs to a series of EU legal acts that are part of the digital strategy of the European Commission. An evaluation of the European Commission had shown that the previous NIS Directive and its implementation in the individual EU member states had not led to a sufficient level of cyber security in the EU. Therefore, the cyber security obligations are tightened by NIS-2.</p><h3><span>Scope Of Application: Which Companies Are Subject To The New Cyber Security Obligations?</span></h3><p>Previously, the BSIG differentiated between three categories of companies: (1.) operators of critical infrastructure (Section&nbsp;8a&nbsp;BSIG), (2.) providers for digital services (Section&nbsp;8c&nbsp;BSIG) and (3.) companies in the special public interest (so-called "UBI", Section&nbsp;8f&nbsp;BSIG).</p><p>Now, Section&nbsp;28&nbsp;BSIG (new version) differentiates between so-called particularly important facilities (Section&nbsp;28&nbsp;(1)&nbsp;BSIG) and important facilities (Section&nbsp;28&nbsp;(2)&nbsp;BSIG). The exhibits 1 and 2 to the BSIG define, when a company - depending on the affiliation to a particular sector / an industry - is to be qualified as a particularly important or important facility.</p><p>The following&nbsp;<strong>criteria</strong> are decisive&nbsp;<strong>for determining whether a company falls within the scope of application of NIS-2</strong>: (1.) the classification as a critical infrastructure operator ("<i>KRITIS-Betreiber</i>") (i.e. as a particularly important or important facility), (2.) the affiliation to a sector / an industry and (3.) the size of the company.</p><p>In addition to operators of critical installations, providers of qualified trust services and providers of telecommunications services or operators of telecommunications networks, companies that employ at least 250 people and have an annual turnover of more than EUR 50 million or an annual balance sheet total of more than EUR 43 million are also&nbsp;<strong>particularly important facilities</strong>.</p><p>However,&nbsp;<strong>important facilities</strong> are not only critical infrastructure companies but also manufacturing industrial companies with more than 50 employees and an annual turnover of more than 10 million euros, provided that they belong to one of the sectors / industries mentioned in exhibit 1 or 2 of the BSIG.</p><p>Therefore, the scope of application has been significantly extended compared to the previous NIS Directive of 2015.</p><p>NIS-2 is of particular importance for the "manufacturing" sector. For the first time, it is covered by the new cyber security obligations. Many companies, whose business models are neither digital nor have a special relation to data, will therefore have to deal with cyber security compliance in more depth for the first time.</p><h3><span>Tightened Cyber Security Obligations Pursuant To The BSIG</span></h3><p>In the implementation of the NIS-2 Directive, the BSIG significantly extends the scope of application of cyber security obligations. Compared to the NIS Directive, the NIS-2 Directive also contains a much more comprehensive catalogue of cyber security obligations. Violations of cyber security obligations are also to be severely sanctioned. According to the Act on the German Federal Office for Information Security (BSIG), fines of EUR&nbsp;100,000 to 10 million are provided for violations. In addition, registration and reporting obligations are introduced for companies in the event of a cyber security incident.</p><h3><span>Cyber Security Measures And Risk Management</span></h3><p>Pursuant to Section 30 (1) sentence 1 BSIG, so-called particularly important and so-called important facilities are obliged "to take suitable, proportionate and effective technical and organisational measures in order to avoid disruptions to the availability, integrity and confidentiality of information technology systems, components and processes, that they use for rendering their services, and to minimise the impact of security incidents."</p><p>In doing so, the extent of risk exposure, the size of the facility, the implementation costs, the probability of occurrence and severity of security incidents and their effects must be taken into account, cf. Section&nbsp;30&nbsp;(1)&nbsp;sentence&nbsp;2&nbsp;BSIG.</p><p>The obligations for risk management include, among others, the following measures, to which Section&nbsp;30&nbsp;(2)&nbsp;BSIG refers as&nbsp;<strong>minimum requirements</strong>:</p><ul><li><span>Concepts relating to risk analysis and security for information systems</span></li><li><span>Security incident management</span></li><li><span>Maintaining operations, such as backup management and recovery after an emergency</span></li><li><span>Crisis management</span></li><li><span>Ensuring security in the supply chain</span></li><li><span>Vulnerability management</span></li><li><span>Risk management in the area of cyber security</span></li><li><span>Training on cyber security</span></li><li><span>Concepts and processes for using encryption technologies</span></li><li><span>Personnel safety: access control and authorisation management</span></li><li><span>Multi-factor authentication or continuous authentication</span></li><li><span>Secured voice, video and text communication and, if necessary, secured emergency communication systems</span></li></ul><p></p><h3><span>Obligation To Register And Report Significant Security Incidents</span></h3><p>Moreover, an&nbsp;<strong>obligation to register</strong> has been introduced, cf. Section&nbsp;33&nbsp;BSIG. The responsible German Federal Office for Information Security (<i>Bundesamt für Sicherheit in der Informationstechnik</i>, BSI) provides for a&nbsp;<strong>two-step registration process&nbsp;</strong>for facilities in Germany concerned by the NIS&nbsp;2 Directive:</p><p>First, companies should create an account with "My company account" ("<i>Mein Unternehmenskonto</i>", MUK), in order to register in the second step with the MUK user account with a BSI portal newly developed for NIS 2. The BSI portal has been activated since January&nbsp;2026. Among other things, it serves as a reporting office for significant security incidents. The deadline for the initial registration of companies with the BSI portal is 6&nbsp;March&nbsp;2026 or three months from the date when a company falls into the category of the important or particularly important facility.</p><p>Companies that fall within the scope of application of NIS&nbsp;2 are therefore recommended to register via the BSI portal by 6&nbsp;March&nbsp;2026 at the latest. On the one hand, this is in order to comply with their obligation to register, and on the other hand to be able to report IT security incidents electronically within the prescribed deadlines.</p><p>The<strong> obligations to report significant security incidents&nbsp;</strong>have also been tightened, cf. Section&nbsp;32&nbsp;BSIG. Within 24 hours (so-called early initial report) or 72 hours (so-called report), reports on significant security incidents must be given in stages. After one month at the latest, a summary final report must be submitted. This entails a considerable administrative burden for companies, as they do not only carry out measures to maintain operations or to restore their IT systems in the event of a cyber-attack, but must report to authorities on type, scope and measures taken.</p><h3><span>Cyber Security As A Compliance Issue And Liability Of The Management</span></h3><p>In particular, the monitoring obligation of the management pursuant to Section&nbsp;38&nbsp;BSIG is new. The board or the management must ensure that suitable and proportionate technical and organisational measures are taken within the company to minimise cyber risks. Moreover, companies are obliged to offer training on IT security for leadership personnel and other employees.&nbsp;</p><p>These obligations cannot be delegated completely. There remains always an ultimate responsibility at the management level. If the management violates these compliance obligations, it will be liable to pay damages to the company.&nbsp;</p><p>The violation of cyber security obligations, thus, constitutes a substantial risk for the management. This risk could be hedged by a D&amp;O insurance if necessary. Companies concerned should review existing insurance contracts. Moreover, it is recommended to evaluate whether it is worth taking out cyber insurance.</p><p>Pursuant to Section&nbsp;91&nbsp;(3) German Stock Corporation Act (<i>Aktiengesetz</i>, AktG), the establishment of a risk management system is already part of the obligations of the board of a stock corporation and, thus, part of general compliance obligations of the management of companies. However, the extension to cyber security obligations is new.</p><h3><span>Practical Note</span></h3><p>After the NIS&nbsp;2 Implementation Act entered into force without transitional periods, it is high time for the companies concerned to act. The following summary shall provide the companies concerned with a (non-exhaustive) guide on the most important points to be clarified as a matter of priority, in order to implement the new cyber security obligations.</p><p><strong>Clarification of applicability of NIS&nbsp;2 and obligations to register:</strong> First, it should be clarified, whether and to what extent NIS&nbsp;2 is applicable to the respective company and whether obligations to register exist with the BSI. This must be determined in the individual case based on the product/service portfolio of a company.</p><p><strong>Inventory and documentation:&nbsp;</strong>Cyber security concepts already existing should be reviewed, risks should be evaluated and the required documentation, such as cyber security concepts, emergency plans, etc. should be developed together with technical and legal experts.&nbsp;</p><p><strong>Prevention of cyber-attacks:</strong> Investments in cyber security pay off, as they are an important contribution to protecting the corporate know-how against industrial espionage and to minimising the risk of high business interruption damage in the event of a cyber-attack. Prevention and timely preparation make the decisive difference here.</p><p><strong>Compliance and liability:</strong> In the age of Industry 4.0 and with a view to the legal innovations, IT security should become a "matter for the boss" in companies. EDP and IT security are to be understood as management tasks in a company. This does not mean that managing directors and board members must be IT experts. Rather, they should consult IT security experts. However, it is not possible to delegate the responsibility completely, as the ultimate responsibility lies with the board or the managing director.</p><p><strong>IT security in the supply chain:</strong> Even if a company does not fall within the scope of application of NIS&nbsp;2, it will have to meet the NIS&nbsp;2 requirements for its clients sooner or later. Companies will be confronted with the fact that their clients will pass on their cyber security obligations to their suppliers.&nbsp;</p><p>The factual scope of application of NIS&nbsp;2 is thus even wider. Numerous companies delivering to companies that must meet the new cyber security requirements pursuant to NIS&nbsp;2 are indirectly affected. This applies, for example, to suppliers to the medical technology and pharmaceutical industries, but also to the manufacturing industry which only produces parts for use in the automotive industry, various areas of mechanical engineering or electrical engineering.</p><p>In fact, almost every company will sooner or later have to deal with the topic of IT security.</p><p><a href="https://www.advant-beiten.com/experten/cv-professional/dr-birgit-muenchbach" target="_blank">Dr&nbsp;Birgit Münchbach</a></p>]]></content:encoded>
                        
                            
                                <category>Corporate/M&amp;A</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/c/b/csm_IT_Data_Header_Scott_5c09647b5c.jpeg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9944</guid>
                        <pubDate>Fri, 23 Jan 2026 12:53:39 +0100</pubDate>
                        <title>Games Law Review 2025: Key Legal Developments and Regulatory Shifts</title>
                        <link>https://www.advant-beiten.com/en/news/games-law-review-2025-key-legal-developments-and-regulatory-shifts</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>The year 2025 was characterized by significant judicial decisions, regulatory enforcement actions, and evolving compliance frameworks affecting the games industry. This overview concentrates on German and EU law.</p><h3><span><strong>Artificial Intelligence</strong></span></h3><p><strong>Protecting games IP against AI&nbsp;</strong></p><p>IP law has always been crucial for games companies, who own valuable assets.</p><p>2025 saw a couple of landmark decisions at the intersection between AI and IP. While neither claimants nor defendants in these cases were games companies, these decisions are highly relevant for the games industry.</p><p>At the Regional Court of Munich, GEMA, Germany's collective society for music rights, secured a favorable ruling against OpenAI's ChatGPT <a href="https://www.gesetze-bayern.de/Content/Document/Y-300-Z-GRURRS-B-2025-N-30204" target="_blank" rel="noreferrer">(decision of 11 November 2025 – 42 O 14139/24)</a>. The Court found that ChatGPT's training model contained unauthorized copies of GEMA members' original works, which were subsequently reproduced and made available through user prompts. This was deemed a breach of copyright law. This precedent establishes important implications for the industry, as there is no reason to assume that games-related IP should be treated differently.</p><p>The Higher Regional Court of Hamburg ruled that AI training using copyrighted material may be permissible under the EU copyright law's Text and Data Mining exception, even if the rights holder had declared its “opt-out” in plain text <a href="https://www.landesrecht-hamburg.de/bsha/document/NJRE001628040" target="_blank" rel="noreferrer">(decision of 10 December 2025 – 5 U 104/24)</a>. The court held that plain text failed to meet the "machine-readable" requirement for a valid “rights reservation” (i.e. “opt out”). This ruling shows the importance to implement proper technical opt-out mechanisms for rights holders wishing to prevent their intellectual property from being used in AI training datasets.</p><p>At a regulatory level, the EU's AI Office published its <a href="https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai" target="_blank" rel="noreferrer">General Purpose AI Code of Practice</a>, providing guidance for businesses seeking compliance with AI Act obligations concerning safety, transparency, and copyright for general-purpose AI models.</p><p><strong>AI Implementation: Ownership and Valuation Risks</strong></p><p>Games companies are also leveraging AI for their own purposes, such as asset creation and AI-assisted coding, and must therefore consider the aforementioned decisions.</p><p>AI-generated content and code generally lacks copyright protection. This necessitates ensuring that key visual elements remain human creations rather than machine-generated content. The frequent use of coding assistants raises questions about code protectability. For companies heavily reliant on AI for asset creation or coding, this presents potential valuation challenges in merger and acquisition contexts, where intellectual property traditionally serves as a key value driver. (see our <a href="https://www.advant-beiten.com/en/news/ki-generierte-software-bei-unternehmenskaeufen" target="_blank">blogpost (German)</a>)</p><p><strong>AI Implementation: Regulatory Constraints</strong></p><p>The availabilty of AI solutions through “AI marketplaces” under open-source licenses has faciliated and integration into local clients and user interfaces. However, determining liability under the AI Act for companies integrating third-party AI into their interfaces remains complex.</p><p>Apart from such marketplaces, the AI Act's impact on the gaming industry has been limited thus far. While the European Commission has indicated that AI integration in games may be prohibited in certain cases, particularly for games designed to be highly addictive or exploit vulnerabilities in children, this remains more of a theoretical concern for the time being. Also, AI use cases specific to the games industry generally do not fall in the "high risk" category, but games companies have to be mindful of the more general requirements, e.g. when using AI for HR purposes.</p><p>More games-specific are the transparency obligations notably regarding NPCs and bot-filled competitive game lobbies.&nbsp;</p><p><strong>Data Protection</strong></p><p>In a decision on AI training using publicly available data, the Higher Regional Court of Cologne ruled that Meta's use of Facebook data for AI training was lawful, rejecting an application for a preliminary injunction filed by the Consumer Protection Association of North Rhine-Westphalia <a href="https://nrwe.justiz.nrw.de/olgs/koeln/j2025/15_UKl_2_25_Urteil_20250523.html" target="_blank" rel="noreferrer">(decision of 23 May 2025 – 15 UKl 2/25)</a>. The Court held that, in this specific context, Meta's "legitimate interest" in AI product development was outweighing data subject interests, provided that users were given transparent information and the opportunity to opt-out. This decision may be useful for games companies aiming to train AI themselves.</p><p><strong>Terms of Use, EULAs, and Consumer Protection</strong></p><p>The Consumer Protection Network (CPC) and European Commission published <a href="https://commission.europa.eu/document/8af13e88-6540-436c-b137-9853e7fe866a_en" target="_blank" rel="noreferrer">Key Principles</a>&nbsp;that, while non-binding, were presented as if they were binding.&nbsp;</p><p>According to the Key Principles, the extensive obligations of the European Consumer Rights Directive should also apply when premium in-game virtual currency is sold or spent. This includes, but is not limited, to the call for a display in real world money, and the sizes in which “bundles” of virtual currencies should be sold.</p><p>Regarding withdrawal rights when premium in-game virtual currency is spent, the CPC identified the following practices to avoid:</p><ul><li><span>Denying consumers' 14-day withdrawal rights for unused in-game virtual currency purchases</span></li><li><span>Denying withdrawal rights for in-game digital content or services contracts, regardless of consideration provided by the consumer</span></li></ul><p>In July 2025, the European Commission published guidelines on the protection of minors, addressing implementation of in-game purchases, virtual currencies, and communication features. These positions align with broader consumer and minor protection initiatives concerning allegedly manipulative design practices.</p><p>The European Commission has announced plans to work on the Digital Fairness Act. This will provide an additional layer of consumer protection, targeting dark patterns and addictive design.</p><h3><span>Loot Boxes</span></h3><p>In late 2025, the German Federal Council (Bundesrat) adopted a resolution calling for significantly stricter loot box regulation to enhance youth protection. The initiative urges an examination of whether loot boxes should be legally classified as gambling due to their "gambling-like mechanisms," potentially resulting in mandatory 18+ age ratings for games containing such features. The Council demands full transparency regarding winning odds and pricing while advocating for unified European regulation within the Digital Fairness Act framework.</p><h3><span>IP Disputes</span></h3><p>In Sony v. Datel cheating proceedings, the German Federal Court of Justice delivered its <a href="https://www.bundesgerichtshof.de/SharedDocs/Pressemitteilungen/DE/2025/2025149.html" target="_blank" rel="noreferrer">final judgement</a> following a 2024 decision by the European Court of Justice, ruling that mere RAM modifications might not constitute copyright infringement. However, this ruling has limited impact on multiplayer game cheat enforcement, as it restricts specific copyright claims on the manipulation of data in the working memory while leaving the tools for enforcing unfair competition law and breach of EULA intact.</p><h3><span>Youth Protection Beyond Violence</span></h3><p>Interaction risks, including chat features and monetization mechanics, are increasingly considered in age ratings. Germany's rating authority USK estimates that approximately one-third of rated games contain such risks, with one-third of those (11% in total) receiving higher age ratings than they would without these mechanics.</p><p>Germany also updated its <a href="https://gesetze.berlin.de/bsbe/document/jlr-JMedienSchStVtrBErahmen" target="_blank" rel="noreferrer">Interstate Treaty on Media Minor Protection</a>, granting the Commission for the Protection of Minors in the Media (KJM) decisive new enforcement tools. The amendment specifically targets loopholes previously allegedly exploited by some foreign providers to bypass German age verification laws. Key measures include authority to order payment service provider transaction blocking to non-compliant platforms and, as last resort, network blocking implementation. The reform transforms KJM's ability to act against offshore violators, shifting from administrative warnings to revenue stream disruption. However, this legislation faces criticism regarding "over-blocking" risks, as broad technical mandates could lead to inadvertent censorship of legitimate content if automated filters lacking contextual nuance are introduced.</p><p>Dr Andreas Lober<br>Lennart Kriebel<br>Daniel Trunk<br>Fabian Eckstein</p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/2/1/csm_AdobeStock_295160836_f5b9396c2b.jpeg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9924</guid>
                        <pubDate>Tue, 13 Jan 2026 14:09:55 +0100</pubDate>
                        <title>AI-Generated Software in Company Acquisitions</title>
                        <link>https://www.advant-beiten.com/en/news/ki-generierte-software-bei-unternehmenskaeufen</link>
                        <description></description>
                        <content:encoded><![CDATA[<p></p><h3><span>Introduction</span></h3><p>Generative AI not only supports the writing of texts and the creation of images but increasingly also the programming of software. This can have an impact on the applicability of copyright protection to software. This is also important in the case of company acquisitions. Where the software has been largely developed by AI, it may lack copyright protection which affects the intrinsic value of the target company. This must be taken into account in the context of due diligence as well as in the drafting of contracts.</p><h3><span>Legal Context</span></h3><p>Computer programmes are protected by copyright if they represent individual works in the sense that they are the result of their author's own intellectual creation. According to this principle, computer programmes have usually been protected by copyright until now. Since generative AI has also found its way into software development, the question arises as to how this affects the protectability. In essence, a computer programme will be able to protect if a human uses AI only as a subordinate tool. This will be the case if, for instance, AI tests the software to be developed and uncovers inconsistencies. If, however, relevant parts of the code are generated by AI, they will in many cases lack protectability. The exact distinctions are currently still subject to further development. Nevertheless, one should not be too hasty to speak of a gray area overall. The principles are already relatively clear but the specific outcome depends highly on the facts of each individual case.</p><p>All this applies regardless of whether the AI provider grants the user (i.e. software developer) all rights to the work results of the AI. If no copyright is created because the human contribution is too small, no copyright can be transferred.</p><h3><span>Effects on due diligence</span></h3><p>Nowadays, software developers can hardly do without the use of AI in development. The question is thus less whether AI will be used but rather how it will be used. And this question should also be asked as part of the due diligence. Disclosed internal guidelines and documentation on employee training on the use of AI can provide information, as can relevant license agreements. In addition, it is advisable to consult dedicated experts so that the actual use can be verified as accurately as possible. With only superficial due diligence, risks could be overlooked; if W&amp;I insurance is to be taken out as part of the transaction, the associated policy could cancel or reduce the scope of the guarantee to the extent that gaps have been identified in the due diligence.&nbsp;</p><h3><span>Effects on contract documents</span></h3><p>In addition to general guarantees of ownership of all relevant intellectual property rights (IP), there are separate guarantees with regard to the use of AI, for which attachments with specific descriptions or disclosures may then be manufactured. If the guarantee clause were too generic, there would be a risk that, in the event of an (alleged) breach of the guarantee, legal ambiguity would arise as to whether the particular case falls under the guarantee or not.&nbsp;</p><h3><span>Other legal issues: Third Party Rights, AI Act, Scraping and Data Licenses, International Aspects</span></h3><p>A question that must be separated from the above considerations but is nevertheless related, is whether any AI-generated code infringes the rights of third parties. This could be the case, for example, if the AI largely reproduces the foreign code – with which it was trained. The risk can be reduced with a software scan but not completely eliminated; on the other hand, there is also the risk of foreign code being incorporated when human programmers are used. On the other hand, there is likely to be a greater risk if visual content is AI-generated. However, this is not the subject of this article.</p><p>If the software solution in question itself represents AI as part of the target company or as an asset to be transferred, not only the AI Act should be kept in mind but also the origin of the datasets with which it was trained. If these are due to web scraping (automated reading of data on websites using software bots or scripts), copyright and data protection questions may arise. Even the acquisition of a license from a commercial provider is only useful if the latter in turn has all the necessary rights himself; a look at the license terms is advisable in any case (for instance, with regard to limits of use by the licensee).</p><p>In cross-border company acquisitions, particularly when the target company operates internationally or even globally, the copyright challenges relating to AI-generated software are even greater. Copyright is basically national law, although the requirements for the creation of copyright protection are similar in most countries and thus also the principles for the legal issues relevant here. However, developments are still ongoing at the international level, and a Chinese court may decide the legal issues raised here differently than an American court. The guarantee declarations of the transaction documents should also contain flexible wording that takes into consideration the different legal frameworks in the jurisdictions concerned.&nbsp;</p><h3><span>Conclusion and recommendation for action</span></h3><p>If AI is not only used as a subordinate tool in the creation of software, the software may not be eligible for protection. The software development process should therefore be scrutinized as part of the due diligence process. The findings will have to be reflected in the contract documentation when the company is acquired. Other follow-up issues such as third-party rights, AI Act, scraping and data licenses as well as international aspects must also be considered.&nbsp;</p><p><a href="https://www.advant-beiten.com/en/experts/cv-professional/dr-andreas-lober" target="_blank">Dr&nbsp;Andreas Lober</a><br><a href="https://www.advant-beiten.com/en/experts/cv-professional/tassilo-klesen" target="_blank">Tassilo Klesen</a></p>]]></content:encoded>
                        
                            
                                <category>Corporate/M&amp;A</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/4/b/csm_AdobeStock_61974553_b22cb4c397.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9905</guid>
                        <pubDate>Fri, 09 Jan 2026 09:04:11 +0100</pubDate>
                        <title>Games industry legal trends to watch in 2026: AI, child safety, loot boxes and more</title>
                        <link>https://www.advant-beiten.com/en/news/games-industry-legal-trends-to-watch-in-2026-ai-child-safety-loot-boxes-and-more</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>In this article, published on January 2, 2026, on gameslawindustry.biz, Dr. Andreas Lober looks back on his predictions for the gaming industry from 2025, highlighting his accurate forecasts on legal trends, such as disputes related to AI and stricter regulations for developers. At the same time, he provides an outlook on what 2026 might bring.</p><p>You can find the article under this <a href="https://www.gamesindustry.biz/games-industry-legal-trends-to-watch-in-2026" target="_blank" rel="noreferrer">link</a>.</p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/6/e/csm_AdobeStock_222147805_ee91995c20.jpeg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9818</guid>
                        <pubDate>Mon, 08 Dec 2025 09:57:09 +0100</pubDate>
                        <title>ADVANT Beiten Advises ProMach on the Acquisition of DFT Technology GmbH</title>
                        <link>https://www.advant-beiten.com/en/news/advant-beiten-beraet-promach-beim-erwerb-der-dft-technology-gmbh</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>Dusseldorf, 8 December 2025</strong> – The international law firm ADVANT Beiten has provided comprehensive legal advice to the US-based global packaging and process solutions provider ProMach on the acquisition of DFT Technology GmbH, a Northern-Germany-based specialist for thermal product treatment systems. The parties have agreed not to disclose the transaction volume.</p><p>ProMach is a leading international platform in the field of packaging and processing technologies.</p><p>DFT is an established provider of innovative solutions in the field of sterilization, pasteurization and other thermal processes for the food and beverage industry. With the acquisition of DFT, ProMach is continuing its growth strategy in Europe.</p><p>The international cooperation within the ADVANT alliance played a central role in this transaction: our Italian alliance partner ADVANT Nctm has been advising ProMach in Italy for many years.</p><p>ADVANT Beiten entered into the mandate in close coordination with the US law firm Thompson Hine, which regularly advises ProMach on legal matters in the United States.</p><p><strong>Advisors to ProMach:</strong><br>ADVANT Beiten: Prof Dr Hans-Josef Vogel (Dusseldorf), Roy Naor (Frankfurt, both Corporate/M&amp;A, lead partners), Dr Andreas Imping, Anna Kubitz (both Labour Law), Mathias Zimmer-Goertz, Christian Döpke (both IP/IT), Sarah Peters, Simon Litterst (both Corporate/M&amp;A, all Dusseldorf), Christopher Harten (Dispute Resolution, Hamburg), Marcus Mische, Markus Linnartz (both Tax), Thomas Herten (Real Estate, all Dusseldorf), Katrin Lüdtke (Public Sector, Munich).</p><p><strong>Public Relations</strong><br>Frauke Reuther<br>Manager Kommunikation<br>ADVANT Beiten<br>+49 (69) 75 60 95 - 570<br>frauke.reuther@advant-beiten.com</p>]]></content:encoded>
                        
                            
                                <category>Labour Law</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                                <category>Real Estate Law</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Dispute Resolution</category>
                            
                                <category>Tax Law</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                                <category>Industrials</category>
                            
                                <category>Public Sector</category>
                            
                                <category>Real Estate</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/0/8/csm_Life-Sciences-Healthcare_webjpg_437142f686.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9763</guid>
                        <pubDate>Mon, 24 Nov 2025 09:55:00 +0100</pubDate>
                        <title>ADVANT Beiten Advises Zoot Sports on the Acquisition of Tailwind Brands GmbH</title>
                        <link>https://www.advant-beiten.com/en/news/advant-beiten-beraet-zoot-sports-bei-der-uebernahme-der-tailwind-brands-gmbh</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>Munich, 24. November 2025 </strong>- ADVANT Beiten has provided comprehensive legal and tax advice to Zoot Sports, based in Carlsbad (California, USA), on the acquisition of Tailwind Brands GmbH, based in Bönen, Germany. The transaction represents an important step in Zoot's European growth strategy and strengthens the company's market position in the triathlon and endurance sports sector. The acquisition gives Zoot direct access to the European market as well as to Tailwind's existing distribution structures and long-standing trading relationships. The parties have agreed not to disclose the transaction volume.</p><p>ADVANT Beiten's interdisciplinary team supported Zoot throughout the entire acquisition process - from the legal and tax due diligence to the structuring and negotiation of the transaction agreements through to the successful closing.</p><p>Zoot Sports was founded in 1983 in Kona, Hawaii - the birthplace of the Iron Man triathlon. The company specializes in innovative clothing, shoes and equipment for triathletes and endurance athletes and is one of the world's leading brands in this segment. Zoot stands for technical precision, high quality and athlete orientation and sells its products in over 25 countries. Since 2023, Zoot has been part of the Italian MVC Group, an international sporting goods company based in Italy.</p><p>Tailwind Brands is a company based in Bönen, which specializes in the distribution and brand management of premium sports and lifestyle brands. The company has an established distribution network in the DACH region as well as long-standing partnerships with leading sports retailers and online platforms. Tailwind has made a name for itself as a competent partner for the development and expansion of international brands in the European market.</p><p>With the acquisition of Tailwind Brands, Zoot Sports is laying the foundation for accelerated expansion in Europe. The combination of Zoot's international brand strength with Tailwind's regional market and sales expertise offers considerable growth potential in the coming years.</p><p><strong>Advisor Zoot Sports:</strong><br>ADVANT Beiten: Dr Markus Ley (Corporate/M&amp;A, Munich), Dr. Erik Schmid, Virginia Mäurer (both Employment Law, Munich), Susanne Klein, Jason Komninos (both IP/IT, Frankfurt), Markus Linnartz (Tax, Dusseldorf), Petra Fendt (Banking &amp; Finance, Munich), Anja Fischer (Real Estate, Munich).</p><p><strong>Public Relations</strong><br>Frauke Reuther<br>Communications Manager<br>ADVANT Beiten<br>+49 (69) 75 60 95 - 570<br><a href="mailto:frauke.reuther@advant-beiten.com">frauke.reuther@advant-beiten.com</a></p>]]></content:encoded>
                        
                            
                                <category>Labour Law</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                                <category>Real Estate Law</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Tax Law</category>
                            
                                <category>Banking &amp; Finance</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                                <category>Real Estate</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/f/4/csm_Kartellrecht_bearbeitet_high_quality2_31de18587f.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9671</guid>
                        <pubDate>Thu, 23 Oct 2025 18:19:12 +0200</pubDate>
                        <title>China: New Cybersecurity Incident Reporting Measures </title>
                        <link>https://www.advant-beiten.com/en/news/china-new-cybersecurity-incident-reporting-measures</link>
                        <description></description>
                        <content:encoded><![CDATA[<p class="text-justify">Network data processors in China are legally required to report cybersecurity incidents to authorities under the China Data Security Law, the China Personal Information Protection Law, the China Cybersecurity Law and other applicable Chinese laws and regulations, such as the Network Data Security Management Regulations (which&nbsp;came into effect on 1 January 2025 and which oblige network data processors to report to the&nbsp;competent Chinese authorities within 24 hours if they discover risks in their network products or services that may cause (but have not necessarily materialized in) threats to national security or&nbsp;the&nbsp;public interest.</p><p class="text-justify">The new&nbsp;<strong>Measures on National Cybersecurity Incident Reporting&nbsp;</strong>issued by the Cyberspace Administration of China (<strong>CAC</strong>) and&nbsp;<strong>coming into effect on 1 November 2025</strong>&nbsp;require much faster action&nbsp;- between <strong>1&nbsp;and</strong> <strong>4 hours</strong> if&nbsp;<strong>network operators</strong>&nbsp;detect a&nbsp;<strong>cybersecurity incident</strong>&nbsp;that has&nbsp;caused&nbsp;harm to networks and information systems, or their data and business applications, and has a negative impact on the country, society, or economy due to human factors, network attacks, vulnerabilities, software or hardware defects or failures, force majeure, etc.</p><h3 class="text-justify"><span><strong>Who is governed by the new Measures?</strong></span></h3><p class="text-justify">All network operators are governed by the new Measures, that is,&nbsp;everyone who, as&nbsp;an&nbsp;owner or administrator of networks or&nbsp;network services, builds, operates, or provides services through networks within China. This includes but&nbsp;is&nbsp;not limited to critical information infrastructure (<strong>CII</strong>) operators (so-called <strong>CIIOs</strong>, i.e., enterprises that operate CIIs and that have been notified by the competent authorities that they are categorized as CIIOs) as well as government entities.</p><h3 class="text-justify"><span>What is considered a cybersecurity incident under the new Measures?</span></h3><p class="text-justify">The new Measures divide&nbsp;such incidents into four different levels based on their severity and impact:&nbsp;</p><figure class="table"><table style="border-style:none;" class="contenttable"><tbody><tr><td style="background-color:#823434;border-bottom:1.0pt solid windowtext;border-left:1.0pt solid windowtext;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:70.4pt;"><p class="text-justify"><span><strong>Threshold</strong></span></p></td><td style="background-color:#823434;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:106.3pt;"><p class="text-justify"><span><strong>Exceptionally Major</strong></span></p></td><td style="background-color:#823434;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:106.3pt;"><p class="text-justify"><span><strong>Major</strong></span></p></td><td style="background-color:#823434;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:106.35pt;"><p class="text-justify"><span><strong>Relatively Major</strong></span></p></td><td style="background-color:#823434;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid windowtext;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:3.0cm;"><p class="text-justify"><span><strong>General</strong></span></p></td></tr><tr><td style="background-color:#823434;border-bottom:1.0pt solid windowtext;border-left:1.0pt solid windowtext;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:70.4pt;"><p><span><strong>Impact</strong></span></p><p><span>&nbsp;</span></p></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:106.3pt;"><span>Important network &amp; information systems suffer exceptionally severe system losses, causing large-scale system unresponsiveness and loss of business processing capabilities; other incidents posing exceptionally severe threats or impacts on national security, social order, economic construction, and public interests</span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:106.3pt;"><span>Important networks and information systems suffer severe system losses, causing long-term system disruption or partial unresponsiveness, substantially affecting business processing capabilities; other incidents posing a severe threat or impact on national security, social order, economic construction, and public interests</span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:106.35pt;"><span>Important networks and information systems suffer large system losses, causing system disruption, significantly affecting system efficiency and business processing capabilities; other incidents posing a relatively severe threat or impact on national security, social order, economic construction, and public interests</span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid windowtext;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:3.0cm;"><span>Other cybersecurity incidents that pose certain threats or impact on national security, social order, economic construction, and public interests, but do not meet the thresholds of the higher categories to the left</span></td></tr><tr><td style="background-color:#823434;border-bottom:1.0pt solid windowtext;border-left:1.0pt solid windowtext;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:70.4pt;"><span><strong>Data leaked</strong></span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:106.3pt;"><span>Core/important data &amp; extensive personal information are leaked, posing an exceptionally severe threat to national security and social stability</span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:106.3pt;"><span>Core/important data &amp; large numbers of personal information are leaked, posing a severe threat to national security and social stability</span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:106.35pt;"><span>Important data and a relatively large number of personal information are leaked, posing a relatively severe threat to national security and social stability</span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid windowtext;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:3.0cm;"><span>&nbsp;</span></td></tr><tr><td style="background-color:#823434;border-bottom:1.0pt solid windowtext;border-left:1.0pt solid windowtext;border-right:1.0pt solid #CCCCCC;border-top-style:none;height:49.7pt;padding:0cm 5.4pt;vertical-align:top;width:70.4pt;"><span><strong>Personal information leaked</strong></span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;height:49.7pt;padding:0cm 5.4pt;vertical-align:top;width:106.3pt;"><span>&gt; 100&nbsp;mil data subjects</span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;height:49.7pt;padding:0cm 5.4pt;vertical-align:top;width:106.3pt;"><span>&gt; 10&nbsp;mil data subjects</span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;height:49.7pt;padding:0cm 5.4pt;vertical-align:top;width:106.35pt;"><span>&gt;&nbsp;1&nbsp;mil data subjects</span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid windowtext;border-top-style:none;height:49.7pt;padding:0cm 5.4pt;vertical-align:top;width:3.0cm;"><span>&nbsp;</span></td></tr><tr><td style="background-color:#823434;border-bottom:1.0pt solid windowtext;border-left:1.0pt solid windowtext;border-right:1.0pt solid #CCCCCC;border-top-style:none;height:48.9pt;padding:0cm 5.4pt;vertical-align:top;width:70.4pt;"><span><strong>Direct economic loss&nbsp;</strong></span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;height:48.9pt;padding:0cm 5.4pt;vertical-align:top;width:106.3pt;"><span>&gt; RMB&nbsp;100&nbsp;mil</span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;height:48.9pt;padding:0cm 5.4pt;vertical-align:top;width:106.3pt;"><span>&gt; RMB&nbsp;20&nbsp;mil</span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;height:48.9pt;padding:0cm 5.4pt;vertical-align:top;width:106.35pt;"><span>&gt;RMB&nbsp;5&nbsp;mil</span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid windowtext;border-top-style:none;height:48.9pt;padding:0cm 5.4pt;vertical-align:top;width:3.0cm;"><span>&nbsp;</span></td></tr><tr><td style="background-color:#823434;border-bottom:1.0pt solid windowtext;border-left:1.0pt solid windowtext;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:70.4pt;"><span><strong>CII disruption&nbsp;</strong></span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:106.3pt;"><span>Disruption of the entire CII of &gt; 6&nbsp;hours or disruption of main functions of &gt; 24&nbsp;hours</span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:106.3pt;"><span>Disruption of the entire CII of &gt; 1&nbsp;hour or disruption of main functions of &gt; 3&nbsp;hours</span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:106.35pt;"><span>Disruption of the entire CII for &gt; 10&nbsp;min. or disruption of main functions of &gt; 30&nbsp;min.</span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid windowtext;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:3.0cm;"><span>&nbsp;</span></td></tr><tr><td style="background-color:#823434;border-bottom:1.0pt solid windowtext;border-left:1.0pt solid windowtext;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:70.4pt;"><span><strong>Disruption of essential service for:</strong></span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:106.3pt;"><span>&gt; 50% of the population of one or more provinces or &gt;&nbsp;10&nbsp;mil people</span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:106.3pt;"><span>&gt; 50% of the population of one or more municipalities or &gt; 1&nbsp;mil people</span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:106.35pt;"><span>&gt;&nbsp;30%&nbsp;of the population of one or more municipalities or &gt;100k people</span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid windowtext;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:3.0cm;"><span>&nbsp;</span></td></tr></tbody></table></figure><p>Note: If any one threshold is met for one of the four incident levels, the network operator&nbsp;must be classified under the higher level of cybersecurity incident that has been met.&nbsp; In other words, the thresholds for each incident level should be read independently,&nbsp;not cumulatively.</p><h3 class="text-justify"><span>What are the reporting and other obligations under the new Measures?</span></h3><p class="text-justify">Once a network operator becomes aware of a cybersecurity incident involving its own network/business, it must conduct an incident assessment following the Guidelines for the Classification of Cybersecurity Incidents which are appended to the new Measures.&nbsp;</p><p class="text-justify">The new Measures allocate different reporting obligations depending on the nature of the network operator and the severity of the incident:&nbsp;</p><figure class="table"><table style="border-style:none;" class="contenttable"><tbody><tr><td style="background-color:#823434;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:155.45pt;"><p class="text-justify"><span><strong>CIIOs</strong></span></p></td><td style="background-color:#823434;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:134.65pt;"><p class="text-justify"><span><strong>Central &amp; State Government and direct Affiliates</strong></span></p></td><td style="background-color:#823434;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:177.2pt;"><p class="text-justify"><span><strong>Other network operators</strong></span></p></td></tr><tr><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:155.45pt;"><p><span>Incidents at or above&nbsp; “relatively major” levels must be reported within 1 hour to the CAC protection department &amp; PSB.</span></p><p>&nbsp;</p><p>&nbsp;</p><p><span>Incidents at “major or exceptionally major”&nbsp;levels must be reported within 30 minutes to the CAC protection department &amp; PSB and they shall report the incident to national CAC and the PSB department of the State Council.&nbsp;</span></p><p>&nbsp;</p></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:134.65pt;"><p><span>Incident at or above&nbsp; &nbsp;“relatively major” levels must be reported within 2 hours to the cybersecurity work unit of their department.</span></p><p>&nbsp;</p><p><span>Incidents at the “major or exceptionally major” levels shall be reported within 1 hour by the cybersecurity work units of the relevant department to the national CAC department who shall conduct the onward reporting.&nbsp;</span></p></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid windowtext;border-left-style:none;border-right:1.0pt solid #CCCCCC;border-top-style:none;padding:0cm 5.4pt;vertical-align:top;width:177.2pt;"><p><span>Incidents at or above the “relatively major” level shall be reported within 4 hours the provincial CAC department.</span></p><p>&nbsp;</p><p>&nbsp;</p><p>&nbsp;</p><p><span>Incidents at the “major or exceptionally major” levels shall be reported within 1 hour to the provincial CAC department who shall report to the national CAC department and to the relevant departments at the same level.</span></p></td></tr></tbody></table></figure><p class="text-justify">CAC provides different reporting channels such as the&nbsp;telephone hotline reachable&nbsp;at 12387, as well as email (12387@cert.org.cn) and other reporting modes, all accessible via&nbsp;the&nbsp;CAC’s website&nbsp;<a href="https://12387.cert.org.cn/index.html" target="_blank" rel="noreferrer">https://12387.cert.org.cn/index.html</a>.&nbsp;</p><p class="text-justify">The reporting timelines&nbsp;are calculated from the point in time when the network operator becomes aware of the incident. If the circumstances of the incident cannot be determined in full within the statutory notification deadlines, the network operator shall submit a preliminary report (containing whatever information is available at that time) and then provide an updated comprehensive report as soon as possible once more information becomes available.&nbsp;</p><p class="text-justify">In addition, interim updates on major developments, as well as a final summary report, shall be provided within 30 days after the incident&nbsp;has been remedied&nbsp;(including information on&nbsp;the cause of the incident, remedial measures taken, scope of impact, accountability, and improvements made).</p><p class="text-justify">Reports should include the following&nbsp;information:</p><ul><li><span>Affected entity and system</span></li><li><span>Time, place, type, and level of incident; impact, damage, measures taken and results thereof</span></li><li><span>Preliminary analysis&nbsp;of&nbsp;the cause of&nbsp;the &nbsp;incident</span></li><li><span>Suggested remedies and support</span></li><li><span>Security measures&nbsp;in place at the time of the incident</span></li><li><span>Potential attacker information, attack path, vulnerabilities, and, in&nbsp;the&nbsp;case of ransomware incidents, the ransom amount requested and payment method</span></li><li><span>Other facts material to the incident</span></li></ul><p class="text-justify">In addition, if for certain industry sectors special reporting obligations apply, these shall be followed as well and in case of any illegal or criminal activities being suspected, PSB must always also be notified.</p><p class="text-justify">If network operators employ external IT service providers, the contracts between&nbsp;them must&nbsp;require such&nbsp;providers to immediately notify&nbsp;the&nbsp;network operators of any incidents in their networks and to&nbsp;assist with the mandatory reporting thereof.</p><p class="text-justify">Any failure to comply with reporting obligations under the new Measures exposes network operators and their responsible employees or&nbsp;agents to liabilities under the Chinese Cybersecurity Law, Data Security Law, Personal Information Protection Law and other applicable Chinese laws and regulations. Fines can range from RMB 50k to RMB 50 mil depending on the seriousness of the incident and the type of data involved and network operators are exposed to heavier consequences if they delay of proper reporting caused more serious consequences. Any reasonable and necessary protective measures taken by the network operator may mitigate such liability.&nbsp;</p><h3 class="text-justify"><span>How&nbsp;should network operators react to the new Measures?</span></h3><p class="text-justify">Considering the new Measures, network operators should review, revise, prepare and&nbsp;verify:&nbsp;</p><ul><li><span>Incident response policies and plans to align with&nbsp;the&nbsp;accelerated notification requirements</span></li><li><span>Internal procedures to ensure timely escalation of cybersecurity incidents to the appropriate personnel</span></li><li><span>Report templates to align with the information requirements under the new Measures</span></li><li><span>External&nbsp;IT&nbsp;service contracts&nbsp;to ensure they stipulate&nbsp;immediate notification and assistance obligations, or&nbsp;are amended accordingly</span></li></ul><p>Susanne Rademacher<br>Dr Jenna Wang-Metzner<br>Kelly Tang</p>]]></content:encoded>
                        
                            
                                <category>China Desk</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                                <category>IT and the Law of Data</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/6/b/csm_AdobeStock_118624234_b9df4849c1.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9439</guid>
                        <pubDate>Thu, 14 Aug 2025 08:26:35 +0200</pubDate>
                        <title>ADVANT Beiten Advises the Principal Shareholder of CFH Gmbh on Strategic Partnership with Yancoal International Holding Co., Ltd.</title>
                        <link>https://www.advant-beiten.com/en/news/advant-beiten-beraet-den-hauptgesellschafter-der-cfh-gmbh-bei-strategischer-partnerschaft-mit-yancoal-international-holding-co-ltd</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>Dusseldorf, 14&nbsp;August&nbsp;2025 -&nbsp;</strong>ADVANT Beiten advised the principal shareholder of CFH GmbH with its registered office in Marl, Germany, on the conclusion of a strategic partnership with Yancoal International Holding Co., Ltd. - a subsidiary of the Chinese Yankuang Energy Group and Shandong Energy Group with an international team.&nbsp;</p><p>Yancoal International Holding Co., Ltd. acquires 51 percent of the shares in CFH GmbH within the scope of the transaction. The parties have agreed not to disclose the transaction volume.</p><p>The globally operating CFH Group of Companies bundles under its umbrella a number of subsidiaries and holding companies, all specialising in engineering services enabling innovative solutions related to the topic of air at the workplace.&nbsp;</p><p>Yancoal International Holding Co., Ltd. brings comprehensive experience in global resource allocation and industrial cooperation. The stake of Yancoal International Holding Co., Ltd. represents an important milestone in the international growth strategy of CFH Group of Companies. The partnership opens up new opportunities for technological innovation, global market presence and sustainable development. New standards in developing intelligent ventilation and environmental technologies are defined together - in particular for applications in mining, tunnelling and industry.&nbsp;</p><p>The international team of ADVANT Beiten headed by Dr Martin Rappert (Dusseldorf) and Susanne Rademacher (Beijing) regularly advises companies on investments and business activities in Europe and the People's Republic of China.</p><p><strong>Advisors to CFH GmbH:&nbsp;</strong><br><strong>ADVANT Beiten</strong>: Dr Martin Rappert, Nico Frielinghaus, Prof Dr Hans-Josef Vogel, Dr Winfried Richardt, Sarah Heinrichs, Simon Litterst (all Dusseldorf), Susanne Rademacher (Beijing, all Corporate/M&amp;A), Christian Döpke, Mathias Zimmer-Goertz (Data Protection/IP, Dusseldorf), Christoph Heinrich (Antitrust, Munich), Dr Christian von Wistinghausen (Foreign Trade Law, Berlin), Thomas Herten (Real Estate, Dusseldorf), Vasily Ermolin (Sanctions, Moscow).</p><p><strong>Media Contact</strong><br>Frauke Reuther<br>Manager Kommunikation<br>ADVANT Beiten<br>+49 (69) 75 60 95 - 570<br><a href="file:///C:/Users/fmannott/AppData/Local/Microsoft/Windows/Temporary%20Internet%20Files/Content.Outlook/99IBPS14/frauke.reuther@advant-beiten.com" target="_blank">frauke.reuther@advant-beiten.com</a></p>]]></content:encoded>
                        
                            
                                <category>China Desk</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Antitrust Law</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                                <category>Industrials</category>
                            
                                <category>Real Estate</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/beiten/Header_Bilder_Scott/Bejing_16x9.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9411</guid>
                        <pubDate>Tue, 05 Aug 2025 13:49:31 +0200</pubDate>
                        <title>ADVANT Beiten Advises apoBank on the Restructuring and Expansion of the Sales Joint Venture with AXA</title>
                        <link>https://www.advant-beiten.com/en/news/advant-beiten-beraet-apobank-bei-der-neugestaltung-und-vertiefung-des-vertriebs-joint-ventures-mit-der-axa</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>Frankfurt, 5&nbsp;August&nbsp;2025</strong> - The international commercial law firm ADVANT Beiten advises Deutsche Apotheker- und Ärztebank eG (apoBank) comprehensively on the restructuring and expansion of the existing sales joint venture with AXA.&nbsp;</p><p>ApoBank and the AXA Insurance Group have been cooperating in the sale of financial and insurance products for more than 25&nbsp;years. Both companies now want to bundle the sales activities of their mobile sales companies apoFinanz and Deutsche Ärzte Finanz more closely.&nbsp;</p><p>As part of the restructuring, apoFinanz will be merged with Deutsche Ärzte Finanz. At the same time, apoBank acquires additional shares in Deutsche Ärzte Finanz. The merger creates the largest financial sales organisation for academic health professionals in Germany. With around 500 independent financial advisors, the new company will serve more than 320,000 customers. The merger will be completed in August 2025. A cross-office team from ADVANT Beiten is providing apoBank with comprehensive legal advice.</p><p>With more than half a million customers and total assets of around EUR&nbsp;52 billion, apoBank is the largest cooperative retail bank in Germany and the number one financial services provider in the healthcare sector. Its customers are primarily members of the healthcare professions, their professional organisations and associations, healthcare facilities and companies in the healthcare market.</p><p>With the reorganisation of their joint sales subsidiaries, the partners want to combine the strengths of the companies and use the synergies for additional growth.&nbsp;</p><p><strong>Advisors to apoBank:&nbsp;</strong></p><p><strong>ADVANT Beiten</strong>: Heinrich Meyer, Rainer Süßmann (both lead partners in charge, Banking/Finance, Frankfurt), Dr&nbsp;Christian Ulrich Wolf, Maren Dedert (both Corporate/M&amp;A, Hamburg), Christoph Heinrich, Prof&nbsp;Dr&nbsp;Christian Heinichen (both Antitrust Law, Munich), Oliver Korte, Christopher D. Harten (both Commercial, Hamburg), Dr&nbsp;Thomas Drosdeck, Dr&nbsp;Gerald Müller-Machwirth (both Labour Law), Susanne Klein, Lennart Kriebel and Daniel Trunk (all IT- and Data protection Law, all Frankfurt)</p><p class="text-justify"><strong>Advisor to AXA:&nbsp;</strong>Hengeler Mueller</p><p class="text-justify"><strong>Public Relations</strong><br>Frauke Reuther<br>Communications Manager<br>ADVANT Beiten<br>+49 (69) 75 60 95 - 570<br><a href="file:///C:/Users/fmannott/AppData/Local/Microsoft/Windows/Temporary%20Internet%20Files/Content.Outlook/99IBPS14/frauke.reuther@advant-beiten.com" target="_blank">frauke.reuther@advant-beiten.com</a></p><p>Heinrich Meyer<br>Rechtsanwalt&nbsp;<br>ADVANT Beiten<br>Phone: +49 69 756095-414<br><a href="mailto:heinrich.meyer@advant-beiten.com">heinrich.meyer@advant-beiten.com</a></p>]]></content:encoded>
                        
                            
                                <category>Labour Law</category>
                            
                                <category>Financial Services and Insurance Law</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Antitrust Law</category>
                            
                                <category>Tax Law</category>
                            
                                <category>Banking &amp; Finance</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/e/7/csm_AdobeStock_447195483_d1a556d1f1.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9396</guid>
                        <pubDate>Fri, 01 Aug 2025 13:33:23 +0200</pubDate>
                        <title>Cyber security for digital products: New obligations for manufacturers, importers and traders pursuant to the Cyber Resilience Act</title>
                        <link>https://www.advant-beiten.com/en/news/cybersicherheit-bei-digitalen-produkten-neue-pflichten-fuer-hersteller-importeure-und-haendler-nach-dem-cyber-resilience-act</link>
                        <description>The increasing digitalisation and networking of products requires enhanced security measures to prevent cyber attacks. The Cyber Resilience Act (CRA) of the European Union addresses this issue and establishes mandatory cyber security standards for products with digital elements. The aim is to minimise the risk of cyber incidents and to strengthen confidence in digital technologies.</description>
                        <content:encoded><![CDATA[<p></p><h3><span>Cyber Resilience Act? (CRA): Uniform security standards for&nbsp;products with digital elements</span></h3><p>The European Union is creating a comprehensive and binding set of rules and regulations to strengthen the cyber security of products with digital elements with the Cyber Resilience Act (CRA). The aim of the regulation is to establish uniform cyber security standards for the European single market and thereby significantly reduce the risk of cyber attacks. At the same time, the confidence of consumers and companies in digital technologies should be strengthened.</p><p>The CRA obliges manufacturers, importers and traders to meet cyber security requirements during the entire product life cycle - from design and development through manufacturing and marketing to continuous maintenance and updating. This is to ensure that products are not only safe when they are placed on the market but also meet current security requirements throughout their life cycle.</p><h3><span>Which products does the CRA apply to?</span></h3><p>In principle, the regulation covers all products with digital elements that are manufactured, imported or distributed in the territory of the European Union. Products with digital elements are both software and hardware products and their data teleprocessing solutions, as well as software or hardware components that are placed on the market separately. These include, in particular, products that are capable of processing, storing or transmitting data - such as smart home devices, networked household appliances, mobile devices as well as other internet enabled products. Software products such as firmware, operating systems and applications also fall within the scope.&nbsp;</p><p>Products, however, that are covered by already existing, sector-specific EU rules with equivalent cyber security requirements - such as medical devices pursuant to the Medical Device Regulation or certain spare parts that must be manufactured to the exact specifications of the parts to be replaced and, therefore, do not involve any additional cyber security risks, are excluded from the scope of application.&nbsp;</p><h3><span>Schedule: Staged entry into force of the CRA and transitional periods</span></h3><p>The CRA already came into force on 10&nbsp;December&nbsp;2024. The regulation will be implemented in several stages. Conformity assessment bodies should already assess the fulfilment of the requirements of the CRA for products with digital elements as of 11&nbsp;June&nbsp;2026. Reporting requirements for specialist units and security incidents will be in place as of 11&nbsp;September&nbsp;2026. The transitional period will end completely as of 11&nbsp;December&nbsp;2027 so that new cyber security requirements for products with digital elements will be binding as of that date. This applies to new products placed on the market as of 11&nbsp;December&nbsp;2027 and for products previously placed on the market that have undergone significant changes.</p><h3><span>To whom do the obligations under the CRA apply?</span></h3><p>The CRA does not only oblige manufacturers, but all actors along the value-added chain of a product - among them importers, traders and authorised representatives - to meet cyber security requirements. Companies managing, providing or significantly changing digital products are also covered by the obligations of the regulation. This also expressly applies to developers or operators of open source software, provided that they offer their products under normal market conditions (Art.&nbsp;3&nbsp;No.&nbsp;12&nbsp;CRA).</p><p>A key innovation lies in the legal extension of the so-called capacity as manufacturer. Pursuant to Art.&nbsp;22&nbsp;CRA, any natural or legal person is deemed to be a manufacturer who significantly changes a product with digital elements and places it on the market again - regardless of whether the person has previously acted as a trader or importer. The regulation thus follows the system of the European Product Safety Law, according to which the placing on the market of a product is the decisive criterion.</p><p>The term "placing on the market" is not linked to a physical handover for purely software-based products. The decisive criterion in these cases is the moment when the software is made available for download, the access code is transmitted or the activation for users becomes technically feasible.</p><h4><span>1. Obligations for manufacturers</span></h4><p>The cyber security requirements of the CRA are primarily aimed at manufacturers. The central message is: Who places digital products on the market, must ensure that they are safe - not only if he has manufactured and/or programmed them himself. The same applies to software components that originate from third parties. Pursuant to Art.&nbsp;13&nbsp;(5)&nbsp;CRA, manufacturers must ensure with "due care" that these parts do not endanger the product's safety. Open source software (OSS) also falls within the scope of application of the CRA. This also applies if OSS is available free of charge on the internet and is not offered by companies but by individuals.&nbsp;</p><h5><span>IT security throughout the entire product life cycle</span></h5><p>Manufacturers of products must meet numerous requirements to guarantee the safety of their products during the entire life cycle.&nbsp;</p><p>The cyber security of a product must be guaranteed during the entire so-called "life cycle" of a product, i.e., from development to the end of its useful life. For Software, this means in particular creating a secure architecture, using secure standard configurations and regularly providing security updates. Corresponding processes to continuously ensure product integrity must be set up if they have not been implemented yet.</p><h5><span>Reporting Requirements</span></h5><p>Manufacturers are obligated to report weaknesses and major security incidents of all products. The report must be addressed to the responsible Computer Security Incident Response Team (CSIRT) as well as to the European Union Agency for Cybersecurity (ENISA). Established deadlines must be observed: Incidents must be reported within 24 hours of becoming known, subsequently further relevant information will be provided.</p><h5><span>Conformity assessments</span></h5><p>Before a product is launched on the market, it must be examined whether it meets the requirements of the Cyber Resilience Act. This so-called conformity assessment is mandatory and depends on how the product is classified under the CRA. Depending on how safety-critical it is, varying strict requirements apply. If the product is successfully assessed, it will receive the CE mark - an official evidence that it meets the necessary standards.</p><h5><span>Management of weaknesses and security updates</span></h5><p>Weaknesses in a product must be remedied within a period of at least five years after discovery. This remedy takes the form of security updates and usually must be free of charge. This period corresponds at least to the expected useful life of the product.</p><h5><span>Documentation obligations</span></h5><p>The manufacturer is obliged to document compliance with the security requirements for the product. This documentation must be maintained during the entire life cycle of the product and must be kept up to date. The documentation must meet the minimum requirements of the CRA and must be traceable at any time.</p><h4><span>2. Obligations for importers</span></h4><p>Similar to the manufacturer, the importer may only launch his product if the requirements of the CRA pursuant to Art.&nbsp;19&nbsp;(1)&nbsp;CRA are met. The importer must be able to ensure and prove that the manufacturer's obligations have already been fulfilled. In addition, he is obliged to provide his contact details on the product (if this is impossible, on the packaging or the enclosed documentation). In case of safety deficiencies, both the manufacturer and the competent authorities must be informed. The user must also be informed when safety deficiencies become known.</p><h4><span>3. Obligations for traders</span></h4><p>At first glance, the trader has less obligations than the manufacturer and the importer. He must only verify whether the CE number, declaration of conformity, end date of the support period and the contact details of the manufacturer and importer are available. If the trader determines that the product is CRA-compliant, he may bring this product onto the market. If this is not the case, the trader must also take measures to combat existing security vulnerabilities. For instance, he is obliged to withdraw the product from the market and to inform the competent authorities.</p><h3><span>Sanctions in case of violations of the CRA</span></h3><p>Manufacturers, importers or traders who violate the new cyber security requirements pursuant to the CRA must, in principle, expect consequences. Pursuant to Art.&nbsp;64&nbsp;(3), fines of up to EUR&nbsp;10&nbsp;million or of up to 2% of the total worldwide annual turnover of the preceding financial year of a company may be imposed, whichever is higher. Violations of the manufacturer obligations can result in sanctions of up to EUR&nbsp;15&nbsp;million or 2.5% of the total worldwide annual turnover. Additionally, further restrictive measures may be taken. Pursuant to Art.&nbsp;64&nbsp;(10), exceptions are made for micro and small enterprises and for administrators of open source software. The fine imposed in individual cases will always be based on the specific violation, its gravity and also on the degree of culpability of the actor concerned, i.e., it must be proportionate. Nevertheless, companies should not take this possibility of sanctions lightly. As in data protection law, the same applies to the CRA: In the event of a violation, a good documentation of the cyber security measures taken helps to provide evidence that a company fulfilled its obligations.</p><h3><span>Need for action for companies: What must be done now?</span></h3><p>Companies that manufacture, import or distribute products with digital elements should check these products for possible cyber risks already now and take appropriate security measures if necessary. In addition, they should prepare themselves for their obligations to provide documentation and evidence. Targeted training courses and raising awareness among employees are also indispensable. Agreements with suppliers should be checked to determine whether the suppliers of components also meet appropriate IT security requirements. In addition, it is recommendable to develop an incident response plan which, among other things, ensures compliance with reporting requirements and clearly defines responsibilities in the company.</p><p>Last but not least, the new requirements of the CRA for products with digital elements should already be considered during product design in the development in order that manufacturers will not be taken by surprise by the new cyber security requirements for their products in December&nbsp;2027. Here, legal and technical expertise have to be combined to find solutions that not only meet the requirements of the CRA but are also practicable and economical.</p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/9/4/csm_Cyberangriff_4259cec7ab.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9379</guid>
                        <pubDate>Wed, 30 Jul 2025 11:14:41 +0200</pubDate>
                        <title>Are administrative tools under the PRC Anti-Foreign Sanctions Law (AFSL) a new weapon to deter international IP Disputes against PRC Parties?</title>
                        <link>https://www.advant-beiten.com/en/news/are-administrative-tools-under-the-prc-anti-foreign-sanctions-law-afsl-a-new-weapon-to-deter-international-ip-disputes-against-prc-parties</link>
                        <description></description>
                        <content:encoded><![CDATA[<p class="text-justify">Earlier this year the State Council released the <i>Provisions on Implementation of the PRC Anti-foreign Sanctions Law</i> (<strong>AFSL Provisions, </strong>effective since 23 March 2025) and the <i>Provisions on the Settlement of Foreign-related IP Disputes</i> (<strong>IP Disputes Provisions</strong>, effective since 1 May 2025). While at first sight seemingly not connected, there is a material link between the AFSL Provisions and the IP Disputes Provisions that shows China’s preparedness to use administrative tools to deter foreign judicial acts that China deems harmful against its interest.&nbsp;</p><p class="text-justify">The existence of the AFSL, AFSL Provisions and the IP Dispute Provisions obliges any parties engaged in foreign (= outside China) or domestic legal action involving Chinese parties to carefully assess the risks of any dispute resolution strategies. Not only China-based enterprises but also foreign enterprises are affected by these regulations and must hence balance these Chinese regulatory and compliance requirements with other responsibilities resulting from conflicting sanctions regimes of other jurisdictions such as Europe and the US and general international compliance requirements.</p><h3 class="text-justify"><span>I. Countermeasures under AFSL Provisions in case of “foreign litigation”</span></h3><p class="text-justify">The AFSL Provisions allow the Chinese government to take countermeasures against “<i>promoting and implementing litigation by any foreign country, organisation or individual</i>”, which the Chinese government deems will “<i>endanger the sovereignty, security, and development interests of China</i>”. It is thereby irrelevant where such litigation occurs inside or outside China and the “foreign” element is rather established by a foreign (invested) party promoting or implementing such litigation.</p><p class="text-justify">The potential countermeasures faced by the affected litigation subjects (including natural and legal persons) range from restrictions to enter/leave China, seizing of any kind of property in China; prohibition/limitation on transactions and cooperation with third parties; compulsory property enforcement and other measures.&nbsp;</p><p class="text-justify">Whether the AFSL Provisions will be applied also to private commercial disputes or are more directed against cases of important strategical/political matters remains to be seen. However, given the far-reaching wording and the lack of excluding private party legal action against Chinese parties, one would be amiss to think this could not become a tool at the convenience of Chinese regulatory bodies to invoke countermeasures even in cases of private commercial disputes against Chinese parties if China deems such legal action could endanger the sovereignty, security, and development interests of China.</p><h3 class="text-justify"><span>II. Particular Importance of IP Disputes - Link between the IP Dispute Provisions &amp; AFSL Provisions</span></h3><p class="text-justify">The IP Disputes Provisions are expressly linked to the ASFL and AFSL Provisions. The IP Disputes Provisions emphasise that “<i>containment or suppression”&nbsp;</i>against China and<i> “discriminatory restrictive measures</i>” against Chinese citizens and organisations taken “<i>under the guise of IP disputes</i>” fall within the scope of AFSL.&nbsp;</p><p class="text-justify">While the AFSL uses the terminology of “containment, suppression and&nbsp;discriminatory restrictive measures”, it fails to define these terms. To date there is also no other public legislation known that would specify these terms. This ambiguity makes it very daunting to predict situations in which countermeasures could be taken against what China believes to be a foreign containment, suppression or discriminatory restrictive measures under the guise of international IP disputes in which Chinese enterprises are a party.&nbsp;</p><p class="text-justify">While the IP Disputes Provisions only became effective on 1 May 2025, already on 15 January 2025 the PRC Supreme People’s Court issued a ruling in patent dispute filed by Huawei against Netgear, prohibiting Netgear and its affiliates from seeking anti-suit injunctions in the US and other foreign countries that would restrict Huawei from initiating or continuing patent infringement proceedings in China.&nbsp;</p><p class="text-justify">Given that Chinese enterprises having become increasingly active in the international arena and are leaders in many high-tech sectors, it appears plausible to believe that in the future one will rather see more than less international IP disputes between foreign and Chines parties.&nbsp;</p><p class="text-justify">Therefore, with these new IP Disputes Provisions, any such international IP disputes between foreign and Chinese parties should be subject to a risk assessment if they could create cause for potential countermeasures being invoked by China against the foreign litigants. In addition, foreign parties starting litigation against Chinese parties for IP disputes may also risk other legal consequences such as refusal to recognise and enforce foreign judgments and arbitral awards in China if they would be considered by China to fall under these new provisions.</p><h3 class="text-justify"><span>III. AFSL Provisions in General &nbsp;</span></h3><p class="text-justify">The AFSL obliges China-based organizations and individuals to implement China’s countermeasures to (a) safeguard China’s interests against discriminatory restrictive measures imposed on organizations and individuals, and (b) against interference with China’s internal affairs by foreign countries, or individuals and organisations that have directly or indirectly participated in the formulation or implementation of discriminatory restrictive measures.&nbsp;</p><p class="text-justify">The AFSL entitles Chinese individuals or organisations to initiate civil legal action to demand cessation of infringement and compensation for losses against any organisation or individual that “<i>implements or assists in implementing&nbsp;discriminatory restrictive measures</i>” taken by any foreign country against them.&nbsp;</p><p class="text-justify">Further, the AFSL Provisions allow administrative measures to be taken against such organisations or individuals, including conducting interviews, orders to make corrections and other corresponding measures.&nbsp;</p><p class="text-justify">In both such cases (civil &amp; administrative cases), the related liabilities and administrative penalties apply to China-based and foreign organizations and individuals.</p><p class="text-justify">Legal consequences suffered in case of a failure to execute China’s countermeasures can entail the following: being ordered to make a correction, prohibition/limitation to partake in government procurement and in import/export of goods &amp; services in general,&nbsp;prohibition/limitation to transfer/receive data and personal information across borders and prohibition/limitation to enter/exit China.&nbsp;</p><p class="text-justify">Cooperations involving organizations or individuals against whom countermeasures have been taken are generally prohibited or limited unless an exemption is granted as per the AFSL Provisions. Such an exemption application must be submitted to the State Council department and documentary requirements, review timelines, and substantive evaluation criteria of the exemption mechanism remain subject to further clarification.&nbsp;</p><p class="text-justify">Susanne Rademacher</p>]]></content:encoded>
                        
                            
                                <category>China Desk</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/e/9/csm_ADV_II_Intellectual-Property-4_web_5d075910eb.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9375</guid>
                        <pubDate>Tue, 29 Jul 2025 15:43:25 +0200</pubDate>
                        <title>Accessibility becomes mandatory: What companies need to know</title>
                        <link>https://www.advant-beiten.com/en/news/barrierefreiheit-wird-pflicht-was-unternehmen-wissen-muessen</link>
                        <description></description>
                        <content:encoded><![CDATA[<p></p><h3><span>1. Introduction</span></h3><p>On 28&nbsp;June&nbsp;2025, the German Accessibility Reinforcement Act (<i>Barrierefreiheitsstärkungsgesetz</i>, BFSG) entered into force with the objective of digital inclusion. People with disabilities, handicaps and elderly people should be given equal access to products and services that are important for participation in life in society. This entails new obligations for companies. Violations may result in fines and other sanctions.&nbsp;</p><h3><span>2. Who is affected?</span></h3><p>The Act applies to companies that place the products specified in the BFSG on the market or render services after 28&nbsp;June&nbsp;2025. This includes, in particular, banking services for consumers, telecommunications services, electronic ticketing services, self-service terminals such as ATMs or ticket machines, hardware systems and their operating systems for consumers (computers, tablets, notebooks), devices with interactive performance capabilities such as smartphones and smart tvs, e-books and e-readers.&nbsp;</p><p>In addition, the requirements of the BFSG also apply to all electronic commerce services. Thus, every company is concerned that sells its products or services via an online shop.</p><p>This applies in principle to all companies operating in the relevant areas. In case of services, only micro enterprises are exempted that offer employment to less than ten people and have an annual turnover or an annual balance sheet total of no more than EUR&nbsp;2&nbsp;million. However, they should receive advisory services in order to be able to provide services that are accessible to everyone. Companies, that manufacture, import or distribute products, must also meet the requirements of the BFSG as micro enterprises.&nbsp;</p><p>Accessibility requirements, however, must only be met if their compliance does not require any fundamental change in the essential characteristics of a product or a service. The manufacturer or service provider must document such an assessment and submit it to the competent market surveillance authority upon request.</p><p>In addition, the accessibility requirements apply only insofar as their compliance would not result in a disproportionate financial burden on the company. Companies are obliged to carry out and document an appropriate assessment before providing a product or service and to inform the competent market surveillance authority immediately.</p><h3><span>3. What needs to be done?</span></h3><p>The BFSG transposes the EU Directive 2019/882 ("European Accessibility Act", shortly EAA) into German law. It obliges the addressees to make the products and services covered accessible und provide information.&nbsp;</p><h4><span>3.1 Ensuring accessibility</span></h4><p>Products and services must meet specific requirements for accessibility. They are barrier-free according to the legal definition in section&nbsp;3&nbsp;(1)&nbsp;sentence&nbsp;2&nbsp;BFSG if they can be found, accessed and used by people with disabilities in the usual manner, without any particular difficulties and generally without external help. Regarding the specific requirements, the BFSG refers to the&nbsp;<a href="https://www.gesetze-im-internet.de/bfsgv/BJNR092800022.html" target="_blank" rel="noreferrer">Regulation on the Accessibility Requirements (BFSGV)</a> (<i>in German</i>).</p><p>Products must contain components, functions and characteristics that enable people with disabilities to access, perceive, operate, understand and control the product. The same applies to the product packaging, user instructions and warnings. For instance, they must be made available via more than one sensory channel, must be easy to find and linguistically understandable and must be displayed in an appropriate font size.</p><p>Services must provide for functions, procedures and possible changes in the performance that are tailored to the needs of people with disabilities. This relates, in particular, to information on the functioning of the service. Comparable requirements for the comprehensibility and perceptibility apply here as for product packaging.</p><p>If services are offered online, the corresponding websites, including mobile apps, must also be designed to be perceptible, operable, understandable and robust. This includes ensuring interoperability with assistive technologies, such as screen readers.</p><p>In addition to these general requirements, the BFSGV contains numerous additional regulations regarding certain products and services, such as telecommunications services, banking services or e-books.&nbsp;</p><p>When fulfilling the requirements of the BFSGV, companies must observe the state of the art. For products and services that comply with harmonised standards or technical specifications, it is presumed that they meet the requirements of the BFSGV.&nbsp;</p><p>Manufacturers and providers may only place their products and services on the market and/or offer them if they meet the accessibility requirements. Traders must monitor compliance with these obligations of the manufacturer and may only make a product available on the market if it is compliant. If there is reason to assume that a product does not meet the accessibility requirements, traders may not distribute it.</p><h4><span>3.2 Information obligations</span></h4><p>In addition to the implementation of the accessibility requirements, service providers are also obliged to provide information on how these requirements are actually met. Additionally, this information must contain at least a general description of the service in an accessible format, descriptions and explanations that are required to understand the performance of the service, and the indication of the competent market surveillance authority.</p><p>This information can be included in the General Terms and Conditions used, but may also otherwise be made available, e.g. via a separate link on the website, as far as this is clearly perceptible.</p><h4><span>3.3 Effects on GTC &amp; data protection declarations</span></h4><p>Insofar as a product or service must be made accessible without barriers pursuant to the BFSG, all contents that functionally belong to the product or service must also be accessible without barriers. For instance, this may concern GTC, but also data protection declarations.&nbsp;</p><p>In this case, it must be ensured in particular that there is a text structuring through headings, there are alternative texts for embedded images or other media, a clear, comprehensible language is used, the font size and contrast are appropriate, and the compatibility with screen readers is guaranteed.</p><h3><span>4. Implementation deadlines and transitional provisions</span></h3><p>In principle, companies have had to meet the new accessibility requirements since the Act came into force, thus, since 28&nbsp;June&nbsp;2025. Partially, transitional provisions take effect. By 27&nbsp;June&nbsp;2030, services may be provided using products that have been used lawfully by the service provider already before 28&nbsp;June&nbsp;2025. Agreements on services concluded before 28&nbsp;June&nbsp;2025 must be adapted by 27&nbsp;June&nbsp;2030 at the latest.</p><p>Self-service terminals that companies used to provide services before 28&nbsp;June&nbsp;2025, may continue to be used until the end of their economic useful life, but for no longer than fifteen years after they are put into use.</p><h3><span>5. Sanctions</span></h3><p>Negligent and wilful violations of certain requirements of the BFSG are subject to fines of up to EUR&nbsp;10,000 in minor cases and up to EUR&nbsp;100,000 in serious cases. The specific amount of the fine is based on the circumstances of the individual case.&nbsp;</p><p>The market surveillance authorities of the federal states verify compliance with the requirements of the BFSG. This task should be carried out by the "Market Surveillance Authority of the Federal States for the Accessibility of Products and Services" (<i>Marktüberwachungsstelle der Länder für die Barrierefreiheit von Produkten und Dienstleistungen</i>, MLBF) centrally in the future. In addition to the imposition of fines, market withdrawals of non-compliant products and a prohibition of service provision are imminent.</p><p>Administrative offence proceedings can be initiated ex officio, at the request of a consumer, an association recognised under the German Act on Equal Opportunities of Persons with Disabilities (<i>Behindertengleichstellungsgesetz</i>) or a consumer protection association. Competitors may also take action against alleged violations by way of a warning under competition law. In this case, the assertion of claims for injunctive relief and damages is imminent.</p><h3><span>6. Recommended course of action</span></h3><p>Companies should verify whether they are addressees of the obligations of the BFSG. If necessary, they should check their digital offers for accessibility and adapt them where appropriate. An accessibility audit or a quick check may help to identify and to remedy weak points in the technical implementation of accessibility requirements or of information obligations.&nbsp;&nbsp;</p><p>However, it can also make sense for companies that do not fall within the scope of the BFSG to improve the accessibility of their products and services. In addition to an image gain by supporting inclusion of disadvantaged people, this may also lead to a measurable increase in sales, by reaching new customer groups.</p><p>Kristin Trittermann, LL.M.<br>Mathias Zimmer-Goertz</p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Corporate Criminal Law &amp; Compliance</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/0/0/csm_AdobeStock_203623925_c7e3aa54eb.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9333</guid>
                        <pubDate>Mon, 21 Jul 2025 16:52:35 +0200</pubDate>
                        <title>The Hidden Power of Intellectual Property Rights: Geostrategic Potentials of Industrial Property Rights</title>
                        <link>https://www.advant-beiten.com/en/news/die-verborgene-macht-von-immaterialgueterrechten-geostrategische-potenziale-von-gewerblichen-schutzrechten</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>In an increasingly fragmented world order characterized by global trade conflicts, supply chain risks and rivalries over technologies, resources and spheres of influence, economic and technological dependencies are becoming increasingly important. In view of this, the strategic dimension of intellectual property rights (“IP rights”) is gaining ever greater attention. After all, whoever controls access to key technologies has geopolitical influence. In the past, IP rights were primarily viewed from a legal and economic perspective. However, it is becoming more and more evident that IP rights, especially patents and trade secrets, can represent strong strategic leverage. Especially for companies operating in security-relevant sectors such as defense and aerospace but also for companies developing technologies with dual-use potential, it is crucial to understand the potential risks and opportunities that arise when IP rights are "weaponized".</p><h3><span>From Property Rights to Instruments of Power</span></h3><p>Intellectual property rights – particularly patents – are traditionally understood as tools for protecting technical innovations. However, their role extends beyond exploitation through licensing or litigation. Rather, IP rights can be leveraged strategically to block competitors from market access, strengthen one's own strategic position, or even control critical infrastructures.</p><p>IP rights can thus become a strategic instrument through the consistent use of the existing legal framework, for example, by withdrawing licenses from certain players or by selectively sharing know-how. The accumulation of extensive IP rights portfolios in security-relevant technologies – such as satellite communication, drone technology, sensor systems, cryptography or artificial intelligence – can also serve as a strategic deterrent.</p><p>Those holding exclusive rights in key markets can not only block third parties from entering the market, but also activate regulatory leverage – for instance in the context of export controls, security reviews or investment screening procedures.</p><p>In this context, IP rights can be used strategically in a number of ways:</p><ul><li><span><strong>Strategic Acquisition and Monopolization:</strong> Companies may seek to acquire or assert control over critical IP rights in key areas as a means of excluding competitors, shaping supply chains or restricting access to essential technologies.</span></li><li><span><strong>Enforcement of Sanctions and Export Controls:</strong> IP licenses or the transfer of IP-protected technologies can be leveraged to pursue strategic goals or undermine the capabilities of competitors or adversarial players. This applies in particular to dual-use technologies that can be used for both civilian and military purposes.</span></li><li><span><strong>Active IP Protection and Enforcement:&nbsp;</strong>Safeguarding relevant technologies from unauthorized acquisition or reverse engineering requires a robust and proactive approach. This includes not only preventive measures and internal security protocols but also the consistent extrajudicial and judicial enforcement of IP rights so as to prevent the outflow of expertise and ensure long-term competitiveness.</span></li><li><span><strong>Defense against Unwanted Technology Transfer ("IP leakage"):</strong></span><br><span>IP assets and sensitive technologies must be protected from strategically motivated access attempts by potentially adversarial partners or entities.</span></li></ul><p></p><h3><span>Leveraging the Legal Framework</span></h3><p>For companies in the defense and aerospace sector, but also for companies that develop dual-use technologies, it is essential to develop a proactive IP strategy that addresses the aforementioned risks and at the same time optimally protects and uses their own IP assets. The existing legal framework offers numerous ways to achieve this objective:</p><ol><li><span><strong>Robust IP Protection:</strong> One essential measure is the implementation of a comprehensive IP strategy, including the protection of trade secrets and technical know-how. This also entails the consistent implementation of strict internal processes to protect confidential information.</span></li><li><span><strong>Due Diligence for M&amp;A Transactions and Cooperations:</strong> In M&amp;A transactions or R&amp;D partnerships, a thorough IP due diligence process is essential – not only to uncover potential infringement risks but also to assess dependencies on critical technologies or third-party rights.</span></li><li><span><strong>Strategic Licensing and Technology Transfer Agreements:</strong> By drafting contracts appropriately and implementing technology transfer controls, companies can manage access to their IP rights while ensuring compliance with export control laws. This can include the inclusion of "clawback" clauses that allow for the withdrawal of licenses in the event of certain geopolitical developments.</span></li><li><span><strong>Active enforcement of IP rights:</strong> In the event of IP infringements, swift and consistent legal enforcement is crucial. This can include legal proceedings, arbitration or recourse to customs authorities to prevent the sale and import of infringing products.</span></li><li><span><strong>Geopolitical Risk Management in Contract Drafting:</strong> Contracts with international partners should explicitly include clauses that address the impact of sanctions, export restrictions or other geopolitical events on IP usage rights.</span></li></ol><p></p><h3><span>Conclusion</span></h3><p>The strategic deployment of IP rights described above illustrate the great importance of IP rights in a geopolitical context. For companies operating in the defense, aerospace dual-use sectors, a sound understanding of these relationships and the resulting dynamics is essential. IP rights are no longer just a competitive factor but an integral part of risk mitigation and national security.</p>]]></content:encoded>
                        
                            
                                <category>Intellectual Property</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Defence &amp; Security</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/9/7/csm_Produkthaftung_5637119234.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9079</guid>
                        <pubDate>Fri, 06 Jun 2025 09:27:00 +0200</pubDate>
                        <title>ADVANT Beiten Advises Banyan Software on Acquisition of star/trac</title>
                        <link>https://www.advant-beiten.com/en/news/advant-beiten-beraet-banyan-software-bei-uebernahme-von-star-trac</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>Berlin/Freiburg, 6 June 2025 -&nbsp;</strong>The international law firm ADVANT Beiten has provided comprehensive legal and tax advice to Banyan Software on the acquisition of star/trac supply chain solutions GmbH, a specialized provider of yard and transport management solutions for the chemical, industrial and logistics sectors. The parties have agreed not to disclose the purchase price. The acquisition further strengthens Banyan Software's market position in the DACH region.</p><p>Banyan Software was founded in 2016 and regularly acquires growing software companies with the aim of developing them over the long term as part of a buy-and-hold strategy. Banyan Software has offices in Canada, the UK and the DACH region.</p><p class="text-justify">Headquartered in&nbsp;Munich, Germany, star/trac is specialised in optimizing complex yard management operations. Its innovative solutions significantly enhance operational efficiency, reduce truck waiting times, and ensure compliance with the stringent safety and regulatory standards.</p><p class="text-justify">ADVANT Beiten advises Banyan Software regularly on the implementation of its growth strategy in the DACH region, most recently in January 2025 on the acquisition of FoxInsights.</p><p class="text-justify"><strong>Advisor Banyan Software:</strong><br><strong>ADVANT Beiten:</strong> Christian Burmeister (Lead), Damien Heinrich, Julius Bauer (all Corporate/M&amp;A), Heiko Wunderlich, Fabian Buker (both Tax), Mathias Zimmer-Goertz, Christian Döpke (both IP/IT), Lelu Li (FDI), Alexander Grässel (Labor &amp; Employment Law).</p><p><strong>Public Relations</strong><br>Frauke Reuther<br>Manager Kommunikation<br>ADVANT Beiten<br>+49 (69) 75 60 95 - 570<br><a href="mailto:frauke.reuther@advant-beiten.com">frauke.reuther@advant-beiten.com</a></p>]]></content:encoded>
                        
                            
                                <category>Labour Law</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Tax Law</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                                <category>Industrials</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/f/6/csm_Corporate_MUA_Header_Scott_229c37dd99.jpeg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-8927</guid>
                        <pubDate>Fri, 02 May 2025 15:15:17 +0200</pubDate>
                        <title>What the upcoming German Government plans for Media and the Digital Industry</title>
                        <link>https://www.advant-beiten.com/en/news/digital-und-medienpolitik-im-koalitionsvertrag-von-union-und-spd</link>
                        <description>As the members vote of the Social Democrats (SPD) has cleared the way for a new government, we would like to summarize what the new government has planned for the media and digital sector. This article is based on the so-called “coalition agreement”, in which the parties of the future government describe and agree on what they intend to do.</description>
                        <content:encoded><![CDATA[<p></p><h3><span>Path to an “AI Nation” and Cloud Infrastructure</span></h3><p>The future government has outlined the ambitious goal of making Germany Europe’s leading “AI Nation.” At the core of this vision are substantial investments into developing a high‑performance cloud and AI infrastructure to serve as the foundation for data‑driven applications. Significant resources will also be devoted to integrating artificial intelligence with robotics. Lightweight construction technologies and 3D printing are identified as key drivers for modernizing traditional manufacturing processes.</p><h3><span>Data Strategy and Data Protection</span></h3><p>“Public money, public data” is the principle which shall make sure that any data generated with public funds is generally available for governmental and societal use. To this end, the future government plans a comprehensive “Data Code” to consolidate existing regulations and to establish a right to open data related to government institutions. Coupled with strengthened data trustees this measure is intended to ensure trust in the quality and integrity of such datasets.</p><p>There are plans to reorganize data protection supervision by bundling responsibilities and competencies under the Federal Commissioner for Data Protection, who may be renamed the Federal Commissioner for Data Use, Data Protection and Freedom of Information. The Data Protection Conference (DSK) will be anchored in the Federal Data Protection Act (BDSG) in order to continuously develop common standards. For public services, the future government aims to replace consent-based processes with “opt‑out solutions” where feasible. At the European level, it will seek to exempt nonprofit associations, small and medium‑sized enterprises, and low‑risk data processing from the scope of the GDPR.</p><h3><span>Administration 4.0 and E‑Justice</span></h3><p>A key priority is the digitalization of public administration and the justice system. Administrative processes will be automated and accelerated, with AI playing a key role. Formal requirements for written documentation will be eased so that digital documents can be used without legal barriers. A nationwide “Justice Cloud” is also planned, into which case files and documents from courts and public prosecutors’ offices will be migrated. This will be complemented by a user-friendly "Justice Portal" offering digital filing procedures, an enforcement register and, in the future, AI-assisted support functions - particularly aimed at significantly shortening civil proceedings.</p><h3><span>European Framework and Platform Regulation</span></h3><p>The parties in the future government intend to implement EU digital legislation in Germany in an innovation-friendly and coherent manner. They plan to set up a central service office to manage the national implementation of the AI Act in order to minimize bureaucratic hurdles for companies. To strengthen digital resilience against cyber threats, the EuroStack initiative will be supported. Regarding platform regulation, the focus will be on rigorous enforcement of the Digital Services Act (DSA). Providers will be required to promptly remove illegal content and actively combat systemic risks such as disinformation. The future government will also explore mandatory bot identification and a ban on manipulative design practices ("dark patterns"). At the same time, criminal law will be modernized to close gaps in the prosecution of deepfakes and image‑based sexual violence, and platforms will face stricter cooperation obligations. The planned “Digital Violence Protection Act” will enable the blocking of anonymous hate accounts and create an interface for law‑enforcement authorities. Independent bodies in media supervision will receive clear legal mandates to counter manipulation of information, hate, and incitement on digital platforms. The mass and coordinated use of bots and fake accounts will be prohibited. Finally, Germany will proceed with implementing the NIS 2 Directive, the implementation deadline having already passed.</p><h3><span>Contract Law and Consumer Protection</span></h3><p>Consumer and contract law will also become more digital. So-called "smart contracts" will allow simple compensation and refund cases - such as ticket purchases - to be processed almost automatically via pre-populated online forms where the necessary data is already available. A reform of the law on standard terms and conditions (AGB) is planned to give large companies confidence that their mutually agreed terms will be reliably recognized in practice; this may entail a relaxation of the control of terms in B2B transactions. For telephone-based subscription agreements, a universal confirmation solution will be introduced to avoid burdensome follow-up verifications. The "by design" and "by default" principles will oblige providers to make digital offerings consumer-friendly from the outset.</p><h3><span>Copyright and Media Law in the Digital Age</span></h3><p>According to the coalition agreement, the government aims to strike a fair balance between creators, industry, and users. Notably, it proposes to compensate authors for the use of their works in generative AI systems - suggesting a form of copyright levy. In the digital music market, streaming platforms would be required to transparently share revenues with artists.</p><h3><span>Conclusion</span></h3><p>Many topics are described only in broad strokes, but the coalition agreement between the conservative parties (CDU/CSU) and the SPD does contain some specific initiatives. Whether and to what extent these plans will be implemented remains to be seen. In any case, the declared objectives are to digitize processes, reduce bureaucracy, and make significant investments in the digital space. We will continue to follow developments closely.</p><p>Fabian Eckstein</p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/7/2/csm_LMS_Web_Grau_a72145eb55.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-8446</guid>
                        <pubDate>Mon, 10 Feb 2025 13:11:14 +0100</pubDate>
                        <title>ADVANT Beiten Advises Banyan Software on Acquisition of FoxInsights</title>
                        <link>https://www.advant-beiten.com/en/news/advant-beiten-beraet-banyan-software-bei-uebernahme-von-foxinsights</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>Freiburg, 10 February 2025</strong> - The international law firm ADVANT Beiten has provided comprehensive legal and tax advice to Banyan Software on the acquisition of FoxInsights, market leader in the field of tank remote monitoring. The parties have agreed not to disclose the purchase price. The acquisition further strengthens Banyan Software's market position in the DACH region.</p><p>Banyan Software was founded in 2016 and regularly acquires growing software companies with the aim of developing them over the long term as part of a buy-and-hold strategy. Banyan Software has offices in Canada, the UK and the DACH region.</p><p>FoxInsights, headquartered in Munich, is a spin-off of one of the Top3 Innovation Labs (EnBW Innovation) in Germany. The company offers IoT-based remote tank monitoring solutions. Through digitalisation and data analytics, FoxInsights optimises the sales and ordering process as well as supply chains in the energy, mobility and recycling sectors.</p><p><strong>Advisor Banyan Software:</strong><br>ADVANT Beiten: Christian Burmeister (Lead), Damien Heinrich (both Corporate/M&amp;A), Dr Christian von Wistinghausen, Lelu Li (both Investment Control), Heiko Wunderlich, Fabian Buker (both Tax), Mathias Zimmer-Goertz, Christian Döpke (both IP/IT), Dr Erik Schmid, Alexander Grässel (both Labor &amp; Employment Law).</p><p><strong>Public Relations</strong><br>Frauke Reuther<br>Manager Communications<br>ADVANT Beiten<br>+49 (69) 75 60 95 - 570<br><a href="mailto:frauke.reuther@advant-beiten.com">frauke.reuther@advant-beiten.com</a></p>]]></content:encoded>
                        
                            
                                <category>Labour Law</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Tax Law</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/beiten/Header_Bilder_Scott/Handschuetteln_klein.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-8314</guid>
                        <pubDate>Fri, 03 Jan 2025 16:44:17 +0100</pubDate>
                        <title>Tattoos in video games - and what the German Federal Court of Justice&#039;s “photo wallpaper ruling” might have to do with it</title>
                        <link>https://www.advant-beiten.com/en/news/tattoos-in-videospielen-und-was-das-fototapeten-urteil-des-bgh-damit-zu-tun-haben-koennte</link>
                        <description>The depiction of tattoos of real people, mostly athletes, in video games is a recurring issue in US courts. In Germany, no such cases are known so far. The decision that has already gone down in the history of the Federal Court of Justice as the &quot;photo wallpaper ruling&quot; at least gives an idea of how such a dispute would end in Germany.</description>
                        <content:encoded><![CDATA[<p></p><h3>The Hayden vs. Take-Two Case: When Tattoo Art Goes Digital</h3><p>Jimmy Hayden is a renowned tattoo artist from Cleveland. He counts several NBA stars among his clients, including Shaquille O'Neal, Kyrie Irving and, relevant to this case, LeBron James. His tattoos have been the subject of a long-running legal battle with video game publisher Take-Two Interactive, the company behind the popular "NBA 2K" series of video games.</p><p>Hayden filed a lawsuit in 2017. In his lawsuit, which was revised in 2019, he argued that the detailed reproduction of the tattoos he had engraved in several titles in the "NBA 2K" series infringed on his copyrights.&nbsp;</p><p>The key legal question was: Does a video game company need the tattoo artist's permission to display the tattoos as part of a licensed likeness of the athlete? Take-Two argued that the license to use James' likeness included the right to display his tattoos. The Ohio federal jury agreed with this argument. It ruled that Take-Two's agreement to use James' likeness impliedly granted it the right to display his tattoos.</p><p>But this is not the only case of its kind. Take-Two won a similar lawsuit in a New York federal court in 2020. The case concerned the depiction of tattoos of the late basketball player Kobe Bryant and other NBA players.&nbsp;</p><p>However, another case shows that the law in this area is not yet fully established: In 2022, an Illinois jury ordered Take-Two to pay damages to a tattoo artist whose work was featured on the body of wrestler Randy Orton in the "WWE 2K" game series, even though the damages amounted to only $3,750.</p><p>These differing decisions illustrate that the legal assessment of tattoos in another medium is still evolving, as tattoo artist Hayden is said to have already appealed the most recent decision.</p><h3>What the "photo wallpaper rulings” of the German Federal Court of Justice have to do with it</h3><p>Although there has not yet been a comparable decision in Germany regarding the depiction of tattoos in video games, the recent rulings of the German Federal Court of Justice (BGH, rulings of September 11, 2024 - I ZR 139/23; I ZR 140/23; I ZR 141/23) regarding so-called photo wallpapers could provide an indication of how such a decision would turn out in German courts.</p><p>The BGH had to deal with a number of cases concerning the display of photo wallpapers on the Internet. The cases before the BGH revolved around a company founded by a professional photographer that marketed photo wallpapers featuring his photographs. In three different constellations, these wallpapers were placed on the Internet as images by the respective defendants: A private user showed the wallpaper as a background in Facebook videos, a media agency presented a client project in which the wallpaper could be seen, and a hotel operator advertised with photos of its decorated rooms. In each case, the photographer's company took legal action against the use, seeking damages and reimbursement for the cost of the warning.</p><p>However, the BGH clearly rejected these claims and assumed "clear consent". The core consideration of the court: Anyone who places a copyrighted work such as a photo wallpaper on the market without special restrictions must expect certain usual uses. Today, this includes the fact that the wallpaper can be seen in photos or videos posted on the Internet - not only in a private context, but also in a commercial context.</p><p>It is particularly interesting that the BGH did not limit these considerations to the direct purchaser of the wallpaper. Third parties, such as the media agency in this case, may also rely on implied consent if their use is considered customary. The court emphasized that the author is, of course, free to prohibit certain uses - but he must then also make such restrictions clear, for example through corresponding contractual agreements or clearly visible reservations of rights.</p><p>These considerations should also apply to celebrity tattoos in video games. A tattoo artist also takes his or her work "out into the world" without any particular restrictions - moreover, he or she applies it to the skin of a person who naturally moves around in public and is photographed or filmed doing so. In the case of prominent sports stars such as LeBron James, this media presence is even an essential part of their professional activity. Following the logic of the BGH, a tattoo artist would therefore have to expect that his work would be depicted together with its "wearer" - be it in traditional media, on social networks, or even in video games.</p><p>It is up to the authors of the tattoos to regulate their works in explicit agreements with their "objects", the tattooed persons. The extent to which such regulations would then be effective, particularly with regard to the personal rights of the tattooed person, offers potential for further decisions by the BGH.</p><p>Fabian Eckstein</p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital Compliance</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/8/f/csm_AdobeStock_295160836_9862a8b6b6.jpeg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-8091</guid>
                        <pubDate>Mon, 21 Oct 2024 11:51:27 +0200</pubDate>
                        <title>How the Digital Services Act Can Help Enforce IP Rights</title>
                        <link>https://www.advant-beiten.com/en/news/how-the-digital-services-act-can-help-enforce-ip-rights</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>There has been a lot of discussion about the EU's Digital Services Act (“DSA”) since it came into force. The focus is often on the extensive list of obligations that service providers must meet under the DSA (and, of course, the massive fines for non-compliance). In this article, we want to explore how the DSA can benefit IP owners.</p><h3><span>What is the DSA? Who does it apply to?</span></h3><p>The DSA aims to create a safe and transparent online environment by strengthening consumer protection and the safeguarding of fundamental rights in the digital space. This regulation, which applies to the provision of intermediary services since February 17, 2024, entails extensive due diligence obligations on hosting services and especially online platforms to regulate the handling of illegal content, disinformation and other digital risks.</p><p>Online platforms are, simplified, services that allow the publication of information provided by and stored for the user (the user can also be a business!), if that is not merely a subordinate function.</p><h3><span>The DSA as a toolbox for your IP:</span></h3><p>IP infringements are common on online platforms (think, for example, of online marketplaces) and other hosting services. Movies or music are uploaded to file-sharing sites, where they are freely available to other users them. Online marketplaces list unlicensed and counterfeit goods sold at low prices. A mobile clone of a popular video game is released in an app store, generating revenue from in-app purchases while exploiting the original game's IP. In many cases, uploaders do not use their real names or provide an address. Sometimes they are based in countries where intellectual property rights are difficult to enforce. The DSA is primarily a set of rules for the providers of these services used by uploaders. However, it also offers some help for taking action against infringing content and can facilitate access to information about its uploaders.&nbsp;</p><h3><span>Contact the service provider:</span></h3><p>Under the DSA, hosting services and online platforms must provide an easily accessible and user-friendly notification mechanism that allows individuals or entities to notify them of illegal content on their services. Typically, this mechanism is accessible either in the footer or next to shareable content. Upon the receipt of this notice, it is deemed that service providers have actual knowledge of the existence of the specific content reported. As long as the provider of the service (e.g. the online platform) does not know about infringing content the content, it is generally not liable. This exception has been known for many years as the "host provider privilege" or "safe harbor" for hosting providers. It was established in the EU through the EU by Directive 2000/31/EC, also known as the E-Commerce Directive (and is pretty similar to the “safe harbor” under the DMCA in the United States). If providers are informed about an infringement, they must review and act in a timely, diligent, non-arbitrary, and objective manner. Otherwise, they might be liable for the infringing content themselves. This is nothing new, but it should be easier and there is additional pressure on the service provider. (As far as copyright infringements go, the ECJ and national courts such as the German Federal Supreme Court have established some other criteria when service providers can be liable for infringing content. This regime is not restricted by the DSA.)</p><p>Breaches of the DSA on their part can be reported to the competent Digital Services Coordinators (i.e., the authorities responsible for the DSA), which can lead to investigations and ultimately fines. (We won't mention the fines anywhere else in this blog article, but they're worth keeping in mind).</p><h3><span>Online marketplaces:</span></h3><p>The DSA has even more specific rules for online platforms that allow consumers to enter into distance contracts with traders. We see these as potentially powerful tools to reduce counterfeit and pirated goods and other IP infringements. In the past, traders offering illegal products on online marketplaces often provided fake names and identities – IP owners could send take-down notices to online platforms, but did not get hold of the trader actually offering the goods.</p><p>Under the DSA, providers of online marketplaces now have to ensure what is called the “traceability of the traders” (aka “Know Your Business Customer”). The provider of the online marketplace must obtain the following information:</p><ul><li><span>the name, address, telephone number and email address of the trader;</span></li><li><span>the trade register, registration number or equivalent means, if applicable; and</span></li><li><span>a self-certification by the trader to only offer products or services that comply with the applicable rules of Union law</span></li></ul><p>This information must be easily accessible and comprehensible to any user of the online marketplace.</p><p>Additionally, the provider of the online marketplace must obtain</p><ul><li><span>a copy of the identification document or other electronic identification;</span></li><li><span>the payment account details.</span></li></ul><p>This information must be collected before the trader can offer its products on the online marketplace, and the provider must use best efforts to assess whether the provided information is reliable and complete. For traders who were already active on the online marketplace before the DSA entered into force, the provider must obtain the relevant information until February 17, 2025. If the trader's information is inaccurate, incomplete or out of date, the online marketplace must ask the trader to rectify the situation. Otherwise, the service provider must suspend its service to the trader. These obligations are now starting to show an effect, and the information can be found on many online marketplaces where it wasn't available before. Recently, the online marketplace TEMU&nbsp;<a href="https://www.wettbewerbszentrale.de/dsa-verfahren-temu-verpflichtet-sich-zur-unterlassung/" target="_blank" rel="noreferrer">undertook to comply with the Know Your Business Customer obligations under the DSA</a> after being sued by the Wettbewerbszentrale, a German organization for the enforcement against unfair commercial practices.&nbsp;</p><p>Providers of online marketplaces must also randomly check whether products or services offered have been identified as illegal through official, freely accessible and machine-readable online sources. If products or services are identified as being illegal, the provider of the marketplace must inform all the purchasers of the fact that they were illegal, along with the identity of the trader and any relevant means of redress.&nbsp;</p><p>Consequently, persistence can pay off. Traders who repeatedly offer infringing products mean a lot more work for online marketplaces. There is also an increased risk of personal liability. In addition to costly claims and court orders, reporting slow or inadequate DSA-compliance to the Digital Services Coordinators can be issues that make the online marketplace less attractive to bad actors.</p><h3><span>Very Large Online Platforms:</span></h3><p>Very Large Online Platforms (VLOPs) are online platforms with at least 45 million monthly active users in the EU on average, and are&nbsp;<a href="https://digital-strategy.ec.europa.eu/en/policies/list-designated-vlops-and-vloses" target="_blank" rel="noreferrer">designated</a> by the European Commission. These VLOPs must perform risk assessments on a regular basis to identify systemic risks in the EU stemming from the design or functioning of their service and related systems. The repeated violation of IP rights can be seen as such a systemic risk which must consequently be mitigated in the future. It remains to be seen how IP infringements on VLOPs will be mitigated if they are identified as a systemic risk. At least for VLOPs&nbsp;<a href="https://www.advant-beiten.com/en/news/e-commerce-action-plan-germanys-strategy-to-protect-online-shoppers-in-the-eu" target="_blank">that repeatedly offer products and services in breach of EU law</a>, the mitigation measures could become much stricter than what is already covered by the DSA to deal with such illegal offerings.</p><h3><span>Seek the assistance of a trusted flagger:</span></h3><p>Trusted flaggers are special entities under the DSA that detect specific potentially illegal content and notify the online platforms. Providers of online platforms must prioritize reports from trusted flaggers and process them without delay. Trusted flaggers are designated by the competent Digital Services Coordinator in the state they have their establishment if they meet the respective criteria. They have particular expertise in their field of competence which is taken into account by the service providers who receive the notice. The European Commission has updated&nbsp;<a href="https://digital-strategy.ec.europa.eu/en/policies/trusted-flaggers-under-dsa#:~:text=Trusted%20flaggers%20are%20special%20entities%20under%20the%20DSA.,content%2C%20and%20notifying%20it%20to%20the%20online%20platforms." target="_blank" rel="noreferrer">a list of trusted flaggers</a>. The list will be updated regularly as more will be added in the future.</p><h3><span>Conclusion:</span></h3><p>While the legal grounds for taking action against infringing products on the internet remain unaffected, the DSA is more than just a comprehensive set of difficult obligations to comply with. It is a robust framework designed to make it easier to take action against illegal content by simplifying notifications and putting appropriate pressure on online service providers. If they do not respond diligently and promptly, they may not only lose their liability privilege, but also be subject to enforcement by the authorities. One important aspect will be how rigorous the authorities are in ensuring compliance. Advocating for proper regulatory action is, therefore, crucial. If applied wisely, it can be a powerful tool for protecting intellectual property rights in the European Union.&nbsp;</p><p><a href="https://www.advant-beiten.com/experten/cv-professional/daniel-trunk" target="_blank">Daniel Trunk</a></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/a/0/csm_IP_Header_Scott_3f0bc7d17d.jpeg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-8074</guid>
                        <pubDate>Wed, 16 Oct 2024 09:43:34 +0200</pubDate>
                        <title>ADVANT Beiten Advises Amphenol on Acquisition of Luetze Group</title>
                        <link>https://www.advant-beiten.com/en/news/advant-beiten-beraet-amphenol-bei-uebernahme-der-luetze-gruppe</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>Berlin, 16 October 2024</strong> - The international law firm ADVANT Beiten has advised the NYSE-listed US group Amphenol Corporation on the acquisition of all shares in Luetze Consulting &amp; Services GmbH &amp; Co. KG, the holding company of Luetze International Group. The parties agreed not to disclose the transaction volume.</p><p>Amphenol is one of the world’s largest designers, manufacturers and marketers of connectors and interconnect systems, antennas solutions, sensors and high-speed cable.</p><p>Luetze International Group is active worldwide and consists of various companies in a holding structure. The group of companies has a tradition of over 60 years in automation and is one of the leading companies in the industry today. Luetze Group offers innovative solutions in the areas of highly flexible cables, cable assemblies, interfaces, power supply and monitoring as well as control cabinet wiring.</p><p>Luetze Group's range of services complements Amphenol's portfolio in various segments of the fast-growing electronics market and underlines Amphenol's future-oriented, cross-border positioning.</p><p>In this transaction, ADVANT partner firm ADVANT Altana advised on French law, Fox Williams advised on UK law, Havel &amp; Partners advised on Czech law, Kellerhals Carrard advised on Swiss law and E+H advised on Austrian law.</p><p>ADVANT regularly advises Amphenol on European M&amp;A projects, most recently ADVANT Altana and ADVANT Beiten jointly advised Amphenol on the acquisition of the CMR Group based in France.</p><p><strong>Advisor Amphenol Corporation:</strong> ADVANT Beiten: Dr Christian von Wistinghausen, Tassilo Klesen (both lead partners in charge), Olga Prokopyeva (all Corporate/M&amp;A, Berlin), Susanne Rademacher, Lelu Li, Kelly Tang, Dr Jenna Wang-Metzner (all Corporate/M&amp;A, Beijing), Michael Riedel (Labour &amp; Employment, Berlin), Carsten Pütger, Danah El-Ismail (both Real Estate, Berlin), Mathias Zimmer-Goertz, Christian Döpke (both IP/IT/Media, Dusseldorf), Uwe Wellmann (Antitrust Law, Berlin), Christoph Heinrich (Antitrust Law, Munich), Dr Marion Frotscher and Simon Bauer (both Tax, Hamburg).</p><p><strong>Advisor Sellers of Luetze Group:</strong> Heuking Kühn Lüer Wojtek: Dr. Rainer Herschlein, LL.M., Dr. Emanuel Teichmann (both Corporate/M&amp;A, Stuttgart), Dr. Stefan Bretthauer, Jia-Xi Liu (both Antitrust Law, Hamburg).</p><p><strong>Public Relations</strong><br>Frauke Reuther<br>Manager Kommunikation<br>ADVANT Beiten<br>+49 (69) 75 60 95 - 570<br><a href="mailto:frauke.reuther@advant-beiten.com">frauke.reuther@advant-beiten.com</a></p>]]></content:encoded>
                        
                            
                                <category>Labour Law</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                                <category>Real Estate Law</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Antitrust Law</category>
                            
                                <category>Dispute Resolution</category>
                            
                                <category>Tax Law</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                                <category>Real Estate</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/c/b/csm_IT_Data_Header_Scott_5c09647b5c.jpeg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-7974</guid>
                        <pubDate>Tue, 10 Sep 2024 15:42:16 +0200</pubDate>
                        <title>E-Commerce Action Plan: Germany’s Strategy to protect Online Shoppers in the EU</title>
                        <link>https://www.advant-beiten.com/en/news/e-commerce-action-plan-germanys-strategy-to-protect-online-shoppers-in-the-eu</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>On 6 September, the German Federal Ministry of Economics and Technology (“BMWK”) published an <a href="https://www.bmwk.de/Redaktion/DE/Downloads/A/aktionsplan-e-commerce.html" target="_blank" rel="noreferrer">E-Commerce Action Plan</a> proposing a strategy for effective enforcement of EU law and a level playing field for all businesses. The BMWK points out that EU-standards are often not respected, in particular in relation to products from third countries. This includes infringements of product safety rules, consumer laws, customs and import regulations as well as intellectual property rights.</p><p>The Action Plan sets out a series of measures to address the challenges posed by e-commerce. Here is a closer look at its key elements.</p><h3>Enhanced Market Surveillance and Customs Controls</h3><p>The BMWK proposes to extend the powers of market surveillance authorities so that they can take direct action against online platforms if no responsible economic operator can be identified. Additionally, it proposes a collaborative approach between national and European market surveillance authorities and customs. This would include automated controls, coordinated inspections and test purchases to ensure that imported goods comply with EU safety, environmental and quality standards. Economic operators shall ensure that they can be contacted by the authorities throughout the distribution of their products and appoint a legal representative in the EU.</p><h3>Abolition of the EUR 150 duty-free limit</h3><p>The Action Plan provides for the rapid end of the EUR 150 duty-free limit quickly. At present, only import VAT is payable on purchases from online retailers outside the EU worth less than EUR 150, but not customs duties. This has led to a flood of cheap goods on the European market. It is even suspected that many of these goods are split into several packages to remain below the duty-free limit.</p><h3>Enforcement of the Digital Services Act (DSA)</h3><p>The BMWK calls on the European Commission to strictly enforce the DSA. Illegal offers, such as unsafe products or product piracy, must be removed and must not be available in the European Union. For active enforcement the DSA, the European Commission should work with the national Digital Services Coordinators to collect data on infringements so as to identify systematic violations. In addition, fines should be imposed to deter operators from committing further infringements. The reporting tool of the Federal Network Agency, Germany’s (main) Digital Services Coordinator, should be more strongly promoted.</p><h3>Informing Consumers</h3><p>The BMWK is proposing a “Digital Product Pass” containing all relevant information on the safety of a product, as well as on environmental and health protection. Operators of online trading platforms shall be obliged to review this information for completeness and plausibility.</p><p>In addition, the BMWK and associations shall provide information with the aim of motivating consumers to make sustainable purchasing decisions.</p><h3>Data Protection</h3><p>The Action Plan also addresses data privacy concerns, calling for closer collaboration between national data protection authorities and the creation of an EU-wide data protection body to ensure that personal data collected by online platforms is handled responsibly and in compliance with the General Data Protection Regulation (GDPR).</p><h3>Representative Actions</h3><p>In addition to market surveillance authorities, associations should also be able to enforce the provisions of the EU Market Surveillance Regulation.</p><h3>Continuous Evaluation</h3><p>Finally, the Action Plan includes provisions for regular public reporting by the European Commission to ensure continuous evaluation and, if necessary, adaptation of the strategies.</p><h3>Increasing Pressure on Online Platforms</h3><p>The BMWK takes the view that the level playing field is threatened by non-EU economic operators that do not comply with existing EU legislation. It refers in particular to the range of products offered on Temu and SHEIN, which have recently become very successful in Germany. This increases the pressure on both online platforms which have <a href="https://digital-strategy.ec.europa.eu/en/news/commission-requests-information-online-marketplaces-temu-and-shein-compliance-digital-services-act" target="_blank" rel="noreferrer">also received requests for information under the DSA from the European Commission</a>. It remains to be seen what the results of the Commission's investigations will be and how the DSA will be implemented in practice. What is certain is that market surveillance authorities, consumer watchdogs and competitors will be watching these developments closely.</p><p><a href="https://www.advant-beiten.com/experten/cv-professional/daniel-trunk" target="_blank">Daniel Trunk</a></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/b/f/csm_Digital_Media_Header_Scott_99bf6e4dc6.jpeg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-7972</guid>
                        <pubDate>Mon, 09 Sep 2024 16:40:04 +0200</pubDate>
                        <title>Consent Management Regulation - Goodbye cookie banner?</title>
                        <link>https://www.advant-beiten.com/en/news/einwilligungsverwaltungsverordnung-cookie-banner-ade</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>According to a recent <a href="https://www.bitkom.org/Presse/Presseinformation/Drei-Viertel-von-Cookie-Bannern-genervt" target="_blank" rel="noreferrer">study by Bitkom</a>, 76% of internet users feel annoyed by cookie banners. The German government therefore passed the so-called Consent Management Regulation (EinwV) last week, which is intended to reduce the number of cookie banners and improve the user experience on the internet.</p><p>Section 26 of the German Telecommunications Digital Services Data Protection Act (TDDDG), which was introduced in December 2021 as the "TTDSG", provides the Federal Government with the power to issue regulations to govern so-called consent management services.</p><p>The original idea of such services, which are also discussed under the keyword of "Personal Information Management System (PIMS)", was that the internet user would submit their personal cookie preferences once to the PIMS and the providers of digital services would be able to request these preferences from the PIMS. Users would have the option of agreeing to all cookies, generally accepting or rejecting individual categories of cookies across the board (e.g. statistics cookies or marketing cookies) or rejecting all unnecessary cookies.</p><h3>(In)permissibility of general consents</h3><p>The problem with such blanket consent to the use of cookies, even if it is only given for certain categories of cookies, is that the internet user cannot really give informed consent in this case. Even though providers of digital services often use similar cookies and tools, they are not exactly the same. Each provider uses different cookies in some cases and therefore also transmits information from internet users to different recipients. Internet users would thus never know exactly what processing they are consenting to at the time of giving their consent, let alone to whom their data is being transmitted. For this reason, the German government has also decided against blanket default settings and comments on this in the explanatory memorandum to the regulation:</p><blockquote><p><i>“General default settings for possible consent requests from the provider of digital services, which are made by the end user without reference to the specific use of a digital service, do not meet the requirements for the management of consent.”</i></p></blockquote><p>However, this also means that the desired effect of PIMS, namely, to reduce the number of cookie banners, is lost.&nbsp;</p><h3>Solution through the EinwV?</h3><p>Section 3 (1) of the now adopted Consent Regulation (EinwV) stipulates that the approved consent management service (i.e. the PIMS) stores the end user's cookie settings when they use a digital service for the first time. According to its wording, internet users will still have to see a cookie banner every time they visit a website for the first time.<br>The approved service must also be user-friendly, i.e. transparent and comprehensible, and a request to review the end user's settings may only be made after one year at the earliest (Section 4 EinwV). It must also be possible to switch to another approved consent management service at any time (Section 5 EinwV). Furthermore, in accordance with Section 6, a competition-compliant procedure is required for providers of digital services. Finally, integration into so-called retrieval and display software (usually presumably Internet browsers) should be made possible (Section 7 EinwV).</p><p>As the name "<i><u>approved</u> consent management service</i>" makes clear, the service must be approved. This is done in accordance with the procedure described in Part 3 of the Regulation. The competent body for this is the Federal Commissioner for Data Protection and Freedom of Information (Section 8 EinwV).</p><p>Part 4, the last part of the regulation, defines technical and organizational measures for providers of digital services as well as manufacturers and providers of retrieval and display software. Particular attention should be paid to Section 18 (1) of the Consent Regulation, which declares the integration of approved consent management services by digital service providers to be voluntary. This provision has been criticized by consumer advocates as the requirements of the regulation can easily be circumvented in this way. Moreover, the fact that the use of consent management services is voluntary will probably result in them rarely being used, especially in practice. In light of the study cited at the beginning, the proportion of those who use such a service to generally reject non-optional cookies is likely to be very high. The providers of digital services will also assume this and therefore have no interest in using such services. They will be inclined to continue to use cookie banners to access the data of at least those users who click on "accept all" because they actually want to give their consent, do not really care or simply like to press green buttons.</p><h3>Conclusion</h3><p>There are major doubts as to whether the adopted regulation can really reduce the number of cookie banners on the internet. It can also only regulate consent in accordance with Section 25 (2) TDDDG. In practice, however, consent is often also obtained via cookie banners in accordance with the GDPR (in particular also in accordance with Article 49 para. 1 a) GDPR). Strictly speaking, these cannot then be obtained through the consent management service, which would probably entail that the previous cookie banners would have to remain in place for these consents in any case.</p><p>However, another argument against the regulation is that the use of the consent management service does not appear to have any added value for either users or service providers. Users would still have to make a setting at least for every new website and even several times if the website uses new cookies or other tools, because no blanket default setting for different providers of digital services is to be legally permissible. Service providers, on the other hand, are presumably not interested in participating in consent management, which will probably result in more refusals of optional cookies.</p><p>Ultimately, though, the relevance of the services for consent management will depend on the specific technical design. If this is kept as easy to install and low-threshold as possible, it could perhaps be attractive for some digital service providers. With a well-functioning solution that actually makes things easier for the user, these service providers could then advertise particularly user-friendly cookie handling.</p><p><a href="https://www.advant-beiten.com/experten/cv-professional/fabian-eckstein" target="_blank">Fabian Eckstein</a></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital Compliance</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/b/f/csm_Digital_Media_Header_Scott_99bf6e4dc6.jpeg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-7878</guid>
                        <pubDate>Mon, 05 Aug 2024 13:37:48 +0200</pubDate>
                        <title>ADVANT Beiten Advises Shareholders of Fischer Information Technology on Sale to Quanos</title>
                        <link>https://www.advant-beiten.com/en/news/advant-beiten-beraet-die-gesellschafter-der-fischer-information-technology-bei-veraeusserung-an-quanos</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>Freiburg, 5 August 2024</strong>&nbsp;– The international law firm ADVANT Beiten has advised the shareholders of Fischer Information Technology GmbH on the sale of all shares to Quanos Group GmbH. Fischer Information Technology specialises in software solutions for technical documentation and the digitalisation of product information. Quanos is the world's leading provider of AI-based software solutions for industrial after-sales and technical documentation.</p><p>The transaction was backed by Keensight Capital, one of the leading private equity managers for Europe-wide growth buyout investments. The parties have agreed not to disclose the transaction volume.</p><p>Fischer Information Technology has focused on expertise in the development of reliable software for the efficient management, organisation and distribution of technical documentation and product information since its foundation in 1985. The company has played a key role in shaping the European market for technical documentation software.</p><p>Quanos was formed by software experts for after-sales, service and technical documentation, optimised by AI capabilities. The company offers innovative, successful and reliable technology to more than 1,200 customers worldwide.</p><p>The acquisition of Fischer IT strengthens Quanos' market presence and increases the customer base to 1,400 customers worldwide. This enables Quanos to offer a wide product portfolio that delivers significant added value to the joint customer base. In addition, Fischer IT's proven technical expertise will further enhance Quanos' innovative potential.</p><p><strong>Advisor to Fischer Information Technology GmbH:&nbsp;</strong><br>ADVANT Beiten: Gerhard Manz, Dr Christian Osbahr (both Corporate/M&amp;A, Freiburg), Dr Birgit Münchbach und Dr Holger Weimann (both IP/IT, Munich)</p><p><strong>Advisor to Quanos Group GmbH:</strong><br>Renzenbrink &amp; Partner: Team Dr Ulf Renzenbrink</p><p><strong>Media Contact</strong><br>Frauke Reuther<br>Manager Kommunikation<br>ADVANT Beiten<br>+49 (69) 75 60 95 - 570<br><a href="mailto:frauke.reuther@advant-beiten.com">frauke.reuther@advant-beiten.com</a></p><p><a href="https://www.advant-beiten.com/experten/cv-professional/gerhard-manz.html" target="_blank">Gerhard Manz</a><br>Rechtsanwalt<br>ADVANT Beiten<br>+49 (761) 15 09 84 - 11<br><a href="mailto:gerhard.manz@advant-beiten.com">gerhard.manz@advant-beiten.com</a></p>]]></content:encoded>
                        
                            
                                <category>Corporate/M&amp;A</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/f/6/csm_Corporate_MUA_Header_Scott_229c37dd99.jpeg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-6814</guid>
                        <pubDate>Wed, 26 Jun 2024 19:12:00 +0200</pubDate>
                        <title>ADVANT Beiten Advises Aesculap on Sale of TETEC AG to the Canadian Octane Group</title>
                        <link>https://www.advant-beiten.com/en/news/advant-beiten-beraet-aesculap-bei-veraeusserung-der-tetec-ag-an-kanadische-octane-gruppe</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>Dusseldorf, 26 June 2024</strong> – The international law firm ADVANT Beiten has provided interdisciplinary advice to Aesculap AG, a subsidiary of the B. Braun group seated in Melsungen, Germany, on the sale of its participation in TETEC Tissue Engineering Technologies AG, Reutlingen, Germany, to the Canadian Octane group. The parties have agreed not to disclose the transaction volume.</p><p>TETEC AG, which specialises in regenerative medicine, had been integrated into the international medical technology group B. Braun through the surgical division Aesculap, based in Tuttlingen, Germany. In future, Aesculap will strategically focus even more strongly on innovative medical technology relating to surgical processes in the operating room, which means that the regenerative medicine business segment no longer fits into the medical technology group's portfolio.</p><p>In the United States, B. Braun has partnered with Octane Medical for more than ten years. With the completion of the transaction, the Canadian specialist for regenerative medicine has taken over TETEC completely, including the approximately 160 highly specialised employees at the site in Reutlingen, Germany.</p><p>Octane is a global group of companies headquartered in Ontario, Canada, with subsidiaries in the United States and Europe, specialising in innovative processes, biomaterials and bioreactors for regenerative medicine. Part of the group are Octane Clinical Systems, Octane Orthobiologics, Octane Exo, Octane Biotech and Octane Biotherapeutics (BioTx).</p><p>B. Braun is one of the world's leading medical technology companies. With over 60,000 employees, B. Braun is a reliable partner that develops intelligent solutions and sets pioneering standards to accelerate progress in healthcare.</p><p><strong>Advisors to Aesculap AG:</strong><br>ADVANT Beiten: Dr Sebastian Weller (lead partner), Nico Frielinghaus, Dr Winfried Richardt, Markus Schönherr, Sarah Heinrichs, Simon Litterst (all Corporate/M&amp;A), Christian Schenk, Markus Linnartz (both Tax), Thomas Herten (Real Estate), Christian Döpke (Data Protection Law, all Dusseldorf), Dr Erik Schmid (Labour Law), Christoph Heinrich (Antitrust Law, both Munich), Rainer Süßmann (Banking &amp; Finance, Frankfurt), Dr Christian von Wistinghausen, Lelu Li (both Foreign Trade Law, Berlin).</p><p><strong>Advisor to Octane Medical:</strong><br>Osborne Clarke</p><p><strong>Media Contact</strong><br>Frauke Reuther<br>Manager Kommunikation<br>ADVANT Beiten<br>+49 (69) 75 60 95 - 570<br><a href="mailto:frauke.reuther@advant-beiten.com">frauke.reuther@advant-beiten.com</a></p><p><a href="https://www.advant-beiten.com/en/experts/dr-sebastian-weller" target="_blank">Dr Sebastian Weller</a><br>Rechtsanwalt<br>ADVANT Beiten<br>+49 (211) 51 89 89 - 134<br><a href="mailto:sebastian.weller@advant-beiten.com">sebastian.weller@advant-beiten.com</a></p>]]></content:encoded>
                        
                            
                                <category>Labour Law</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                                <category>Real Estate Law</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Antitrust Law</category>
                            
                                <category>Tax Law</category>
                            
                                <category>Banking &amp; Finance</category>
                            
                                <category>Industrials</category>
                            
                                <category>Real Estate</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-6835</guid>
                        <pubDate>Fri, 31 May 2024 09:01:00 +0200</pubDate>
                        <title>Silent whistleblowers? Effects of the Whistleblower Protection Act on confidentiality agreements</title>
                        <link>https://www.advant-beiten.com/en/news/schweigsame-hinweisgeber-auswirkungen-des-hinweisgeberschutzgesetzes-auf-vertraulichkeitsvereinbarungen</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>In addition to the much-publicised obligations, in particular the establishment of reporting channels, the new Whistleblower Protection Act (HinSchG) primarily contains rights for whistleblowers. They now have an explicit right to report certain violations of the law. In the first instance, they should contact the internal reporting offices (Section 7 (1) HinSchG), but they can also directly contact the external reporting offices that have been set up at certain authorities. In particular, offences punishable by criminal or administrative fines may be reported, although the latter are restricted to those which serve to protect life, limb or health or the rights of employees or their representative bodies. In addition, there is a long catalogue of violations of all kinds of special laws listed in Section 2 of the HinSchG.</p><p>This right to report such violations is protected, inter alia, by Section 39 of the HinSchG, which provides that <i>"Agreements that restrict the rights of whistleblowers or other persons protected by this Act are invalid"</i>.</p><p>Agreements that are likely to prohibit the reporting of violations are typically confidentiality agreements, also known as non-disclosure agreements (NDAs). They are often found in employment contracts, collective bargaining agreements or works agreements. However, they are also frequently included in contracts with other companies or persons who do not have an employment relationship with the person who is to benefit from the confidentiality. However, the HinSchG not only protects the employees of a company, but also those persons who may obtain information about breaches in connection with their professional activity or in the run-up to a professional activity (see Section 1 (1) HinSchG). The scope of protection is therefore very broad, so that initially all confidentiality and non-disclosure agreements are likely to be affected.</p><p>Such agreements typically require that information obtained during or prior to a contractual relationship be used only for its intended purpose, or generally prohibit such information from being disclosed to third parties. It depends, of course, on the precise structure of the agreement. For example, if the wording of the agreement allows reports to be made to internal bodies, the right to report a breach internally will not be affected, but external reports are likely to be affected. The general restriction on disclosure of information, including internally, therefore inevitably restricts the right under the HinSchG to report breaches that occur during the contractual relationship. Nothing remains of the right to report violations if such an agreement generally prohibits the disclosure of internal information to others.</p><p>Section 6(2) HinSchG makes it clear that information which is subject to a contractual obligation of confidentiality may nevertheless be passed on or disclosed to the competent authority under the conditions of the HinSchG. In addition, Section 39 HinSchG allows the entire confidentiality obligation to be annulled.</p><p>Non-disclosure agreements that do not take into account the rights arising from the new HinSchG are ineffective pursuant to Section 39 HinSchG and are therefore null and void (Section 134 BGB). In most cases, there will also be no room for reinterpretation or extend-ed contractual interpretation in order to save the remaining content of the agreement. This is because confidentiality agreements are regularly pre-formulated for a large number of contracts (Section 305 (1) BGB). They are therefore subject to the control of the general terms and conditions, which excludes a reduction of the confidentiality agreements in order to preserve their validity (Section 306 (2) BGB). They cannot therefore simply continue to exist with the proviso that the person obliged to maintain confidentiality may disclose everything permitted by the HinSchG, but must keep everything else confidential. On the contrary, the new HinSchG carries the risk that confidentiality agreements which do not take into account the protection of the person making the disclosure will be null and void. This in turn means that the person who has promised confidentiality under such an agreement is no longer bound by it and can theoretically disclose information freely, unless this is prohibited by other provisions (such as Section 4 of the German Trade Secrets Act or Section 201 of the German Criminal Code).</p><p>There appears to be no impact on contracts concluded before the new law came into force. As the law does not expressly provide for retroactive effect, it cannot be assumed, also for constitutional reasons, that the legislator intended to apply retroactively to older contracts, so that these should not be affected. However, it should be checked whether future confidenti-ality agreements, or the templates or models on which they are based, take sufficient account of the rights arising from the HinSchG, i.e. whether they comply with the require-ments of Section 6 of the HinSchG. At present, we assume that minor amendments will be sufficient to avoid the threat of Section 39 of the HinSchG and the associated ineffectiveness of the confidentiality agreement as a whole.</p><p><a href="https://www.advant-beiten.com/en/experts/fabian-eckstein" target="_blank">Fabian Eckstein</a></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Corporate Criminal Law &amp; Compliance</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-6820</guid>
                        <pubDate>Thu, 02 May 2024 08:23:00 +0200</pubDate>
                        <title>Update AI Act - the ten most important questions for users of AI systems</title>
                        <link>https://www.advant-beiten.com/en/news/update-ai-act-die-zehn-wichtigsten-fragen-fuer-anwender-von-ki-systemen</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>After the political agreement on the AI Act was effectively announced in the media in December 2023, the now provisionally final version was adopted on 13 March 2024. The AI Act was approved by the European Parliament with an overwhelming majority of 523 votes to 46. All that now remains is for the legal and linguistic experts to review it and for the Council to formally adopt the Regulation. This is expected to happen before the end of the current legislature (or by July 2024).</p><p>There is no doubt that manufacturers of AI systems will have to comply with the provisions of the AI Act and will therefore certainly be keeping a close eye on this European Regulation. However, companies that "only" use AI should do the same. In the following, we have compiled the ten practical questions that companies should ask themselves if they are using or planning to use AI.</p><h3>1. Which companies must comply with the provisions of the AI Act?</h3><p>Most of the provisions of the AI Act deal with prohibited and high-risk AI systems and the resulting obligations for providers, as well as for importers and distributors of such AI systems. However, this does not mean that users of an AI system can now sit back and relax. On the contrary: users (referred to as "deployers" in the AI Act) of AI systems are also covered by the AI Act and must comply with extensive obligations.</p><p>The AI Act applies not only to companies based in the EU, but also to providers and deployers based outside the EU, provided that the output generated by the AI systems is used in the EU.</p><h3>2. Excluded areas of application</h3><p>First, the AI Act excludes from ist scope the use of AI by natural persons for purely personal, non-professional purposes from the scope of application. AI systems that are developed and used exclusively in the field of scientific research and development are also excluded from the scope of application.</p><p>The provision that the AI Act does not apply to certain AI with free and open source licenses (open source) may become significant in the future. The AI Act provides for another significant exception for the use of AI systems in the military, defense and national security sectors. In addition, Member States have the option to provide for further exceptions in specific areas. For example, they can provide for further legal and administrative provisions on the use of AI systems by employers to provide further protection for employees.</p><h3>3. Prohibited AI systems</h3><p>AI systems that pose an unacceptable risk are completely prohibited under Art. 5 AI Act. This includes AI systems in the following eight areas:</p><ul><li>Techniques of subliminal influence beyond human consciousness to significantly distorting or harm a person's behaviour</li><li>Targeted exploitation of the vulnerabilities of certain groups of people due to their age or disability</li><li>Social scoring</li><li>The use of profiling systems to assess or predict the risk of an individual committing a criminal offense</li><li>Non-targeted collection (scraping) of facial images from the Internet or from video surveillance systems to create facial recognition databases</li><li>The use of emotion recognition systems in the workplace and in educational institutions</li><li>The use of biometric categorisation systems</li><li>The use of 'real-time' remote biometric identification systems in public spaces for purposes of law enforcement (although this is declared permissible within narrow limits).</li></ul><p></p><h3>4. Which systems are high-risk AI systems?</h3><p>The core of the AI Act are the regulations on so-called high-risk AI systems. In principle, AI systems are considered high-risk AI systems if they pose a significant threat to fundamental rights.</p><p>A high-risk AI system exists if an AI system is used as a safety component for a product that falls under the EU harmonisation legislation listed in Annex I or is itself such a product. This includes, for example, machinery, toys and medical devices.</p><p>An AI system is also considered to be a high-risk AI system if it falls into one of the following areas of Annex III:</p><ul><li>Remote biometric identification systems and AI systems for biometric categorisation and emotion recognition</li><li>Critical infrastructure: This includes AI systems that are intended to be uses as safety components in the management and operation of critical digital infrastructure, road traffic or in the supply of water, gas, heating and electricity.</li><li>Education and vocational training: AI systems are covered if they are used to make decisions on the access of natural persons to educational and vocational training institutions.</li><li>Employment, workers management and access to self-employment: AI systems used for analyzing, filtering and evaluating applicants are covered.</li><li>Certain essential private and essential public services and benefits: This includes, for example, AI systems that are used to evaluate the creditworthiness and credit score of natural persons.</li><li>Law enforcement</li><li>Migration, asylum and border control management</li><li>Administration of justice and democratic processes</li></ul><p>However, the AI Act provides for an important exception: AI systems from the aforementioned Annex III categories can be exempted from classification as high-risk AI systems under certain conditions. The prerequisite is that there is no significant risk of harm to the health, safety or fundamental rights of natural persons. Examples include AI systems that ae intended to perform a narrow prcedural task. The same applies if the AI system is used to improve an activity previously carried out by humans. The assessment of whether such an exemption applies must be carried out by the company itself as part of a risk evaluation and documented accordingly.</p><h3>5. What regulations apply to deployers of high-risk AI systems?</h3><p>Companies that use high-risk AI systems as deployers must fulfill a comprehensive catalog of obligations. These include the following, for example:</p><ul><li>They shall take appropriate technical and organizational measures to ensure that the high-risk AI systems are used in accordance with the instructions for use.</li><li>They transfer human supervision to natural persons.</li><li>They ensure that input data is relevant and sufficiently representative with regard to the purpose of the AI system.</li><li>They monitor the operation of the high-risk AI system on the basis of the instructions for use and, if necessary, inform the suppliers or, in the event of serious incidents, the importer, distributor and the relevant authorities.</li><li>You keep automatically generated logs for at least six months.</li><li>If they are also employers, they must inform the employees concerned and the employee representatives about the use of a high-risk AI system in the workplace.</li><li>They are subject to an obligation to cooperate with the authorities.</li></ul><p>The fundamental rights impact assessment for high-risk AI systems, which was originally required for all deployers, is now only foreseen in the current text of the Regulation for state institutions and private companies performing public services, as well as for those high-risk AI systems where public services, credit assessment or risk-based pricing of life and health insurance are affected, Art. 27 AI Act.</p><p>Under certain conditions, deployers may also become providers of a high-risk AI system themselves and then be subject to the stricter provider obligations, such as the establishment of a risk management system, the implementation of a conformity assessment procedure and registration in an EU database. Such a change of responsibility comes into effect if a high-risk AI system is placed on the market or put into operation under its own name or brand, or if a significant change is made to a high-risk AI system.</p><h3>6. What obligations apply to deployers of AI systems that are not high-risk AI systems?</h3><p>While the comprehensive list of obligations outlined above applies to deployers of high-risk AI systems, deployers of low-risk AI systems are generally only subject to certain transparency obligations, Article 50 AI Act. For example, they must disclose if content such as images, videos or audio content constituting a deep fake has been artificially generated or modified by an AI. The same obligation applies when an AI generates or manipulates text that is published with the purpose of informing the public on matters of public interest.</p><h3>7. What applies to SMEs?</h3><p>The declared aim of the AI Act is to create an innovation-friendly regulatory framework. Accordingly, the legislator has introduced regulatory relief for micro, small and medium-sized enterprises (SMEs) - including start-ups - based in the EU. For example, SMEs can benefit from non-material and financial support. Finally, under certain conditions, SMEs are to be given priority and free access to so-called regulatory sandboxes. Finally, fines can be capped.</p><h3>8. When does the AI Act apply?</h3><p>Exact dates cannot yet be given, as the final text oft he AI Act needs to be published in the Official Journal of the EU before it can enter into force. The ban on AI systems will take effect six months after the Regulation comes into force. The majority of the provisions of the AI Act will apply 24 months after entry into force. However, the obligations stipulated for high-risk AI systems will only apply after 36 months.</p><h3>9. How are violations of the AI Act sanctioned?</h3><p>Non-compliance with the requirements of the AI Act can result in exorbitant fines. These vary depending on the violation and the size of the company. While violations of prohibited AI systems can result in fines of up to EUR 35 million or 7% of global annual turnover, other violations of obligations under the AI Act can result in fines of up to EUR 15 million or 3% of annual global turnover. Fines of up to EUR 7.5 million or 1% of turnover may be imposed for providing of false information.</p><p>Several national and EU-wide authorities are involved in enforcement, resulting in a complex structure of responsibilities and coordination procedures. In Germany, it is not yet clear which authority will ensure compliance with the requirements of the AI Act. The Federal Network Agency and the Federal Office for Information Security are being discussed.</p><h3>10. ToDos for companies</h3><p>First of all, each company should determine and classify the risk class to which the AI systems used belong. The requirements for their proper use are then derived from this categorisation. Especially for future projects, it is important to involve the departments responsible for AI in the company at an early stage to ensure sufficient testing and compliance with the regulations. This is highly recommended, especially in view of the high fines.</p><p><a href="https://www.advant-beiten.com/en/experts/dr-peggy-muller" target="_blank">Dr Peggy Müller</a></p><p>Another article on this topic can be found under this <a href="https://www.advant-beiten.com/en/blogs/iim/kuenstliche-intelligenz-was-wichtiger-ist-als-das-ki-gesetz" target="_blank">link</a>.</p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital Compliance</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-1700</guid>
                        <pubDate>Tue, 09 Apr 2024 18:00:00 +0200</pubDate>
                        <title>Artificial intelligence: what is more important than the AI Act?</title>
                        <link>https://www.advant-beiten.com/en/news/kuenstliche-intelligenz-was-wichtiger-ist-als-das-ki-gesetz</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>The EU recently passed the EU Artificial Intelligence Act (AI Act) with much fanfare.</p><p>The Act is a milestone (see our blog post for more details). It is really relevant for providers and deployers of AI systems, especially those with high risks. However, most of the practical and legal issues associated with the use of AI are not regulated or even addressed in the law. They remain to be negotiated between the parties.</p><h3>1. Internal: Clear rules</h3><p>Wherever employees have access to the Internet, they use to at least experiment with AI, in particular to see what ChatGPT, Copilot, Claude, Dall-E, Midjourney and others can do. It has also become widely known that there can be risks for the company in using them. This has already cost some people their jobs. It is therefore all the more surprising that many companies still do not have internal guidelines on the correct use of artificial intelligence in the workplace. It is essential to regulate the handling of sensitive information and the use of the results of AI work, but ideally also responsibilities, accountability, and documentation requirements. One thing is certain: these systems will be used. A total ban would be impossible to enforce and would also hamper productivity.</p><h3>2. Reliable contracts</h3><p>Many organizations buy AI solutions from third parties or license software that includes AI. This should be governed using contracts that take into account the specific issues associated with the use of AI - not just outdated standard IT terms and conditions that are still silent on the subject of AI. Of course, there is nothing wrong with adapting outdated IT standard terms and conditions to the many new practical and legal requirements.</p><p><strong>Some important challenges:</strong></p><p>No licensee or user should rely on the legal compliance of generative AI systems (such as Chat GPT, etc.). In particular, it is questionable whether the data used for training has been obtained and used legally, especially with regard to data protection, personal rights and third party copyrights. This does not mean that a company should generally refrain from using such systems. But the distribution of risk must be properly regulated.</p><p>Artificial intelligence also sometimes produces undesirable results or exhibits strange behavior. For example, the results of AI generated work can infringe the rights of third parties. Rights clearance can be much more difficult here than with human-generated work, because the AI does not or cannot disclose which authors it has used in the first place (a particular problem: this makes proper disclosure of the use of open source code almost impossible and the use therefore inadmissible). There have also been reports of chatbots used on company websites that have literally fallen flat on their faces - because the chatbot gave customers rights that they would not have had under the contract. Finally, AI also makes mistakes, which can have unexpected consequences: With this in mind, some systems regularly accept a certain level of error tolerance. However, if the settings of an AI system, for example for fraud prevention, are so strict that it only approves a transaction if fraud can be ruled out 100%, it is unlikely to ever approve a transaction. At the same time, however, a more “tolerant” setting means a conscious acceptance of wrong decisions, which can, for example, invalidate the insurance cover that would exist for wrong human decisions. </p><p>In general, the point is that AI is effective but often operates in an opaque way and will sooner or later produce errors. It is therefore necessary to regulate contractually how the lack of transparency is dealt with and who bears the risk if it is not possible to determine where the error was made - and also what level of error probability is still acceptable.</p><p>The usual standards of intent and gross negligence found in most standard contracts are not useful here: both parties know that errors can occur. It is therefore necessary to regulate which errors are attributable to which party. This can be done, for example, in provisions on data quality, service levels and indemnity clauses. Of course, there is no boilerplate solution for every use of AI. However, it is important that the issue is considered and regulated appropriately.</p><p>It is also important to regulate the extent to which the AI can be 'trained' using the licensee's data, and whether other customers can also benefit from what the AI learns in this way. In the worst case, the data used for training could be disclosed to other customers or their end users of the AI, which could constitute a violation of privacy rights, intellectual property rights or trade secrets. If the licensee's dataset includes personal data, it generally must not be used to train the AI for other customers anyway.</p><p>In connection with the AI Act, the European Commission has also presented draft standard contractual clauses for the procurement of AI systems by public authorities (AI SCC). The requirements set out in the AI SCCs are intended to ensure that the contract terms comply with the requirements of the AI Act, with one version of the AI SCCs published for high-risk AI systems and one for non-high-risk AI systems.;</p><p>The AI SCCs cannot be used as the sole contractual basis for the use of AI, as many issues relevant to contract law (e.g. liability, intellectual property) are not addressed or are inadequately addressed. Nevertheless, the AI SCCs can provide useful points of reference for negotiating contractual terms, even between private companies.</p><h3>3. HR software</h3><p>As mentioned above, EU legislation on artificial intelligence will not apply across the board, but will impose specific obligations on providers and deployers of AI systems. However, there is one area of application that deserves special mention: Software in the HR sector is often considered a high-risk system, in particular recruitment tools (for the recruitment and selection of candidates or the placement of targeted job advertisements) and personnel management tools. High risk systems are subject to particularly strict requirements.</p><p><a href="https://www.advant-beiten.com/en/experts/dr-andreas-lober" target="_blank">Dr Andreas Lober</a><br><a href="https://www.advant-beiten.com/en/experts/lennart-kriebel" target="_blank">Lennart Kriebel</a></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital Compliance</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-1692</guid>
                        <pubDate>Thu, 21 Mar 2024 17:00:00 +0100</pubDate>
                        <title>The Cyber Resilience Act: What You Should Know Now</title>
                        <link>https://www.advant-beiten.com/en/news/der-cyber-resilience-act-was-sie-schon-jetzt-wissen-sollten</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>Almost unnoticed in the shadow of the AI Regulation, the so-called Cyber Resilience Act ("CRA") was passed by the European Parliament on March 12, 2024. This comprehensive law introduces extensive security requirements for manufacturers, importers, and distributors of hardware and software products intended for the European Union market. The goal of the CRA is to improve cybersecurity and combat widespread vulnerabilities that can have far-reaching consequences due to, among other things, inconsistent provision of security updates and lack of user understanding. In this way, the law complements the NIS-2 Directive, which focuses primarily on corporate cybersecurity.</p><h3>What does the Cyber Resilience Act cover?</h3><p>The scope of the CRA is very broad, covering all types of hardware and software, from low to high risk. The CRA initially distinguishes between three categories of products:</p><ul><li>"Basic" products with digital elements</li><li>Class I and II important products with digital elements, and</li><li>Critical products with digital elements.</li></ul><p>The requirements for the products vary depending on the category.</p><p>Class I important products include:</p><ul><li>Identity management systems</li><li>Stand-alone and embedded browsers</li><li>Password managers</li><li>Anti-malware</li><li>Network management systems</li><li>Security information and event management systems</li><li>Boot managers</li><li>Public key infrastructures and digital certificates issuance software</li><li>Physical and virtual network interfaces</li><li>Operating systems</li><li>Routers, modems, and switches</li><li>Microprocessors</li><li>Microcontrollers</li><li>Application-specific integrated circuits and field-programmable gate arrays</li><li>Smart home general purpose virtual assistants</li><li>Smart home products with security features</li><li>Internet connected toys</li><li>Wearables for health monitoring</li></ul><p>Class II important products include:</p><ul><li>Hypervisors</li><li>Container runtime systems</li><li>Firewalls</li><li>Intrusion detection and/or prevention systems</li><li>Tamper-resistant microprocessors and microcontrollers</li></ul><p>The annex of critical products currently includes hardware devices with security boxes, smart meter gateways in intelligent metering systems, and smartcards or similar devices. Both lists are to be expanded and specified by the EU Commission through delegated acts in the future.</p><h3><strong>Essential Cybersecurity Requirements:</strong></h3><p>In order to make a product with digital elements available in the EU, it must meet some essential requirements. First, the manufacturer must assess and document the cybersecurity risks of the product, taking into account the results during planning, production, and the expected lifetime of the product. Based on this assessment, the products must, in particular</p><ul><li>be free of known exploitable vulnerabilities,</li><li>have secure configurations enabled by default, and</li><li>enable free security updates automatically.</li></ul><p>They must</p><ul><li>protect against unauthorized access,</li><li>maintain the confidentiality and integrity of data,</li><li>minimize data processing, and</li><li>ensure core functionality even after disruptions.</li></ul><p>Product design must minimize attacks, limit impact, and provide transparent security information. This includes an obligation to identify and document exploitable vulnerabilities, regularly review product security, and take precautionary measures, including a coordinated vulnerability disclosure policy. The support period for products with digital elements, during which security updates must be provided and technical documentation must be produced, shall generally be at least five years. The end of the support period shall be clearly and conspicuously disclosed at the time of purchase.</p><p>Importers and distributors of products are also required to ensure that the products comply with the requirements of the Regulation.</p><h3>Conformity Assessment and CE Marking:</h3><p>For products with digital components, an EU declaration of conformity from the manufacturer is required, ensuring compliance with the requirements set out in the CRA or further regulations. The corresponding CE Marking must be visibly, legibly, and permanently affixed to the product. For software products, the software must be indicated either on the conformity declaration or on the accompanying website.</p><p>The intended conformity assessment procedure can be conducted by the manufacturer on their own responsibility for products not classified as important or critical. The involvement of an independent notified body is voluntary for important products of Class I but mandatory for Class II.</p><h3>Point of Contact:</h3><p>Manufacturers shall designate a single point of contact where users can report vulnerabilities and obtain information. The single point of contact should not only be automated but also enable contact with a human employee.</p><h3>Reporting Obligations:</h3><p>Manufacturers must report security breaches by malicious actors and cybersecurity incidents that pose an increased risk to users or other individuals. The European Union Agency for Cybersecurity (ENISA) will set up a uniform reporting platform for these reports, which must generally be made immediately but can be delayed for a necessary period for security reasons in individual cases. Addressed vulnerabilities will be recorded in a European vulnerability database in agreement with the manufacturer.</p><h3>Monitoring and Enforcement:</h3><p>Monitoring and enforcement are primarily carried out by market surveillance authorities, which must now be designated in each Member State. These can also demand access to internal data from manufacturers to assess product conformity.</p><p>In case of violations, as with other EU legislation, depending on the nature and severity, substantial fines can be imposed. In the case of the Cyber Resilience Act, they can amount to up to 15 million euros or 2,5% of the company's total worldwide annual turnover in the preceding financial year. The specific rules are left to the EU Member States.</p><h3>Timeline</h3><p>The CRA must now be formally adopted by the Council of the European Union. This is expected to take place in April 2024. In line with other EU legislation, the CRA will then enter into force on the twentieth day following its publication in the Official Journal of the European Union. The Regulation will be fully applicable 36 months after its entry into force, although some aspects, including the obligation to report security incidents, will apply earlier.</p><p>Products with digital elements placed on the market before the full entry into force of the Regulation will not be subject to the requirements, provided they are not significantly modified after that date. However, this does not apply to the obligation to report security incidents</p><h3>Assessment</h3><p>The Cyber Resilience Act obliges economic operators to exercise particular care in the context of cybersecurity. On the one hand, this leads to considerable additional efforts, but on the other hand, it provides a certain degree of legal certainty, as the CRA applies throughout the European Union. Thus, products that comply with the requirements of the Regulation can, in principle, be marketed in any other EU Member State without stricter cybersecurity requirements hindering economic activity. Although the requirements of the Cyber Resilience Act will not be fully applicable for approximately 36 months, they need to be considered early for products with long development cycles and long-term contracts.</p><p><span lang="EN-US"><span><span>From a legal perspective, in addition to compliance with mandatory disclosures, new aspects will play a critical role in the negotiation of IT contracts. For example, manufacturers who obtain components for their products from third parties should require assurances that these components are compliant with the CRA.</span></span></span></p><p><strong><a href="https://www.advant-beiten.com/en/experts/daniel-trunk" target="_blank">Daniel Trunk</a></strong></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital Compliance</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-1685</guid>
                        <pubDate>Sun, 17 Mar 2024 17:00:00 +0100</pubDate>
                        <title>Cloud, SaaS and edge business models under fire</title>
                        <link>https://www.advant-beiten.com/en/news/cloud-saas-und-edge-geschaeftsmodelle-unter-feuer</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>The EU Data Act came into force on January 11, 2024. Up to now, connected products have been the main focus of public interest.</p><p>However, providers of cloud, SaaS, edge and similar services are also affected. The Data Act dedicates a separate chapter to them. This Chapter VI contains regulations for so-called data processing services and primarily aims to make it easier to switch between different services, i.e. to remove existing barriers to switching.</p><p>In particular, if providers work with long term-contracts or the export of customer data is complex, the business model must be reviewed- ideally immediately.</p><p>The main reasons for this are as follows:</p><p><strong>Long contract terms are obsolete.</strong> The customer can initiate a switch to another provider at any time with a notice period of two months. As a rule, the switch should be successfully completed after a further 30 days. After a successful switch, the previous contract is general-ly deemed to be terminated. The previous practice of refinancing providers' initial investments via certain minimum contract terms will therefore no longer work without further ado. Set-up fees, which have become less important in recent years as a result of SaaS services becoming more popular, could be considered as an alternative, as could payments in the event of premature contract termination (e.g., termination fees).</p><p><strong>Exit support can be very costly, but must generally be provided free of charge in the future.</strong> Since January 11, 2024, only reduced switching fees may be charged; from January 12, 2027, switching must be free of charge. At the same time, however, the Data Act provides for comprehensive support obligations that the source provider cannot evade.</p><p><strong>The provider is – to a certain extent – responsible for interoperability with the new provider's system.</strong></p><p>These issues should be addressed immediately, as they will force many providers to adapt their business model. As soon as the Data Act will fully come into force on September 12, 2025, a whole range of other obligations will be added, in particular</p><ul><li>Adaptation of contracts (the Data Act specifies mandatory contract clauses)</li><li>Abolition of technical and organizational barriers to change</li><li>Extensive information obligations</li></ul><p>In addition to civil litigation with customers, breaches of the Data Act can also result in sanctions being imposed by the regulatory authorities; the maximum amount of fines has not yet been determined. Particularly juicy: The provisions on data processing services are likely classified as market conduct rules and thus subject to competition law. Breaches could be subject to warnings from competitors.</p><p>Providers of data processing services must also implement safeguards against unauthorized access from public bodies in third countries.</p><p>Our <a href="https://www.advant-beiten.com/en/blogs/iim/eu-data-act-relevance-companies-iot-and-beyond" target="_blank">blog post</a> provides an overview of the provisions of the Data Act, including those relating to networked products.</p><p><a href="https://www.advant-beiten.com/en/experts/dr-andreas-lober" target="_blank">Dr Andreas Lober</a><br><a href="https://www.advant-beiten.com/en/experts/lennart-kriebel" target="_blank">Lennart Kriebel</a></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital Compliance</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-1639</guid>
                        <pubDate>Wed, 20 Dec 2023 17:00:00 +0100</pubDate>
                        <title>The AI Act - The Agreement and What It Means</title>
                        <link>https://www.advant-beiten.com/en/news/der-ai-act-die-einigung-und-was-sie-bedeutet</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><span><span><span>As Ursula von der Leyen, President of the European Commission, put it: This is a historic moment. On 8 December 2023, after a three-day-marathon of negotiating, the European regulation efforts were awarded with a preliminary political agreement on the first comprehensive European act on artificial intelligence: the AI Act. It is not, as from time to time even the EU itself claims, the first regulation on AI worldwide. With an executive order in the United States and an Act on Automated Decision-Making in China, corresponding regulations already exist in other parts of the world. </span></span></span></p><p><span lang="EN-GB"><span><span>The AI Act aims to ensure that only AI systems which are both safe and respect the fundamental rights and values of the EU are brought onto the European market and are used in the EU. Still, even though an agreement has been reached, the outcome of the negotiations was announced although there is not yet a consolidated text to present. The political agreement will be put into a final text over the coming months. To this end, a number of technical negotiation meetings have been scheduled until the end of February. As some of the information currently available varies widely , we will have to wait until the final text will be published in the first quarter of 2024. The overview below presents the most significant known regulations.</span></span></span></p><h3><span><span><span>Definition of an AI System</span></span></span></h3><p><span><span><span>The new AI Act will include an amended definition of AI systems compared to the European Parliament's last proposals, which is close to the OECD's definition. The OECD's definition is as follows:</span></span></span></p><p><span><span><span>“<em>An AI system is a machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. Different AI systems vary in their levels of autonomy and adaptiveness after deployment</em>.” </span></span></span></p><p><span lang="EN-GB"><span><span>This definition is particularly criticised because it is extremely broad and therefore even includes simple auto-correction or Excel functions, for example. In this respect, the final wording of the Act including its recitals which, as we know, may often be used to fine-tune certain terms must be awaited.</span></span></span><span><span><span> </span></span></span></p><h3><span><span><span>Risk-based Approach</span></span></span></h3><p><span><span><span>The Regulation, which is based on a proposal by the EU Commission in April 2021 and is part of the EU's digital strategy, follows a risk-based approach. It categorises AI systems into different groups depending on the risk they pose: from minimal risk to high-risk and even banned AI systems. </span></span></span></p><p><span lang="EN-GB"><span><span>According to this approach, six principles apply to all AI systems. AI systems should (1) enable human agency and oversight, (2) be technically robust and safe, (3) comply with privacy and data protection regulations, (4) be transparent, (5) ensure diversity, non-discrimination and fairness and (6) ensure social and environmental well-being.</span></span></span><span><span><span> </span></span></span></p><h3><span><span><span>Banned AI Systems</span></span></span></h3><p><span><span><span>AI systems involving an unacceptable risk will be banned in the EU. These include, for example, systems using manipulative techniques, systems that exploit weaknesses or vulnerabilities, social scoring and databases based on mass facial recognition. </span></span></span></p><p><span><span><span>Until the very end there was an intense debate as to whether AI for facial recognition should be permitted or not. While individual countries, such as France, supported the use of AI for facial recognition, arguing that it could be used to ensure security around major events such as the 2024 Olympic Games, most remained sceptic. Despite a tough battle over several days of negotiations, a complete ban on real-time biometric identification could not be achieved against the massive resistance of the member states. After lengthy discussions, the bans involving the recognition of emotions and remote biometric identification were adjusted. </span></span></span></p><p><span><span><span>The ban on AI systems for emotion recognition now only applies in the workplace and in education. It will however still be permissible to use such systems for medical or safety reasons, for example to monitor pilot fatigue. </span></span></span></p><p><span lang="EN-GB"><span><span>The regulations on remote biometric identification have also been amended. Both 'real time' and 'post' identification will remain banned. Exceptions are expected for the prosecution of criminal offences in clearly defined cases. The AI Act also includes a catalogue of protective measures to prevent potential misuse.</span></span></span></p><h3><span><span><span>High-risk Systems</span></span></span></h3><p><span><span><span>A large part of AI systems will be categorised as high-risk AI systems. These are, for example, AI based medical devices or autonomous vehicles. In general, education, critical infrastructure, migration, asylum, or border controls are considered critical high-risk areas. </span></span></span></p><p><span><span><span>High-risk AI systems will have to comply with a number of requirements and obligations to be approved in the EU. For example, conformity assessments must be carried out and a quality and risk-mitigation system must be integrated. High-risk AI systems will also have to be registered in the corresponding EU database. The requirement to carry out an impact assessment for fundamental rights remains unchanged, although this will now only apply to public organisations and private bodies that provide essential public services, such as hospitals or banks. Further changes have been made to the responsibilities and the roles of the various players.</span></span></span></p><p><span lang="EN-GB"><span><span>Further, a filter system has been introduced. An AI system can lose its classification as a high-risk system if it fulfils one of a total of four conditions, for example if it (1) is intended to monitor or improve a human activity or (2) is only used to recognise decision-making patterns or deviations from previous decision-making patterns, (3) is only used to carry out preparatory tasks for a human activity relevant for critical applications or (4) is only intended to carry out procedural tasks.</span></span></span><span><span><span> </span></span></span></p><h3><span><span><span>AI Systems with Limited Risk</span></span></span></h3><p><span lang="EN-GB"><span><span>Specific transparency obligations will apply to AI systems with limited risk. These will, above all, include the information that a certain content has been generated by AI. The aim is to ensure that users can make informed decisions about further use.</span></span></span></p><h3><span><span><span>Generative AI</span></span></span></h3><p><span><span><span>Also in the field of generative AI there will be some changes, unsurprisingly, as these provisions were the most controversial. While the European Parliament ‑ not least in view of ChatGPT - supported a regulation of generative AI systems, the Commission had recently been of the opinion that these AI systems did not require a regulation. It was instead sufficient if manufacturers submit to voluntary commitments. </span></span></span></p><p><span><span><span>These AI systems are now called 'general purpose AI' instead of 'foundation models'. The definition of general purpose AI was amended so that it now only includes large generative AI systems.</span></span></span></p><p><span><span><span><em>“‘General purpose AI model’ means an AI model, including when trained with a large amount of data using self-supervision at scale, that is capable to competently perform a wide range of distinct tasks regardless of the way the model is released on the market.”</em></span></span></span></p><p><span><span><span>Developers of general purpose AI models will have to comply with certain minimum requirements, such as creating technical documentation, providing information for downstream providers and providing information about training and testing procedures. They must also comply with copyright regulations and the products generated must be labelled with a watermark. </span></span></span></p><p><span><span><span>Large AI systems posing systemic risks, so-called 'systemic risk AI' or top tier models that exceed a certain computing power (1025 FLOPs) during training, must fulfil additional obligations. These include, for example, setting up a risk-mitigation system and maintaining an appropriate level of cyber security. Details of this have not yet been finalised. Still, it is assumed that OpenAI's GPT4 and Google's Gemini will be considered to be systems with systemic risk. Models of the European developers Aleph Alpha and Mistral on the other hand will most likely not be categorised as AI models with systemic risk based on their computing power. <span><span><span><span><span>Honi soit qui mal y pense.</span></span></span></span></span> </span></span></span></p><p><span lang="EN-GB"><span><span>Linking transparency requirements to computing power is heavily criticised, as the capability alone says little about the risks of an AI system. In order to be able to make adjustments as technology develops, the Commission will be able to adjust the current threshold and also define additional criteria.</span></span></span><span><span><span> </span></span></span></p><h3><span><span><span>Open Source Models</span></span></span></h3><p><span lang="EN-GB"><span><span>The previous proposal also excluded models based on open source licences from the AI Act. According to the recent agreement, only those open source generative purpose AI systems that are categorised as systemic risk AI systems are to fall within the scope of the AI Act. They are also not exempt from the requirements for high-risk AI systems. This is to be welcomed, as the mere fact that an AI model is based on open source licences or not says little about the risk it poses.</span></span></span></p><h3><span><span><span>Copyright Requirements</span></span></span></h3><p><span lang="EN-GB"><span><span>According to the regulation, AI developers will have to disseminate a copyright policy and a detailed summary of the content they have used to train their generative purpose AI models. This transparency requirement is intended to let authors determine whether their work has been used. It has not been specified yet what exactly 'detailed' means. If the information provided so far is to be believed, the text and data mining limitation for generative AI is explicitly recognised. This had been controversial. The background: Interference with copyright exploitation rights is only permitted if the rights are exempted by limitation provisions. The limitations for text and data mining, i.e. the automated analytical technique of works to obtain information about patterns, trends and correlations, are relevant for the multiplication which happens in the training of AI. According to the text and data mining limitation, the reservations of rights holders in particular must be observed.</span></span></span></p><h3><span><span><span>Penalties</span></span></span></h3><p><span lang="EN-GB"><span><span>The penalties under the AI Act have been amended again, but remain differentiated in proportion to the seriousness of the irregularity. For example, a breach of the ban on certain systems and non-compliance with data requirements may be penalised with up to 7% of the company's global annual turnover or EUR 35 million.</span></span></span></p><h3><span><span><span>Enforcement and Authorities</span></span></span></h3><p><span lang="EN-GB"><span><span>An AI Office is (already) being set up in the European Commission to enforce the regulation of generative purpose AI systems. All other AI systems will be monitored by the competent national authorities. In order to ensure the uniform application of legislation, they will meet regularly in a European Committee on Artificial Intelligence.</span></span></span></p><h3><span><span><span>Right to Lodge a Complaint</span></span></span></h3><p><span lang="EN-GB"><span><span>Another new addition is the possibility for natural and legal persons to lodge a complaint with the competent national authority about non-compliance with the requirements of the AI Act.</span></span></span></p><h3><span><span><span>Entry into Force of the AI Act</span></span></span></h3><p><span><span><span>In principle, the majority of the AI Act's catalogue of obligations will apply 24 months after its entry into force. However, the current draft of the AI Act provides for certain obligations to apply earlier. For example, the ban on certain systems will take effect just six months after the Act comes into force, which means it is expected to apply as early as over the course of 2024. The requirements for generative purpose AI systems will apply just 12 months after the AI Act comes into force. </span></span></span></p><p><span lang="EN-GB"><span><span>It is therefore highly advisable to review the provisions of the AI Act at an early stage, not least in view of the fact that the conversion of any systems may well take some time.</span></span></span><span><span><span> </span></span></span></p><h3><span><span><span>Next Steps </span></span></span></h3><p><span lang="EN-GB"><span><span>As mentioned at the beginning of this post, the AI Act is not yet final - and it may still be a while. Although the recently announced political agreement on the key points has been reached, the technical aspects of the legal text still have to be negotiated in detail over the next few weeks. It may take a while for the bits and pieces to be divided and negotiated, with a lot of the details being figured out later. Finally, the EU bodies must then approve the final text of the regulation. As it is a regulation, it applies directly in all Member States and does not need to be transposed into national law.</span></span></span></p><h3><span><span><span>Conclusion</span></span></span></h3><p><span lang="EN-GB"><span><span>With the AI Act, the EU intends to keep what it calls an 'extremely delicate balance' between boosting innovation and uptake of AI in Europe on the one hand and respecting the fundamental rights of EU citizens on the other. However, the final document which contains more than 250 pages comes across as a bureaucratic nightmare, imposing high documentation requirements on many companies. Due to the vagueness of many regulations, there will be a range of grey areas that could lead to uncertainties and, in the worst case, to considerations as to whether the use of AI should initially be avoided against this background until a uniform application practice of the competent authorities emerges. Nonetheless, the EU's attempt to address this major contemporary issue and to take account of dynamic developments by continuously adapting the provisions, as explicitly envisaged, is to be welcomed in principle.</span></span></span></p><p><a href="https://www.advant-beiten.com/en/experts/dr-peggy-muller" target="_blank"><span><span><span>Dr Peggy Müller</span></span></span></a></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital Compliance</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-1564</guid>
                        <pubDate>Thu, 09 Nov 2023 17:00:00 +0100</pubDate>
                        <title>EU Data Act: Action required for Connected Products, Related Services and Cloud Computing </title>
                        <link>https://www.advant-beiten.com/en/news/eu-data-act-relevance-companies-iot-and-beyond</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><em>You would like to hear from us personally about the <strong>new obligations under the Data Act</strong>? Then register for our webinar: <a href="https://events.teams.microsoft.com/event/5a3a01a1-3fea-4a19-9f4e-d80e7f5f8f5f@fefb03b4-cfed-4293-bd9c-32a29868fe16" target="_blank" rel="noreferrer">Registration</a></em></p><p>On 27 November 2023, the EU Council adopted the Data Act, which was the final requirement after the the text had been adopted by the European Parliament on 9 November 2023. Following the formal adoption by the Council, the new regulation will be published in the EU’s official journal in the coming weeks and will enter into force 20 days after this publication.</p><p>The Data Act - an EU regulation and as such directly applicable in all EU member states - provides for harmonized rules for "fair access to and use of data". Unlike the GDPR it is not limited to personal data. The aim is to make this data commercially usable.</p><p>It is clear already that the Act will go well beyond regulating the „Internet of Things“ (IoT). It relates in particular to "connected products" and cloud services.</p><p>Below we provide an initial overview.</p><p><strong>Data Sharing:</strong> Far-reaching obligations are imposed on data holders, in particular provision and access obligations in relation to user data.</p><p>Data from connected products or related services may have to be shared with the user or a third party (data recipient). This is intended to strengthen the rights of users in relation to the data holder. It is also intended to encourage new players to invest in the data economy.</p><p>Connected products and related services must be designed in accordance with the requirements of the Data Act ("access by design"). Moreover, the Act requires data holders to make data from connected products or related services accessible free of charge and, where applicable, continuously in realtime.<br>To date, many connected products and related services have not been designed with this in mind, which is why the Data Act and its obligations must be considered from the very beginning of product development in future.</p><p>Vice versa, data holders are no longer allowed to freely share non-personal data with other players - for advertising purposes, for instance. In this respect, the right to share data is generally restricted to the extent necessary to fulfil the user contract. Any further sharing of non-personal data may in future require a data licence agreement. This is also likely to affect existing data records.</p><p>With a few exceptions , small and certain medium-sized enterprises are exempt from the obligation to share data (less than 50 employees or EUR 10 million annual turnover).</p><p><strong>UNFAIR CONTRACTUAL CLAUSES:</strong> The provisions on unfair contractual terms (Chapter IV) are meant to prevent the abuse of contractual imbalances. The law introduces a ban on unilaterally imposed unfair terms in B2B contracts and is based on the law on general terms and conditions. In addition to a general clause, the Data Act also contains (non-exhaustive) examples of unfair terms. These include, for instance, provisions that limit liability for the quality of the data provided. Furthermore, exclusive rights of use to data that are imposed unilaterally can be problematic. To support this, the European Commission is to publish model contract clauses that companies can use use for orientation.</p><p><strong>DATA FOR THE PUBLIC SECTOR:</strong> In emergencies, such as natural catastrophes, public sector bodies must be provided with data that is required to deal with the emergency.</p><p><strong>REGULATING DATA PROCESSING SERVICES, ESPECIALLY CLOUD SERVICES:</strong> The Data Act is intended to facilitate switching between similar "data processing services" (Chapter VI). The generic term "data processing services" includes, inter alia, Software as a Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS). These provisions are intended to break up the EU cloud market and facilitate the portability of data between cloud providers. The regulations are very detailed and primarily cover technical and organisational measures, but also contractual details. For instance, a maximum limit for cancellation periods is provided for. Furthermore, interfaces must be created for data transfer when exporting data between different cloud service providers. In addition to these very detailed requirements in individual cases, however, there is also a seemingly endless ban on obstacles to switching ("In particular, providers of data processing services may not impose any pre-commercial, commercial, technical, contractual or organizational obstacles and must remove such obstacles"). Exceptions apply to "custom-built“ data processing services.</p><p><strong>INTERNATIONAL DATA TRANSFER AND INTEROPERABILITY:</strong> International data transfer is also specifically regulated to prevent unlawful access to non-personal data by foreign state authorities (Chapter VII). However, the requirements are not identical to the provisions of the GDPR on data transfers to third countries. Additionally, regulations on interoperability are provided for (Chapter VIII).</p><h3>Late Changes to Definitions</h3><p>The law-making process for the Act started in early 2022. There were still significant changes in the legislative process, even in provisions such as the definitions of "connected product" and "related services". These are, however, fundamental to the area of application of the Act, specifically for determining who is considered a "data holder" and is thus affected by numerous obligations. The European Commission’s initial draft still excluded devices such as PCs, Smartphones, and game consoles. In the text which has been adopted now, they are no longer excluded.<br>The definition of the term "connected product" now reads as follows:<br>‘connected product’ means an item that obtains, generates or collects data concerning its use or environment and that is able to communicate product data via an electronic communications service, physical connection or on-device access, and whose primary function is not the storing, processing or transmission of data on behalf of any party other than the user;</p><p>‘related service’ means a digital service, other than an electronic communications service, including software, which is connected with the product at the time of the purchase, rent or lease in such a way that its absence would prevent the connected product from performing one or more of its functions, or which is subsequently connected to the product by the manufacturer or a third party to add to, update or adapt the functions of the connected product;</p><h3>Trade Secrets still little protected</h3><p>The obligation to share data may even extend to trade secrets, although there have also been some changes in the course of the legislative process. It is striking to see that the protection of trade secrets appears to be weaker than under the GDPR. In principle, the protection of trade secrets comprises a multi-level mechanism: the relevant data must first be identified as a trade secret by the data holder or trade secret holder. The parties involved in the data transfer must then agree on contractual, technical and organizational measures to ensure the confidentiality of the trade secrets to be transferred. Model contractual terms will also be available for this purpose in future. Once protective measures have been agreed, trade secrets must also be disclosed. It remains unclear how a data holder should enforce these protective measures in practice vis-à-vis the recipients of the data, i.e. typically their own users or authorized third parties. Basically, the disclosure of trade secrets can only be suspended if no agreement can be reached on the protective measures to be taken or if these are insufficiently implemented by the recipient of the data. However, the latter will often be accompanied by the compromising of trade secrets. Any decision to suspend the transfer of data must be justified by the data holder and reported to the competent authority.</p><p>The data holder may also refuse to disclose trade secrets ex ante in individual cases under exceptional circumstances if he can prove that the disclosure of the trade secret is very likely to cause him serious harm - in this case, too, the data holder must inform not only the user of the refusal, but also the competent national authority. The threshold for the right to refuse ("highly likely to suffer serious economic damage") has been somewhat weakened as of late, but is still very high. This is regrettable from the perspective of the data holder or trade secret holder, as this ex ante right could in many cases be the most effective way of preventing the disclosure of trade secrets from the outset.</p><h3>What about the GDPR?</h3><p>Unlike the GDPR, the Data Act applies to both non-personal data and personal data. The GDPR primarily serves to protect natural persons and creates a legal basis for the processing of personal data. The Data Act, in contrast, primarily aims to realize the free movement of data. The Data Act does not affect the GDPR, i.e. in cases where a connected product or a related service is used and personal data is also generated, both laws apply in parallel.<br>In particular, the Data Act is not intended to reduce the protection offered by the GDPR for personal data and therefore cannot serve as a legal basis for data processing under the GDPR. In practice, this will probably cause more difficulties than it seems at first glance, especially if a connected product or a related service collects personal and non-personal data - in this case, the latter may have to be passed on, but the former may not (as far as persons other than the user are concerned) or not easily: In any case, the question then arises as to whether a legal basis within the meaning of the GDPR would allow a transfer. This may create difficult situations for data holders in the future. They must now decide more conclusively than before which data is actually personal data: Disclosure may not be mandatory for this data, but it is for data without a personal reference. This is not made any easier by the fact that data from connected products will often have a "relative" personal reference - and the question of relative personal reference is currently before the ECJ.<br>There may also be discussions on the question of whether owners of trade secrets can rely on the fact that the GDPR appears to weigh their interests more heavily than the Data Act.</p><h3>Timeline</h3><p>Following the adoption by the Council and the publication in the official journal, the Data Act will be directly applicable in all EU member states after a transitional period of 20 months, without the need for member state implementation of the regulations. The so-called "access by design" obligation, i.e. the requirement to design (new) connected products and related services, only applies after a further 12 months. Apart from this "access by design" obligation, however, the Data Act not only affects new connected products and related services, but also - at least in principle - those already on the market. This means that owners of existing data records or existing data silos could potentially also be subject to the new rules, in particular the data provision obligations and the restrictions on data use (such as the requirement of a data licence agreement). For such potential data holders in particular, the period of 20 months could be quite short to adequately prepare for the obligations of the Data Act.</p><p><a href="https://www.advant-beiten.com/en/experts/dr-andreas-lober" target="_blank">Dr Andreas Lober</a><br><a href="https://www.advant-beiten.com/en/experts/lennart-kriebel" target="_blank">Lennart Kriebel</a></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital Compliance</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-1568</guid>
                        <pubDate>Tue, 11 Jul 2023 18:00:00 +0200</pubDate>
                        <title>Free rein for data transfers to the U.S.?</title>
                        <link>https://www.advant-beiten.com/en/news/freie-bahn-fuer-datenuebertragungen-die-usa</link>
                        <description></description>
                        <content:encoded><![CDATA[<p></p><h3>The ECJ ruling of July 16, 2020 and its impact</h3><p>The European Court of Justice (ECJ) had ruled in the so-called "Schrems II" judgment in July 2020 that the so-called EU-US Privacy Shield, which until then had served in practice as the most important mechanism for data transfers to the U.S., was ineffective (we reported in our <a href="https://www.advant-beiten.com/sites/default/files/downloads/Privacy%20Ticker%20July%202020_BEITEN%20BURKHARDT.pdf" target="_blank">Privacy Ticker July 2020</a>). Since then, there has been major uncertainty as to whether and under what conditions data transfers to the U.S. were still legally possible. The ruling thus had significant implications for transatlantic data exchange. This applied above all, but not only, to the use of popular online services such as Google and Facebook. The ECJ had argued that data privacy standards in the U.S. were inadequate, in particular due to the excessive powers of the U.S. intelligence services, and that European citizens were not adequately protected against government surveillance and misuse of data. The ECJ also criticized the lack of effective legal protection for EU citizens in the U.S. with regard to their data protection rights.</p><p>Alternative safeguards for data transfers, such as the conclusion of standard contractual clauses ("SCCs") or even obtaining consent for data transfers to third countries, especially the U.S., remained highly controversial and always carried a certain risk of not being able to hold up under judicial review or of incurring a substantial fine from a data protection authority.</p><h3>The EU-US Data Privacy Framework as a solution</h3><p>After the EU Commission and the U.S. government announced in March 2022 that they had agreed in principle on a legal framework for transatlantic data transfers, the EU Commission has finally issued the long-awaited adequacy decision for the EU-US Data Privacy Framework ("Data Privacy Framework"). In doing so, it is responding to the ECJ's objections in the "Schrems II" ruling and once again certifies that the U.S. has an adequate level of data protection within the meaning of the GDPR, but this time under certain conditions.</p><p>Similar to the former "Privacy Shield", the Data Privacy Framework is based on a system of certification. US organizations and companies can commit to compliance with the so-called EU-US Data Privacy Framework Principles, which are based on the principles of the GDPR, as well as other principles issued by the US Department of Commerce. The U.S. Department of Commerce will also publish a list on the Internet, similar to the former "Privacy Shield", listing the organizations and companies certified under the Data Privacy Framework.</p><p>In order to certify (or recertify on an annual basis) under the Data Privacy Framework, organizations and companies must publicly commit to compliance with the above principles, make their privacy policies available, and fully implement them. As part of their certification application, they must submit various other information to the U.S. Department of Com-merce. These include their organization, a description of the purposes for which personal data is processed, the personal data covered by the certification, and the chosen method of review, the relevant independent complaint mechanism, and finally the relevant enforcement authority. Organizations and businesses can only receive and process personal data based on the Data Privacy Framework from the time they are added to the U.S. Department of Commerce's Data Privacy Framework list. To ensure legal certainty and to avoid organiza-tions or companies falsely claiming to be certified, when they first become certified, they may not publicly reference their compliance with the Principles or their certification until the U.S. Department of Commerce has determined that the relevant certification application is complete and the organization or company has been added to the list. To continue to rely on the Data Privacy Framework as a transfer mechanism, annual recertification must be conducted.</p><h3>What do companies in the EU need to be aware of?</h3><p>Unfortunately, the mere existence of the adequacy decision or the Data Privacy Framework does not yet mean that companies located in the EU or the EEA can now directly base their data transfers on it. This is because the respective US company to which the data is to be transferred must first be certified and published in the Data Privacy Framework list. This is likely to take some time, as the US companies must first implement the principles and comply with the requirements described above.<br>When the time comes, the privacy policies of the companies transferring data may have to be adapted, as they are likely to rely on mechanisms other than the adequacy decision with regard to data transfers to the U.S. so far. However, the privacy policy must always mention the existence or absence of an adequacy decision by the Commission in the case of data transfers to third countries (Art. 13 (1) (f) GDPR).</p><h3>Conclusion and prospects</h3><p>The EU Commission's adequacy decision for the time being ends a long period of legal uncertainty for the transfer of personal data to the US. Provided that the conditions de-scribed above are met, the decision is likely to lead to significant simplifications in the legal assessment and implementation of lawful U.S. data transfers in practice. However, the Data Privacy Framework has also immediately received harsh criticism because it allegedly deviates too little from the Privacy Shield, which has already failed before the ECJ, and therefore does not offer any real protection for the personal data of EU citizens in the US. So, it remains to be seen how long this agreement will last this time. For the time being, however, many companies based in the EU or EEA that regularly want or need to transfer data to the U.S. can breathe a sigh of relief until the next ECJ ruling on this topic.</p><p><a href="https://www.advant-beiten.com/en/experts/fabian-eckstein" target="_blank">Fabian Eckstein</a></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-3292</guid>
                        <pubDate>Sun, 07 May 2023 18:00:00 +0200</pubDate>
                        <title>ADVANT Beiten Advises astragon Entertainment on Takeover of Independent Arts</title>
                        <link>https://www.advant-beiten.com/en/news/advant-beiten-beraet-astragon-entertainment-bei-der-uebernahme-von-independent-arts</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>Frankfurt am Main, 8 May 2023</strong> - The international law firm ADVANT Beiten has provided legal advice to astragon Entertainment GmbH, Dusseldorf, a subsidiary of Team17 Group PLC, on the takeover of Independent Arts Software GmbH. The parties have agreed not to disclose the transaction volume.</p><p>As one of the leading German games publishers, astragon Entertainment strengthens the development of its own simulation brands with the acquisition. astragon gains an experienced and reliable partner in Independent Arts, thus enabling it to continue the development of existing and new working simulation titles as well as to diversify the portfolio of own productions across various platforms.</p><p>Independent Arts, located in Hamm, Germany, has developed commercial video games since 1990, which makes it one of the oldest and most traditional German development studios. The studio with 39 employees has decades of experience and expertise through its own development projects and porting, as well as a strong creative contribution and an excellent management. Independent Arts welcomes an even closer cooperation and the opportunity to expand personnel and structure of the studio as a part of astragon in order to implement more projects and business strategies in the future.</p><p><strong>Advisors to astragon:</strong><br>ADVANT Beiten: <a href="https://www.advant-beiten.com/en/experts/dr-andreas-lober" target="_blank">Dr Andreas Lober</a> (IT/IP/Media), <a href="https://www.advant-beiten.com/en/experts/dr-guido-ruegenberg" target="_blank">Dr Guido Ruegenberg</a> (Corporate/M&amp;A, both in charge), <a href="https://www.advant-beiten.com/en/experts/lennart-kriebel" target="_blank">Lennart Kriebel</a> (IT/IP/Media), <a href="https://www.advant-beiten.com/en/experts/dr-gerald-peter-muller" target="_blank">Dr Gerald Müller-Machwirth</a> (Labour Law, all Frankfurt).</p><p><strong>Media Contact</strong><br>Frauke Reuther<br>Manager Kommunikation<br>ADVANT Beiten<br>+49 (69) 75 60 95 - 570<br><a href="mailto:frauke.reuther@advant-beiten.com">frauke.reuther@advant-beiten.com</a></p><p>Dr Guido Ruegenberg<br>Rechtsanwalt<br>ADVANT Beiten<br>+49 69 756095-393<br><a href="mailto:guido.ruegenberg@advant-beiten.com">guido.ruegenberg@advant-beiten.com</a></p><p>Dr Andreas Lober<br>Rechtsanwalt<br>ADVANT Beiten<br>+49 69 756095-582<br><a href="mailto:andreas.lober@advant-beiten.com">andreas.lober@advant-beiten.com</a></p>]]></content:encoded>
                        
                            
                                <category>Labour Law</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-1474</guid>
                        <pubDate>Mon, 06 Feb 2023 17:00:00 +0100</pubDate>
                        <title>Is Consumer Protection finally getting teeth? EU Commission targets web stores and shopping apps</title>
                        <link>https://www.advant-beiten.com/en/news/bekommt-der-verbraucherschutz-jetzt-zaehne-eu-kommission-nimmt-web-und-app-shops-ins-visier</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>With the statement "Consumer authorities will finally get teeth to punish the cheaters," former Commissioner for Justice, Consumer Protection and Gender Equality, Vera Jourová, announced the redesigned framework in consumer protection through Directive 2019/2161/EU (known primarily as the "Omnibus Directive").</p><p>And as is the case with the GDPR violations, the sanctions envisaged, which are based on a company's annual global turnover, are indeed quite respectable, if not impressive. The prohibited violation of certain consumer interests can incur costs of up to 4% of the annual turnover.</p><p>Now the European Commission, together with national consumer protection authorities from 23 member states plus Norway and Iceland, presented the results of a Union-wide review of retail websites and shopping apps.</p><p>The review focused on three specific types of manipulative practices (so-called "dark patterns") designed to encourage consumers to take actions that are not in their real interest. These included the hiding of information relevant to decision-making, fake countdowns, and websites whose design was intended to pressure consumers into concluding purchase contracts and subscriptions.</p><p>The results are disappointing:<br>The acting Commissioner for Justice said that of the nearly 400 online stores checked, almost 40% had used manipulative practices to exploit consumers' weaknesses. It would now be up to the national authorities to exert influence on the retailers and take further measures if necessary.</p><p>The coordinated review of store providers is a so-called "sweep" to verify compliance with EU consumer protection law. Enforcing the correction request is now the second step, non-compliance with which may entail such a severe fine in the constellations described.<br>In her statement at the time, Vera Jourová said that cheaters should not get off lightly. Thus, it therefore remains to be seen with some excitement whether the first fines in the millions will now follow that will certainly make it into the headlines.</p><p><a href="https://www.advant-beiten.com/en/experts/daniel-trunk" target="_blank">Daniel Trunk</a></p><p><a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_23_418" target="_blank" rel="noreferrer">To the European Commission press release</a><br><a href="https://www.advant-beiten.com/index.php/en/blogs/iim/consumer-protection-law-will-get-teeth-2022-gdpr-style-fines-horizon" target="_blank">To our original blog post</a></p>]]></content:encoded>
                        
                            
                                <category>Intellectual Property</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-1470</guid>
                        <pubDate>Tue, 31 Jan 2023 17:00:00 +0100</pubDate>
                        <title>Digital Services Act: New obligations for many online services as of 17 February already</title>
                        <link>https://www.advant-beiten.com/en/news/digital-services-act-neue-pflichten-fuer-viele-online-dienste-bereits-ab-dem-17-februar-2023</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>It seems that many online service operators still pay much less attention to the Digital Services Act than they should. The DSA will be a real game changer - for "online platforms" more than for other intermediary services. Therefore, we want to discuss what characterizes an online platform.</p><p>An online platform is – slightly simplified – defined as a hosting service that, at the request of a user of the service, stores and disseminates information to the public (unless it is a minor and purely ancillary feature). A hosting service is any service that stores information provided by, and at the request of, a user of the service.</p><p>The problem with this definition is that it is so wide: Pretty much anything a user of an online service does has something to do with information which is stored somewhere. Users fill in their names and contact details in a web form, choose a nickname under which they are known online, leave comments on a website, review and rate products in an online shop, communicate with others in a chat, store preferences for their news websites, customize avatars in a virtual world, build worlds or otherwise interact with an online game. Business might have their profiles on a delivery service, details on their vehicles in a taxi app, or their products in an online marketplace. Most of this information is stored somewhere by the operator of such service. And, as said above, a hosting service is any service that stores information provided by, and at the request of, a user of the service. This means that online services which do just that might be considered hosting services (the definition of a hosting service is almost identical to the one which was introduced in the e-Commerce Directive – under the e-Commerce Directive, there is some case-law on the definition of hosting service but not a lot which would help us narrow down this overly broad definition). However, even providers who have not been able to invoke the exclusion of liability under the host-provider privilege to date may be affected by the due diligence obligations as a hosting provider.</p><p>As soon as this information is not only stored but shared with the public, the service might even be qualified as an online platform. The DSA contains many new obligations for online platforms. Most of them are only to be complied with by February 2024, but some as early as 17 February 2023 – especially the average number of monthly active users has to be published (very large online platforms with more than 45 million active users are another category with much more burdensome obligations). As of February 2024, all the other obligations apply – for online platforms, they include the obligations to set up an internal complaint-handling system and an out-of-court dispute settlement system, to give priority treatment to trusted flaggers of problematic content, to implement measures and protection against misuse, transparency reporting obligations, restrictions on online interface design and organization (including restrictions of so-called "dark patterns"), to establish rules for advertising on online platforms (with restrictions for personalized advertising which are stricter than GDPR provisions), to implement rules for recommender system transparency and the online protection of minors.</p><p>Some of these obligations can be quite onerous. They require very relevant implementation efforts as – depending on the service – its core processes might have to be reviewed.</p><p>It also seems that the definition of online platform might be broader than it should be, covering services the legislator did not have in mind. Companies are therefore well-advised to examine carefully if their services are in fact online-platforms on a feature-by-feature-basis. This may require legal analysis, e.g. in case the information which is stored consists of elements provided by the operator of the service which leaves little room for abuse, in case the service provider exercises control over the information which is stored or disseminated, or on the question whether a "dissemination" is "public" and is performed "at the request" of the user. A diligent analysis may also have to include a technical analysis, e.g. what type of information is actually stored, and where. Finally, it should be assessed whether the "minor or ancillary feature" exception can be applied.</p><p>These assessments must be carried out individually: For example, in some online shops, the review and rating system may be more important than in others, replays of some online games may be stored just on the user's PC while others store it on the server and let users share them, and the influence a service operator exercises on the information it stores and shares can vary widely.</p><p>ADVANT will host a webinar on the Digital Services Act on 16 February 2023 at 05:00 p.m. CET. <a href="https://teams.microsoft.com/registration/Q0DmmGHP8kih-3TTfgXm3Q,nVTIQn8mkEOzwT5yixb0oA,EmLKQSydP0KA4lCho5NMnw,B9IAiOXMY0abg6hcCZu-mg,3fKt69LuLEGFLAl4IjHibQ,cI3rV8gcx0ulrcx-ZwxF_g?mode=read&amp;tenantId=98e64043-cf61-48f2-a1fb-74d37e05e6dd" target="_blank" rel="noreferrer">Webinar registration | Microsoft Teams</a></p><p><a href="https://www.advant-beiten.com/en/experts/dr-andreas-lober" target="_blank">Dr Andreas Lober</a></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-3260</guid>
                        <pubDate>Tue, 24 Jan 2023 17:00:00 +0100</pubDate>
                        <title>ADVANT Beiten advises Cipla (EU) Limited on its investment in Ethris GmbH</title>
                        <link>https://www.advant-beiten.com/en/news/advant-beiten-beraet-cipla-eu-limited-bei-investition-die-ethris-gmbh</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>Berlin, 25 January 2023</strong> – The international law firm ADVANT Beiten has provided comprehensive legal advice to Cipla (EU) Limited, a wholly-owned subsidiary of Cipla Limited (“Cipla”), headquartered in Mumbai, India, on an investment in Ethris GmbH, based in Planegg near Munich. The acquisition of Ethris' shares was made by Cipla (EU) Limited by way of a capital increase.</p><p>Based on proprietary platform technologies, Ethris has been developing mRNA therapeutics for diseases with inadequate treatment and for regenerative medicine for more than 10 years. The biotechnology company develops highly effective mRNA-based drugs for administration directly into the upper and lower respiratory tract and by intra-muscular injection.</p><p>Cipla is India's third-largest pharmaceutical company and South Africa's third-largest generic drug manufacturer. It has a particular focus on drugs and therapies for respiratory diseases. Cipla became internationally known for its production of low-cost HIV medicines. Founded in 1935, Cipla employs about 23,000 people.</p><p>ADVANT Beiten has a strong positioning in the healthcare sector and in advising international clients on investments in the German market.</p><p><strong>Advisor Cipla Ltd.:</strong><br>ADVANT Beiten: Christian Hipp (Antitrust), Benjamin Knorr (Corporate/M&amp;A and Tax, both leading advisors, Berlin), Dr Dietmar O. Reich (Antitrust, Hamburg and Brussels), Wolf J. Reuter (Employment, Berlin), Robert Schmid(Corporate/M&amp;A, Berlin), Dr Christian Ulrich Wolf (Corporate/M&amp;A, Hamburg), Christian Hess (IP/IT, Munich).</p><p><strong>Advisor Ethris GmbH:</strong><br>m law group. Munich</p><p><strong>Media Contact</strong><br>Frauke Reuther<br>Manager Kommunikation<br>ADVANT Beiten<br>+49 (69) 75 60 95 - 570<br><a href="mailto:frauke.reuther@advant-beiten.com">frauke.reuther@advant-beiten.com</a></p><p>Benjamin Knorr<br>Rechtsanwalt<br>ADVANT Beiten<br>+49 (30) 26471 – 262<br><a href="mailto:benjamin.knorr@advant-beiten.com">benjamin.knorr@advant-beiten.com</a></p>]]></content:encoded>
                        
                            
                                <category>Labour Law</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                                <category>Antitrust Law</category>
                            
                                <category>Tax Law</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Healthcare</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-3258</guid>
                        <pubDate>Tue, 10 Jan 2023 17:00:00 +0100</pubDate>
                        <title>ADVANT Beiten Advises Wienerberger on acquiring significant part of French Terreal Group’s business</title>
                        <link>https://www.advant-beiten.com/en/news/advant-beiten-beraet-wienerberger-beim-erwerb-wesentlicher-geschaeftsbereiche-der</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>Berlin, 11 January 2023</strong> – The international law firm ADVANT Beiten advises the leading international manufacturer of building materials and infrastructure solutions, Wienerberger AG, on acquiring major business units of the Terreal Group, a France-based provider of roofing and solar solutions. The acquisition involves the Terreal businesses in France, Italy, Spain and the USA as well as the Creaton business in Germany.</p><p>The Terreal businesses to be acquired by Wienerberger are expected to generate revenues of EUR 740 million and a run-rate EBITDA of approx. EUR 100 million in 2022. The enterprise value of the respective Terreal businesses amounts to EUR 600 million, subject to customary adjustments. The acquisition agreement was signed at the end of December, marking the start of the exclusive negotiation phase. The closing is expected to occur in the course of 2023.</p><p>The merger control part of the transaction is led by ADVANT Beiten partners Uwe Wellmann and Christoph Heinrich who are jointly responsible for German merger control and coordinate a team of law firms in various jurisdictions. Cross-border merger control advice is provided in cooperation with, inter alia, ADVANT Altana in France, Binder Grösswang in Austria, Woźniak Legal in Poland and Radovanović Stojanović &amp; Partners in Southeastern Europe.</p><p>The M&amp;A work stream was led by E+H (Vienna, Graz). ADVANT Beiten partner Dr. Mario Weichel took over its German part and together with a multidisciplinary team performed the legal due diligence on the Creaton business. ADVANT Altana was responsible for the French due diligence.</p><p><strong>Advisers to Wienerberger:</strong><br>ADVANT Beiten: Uwe Wellmann (Berlin) and Christoph Heinrich (both lead partners, both Competition law), Dr Mario Weichel, Maximilian Matusewicz (both Corporate/M&amp;A), Cathleen Laitenberger (Competition Law), Anja Fischer (Real Estate), Katrin Lüdtke and Philipp Früh (both Public Law), Christian Hess (IP), Michael Ziegler and Petra Fendt (Finance), Chiara Peterhammer (Commercial, all Munich), Nima Valadkhani (Commercial), Wolf J. Reuter (Employment Law) and Dr Ariane Loof (Data Protection, all Berlin).</p><p><strong>Media Contact</strong><br>Frauke Reuther<br>Manager Kommunikation<br>ADVANT Beiten<br>+49 (69) 75 60 95 - 570<br><a href="mailto:frauke.reuther@advant-beiten.com">frauke.reuther@advant-beiten.com</a></p><p>Uwe Wellmann<br>Lawyer<br>ADVANT Beiten<br>+49 30 26471-243<br><a href="mailto:uwe.wellmann@advant-beiten.com">uwe.wellmann@advant-beiten.com</a></p>]]></content:encoded>
                        
                            
                                <category>Labour Law</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                                <category>Contract &amp; Commercial Law</category>
                            
                                <category>Antitrust Law</category>
                            
                                <category>Financial Services and Insurance Law</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Real Estate</category>
                            
                                <category>Public Sector</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-3237</guid>
                        <pubDate>Tue, 22 Nov 2022 17:00:00 +0100</pubDate>
                        <title>Seven New Equity Partners: Strong Growth From Own Ranks</title>
                        <link>https://www.advant-beiten.com/en/news/sieben-neue-equity-partnerinnen-und-partner-starkes-wachstum-aus-den-eigenen-reihen</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong><span><span><span><span>Munich, 23&nbsp;November 2022</span></span></span></span></strong><span><span><span><span> - For the international law firm ADVANT Beiten, all signs clearly point to growth: Following the partners' meeting yesterday, Tuesday, seven new Equity Partners from the firm's own ranks have been admitted to the partnership with effect from 1&nbsp;January 2023.</span></span></span></span></p><p><span><span><span><span>Dr&nbsp;Kathrin Bürger, Dr&nbsp;Silke Dulle, Christina Kamppeter, Susanne Klein, Dr&nbsp;Ralf Hafner, Dr&nbsp;Georg Tolksdorf and Dr&nbsp;Sebastian Weller represent five different legal areas and are spread across five locations.</span></span></span></span></p><ul><li><strong><span><span><span><span>Dr&nbsp;Kathrin Bürger</span></span></span></span></strong> <span><span><span><span>(Labour Law, Frankfurt and München), Licensed Specialist for Labour Law, advises particularly on collective labour law issues. She assists companies with collective bargaining changes and (in-house) collective bargaining negotiations as well as strike preparation measures. Beyond that, Dr&nbsp;Bürger advises companies on the negotiation with works councils, also as a part of conciliation boards, as well as on all kinds of individual labour law issues.</span></span></span></span></li><li><strong><span><span><span><span>Dr&nbsp;Silke Dulle</span></span></span></span></strong><span><span><span><span> (Corporate/M&amp;A, Berlin), Licensed Specialist for Medical Law, provides legal advice to clients of the healthcare sector, especially in the area of hospitals and health insurance companies. Her legal consultancy covers hospital law, social security and pharmaceutical law, procurement law and corporate law.</span></span></span></span></li><li><strong><span><span><span><span>Christina Kamppeter</span></span></span></span></strong><span><span><span><span> (Labour Law, Munich), Licensed Specialist for Labour Law, advises national and international companies on all aspects of individual and collective labour law, in particular regarding negotiations with works councils and trade unions. One focus of her work is on providing labour law advice on restructurings.</span></span></span></span></li><li><span><span><span><span><strong>Susanne Klein</strong> (IP/IT/Media, Frankfurt), Licensed Specialist for Information Technology Law, is a renowned expert in data protection law. In addition, she advises her national and international clients in IT and copyright law.</span></span></span></span></li><li><strong><span><span><span><span>Dr&nbsp;Ralf Hafner</span></span></span></span></strong><span><span><span><span> (Litigation &amp; Dispute Resolution, Munich), advises his national and international clients in complex international disputes on dispute resolution out of court and represents them in arbitration and state court proceedings.</span></span></span></span></li><li><strong><span><span><span><span>Dr&nbsp;Georg Tolksdorf</span></span></span></span></strong><span><span><span><span> (Assets/Succession/Foundations, Hamburg) provides legal advice in the area of inheritance and foundation law as well as (tax-optimized) succession planning for private individuals and (family-owned) companies. Another focus of his work is on the execution of (corporate) wills.</span></span></span></span></li><li><strong><span><span><span><span>Dr&nbsp;Sebastian Weller</span></span></span></span></strong><span><span><span><span> (Corporate/M&amp;A, Dusseldorf) focuses on Corporate/M&amp;A as well as Private Equity/Venture Capital, particularly providing legal advice for take-overs, participations and restructuring projects. He provides support on all issues relating to corporate and transformation law as well as corporate compliance.</span></span></span></span></li></ul><p><span><span><span><span>In addition to the seven new Equity Partners, the following Salary Partners have been appointed Local Partners:</span></span></span></span></p><ul><li><strong>Dr&nbsp;Anne Dziuba</strong>, <span><span><span><span>Labour Law, Munich</span></span></span></span></li><li><strong>Dr&nbsp;Daniel Fischer</strong>, Real Estate, Frankfurt</li><li><strong>Dr&nbsp;Christina Hackbarth</strong>, IP/IT/Media, Munich</li><li><strong>Christian Hipp</strong>, <span><span><span><span>Antitrust Law,</span></span></span></span> Berlin</li><li><strong>Tanja Hogh Holub</strong>, IP/IT/Media, Munich</li><li><strong>Sylvia Jenoh</strong>, Tax, Frankfurt</li><li><strong>Dr&nbsp;Klaus Kemen</strong>, Real Estate, Berlin</li><li><strong>Dr&nbsp;Markus Ley</strong>, Corporate/M&amp;A, Berlin</li><li><strong>Jörn Manhart</strong>, <span><span><span><span>Labour Law</span></span></span></span>, Dusseldorf</li><li><strong>Carsten Pütger</strong>, Corporate/M&amp;A, Dusseldorf</li><li><strong>Dr&nbsp;Jochen Reuter</strong>, Real Estate, Frankfurt</li><li><strong>Dr&nbsp;Winfried Richardt</strong>, Corporate/M&amp;A, Dusseldorf</li><li><strong>Dr&nbsp;Florian Weichselgärtner</strong>, <span><span><span><span>Dispute Resolution</span></span></span></span>, Munich</li><li><strong>Mathias Zimmer-Goertz</strong>, IP/IT/Media, Dusseldorf</li></ul><p><span><span><span><span>Furthermore, the following colleagues successfully continue their career path and have been appointed from&nbsp; Senior Associates to Salary Partners:</span></span></span></span></p><ul><li><strong>Annalena Benz</strong>, Real Estate, Munich</li><li><strong>Jens Ledermann</strong>, Tax, Frankfurt</li><li><strong>Dr&nbsp;Martina Schlamp</strong>, <span><span><span><span>Labour Law</span></span></span></span>, Munich</li></ul><p><span><span><span><span>Beyond growth from its own ranks, ADVANT Beiten also continues its course of targeted growth with lateral hires in selected areas and confirms the salary partnership of the following colleagues:</span></span></span></span></p><ul><li><strong>Christian Burmeister</strong>, Corporate/M&amp;A, Freiburg/Berlin</li><li><strong>Dr&nbsp;Moritz Jenn</strong>e, Corporate/M&amp;A, Freiburg</li><li><strong>Dr&nbsp;Sebastian Kroll</strong>, <span><span><span><span>Labour Law</span></span></span></span>, Munich</li><li><strong>Markus P. Linnartz</strong>, Tax,&nbsp;Dusseldorf</li><li><strong>Dr&nbsp;Ariane Loof</strong>, <span><span><span><span>Labour Law</span></span></span></span>, Berlin</li><li><strong>Dr&nbsp;Michael Matthiessen</strong>, <span><span><span><span>Labour Law</span></span></span></span>, Berlin</li><li><strong>Dr&nbsp;Birgit Münchbach</strong>, Corporate/M&amp;A, Freiburg</li><li><strong>Kristin Müller-Nedebock</strong>, Tax, Hamburg</li></ul><p><span><span><span><span><span><span>"All seniority levels are of central importance for the future of our law firm. We are therefore all the more pleased to be able to accompany so many colleagues of different seniority levels, legal areas and locations on their career paths, comments Philipp Cotta, Managing Partner of ADVANT Beiten, and adds: Our modified career track offers all colleagues even more flexibility in their individual career planning and allows us to emphasise our professional expertise across the different levels even more clearly to our clients."</span></span></span></span></span></span></p><p><span><span><span><span>Congratulations to all elected and confirmed partners.</span></span></span></span></p><p>&nbsp;</p><p>&nbsp;</p><p>&nbsp;</p>]]></content:encoded>
                        
                            
                                <category>Labour Law</category>
                            
                                <category>Private Clients &amp; Foundations</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                                <category>Real Estate</category>
                            
                                <category>Dispute Resolution</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Tax Law</category>
                            
                                <category>Antitrust Law</category>
                            
                                <category>Estate Planning &amp; Law of Foundations</category>
                            
                                <category>Real Estate Law</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-3222</guid>
                        <pubDate>Thu, 06 Oct 2022 18:00:00 +0200</pubDate>
                        <title>ADVANT Beiten advised Sappi Limited on the divestment of graphic paper mills in three European countries</title>
                        <link>https://www.advant-beiten.com/en/news/advant-beiten-beraet-sappi-limited-bei-der-veraeusserung-von-grafischen-papierfabriken</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>Munich/Frankfurt, 7 October 2022</strong> – ADVANT Beiten is advising Sappi Limited ("Sappi") on the German law aspects of the contemplated sale and carve-out transaction involving Sappi's graphic paper mills in Stockstadt (Germany), Maastricht (the Netherlands) and Kirkniemi (Finland) with over 1,400 full-time employees combined to AURELIUS Investment Lux One S.à.r.l. ("Aurelius").</p><p>The transaction is structured as a share deal whereby Aurelius will acquire the specific legal entities, i.e. Sappi Stockstadt GmbH, Sappi Maastricht Real Estate B.V. (including its subsidiary Sappi Maastricht B.V.), Sappi Finland I Oy and Sappi Finland Operations Oy, which own and control the assets and liabilities of the individual mills.</p><p>The enterprise value of the transaction amounts to approximately EUR 272 million and the consideration consists of cash proceeds and retained receivables as well as retained liabilities. The transaction is expected to close in Q1 2023, subject to various standard suspensive conditions.</p><p>Sappi is a global leader in dissolving pulp and paper-based solutions, headquartered in Johannesburg, South Africa. It has over 12,000 employees, manufacturing facilities in ten countries spanning over three continents and customers in over 150 countries worldwide.</p><h4>Advisors to Sappi Limited:</h4><p><strong>Advant Beiten:</strong> Dr Christoph Schmitt (Lead Partner; Banking &amp; Finance) and Dr Markus Ley (Lead Partner, Corporate Law); Dr Mario Weichel and Maximilian Matusewicz (both Corporate Law); Dr Gerald Müller-Machwirth and Maike Pflästerer (both Employment Law); Katrin Lüdtke and Philipp Früh (both Public Law); Anja Fischer (Real Estate); Susanne Klein (IT Law and Data Protection) as well as Christoph Heinrich, Dr Christian Heinichen and Cathleen Laitenberger (all Antitrust and Competition Law).</p><p>Stibbe is advising on the Dutch law aspects and Fondia is advising on the Finnish law aspects of the transaction.</p><p><strong>Media Contact</strong><br>Frauke Reuther<br>Manager Kommunikation<br>ADVANT Beiten<br>+49 (69) 75 60 95 - 570<br><a href="mailto:Frauke.Reuther@advant-beiten.com">Frauke.Reuther@advant-beiten.com</a></p><p>Markus Ley<br>Rechtsanwalt<br>ADVANT Beiten<br>+49 (89) 35 0 65 - 1211<br><a href="mailto:Markus.Ley@advant-beiten.com">Markus.Ley@advant-beiten.com</a></p>]]></content:encoded>
                        
                            
                                <category>Labour Law</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                                <category>Antitrust Law</category>
                            
                                <category>Financial Services and Insurance Law</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Real Estate</category>
                            
                                <category>Public Sector</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-1406</guid>
                        <pubDate>Mon, 03 Oct 2022 18:00:00 +0200</pubDate>
                        <title>The Digital Services Act – &quot;A new Sheriff in Town&quot;</title>
                        <link>https://www.advant-beiten.com/en/news/das-gesetz-ueber-digitale-dienste-new-sheriff-town</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>Thierry Breton, EU Commissioner for Internal Market, announced the Digital Services Act ("DSA"), which is intended to harmonise regulations on the internet at EU level, with the pictorial comparison of "a new sheriff in town".</p><p>It has been 20 years since the EU first laid down a basic legal framework for the regulation of the internet – namely the eCommerce Directive of 2000. Since then, it has been the Member States who took the lead on making the internet a safer or at least better place – however, on national level (e.g. in Germany with the Network Enforcement Act). This led to regulations regarding the internet being very inconsistent across the EU. From a business perspective, at times there was the impression of a fragmentation of the "European Internet".</p><p>Therefore, the EU Parliament and eventually the EU Council on October 4, 2022 approved the DSA. Other than hoped by some and feared by others, the DSA is not a "constitutional law for platforms". Rather it contains basic rules for the so-called intermediary services providers.</p><p>The underlying idea of the DSA is: "What is illegal offline, should be illegal online". At first glance, this sounds like an obvious truism, and in fact the regulations of the DSA are more of a tightening up or standardisation of regulations that already exist in many member states. However, many new obligations have been added with the real novelty being the possibility of initiating sanctions against companies along with a system of fines modelled on the GDPR).</p><h3>To whom the DSA applies</h3><p>The DSA is aimed at "intermediary services providers" who offer their services in the EU. This includes, for example, internet providers, cloud services and content sharing platforms, but also social networks, app stores and online marketplaces.</p><p>The extent of regulation depends on the respective type of intermediary service. A distinction is made between the pure transmission of data ("mere conduit"), transmission with short-term intermediate storage ("caching") and "hosting", with the special case of online platforms. The strictest regulations apply to "very large online platforms" and "very large online search engines".</p><h3>Areas of regulation of the DSA – Harmonising Limited Liability Exemptions and establishing Due Diligence Obligations</h3><p>At first, the DSA establishes a standardised legal framework for the conditional exemption from liability of intermediary service providers for the data or content they transmit. The exemption is mainly based on the knowledge of the intermediary services providers of the illegality of the content.</p><h3>Due Diligence Obligations applying to All Intermediary Services</h3><p>The DSA furthermore lists obligations of the intermediary services providers, some of which are very detailed.</p><ul><li>Providers of intermediary services must act against illegal content when ordered to do so by the relevant national judicial or administrative authority. However, there neither a general duty of the intermediary services providers to monitor all information, nor are they obliged to actively search for facts indicating illegal activities without prior indications.</li><li>Intermediary services providers are required to establish a single point of contact for direct communication with the authorities and the Commission, as well as a point of contact enabling the users of the service to communicate directly and rapidly with the services providers.</li><li>Additional information will need to be provided in the terms and conditions of the services providers. This will ensure the fundamental rights of users, such as freedom of expression, freedom and pluralism of the media, and other fundamental rights are adequately reflected in the terms and conditions. The information shall cover restrictions on content as well as the policies, procedures and tools used for content moderation, as well as the internal procedures for handling complaints.</li><li>Where the intermediary service is primarily directed at or used by minors, the terms and conditions must explain the conditions for and restrictions on the use of the service in a way minors can understand. For providers of intermediary services of any kind, it is advisable to review their general terms and conditions at an early stage according to these standards.</li><li>There are now also transparency obligations (e.g. annual reports) for all services providers. The scope of this obligation varies depending on the type of intermediation service.</li></ul><p></p><h3>Specific Obligations for Hosting Services (including Online Platforms)</h3><p>Providers of hosting services must implement notice and action mechanisms. These must include a report function for illegal content which is easily accessible for users. If restrictions are imposed on user content or behaviour, the services provider must give a clear and specific statement of reasons for the restrictions to any affected recipient of the service. If a hosting provider becomes aware of any information that gives rise to the suspicion of a criminal offence involving a threat to the life or safety of a person, the provider must inform the relevant authorities.</p><h3>Special Category: Online Platforms</h3><p>Online platforms, such as social networks or online marketplaces, are defined as providers of hosting services that not only store information provided by the recipients of the service but also disseminate such information to the public at the recipient's request. Such online platforms will have further obligations.</p><ul><li>Online platforms must establish an internal complaint procedure and out-of-court dispute resolution.</li><li>They shall process notices about illegal content given by "trusted flaggers" without undue delay.</li><li>The DSA entails detailed provisions on how to deal with users that frequently provide manifestly illegal content.</li><li>New transparency obligations apply for advertising on online platforms. Generally, users need to be provided with information about the advertiser and the person who paid for the advertising.</li><li>Online platform providers using "recommender systems" must inform users about the main parameters they use for these recommender systems and what options users have to modify or influence these parameters. This should be detailed in the platform's terms and conditions.</li><li>Online platforms must not present advertising based on profiling that uses "sensitive" personal data, as defined in Art. 9 of the GDPR. This may even apply where the user has consented to the processing of their personal data. Personalised advertising based on profiling to minors must not be presented by online platforms where they are reasonably certain the user is a minor. Online platform providers should review functions such as "recommended for you" or similar. Such algorithm-based suggestions often process user profiles for the purposes of personalised advertising within the meaning of the DSA.</li><li>The DSA expressly prohibits the use of "dark pattern", i.e. application interfaces that interfere with users' free decision-making, for example, by displaying different sizes of consent and rejection options.</li><li>Where a platform allows consumers to conclude distance contracts with traders, the platform must ensure traders are traceable and must therefore collect specific information about the trader's identity.</li></ul><p>For very large online platforms having in average at least 45 million EU users per month, even more comprehensive transparency obligations apply. They must give their users the possibility to refuse recommendations based on profiling. They must establish risk management systems and meet specific compliance requirements. And they must be publicly accountable for meeting these requirements and will be subject to annual independent audits. In a crisis (such as war), very large online platforms may be subject to further obligations. These requirements also apply to very large search engines.</p><h3>Enforcement and Sanctions</h3><p>Non-compliance with the DSA can be punished with heavy fines of up to six percent of the group's annual turnover. The competent national authority of the member state in whose territorial jurisdiction the intermediary services provider falls is responsible for enforcing the regulations of the DSA and imposing the respective fines. In the case of very large online platforms/very large search engines, the responsibility here lies with the Commission.</p><p>Companies will not only be subject to obligations if they are providers of any kind of intermediary services; they will now have the possibility to take better action against illegal content or illegal products (for example, counterfeit products, etc.).<br>The new regulations will probably apply from February 2024 and even earlier for very large online platforms. It remains to be seen whether and how the "new sheriff" will ensure better control and security online.</p><p><a href="https://www.advant-beiten.com/en/experts/dr-andreas-lober" target="_blank">Dr Andreas Lober</a> and <a href="https://www.advant-beiten.com/en/experts/cathleen-laitenberger" target="_blank">Cathleen Laitenberger</a></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-3168</guid>
                        <pubDate>Thu, 19 May 2022 18:00:00 +0200</pubDate>
                        <title>ADVANT Beiten advises Medline on the acquisition of Asid Bonz</title>
                        <link>https://www.advant-beiten.com/en/news/advant-beiten-beraet-medline-beim-erwerb-von-asid-bonz</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>Duesseldorf, 20 May 2022</strong> – ADVANT Beiten has provided comprehensive legal advice to <a href="https://www.medline.eu/" target="_blank" rel="noreferrer">Medline International B.V.</a>, a leading manufacturer and distributor of medical devices in Europe, on the acquisition of 100 per cent of the shares in Asid Bonz GmbH, a leading German supplier of medical devices, from Medi-Globe Group, a portfolio company of Duke Street investment fund. The parties have agreed not to disclose the transaction volume. The acquisition by Medline was executed through the German group company <a href="https://www.medline.eu/de/" target="_blank" rel="noreferrer">Medline International Germany GmbH.</a></p><p>The ADVANT Beiten team around lead partner Dr Sebastian Weller provided full support for the complex transaction across practice groups and offices: from the preparation and structuring of the transaction (including due diligence), to the negotiation, implementation and closing of the transaction including antitrust notification.</p><p>Medline is a leading global healthcare company that manufactures and distributes high-quality medical and surgical products. Medline Europe was founded in 2011 and operates branches, as well as production and distribution centres throughout Europe. </p><p>Asid Bonz is a leading supplier to clinics and hospitals in Germany, offering high-quality products for surgery, anaesthesia, ward care and urology. Asid Bonz was founded in 1811 and is known worldwide for having developed the first anaesthetic ether. In 2021, Asid Bonz achieved a turnover of more than 30 million euros and supplied more than 1,100 hospitals in Germany.</p><p>With similar business models and excellent customer service, the two companies are an excellent strategic fit. In the future, Medline will make the Asid Bonz brand available to its broad European customer base outside of Germany. Within Germany, Asid Bonz sales representatives will have access to selected Medline products to further expand their partnership with customers.</p><p><strong>Advisor to Medline International B.V.:</strong><br>ADVANT Beiten: Dr Sebastian Weller (Corporate/M&amp;A, in charge), Nico Frielinghaus (Corporate/M&amp;A), Dr Tassilo Klesen (Corporate/Commercial), Markus Schönherr (Corporate/M&amp;aA), Dr Patrick Hübner (Investment Control), Peter Weck (Labour Law), Dr Andrea Pomana (Antitrust), Christoph Heinrich (Antitrust), Marco Mirceta (Antitrust), Mathias Zimmer-Goertz (IP), Christian Döpke (Data Protection), Dr Marion Frotscher (Tax), Simon Bauer (Tax), Katrin Lüdtke (Public Law), Sascha Opheys (Subsidies).</p><p><strong>Advisor to Medi-Globe Europe:</strong><br>White &amp; Case: Dr Stefan Koch, lead partner</p><p><strong>Media Contact</strong><br>Frauke Reuther<br>Manager Kommunikation<br>ADVANT Beiten<br>+49 (69) 75 60 95 - 570<br><a href="mailto:Frauke.Reuther@advant-beiten.com">Frauke.Reuther@advant-beiten.com</a></p><p>Dr Sebastian Weller<br>Lawyer<br>ADVANT Beiten<br>+49 (211) 51 89 89 - 134<br><a href="mailto:Sebastian.Weller@advant-beiten.com">Sebastian.Weller@advant-beiten.com</a></p>]]></content:encoded>
                        
                            
                                <category>Labour Law</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                                <category>Contract &amp; Commercial Law</category>
                            
                                <category>Antitrust Law</category>
                            
                                <category>Tax Law</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Healthcare</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-3127</guid>
                        <pubDate>Mon, 07 Feb 2022 17:00:00 +0100</pubDate>
                        <title>ADVANT Beiten Ranked in 15 Legal Areas by The Legal 500 Deutschland; Top Tier Law Firm in the Games Area</title>
                        <link>https://www.advant-beiten.com/en/news/advant-beiten-bei-legal-500-deutschland-15-rechtsgebieten-im-ranking-gefuehrt-top-tier</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>The 2022 edition of The Legal 500 Deutschland ranks ADVANT Beiten among the leading law firms in 15 legal areas; in the area of Games, the firm is listed as a top tier law firm.</p><p>Our partners <em>Dr Andreas Lober</em> (Media/Entertainment), <em>Dr Wolfgang Lipinski</em> (Labour Law) and <em>Dr Gerrit Ponath</em> (Private Clients and Nonprofit Sector) are listed as leading names in their respective legal areas. <em>Wojtek Ropel</em> (Media/Entertainment) and <em>Katharina Fink</em> (Private Clients and Nonprofit Sector) are among the names of the next generation. In addition, numerous lawyers are on the list of recommendations for the various legal areas.</p><h3>Legal areas/practice areas in the ranking:</h3><p>Labour Law, Corporate Law and M&amp;A (medium-sized deals), Industrial Property (Trademark Law and Competition Law), Real Estate and Building Law (Real Estate Law and Project Development), Information Technology (Data Protection and IT/Digitalisation), Media (Gaming, Entertainment, Press Law and Publication Law), Private Clients and Nonprofit Sector, Public Law (Planning and Environmental Law, Public Procurement Law, State Aid Law).</p><p>Congratulations to the practice groups and industry groups and to our recommended lawyers.</p><p><strong>Background:</strong><br>The Legal 500 has been published for 35 years and is an independent guidebook. Law firms and lawyers are recommended exclusively on the basis of their performance. In-house lawyers are given a comprehensive overview of around 400 commercial law firms and 2700 lawyers in Germany. The analysis covers 23 practice areas and 90 rankings. As part of the research of The Legal 500 Deutschland, hundreds of interviews are conducted with lawyers and more than 23,000 clients are surveyed.<br></p>]]></content:encoded>
                        
                            
                                <category>Labour Law</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                                <category>Real Estate</category>
                            
                                <category>Public Law</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Procurement Law</category>
                            
                                <category>Intellectual Property</category>
                            
                                <category>Real Estate Law</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-3112</guid>
                        <pubDate>Thu, 20 Jan 2022 17:00:00 +0100</pubDate>
                        <title>ADVANT Beiten Advises Paca Puratos on the Acquisition of the Business  Operations of the Insolvent frizle fresh foods AG</title>
                        <link>https://www.advant-beiten.com/en/news/advant-beiten-beraet-paca-puratos-beim-erwerb-des-geschaeftsbetriebs-der-insolventen</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>Dusseldorf, 21 January 2022 – ADVANT Beiten has advised Paca Puratos, an Israeli joint venture of the Puratos Group based in Belgium, on the acquisition of the business operations of the insolvent frizle fresh foods AG from the insolvency administrator. The parties have agreed that the purchase price will not be disclosed.</p><p>ADVANT Beiten has originally advised Paca Puratos on the acquisition of shares and on a planned investment of/in frizle fresh foods beraten. In the course of the transaction, however, frizle fresh foods AG, which specialises in innovative food products, had to file for insolvency. The ADVANT Beiten team around lead partner Prof. Dr. Hans-Josef Vogel subsequently changed strategy and advised their client on the acquisition of the full business operations from the insolvency administrator.</p><p>Fresh spaetzle dough in a bag - the founders of frizle fresh foods launched this business idea in 2015. Even though it failed to land a deal in the well-known TV series "Die Höhle der Löwen", the start-up received a lot of media attention and was quickly representedin many retail chains with its product. This was followed by a number of other fresh, liquid doughs and products that were not yet established in the German market.</p><p>PACA, founded in 1934, is leading the Israeli fresh yeast market for more than 40 years. Owner of “Shimrit” a famous Israeli baking goods brand, well known for successful commercial products such as fresh yeast, yeast flours, margarine, naturina, fresh pastry dough bases and fresh batters. PACA is co-owned by Puratos and the Sommerfeld Family. With the acquisition of frizle fresh foods, the company expands its product portfolio of innovative food products and continues their business operations.</p><p><strong>Advisors to Paca Puratos:</strong><br>ADVANT Beiten: Prof. Dr Hans-Josef Vogel (Head, Corporate/M&amp;A), Wilken Beckering (Insolvenzy Law), Dr Winfried Richardt (Corporate/M&amp;A), Mathias Zimmer-Goertz, Christian Döpke (both IP), Thomas Herten (Real Estate), Doreen Methfessel and PeterWeck (both Labour Law, all Dusseldorf).</p><p><strong>Insolvency Administrator frizle fresh foods:</strong><br>Law Firm Rochade Anwälte (Mannheim)</p><p><strong>Media Contact</strong><br>Frauke Reuther<br>Manager Communications<br>ADVANT Beiten<br>+49 (69) 75 60 95 - 570<br><a href="mailto:frauke.reuther@advant-beiten.com ">frauke.reuther@advant-beiten.com</a></p><p><a href="https://www.advant-beiten.com/en/experts/prof-dr-hans-josef-vogel" target="_blank">Prof. Dr Hans-Josef Vogel&nbsp;</a><br>Lawyer<br>ADVANT Beiten<br>+49 (211) 51 89 89 - 0<br><a href="mailto:Hans-Josef.Vogel@advant-beiten.com">Hans-Josef.Vogel@advant-beiten.com</a></p>]]></content:encoded>
                        
                            
                                <category>Labour Law</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Real Estate</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-3108</guid>
                        <pubDate>Mon, 17 Jan 2022 17:00:00 +0100</pubDate>
                        <title>ADVANT Beiten Advises MYPOSTER on Takeover and Exit of JUNIQE</title>
                        <link>https://www.advant-beiten.com/en/news/advant-beiten-beraet-myposter-bei-uebernahme-und-exit-von-juniqe</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>Dusseldorf, 18 January 2022 – The international commercial law firm ADVANT Beiten has comprehensively advised the Munich-based e-commerce group MYPOSTER on the acquisition of all shares in Kollwitz Internet GmbH (JUNIQE), a successful Berlin-based poster start-up, from due diligence to the closing of the transaction. The parties have agreed not to disclose the transaction volume.</p><p>Founded in 2014, the Berlin-based start-up JUNIQE specialises in prints and posters by artists and is excellently positioned in the market. Since its foundation, JUNIQE has received more than 20 million euros in capital from shareholders, including well-known names such as Vorwerk Ventures, High-Tech Gründerfonds and the Cewe Foundation. The founders of JUNIQE leave the operational management but remain closely associated with the company in an advisory capacity. The JUNIQE location in Berlin and the brand will be retained. The number of MYPOSTER employees increases by 70 to 350 with the takeover.</p><p>MYPOSTER was founded in 2011 and has experienced rapid growth in recent years. The MYPOSTER group includes the brands myposter, Kartenliebe, ArtPhotoLimited and its own production company Printhouse. The takeover of JUNIQE is MYPOSTER's largest acquisition to date and represents a milestone for the company. MYPOSTER will further develop JUNIQE's business model strategically and innovatively and thus expand it into an even stronger provider in European e-commerce.</p><p><br><strong>Advisors to MYPOSTER:</strong><br><strong>ADVANT Beiten:</strong>&nbsp;Dr Sebastian Weller (in charge, Corporate/M&amp;A/Venture Capital, Dusseldorf), Dr Martin Rappert, Dr Julia Offermanns, Nico Frielinghaus, Dr Winfried Richardt, Markus Schönherr (all Corporate/M&amp;A, alle Dusseldorf), Tassilo Klesen (Corporate/Commercial, Berlin), Wilken Beckering (Corporate/Commercial, Dusseldorf), Lelu Li (Commercial, Berlin), Thomas Herten (Real Estate, Dusseldorf), Peter Weck (Labour Law, Dusseldorf), Christoph Heinrich (Antitrust, Munich), Mathias Zimmer-Goertz (IP, Dusseldorf), Christian Döpke (Data protection, Dusseldorf), Helmut König (Tax, Dusseldorf), Jan Christian Mohrmann (Tax, Frankfurt), Dennis Grimmer, Vivienne Sulek (both Financial Due Diligence, both Dusseldorf).</p><p><strong>Advisors to JUNIQE:</strong> Osborne Clarke (Nicolas Gabrysch, Alexandra Nautsch)</p><p><strong>Media Contact</strong><br>Frauke Reuther<br>Manager Kommunikation<br>ADVANT Beiten<br>+49 (69) 75 60 95 - 570<br><a href="mailto:frauke.reuther@advant-beiten.com">frauke.reuther@advant-beiten.com</a></p><p>Dr. Sebastian Weller<br>Lawyer<br>ADVANT Beiten<br>+49 (211) 51 89 89 -134<br><a href="mailto:Sebastian.Weller@advant-beiten.com">Sebastian.Weller@advant-beiten.com</a></p>]]></content:encoded>
                        
                            
                                <category>Labour Law</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Tax Law</category>
                            
                                <category>Financial Services and Insurance Law</category>
                            
                                <category>Antitrust Law</category>
                            
                                <category>Contract &amp; Commercial Law</category>
                            
                                <category>Real Estate Law</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-3095</guid>
                        <pubDate>Mon, 13 Dec 2021 17:00:00 +0100</pubDate>
                        <title>ADVANT Beiten Advises Comer Industries on Takeover of Walterscheid Powertrain Group</title>
                        <link>https://www.advant-beiten.com/en/news/advant-beiten-beraet-comer-industries-bei-der-uebernahme-der-walterscheid-powertrain</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><span lang="EN-US">Berlin, 14 December 2021 – The international commercial law firm ADVANT Beiten together with ADVANT Nctm, Italy, has advised Comer Industries S. p. A., a leading global developer and manufacturer of mechatronic solutions and integrated drive systems for major manufacturers of agricultural and industrial machinery, headquartered in Reggiolo, Italy, on all aspects relating to German law in the acquisition of Walterscheid Powertrain Group (WPG), headquartered in Lohmar near Cologne.</span></p><p><span lang="EN-US">WPG is a leading provider of advanced mission-critical drive systems and services for off-highway and industrial applications, headquartered in Lohmar near Cologne, Germany. WPG is represented in 75 countries with components and drive systems for agricultural, industrial, construction and mining machinery and employs more than 2,200 people worldwide.&nbsp;</span></p><p><span lang="EN-US">The merger of Comer Industries, listed on the Borsa Italiana, with WPG will create one of the world's largest suppliers of drive solutions in the agricultural sector, with an expected combined turnover of one billion euros in 2021.</span></p><p><span lang="EN-US">ADVANT Beiten supported the transaction, which was completed in December 2021, in particular by carrying out legal due diligence, conducting a clearing procedure under the German Foreign Trade and Payments Regulation (Außenwirtschaftsverordnung) and assisting with German and Russian antitrust clearance.</span></p><p><span lang="EN-US"><strong>Adviser to Comer Industries:&nbsp;</strong><br>ADVANT Beiten: <a href="https://www.advant-beiten.com/en/experts/dr-christian-von-wistinghausen" target="_blank">Dr Christian von Wistinghausen</a> (Lead Partner in charge), <a href="https://www.advant-beiten.com/en/experts/tassilo-klesen" target="_blank">Tassilo Klesen</a>, <a href="https://www.advant-beiten.com/en/experts/dr-patrick-alois-hubner" target="_blank">Dr Patrick A. Hübner</a>, <a href="https://www.advant-beiten.com/en/experts/lelu-li" target="_blank">Lelu Li</a>, <a href="https://www.advant-beiten.com/en/experts/olga-prokopyeva" target="_blank">Olga Prokopyeva</a> (all Corporate / M&amp;A, Berlin), <a href="https://www.advant-beiten.com/en/experts/dr-klaus-kemen" target="_blank">Dr Klaus Kemen</a>, <a href="https://www.advant-beiten.com/en/experts/robin-maletz" target="_blank">Robin Maletz</a> (both Real Estate, Berlin), <a href="https://www.advant-beiten.com/en/experts/katrin-ludtke" target="_blank">Katrin Lüdtke</a>, (Public Sector, Munich), <a href="https://www.advant-beiten.com/en/experts/michael-ziegler" target="_blank">Michael Ziegler</a>, <a href="https://www.advant-beiten.com/en/experts/petra-fendt" target="_blank">Petra Fend</a>t (both Banking/Finance &amp; Capital Markets, Munich), <a href="https://www.advant-beiten.com/en/experts/christoph-heinrich" target="_blank">Christoph Heinrich</a>, <a href="https://www.advant-beiten.com/en/experts/cathleen-laitenberger" target="_blank">Cathleen Laitenberger</a> (both Antitrust Law, Munich), <a href="https://www.advant-beiten.com/en/experts/uwe-wellmann" target="_blank">Uwe Wellmann</a> (Antitrust Law, Berlin), <a href="https://www.advant-beiten.com/en/experts/susanne-klein" target="_blank">Susanne Klein</a> (IP/IT, Frankfurt), <a href="https://www.advant-beiten.com/en/experts/dr-nicole-hirschvogel" target="_blank">Dr Nicole Hirschvogel</a> (IP/IT, Munich), <a href="https://www.advant-beiten.com/en/experts/julia-alexandra-schutte" target="_blank">Julia Alexandra Schütt</a>e (Employment &amp; Labour, Berlin), <a href="https://www.advant-beiten.com/en/experts/christian-freiherr-von-buddenbrock" target="_blank">Christian Freiherr von Buddenbrock</a> (Employment &amp; Labour, Dusseldorf), <a href="https://www.advant-beiten.com/en/experts/julia-meler" target="_blank">Julia Mele</a>r (Employment &amp; Labour, Munich).</span></p><p><span lang="EN-US">ADVANT Beiten, Moscow (Russia) (for regulatory clearances under Russian law): <a href="https://www.advant-beiten.com/de/experten/vasily-ermolin" target="_blank">Vasily Ermolin</a></span></p><p><span lang="EN-US">ADVANT Nctm, Milan (Italy), NOBILI RTZ Legal</span></p><p><span lang="EN-US"><strong>Adviser to WPG:</strong> Freshfields Bruckhaus Deringer LLP, Milan (Italy)</span></p><p><span lang="EN-US"><strong>Media Contact</strong><br>Frauke Reuther<br>Manager Kommunikation<br>ADVANT Beiten<br>+49 (69) 75 60 95 - 570<br><a href="mailto:frauke.reuther@advant-beiten.com">frauke.reuther@advant-beiten.com</a></span></p><p><span lang="EN-US"><a href="https://www.advant-beiten.com/en/experts/dr-christian-von-wistinghausen" target="_blank">Dr. Christian von Wistinghausen</a><br>Lawyer<br>ADVANT Beiten<br>Tel.: +49 30 26471-351<br><a href="mailto:Christian.Wistinghausen@advant-beiten.com">Christian.Wistinghausen@advant-beiten.com</a></span></p><p>&nbsp;</p>]]></content:encoded>
                        
                            
                                <category>Labour Law</category>
                            
                                <category>Industrials</category>
                            
                                <category>Public Law</category>
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Financial Services and Insurance Law</category>
                            
                                <category>Antitrust Law</category>
                            
                                <category>Real Estate Law</category>
                            
                                <category>Corporate/M&amp;A</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-1238</guid>
                        <pubDate>Wed, 23 Jun 2021 18:00:00 +0200</pubDate>
                        <title>International Data Transfer: New EDPB Recommendations as a Ray of Sunshine on the Horizon?</title>
                        <link>https://www.advant-beiten.com/en/news/internationaler-datentransfer-neue-edsa-empfehlungen-als-silberstreif-am-horizont</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><em><span lang="EN-GB"><span><span>It may be a coincidence, but US President Joe Biden could hardly have wished for better timing: To coincide with his visit to Europe, the European Data Protection Board (EDPB) has published a new paper that makes it at least a little easier for companies to transfer data to the US in some cases.</span></span></span></em></p><p><span lang="EN-GB"><span><span>Version 2.0 of the "Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data" of 18 June 2021 (</span></span></span><span><span><span><a href="https://edpb.europa.eu/system/files/2021-06/edpb_recommendations_202001vo.2.0_supplementarymeasurestransferstools_en.pdf" target="_blank" rel="noreferrer">edpb_recommendations_202001vo.2.0_supplementarymeasurestransferstools_en.pdf (europa.eu)</a></span></span></span><span lang="EN-GB"><span><span>) only brings minor changes compared to the previous version (consultation version of 10 November 2020, </span></span></span><span><span><span><a href="https://edpb.europa.eu/sites/default/files/consultation/edpb_recommendations_202001_supplementarymeasurestransferstools_de.pdf" target="_blank" rel="noreferrer">edpb_recommendations_202001_supplementarymeasurestransferstools_de.pdf (europa.eu)</a></span></span></span><span lang="EN-GB"><span><span>) but in important cases they give international companies some more options.</span></span></span></p><h3><span><span><span>Background</span></span></span></h3><p><span><span><span>On 16 July 2020, in its <a href="http://curia.europa.eu/juris/document/document.jsf?text=&amp;docid=228677&amp;pageIndex=0&amp;doclang=de&amp;mode=req&amp;dir=&amp;occ=first&amp;part=1&amp;cid=9863522" target="_blank" rel="noreferrer">Ruling</a>in the "Schrems II" case (<a href="http://dejure.org/dienste/vernetzung/rechtsprechung?Text=C-311/18" target="_blank" title="C-311/18 (2 related rulings)" rel="noreferrer">C-311/18</a>) the European Court of Justice (ECJ) had declared <a href="https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32016D1250&amp;from=DE" target="_blank" rel="noreferrer">the EU-US Privacy Shield Decision</a> invalid. </span></span></span></p><p><span><span><span>The ruling relates in particular to data transfers to the USA, which until now had very often been covered by the so-called "EU-US Privacy Shield". The ECJ considered the "EU-US Privacy Shield" to be insufficient to ensure an adequate level of data protection within the meaning of the GDPR, primarily due to the far-reaching competences of the US security services.</span></span></span></p><p><span lang="EN-GB"><span><span>Standard contractual clauses (SCCs for short) - previously relied on by many companies for data transfers to the US - can still be used in principle even after Schrems II, but the mere conclusion of the SCCs is not sufficient for this purpose anymore. Rather, additional measures have to be taken.</span></span></span></p><h3><span lang="EN-GB"><span><span>Previous EDPB recommendation</span></span></span></h3><p><span lang="EN-GB"><span><span>The consultation version of the EDPB recommendations adopted on 10 November 2020 addressed the question of what additional measures may be considered.</span></span></span></p><p><span lang="EN-GB"><span><span>Based on the assumption that the US security authorities are not impressed by, for instance, contractual agreements between a EU company (as a data exporter) and a US company (as a data importer), the proposed measures were mainly of a technical and organisational nature, in particular anonymisation and encryption, with the aim of preventing the processing of clear data by the data recipient in the US and thereby preventing US security authorities from accessing personal data. Though additional contractual measures beyond the SCCs were recommended, they were not considered sufficient.</span></span></span></p><h3><span lang="EN-GB"><span><span>Shortcomings of the previous EDPB recommendations: Cloud services, employee data in the group, eCommerce...</span></span></span></h3><p><span><span><span>The Schrems II ruling and the EDPB recommendations confronted many companies with challenges hardly solvable, as no solution was offered for important use cases. For instance, transfer to cloud service providers or other processors requiring access to unencrypted data or remote data access for business purposes was explicitly identified as a problem without a solution (subs. 88 ff). The transfer of employee data within international corporations was not addressed at all, which posed major problems for US corporations in particular.</span></span></span></p><p><span lang="EN-GB"><span><span>In addition, the EDPB was also very restrictive regarding the exceptions in the GDPR, which also include guarantees to secure third-country transfers: "Article 49 of the GDPR is an exception. The exceptions provided for therein must thus be interpreted restrictively; they relate predominantly to processing activities that are only occasional and not repetitive. The EDPB has issued its Guidelines 2/2018 on the exemptions under Article 49 of Regulation 2016/679" (subs. 25 - the English wording here is even stricter than the German). The transfer of employee data within international corporations, the transfer to cloud service providers or cross-border e-commerce are usually not exceptions that only take place occasionally - in fact, they are typically recurring activities.</span></span></span></p><h3><strong><span lang="EN-GB"><span><span>New EDPB Recommendations</span></span></span></strong></h3><p><span><span><span>The new EDPB recommendations also offer no explicit solutions to the problems outlined. </span></span></span></p><p><span><span><span>However, they do give companies a little more leeway. The strict wording of the exceptions under Article 49 GDPR has at least been softened somewhat ("Article 49 GDPR has an exceptional nature. The derogations it contains must be interpreted in a way which does not contradict the very nature of the derogations as being exceptions from the rule that personal data may not be transferred to a third country unless the country provides for an adequate level of data protection or, alternatively, appropriate safeguards are put in place. Derogations cannot become “the rule” in practice, but need to be restricted to specific situations.") Thus, it does not says anymore that Article 49 could not be applied if there were a large number of operations or repeated operations. This allows room for manoeuvre to base the transfer of data to the USA - at least under strict conditions - on the necessity for the fulfilment of the contract or consent, whereas the necessity must be carefully examined and the consent must be given in an informed manner, which may also include specific explanations of the risks of the international transfer of data.</span></span></span></p><p><span lang="EN-GB"><span><span>Finally, the EDPB corrects its course in another detail. When assessing the risks of a data export, it is now possible - to a greater extent than under the consultation version - to take into account whether the respective data importer and the respective data processing activity are actually subject to problematic US laws. Of course, this also requires a precise analysis, which must be documented.</span></span></span></p><h3>Conclusion</h3><p><span><span><span>Data transfers to the USA remain difficult, but the new recommendations are a way in the right direction. So far, companies that wanted to follow the EDPB's recommendations simply were not offered a solution in some important areas. In this respect, the data transfer risk assessment demanded by the data protection authorities was a frustrating exercise because no solution could be found, regardless of the risk identified. There now seems to be some progress in important areas, especially where the data importer in the USA does need access to unencrypted data, for instance in the transfer of employee data within the corporation or in global technical infrastructures such as some cloud services or e-commerce offerings.</span></span></span></p><p><span lang="EN-GB"><span><span>The German data protection authorities are already in the process of investigating the status of the implementation of the Schrems II ruling in companies, for example via questionnaires (</span></span></span><span><span><span><a href="https://www.lda.brandenburg.de/lda/de/service/presseinformationen/details-presse/~01-06-2021-koordinierte-pruefung-internationaler-datentransfers" target="_blank" rel="noreferrer">Coordinated Audit of International Data Transfers | The Brandenburg State Commissioner for Data Protection and for the Right to Inspect Files</a></span></span></span><span lang="EN-GB"><span><span>). Violations will surely be sanctioned. Companies are well advised to carry out the required assessment carefully and in line with the EDPB recommendations and to document this exercise.</span></span></span></p><p><a href="https://www.beiten-burkhardt.com/en/experts/dr-andreas-lober" target="_blank" rel="noreferrer"><span><span><span>Dr Andreas Lober</span></span></span></a></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-1196</guid>
                        <pubDate>Thu, 29 Apr 2021 18:00:00 +0200</pubDate>
                        <title>BAG: Data protection as a trigger for a settlement: a blanket demand for copies of data is insufficient</title>
                        <link>https://www.advant-beiten.com/en/news/datenschutz-als-trigger-fuer-die-abfindung-pauschale-forderung-von-datenkopien-reicht-nicht</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><em>Judgment of the Federal Labour Court of 27 April 2021 in Case No. 2 AZR 342/20</em></p><p>The Federal Labour Court (BAG) was asked to take a decision on the practical question of to what extent an employer must provide an employee who is leaving the company with a copy of email correspondence and make all emails available in which the employee was named. The Court was able to leave open the question about the scope of the right to data copies (Article 15 (3) GDPR) because the appeal failed on procedural grounds.</p><h3>Background</h3><p>Employers are regularly facing claims that can only be met at significant expense in connection with (threatened) actions against unfair dismissal. Rarely will data protection concerns be paramount. Instead, employees are often more interested in increasing the pressure on their (former) employer as motivation for a proposal of a more generous settlement. Data protection is instead used as a pawn by the parties while the right to self-determination of personal information is rarely the focus.</p><p>Claims to the release of comprehensive data copies raise important data protection law issues. When the claim is made for copies of all email exchanges from the whole period of employment, the copies normally reveal personal information not only about the employee making the claim, but also about the communication partner, such as the sender or recipient of each email. The employer is not allowed to simply give out their personal information, even if the employee already knows who they were communicating with. To this extent, the right to data copies under Article 15 (4) GDPR is limited to where the rights and freedoms of other persons are not affected. With respect to any third parties concerned, such as the sender or recipient, the release of email copies constitutes special data processing which requires a legal basis. That is why the employer must either carry out a careful data protection review and document this review before releasing such data copies or ensure that all personal information concerning such third parties is unidentifiable. Both options normally involve considerable effort and expense.</p><h3>Facts of the case</h3><p>The judgment of the BAG is based on facts often be found in cases before German courts. The employer terminated the employment relationship during the probationary period. The employee brought an action against unfair dismissal. At the same time, he brought a claim for all information that the employer had about him, as well as a claim for a copy of this information. He requested the release of all emails that he had sent or received or in which he was named under data protection law. The Labour Court dismissed the claim. The Regional Labour Court ordered the employer to release copies of the documents, which were used to respond to his request for information. Otherwise, the Court dismissed the appeal. With his appeal to the BAG, the employee continued to pursue his request for copies of all email communications in which he is named.</p><h3>Requirement to provide copies of all emails is too “vague”</h3><p>The appeal to the BAG was unsuccessful on procedural grounds (lack of certainty of the application). In the Court’s view, it remained unclear which email copies had to be provided if the claim for information was executed as the employee had simply claimed all emails in which he “is mentioned by name”. The Claimant had to define the emails so specifically that they could be identified without any doubts in enforcement proceedings. The full text of the judgment is not yet available. However, the press release from the Court indicates that the Erfurt Judges require employees to use a so-called action by stages to first bring a claim for information about which emails concerning the employee are in the employer’s possession. Based on this information, the employee would then be able to provide a sufficiently precise application for the delivery of a copy of the data and enforce his rights.</p><h3>Consequences for practice</h3><p>The controversial and very relevant issue of the scope of a claim to a copy of data under data protection law, in particular the extent to which copies of an extensive email portfolio are to be provided, remains unsettled at the highest level. This is unsatisfactory for practice. Failure to properly comply with the right to data copies can result in draconian fines and expensive compensation claims.</p><p>At least it has been clarified that a claim to data copies must be sufficiently specific for the courts. The claim therefore contains “procedural hurdles”, which should dissuade employees from randomly making a blanket claim for their whole email correspondence.</p><p>Instead, a claim for data copies must be sufficiently specific and stipulate which copies exactly are to be provided. This will provide reasonable limits to the scope of such claims and facilitate the transparency and feasibility of such claims for employers.</p><p>Before the highest Court will be able to clarify these data protection law issues, a comparable case with slightly different litigation tactics, such as an action by stages, will need to be brought before the German courts. Employees are unlikely to change their strategy towards their (former) employer, and data protection is unlikely to only become the subject of proceedings when it is the substantive issue. It remains to be seen whether and to what extent an action by stages will be used as such procedures are often very time intensive and thus not expedient for either party.</p><h3>Practical tip</h3><p>Companies should therefore continue their data protection approach and only provide copies of employee data, including individual emails, where the employee has specifically requested the data and where such data can be legally provided (for instance, with part of the information blacked out). Often, the claim for information is brought as “leverage” in combination with an action against unfair dismissal and to strengthen the position when negotiating a settlement. In cases of termination of employment during the probationary period, in particular – like that in the case before the BAG – the employee has few arguments in favour of the payment of a settlement due to the lack of protection against unfair dismissal. In a comparable case of the termination of employment and resulting action against unfair dismissal, any claims for information and copies of data under data protection law should be dealt with as part of a “whole deal”. A so-called factual settlement, for example, could be reached where the data protection law claims are recalled or even waived.</p><p><a href="https://www.advant-beiten.com/en/experts/gerd-kaindl" target="_blank">Gerd Kaindl</a><br><a href="https://www.advant-beiten.com/en/experts/susanne-klein" target="_blank">Susanne Klein</a><br>Lennart Kriebel</p>]]></content:encoded>
                        
                            
                                <category>Labour Law</category>
                            
                                <category>IT and the Law of Data</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-1159</guid>
                        <pubDate>Wed, 17 Mar 2021 17:00:00 +0100</pubDate>
                        <title>Brexit: Impact on the transfer of personal data to the United Kingdom</title>
                        <link>https://www.advant-beiten.com/en/news/brexit-folgen-fuer-uebermittlungen-personenbezogener-daten-das-vereinigte-koenigreich</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><span lang="EN-US"><span><span>The United Kingdom – that is Great Britain and Northern Ireland – is no longer part of the European internal market or the customs union. This impacts all companies that have a business relationship with companies from Great Britain and Northern Ireland. Data protection is not exempt in this respect. Under data protection law, when the United Kingdom left the European Union, it became a so-called third country. The transfer of personal data to a third country is subject to special requirements in accordance with Chapter 5 of the General Data Protection Regulation (GDPR). On 19 February 2021, the European Commission presented drafts for two “Adequacy Decisions” pursuant to Article 45 para. 3 GDPR.</span></span></span></p><p><span lang="EN-US"><span><span>In the following, we provide a brief overview of the recent developments, the current legal position concerning data protection and an outlook of what to expect. This is particularly relevant for companies that can still decide with which business partners they build certain infrastructures in relation to certain services. Here, the country of domicile should possibly be taken into account.</span></span></span></p><h3><span lang="EN-GB"><span><span>Previously</span></span></span></h3><p><span lang="EN-GB"><span><span>The United Kingdom ("<strong>UK"</strong>) withdrew from the European Union ("<strong>EU"</strong>) on 31 January 2020 ("<strong>Brexit"</strong>). After two postponements, the UK and the EU agreed on a withdrawal date of 31 January 2020. </span></span></span><span lang="EN-US"><span><span>On 1 February 2020, the Agreement on the Withdrawal of the United Kingdom from the European Union entered into force. With respect to data protection, the Agreement contains a provision whereby EU data protection law will continue to apply in the UK to the processing of personal data of persons from outside of the UK until 31 December 2020. In other words, after the withdrawal of the UK from the EU, the GDPR continued to apply in the UK and the UK was not considered a third country within the meaning of Article 44 GDPR. From a data protection perspective, everything stayed just as it was until 31 December 2020; this is subject to possible amendments to data protection information and other documentation under data protection law.</span></span></span></p><h3><span lang="EN-GB"><span><span>What applies now?</span></span></span></h3><p>Shortly before the end of this transitional period, the EU and the UK agreed on a Trade and Cooperation Agreement which contains a new transitional rule for data transfers. This new rule provides that, for a new transition period, the transfer of personal data from the EU to the UK will not be considered a transfer of data to a third country according to Article 44 GDPR. This period began with the entry into force of the Agreement on 1 January 2021 and will end either when the EU has adopted an adequacy decision for the UK pursuant to Article 45 para. 3 GDPR (and Article 36 para. 1 of Directive (EU) 2016/680) or, at the latest, four months after the start of this transitional period, on 30 April 2021.</p><p>Accordingly, the transfer of data to the UK will initially continue under the current conditions. The end date of 30 April 2021 can be extended again by two months if no party objects.</p><p><span lang="EN-US"><span><span>Accordingly, until the adoption of an adequacy decision or until 30 April 2021 or 30 June 2021 respectively, nothing will change for the transfer of personal data from the EU to the UK; this is subject to possible amendments to data protection information and other documentation under data protection law.</span></span></span></p><h3><span lang="EN-GB"><span><span>What’s to come</span></span></span></h3><p>The EU Commission is now tasked with presenting a so-called adequacy decision with respect to the United Kingdom in accordance with Article 44 para. 3 GDPR.</p><p>However: The EU Commission can only adopt such an adequacy decision when, after a detailed examination, it concludes that the level of protection for the processing of personal data in the UK is the same as that under the GDPR or that it otherwise ensures an adequate level of protection.</p><p>Because: If an adequacy decision has been adopted for a country or organisation, the country will be treated as a secure third country for the transfer of personal data and, consequently, the additional requirements for the transfer of personal data as set out in Article 44 et seq. GDPR will be fulfilled simply by the existence of the adequacy decision under Article 45 para. 3 GDPR.&nbsp; An adequacy decision has been adopted, for example, for Switzerland, Israel and New Zealand.</p><p><span lang="EN-GB"><span><span>The EU Commission has acted with impressive speed and has already presented a draft for an adequacy decision that would declare that the United Kingdom is a secure third country</span></span></span> <span lang="EN-US"><span><span>for data protection purposes</span></span></span>: <a href="https://ec.europa.eu/info/files/draft-decision-adequate-protection-personal-data-united-kingdom-general-data-protection-regulation_en" target="_blank" rel="noreferrer">LINK</a>.</p><p>In so doing, the EU Commission was undoubtedly faced with challenges: if the adequacy decision is adopted, the case law of the European Court of Justice ("<strong>ECJ</strong>") must be taken into account so that the Commission’s assessment must withstand an examination by the European Data Protection Board ("<strong>EDPB"</strong>) and even possible review by the ECJ.</p><p><span lang="EN-US"><span><span>In this respect, the judgment of the ECJ of 16 July 2020 (Case No. C-311/18 – "<strong>Schrems II"</strong>) is important. In that case, the ECJ declared that the Commission’s Adequacy Decision on the “Privacy Shield” was invalid and an adequate level of data protection could not be guaranteed in the USA. The ECJ criticised the fact that information about EU citizens on US servers could not be protected against access by US authorities and intelligence services. For more Detail:</span></span></span> <a href="https://lfd.niedersachsen.de/startseite/themen/weitere_themen_von_a_z/internationaler_datenverkehr/das_schrems_ii_urteil_des_eugh_und_seine_bedeutung_fur_datentransfers_in_drittlander/das-schrems-ii-urteil-des-europaischen-gerichtshofs-und-seine-bedeutung-fur-datentransfers-in-drittlander-194085.html" target="_blank" rel="noreferrer">LINK</a>.</p><p>In this respect, the EU Commission must examine the rules of the Investigatory Power Act of 2016 as part of its assessment of the level of data protection in the UK. The Act allows focused and thematic mass surveillance, access to devices and grants powers to record communication data. It also includes provisions on the surveillance powers of the British secret services.</p><p><span lang="EN-US"><span><span>Stefan Brink, the Data Protection Officer of the Land of Baden Württemberg commented to the German newspaper <em>Handelsblatt</em> that, "<a href="https://www.handelsblatt.com/politik/deutschland/datenaustausch-in-gefahr-drohender-no-deal-brexit-alarmiert-datenschuetzer/26707782.html?ticket=ST-6091859-HGf1dFVdQReZtbfkbw6N-ap4" target="_blank" rel="noreferrer"><em>due to the "link" between the British secret services and the USA, there are fundamental doubts. Brexit simply reveals what data protectors have known for a while, he said. "The surveillance and information exchange activities of the United Kingdom secret services also infringe the EU Charter of Fundamental Rights as inappropriate and excessive state surveillance of citizens</em></a>".</span></span></span></p><p><span lang="EN-GB"><span><span>It can be assumed that the draft Adequacy Decision takes these points into account. The EDPB and the EU Council must now review the draft. </span></span></span><span lang="EN-US"><span><span>Subsequently, the Adequacy Decision can enter into force and will apply for the next four years – it is limited in scope – and provide legal security with respect to the transfer of personal data from the EU to the UK.</span></span></span></p><h3><span lang="EN-GB"><span><span>What Must be done?</span></span></span></h3><p>We recommend that you follow the ongoing procedures closely. Even if the draft decision leads to an adequacy decision under Article 45 para. 3 GDPR (which is not certain) so that the UK is considered a secure third country, there will still be a need for action. In this case, data protection information will need to be adapted (again). Citizens will need to be informed about the transfer of their personal data to a third country. In addition, when transferring personal data to third countries, the legal basis for the transfer must be provided. This guarantee would then be the adequacy decision.</p><p>In any case, keep abreast of developments concerning this complex issue. An action may be brought against the Adequacy Decision and the ECJ may decide - after receiving requests from the national courts for preliminary rulings – to declare the Adequacy Decision invalid, just as it did in its decision in relation to the "<em>Privacy Shield"</em> for the transfer of personal data to the USA.</p><p><span lang="EN-GB"><span><span>Against this background, it may offer more legal certainty to look for partners based in the EU or the EEA where possible.</span></span></span></p><p><a href="https://www.beiten-burkhardt.com/en/experts/katharina-mayerbacher" target="_blank" rel="noreferrer"><span><span><span>Katharina Mayerbacher</span></span></span></a></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-1140</guid>
                        <pubDate>Tue, 23 Feb 2021 17:00:00 +0100</pubDate>
                        <title>GDPR Fine of 14.5 Million Euros Averted</title>
                        <link>https://www.advant-beiten.com/en/news/dsgvo-bussgeld-ueber-145-millionen-euro-abgewendet</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><span lang="EN-US"><span>Immobiliengesellschaft Deutsche Wohnen SE has been able to avert the record fine in the amount of EUR 14.5 million imposed in 2019 for the time being. The Regional Court Berlin considers the fine notice issued by the Berlin Commissioner for Data Protection and Freedom of Information (<em>Berliner Beauftragter für Datenschutz und Informationsfreiheit</em>, BlnBDI) to be ineffective due to "serious deficiencies".</span></span></p><h3><strong><span lang="EN-US"><span>GDPR Fine in Record Amount</span></span></strong></h3><p><span lang="EN-US"><span>In autumn 2019, the BlnBDI has imposed the highest GDPR fine so far on the Immobiliengesellschaft due to the inadmissible storage of personal tenant data. Information partially several years old regarding tenants, including social and health insurance data, employment agreements, tax data and information on financial circumstances has been stored without apparent purpose and legal basis. The used archive system has not provided any possibility to delete the data no longer required. The fine was preceded by two on-site inspections of the BlnBDI in the years 2017 and 2019. Therefore, the BlnBDI criticised especially that the data protection breach had not been remedied during this period. According to the BlnBDI, the calculation of the fine, however, only amounted to approximately half of the scope approved by the GDPR - despite the record amount.</span></span></p><h3><strong><span lang="EN-US"><span>Appeal against the Fine Notice Provisionally Successful</span></span></strong></h3><p><span lang="EN-US"><span>The Immobiliengesellschaft filed an appeal against the fine notice and this appeal was now successful. The Regional Court Berlin notes that the fine notice cannot be the basis of proceedings due to serious deficiencies. According to the Court, the fine notice must have contained information on specific criminal acts of the management personnel of Deutsche Wohnen SE and on their fault. However, this information was missing. Therefore, the proceedings were discontinued. The competent public prosecution can now lodge an immediate appeal against the decision of the Regional Court within one week after service. The BlnBDI has already announced to ask the public prosecution to do so. The final decision in this matter is therefore still pending.</span></span></p><p><a href="https://www.beiten-burkhardt.com/en/experts/susanne-klein" target="_blank" rel="noreferrer"><span><span><span>Susanne Klein</span></span></span></a></p><p><a href="https://www.beiten-burkhardt.com/en/experts/lennart-kriebel" target="_blank" rel="noreferrer"><span><span><span>Lennart Kriebel</span></span></span></a></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-1036</guid>
                        <pubDate>Tue, 07 Jul 2020 18:00:00 +0200</pubDate>
                        <title>Brexit and Data Protection: Secure Your Data Transfers!</title>
                        <link>https://www.advant-beiten.com/en/news/brexit-und-datenschutz-datentransfers-absichern</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><span><span><span>The transitional period for the UK's withdrawal from the European Union is not extended and thus ends on</span></span></span><span><span><span> 31 December 2020. No use has been made of the consensual extension of the transitional period that is possible under the withdrawal agreement. We assume that there will also be no or only a very limited free trade agreement by 31 December 2020 - this would thus result in a "No Deal Brexit".</span></span></span></p><p><span><span><span>Both European and British companies in all sectors and of all sizes will be faced with major challenges. In the area of data protection law, companies must quickly take precautions to ensure that data transfers between the EU and the UK remain possible even after the end of the transition phase starting 1 January 2021.</span></span></span></p><h3><span><span><span>The British view on data transfer</span></span></span></h3><p><span><span><span>On 31 December 2020, EU law (with some exceptions) will be fully incorporated into UK national law. This also applies to the GDPR, which will be incorporated verbatim into national law ("UK-GDPR"), excluding certain articles on cooperation with other European authorities and adapting to the British situation. Hence, for the time being, no changes in the content of data protection law are evident. </span></span></span></p><h3><span><span><span>The EU view on data transfer</span></span></span></h3><p><span><span><span>However, as of 31 December 2020, Great Britain is to be treated as a third country from a European perspective. After that date, personal data may only be transferred to Great Britain if an adequate level of data protection is ensured for the transfer, as set out in Articles 44 et seq. GDPR. In principle, the parties involved are seeking an "adequacy decision" which would in principle permit data transfers from the EU to the United Kingdom in accordance with Article 45 GDPR. However, the wording of such an adequacy decision before the end of the transitional phase is by no means certain. For one thing, other countries (e.g. South Korea) have been lining up for a long time, and they would be highly dissatisfied with the UK's preference in terms of timing. On the other hand, despite an almost identical legal situation as regards data protection, there is a realistic possibility that a decision on adequacy will not be taken (at least not for the time being). The far-reaching surveillance laws - in particular the <em>British Investigatory Powers Act 2016</em> - and the considerable powers of the secret services in the UK give rise to considerable concerns about the adequacy decision.</span></span></span></p><h3><span><span><span>Need for action: Securing data transfer and making necessary adjustments</span></span></span></h3><p><span><span><span>For this reason, <span>controllers</span> responsible within the EU should prepare for the Brexit without a quick decision on adequacy. Rather, they should ensure that data transfers only take place with appropriate guarantees. Should no adequacy decision have been reached by the end of the year, it is recommended to conclude the standard contractual clauses published by the EU Commission with data recipients in the UK for data transfers via the channel.</span></span></span></p><p><span><span><span>In addition, there is a need for further adjustment both in terms of documentation requirements (e.g. updating the data protection statement and the list of processing activities) and internal organisational issues (e.g. double reporting of data protection incidents, insofar as European and UK data subjects are affected).</span></span></span></p><p><span><span><span><span lang="EN-US">Controllers</span> responsible should address the implementation of these measures as soon as possible, with a view to implementing them before the turn of the year. As of the beginning of next year, supervisory measures are imminent.</span></span></span></p><p><a href="https://www.beiten-burkhardt.com/en/experts/dr-axel-von-walter" target="_blank" rel="noreferrer"><span><span><span>Dr Axel von Walter</span></span></span></a></p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-939</guid>
                        <pubDate>Sun, 15 Mar 2020 17:00:00 +0100</pubDate>
                        <title>Coronaviurs: Impact on IT Contracts</title>
                        <link>https://www.advant-beiten.com/en/news/coronavirus-auswirkungen-auf-it-vertraege</link>
                        <description></description>
                        <content:encoded><![CDATA[<p></p><p><span><span><span lang="EN-US">The coronavirus "SARS-CoV-2" is becoming an increasing burden for human beings and the economy. In view of the rapid development, an illness of employees or an official quarantine of the business premises can also lead for IT contractors to the fact that obligations can no longer be met fully. This can give rise to claims of the principals.</span></span></span></p><p><span><span><span lang="EN-US">In the light of recent events, we provide you with a brief overview of the main questions arising in the context of dealing with IT contracts for contractors. Below you will also find a list with recommendations which we have compiled based on the legal requirements and our experiences.</span></span></span></p><h3><span><span><span lang="EN-US">1. Information requirements</span></span></span></h3><p><span><span><span lang="EN-US">As soon as it becomes evident that the fulfilment of contracts is delayed or stopped, you should inform your contract partners immediately and as a precautionary measure.</span></span></span></p><p><span><span><span lang="EN-US">IT contracts regularly contain information requirements of the contractor, for instance for the case that the contractor threatens to be in default with his/her provision of services or that impediments to the provision of services are foreseeable. If the contractor does not sufficiently fulfil these obligations, claims for damages may be impending for this reason alone.</span></span></span></p><p><span><span><span lang="EN-US">If information requirements are not explicitly regulated in the IT contract, then they may also stem from statutory provisions. Since each contracting party is obliged to be considerate of the interests of the other party. This also includes informing the contracting party that a delay in the provision of the services is impending.</span></span></span></p><h3><span><span><span lang="EN-US">2. Obligation to provide services</span></span></span></h3><p><span><span><span lang="EN-US">For many contractors, the question arises at what point in time they are no longer obliged to provide services and whether this applies permanently or only temporarily.</span></span></span></p><p><span><span><span lang="EN-US">As is so often the case: It depends on the particular case. Under any circumstances, however, contractors should not assume in general that they are no longer obliged to provide services. In such case, not only claims for damages may be impending, but in the worst case the reversed transaction of the entire contract or a substitute performance by a competitor at your expense.</span></span></span></p><p><span><span><strong><span lang="EN-US"><span><span>2.1 Impossibility to provide services</span></span></span></strong></span></span></p><p><span><span><span lang="EN-US">German law initially provides that a debtor does no longer have to provide a service if the provision of the service is impossible for him/her. This can also apply temporarily. The debtor may also refuse the provision of services if the debtor´s necessary expenditure is grossly disproportionate to the interest in the provision of services of the creditor. The law recognizes several case groups here in detail, but all of them are subject to high requirements. An impossibility will be rather the exception than the rule.</span></span></span></p><p><span><span><span lang="EN-US">IT projects may be quickly jeopardised as a result of a loss of personnel. It also involves a lot of effort to find suitable replacement staff and this is usually not suitable to be able to prevent a delay in time due to the necessary training period of replacement staff when schedules are tight. Also due to other circumstances, the implementation of IT projects can currently be disrupted or - allegedly - be made impossible.</span></span></span></p><p><span><span><span lang="EN-US">Nevertheless, the principle applies here: For your own safety, do not assume in general that you are not obliged to the provision of services. The legal requirements for an "impossibility" or a disproportionate effort of the provision of services are high, in most cases too high. Precisely in the IT area, most of the services can be provided "remotely" from all over the world, i.e. even an official quarantine order does not necessarily have to lead - thanks to home office - to the fact that the provision of services becomes impossible. If you wrongly refuse the provision of services, you may be exposed to claims for damages - and apart from that you may be further obliged to provide services.</span></span></span></p><p><span><span><strong><span lang="EN-US"><span><span>2.2 A question of fault</span></span></span></strong></span></span></p><p><span><span><span lang="EN-US">But only since a temporary impossibility and, thus, also a release from the obligation to provide services are not given, this does not yet mean that the current exceptional situation is completely disregarded. Most of the adverse legal consequences (claims for damages and similar) require a fault. A fault is in principle assumed in case of a breach of a service obligation, but the contractor can exculpate himself/herself here, i.e. he/she can prove that he/she is not at fault for the delay in the provision of services and he/she is not even slightly negligent.</span></span></span></p><p><span><span><strong><span lang="EN-US"><span><span>2.3 Contractual guarantees</span></span></span></strong></span></span></p><p><span><span><span lang="EN-US">But caution is recommended here, too. In many cases, contractors have assumed a contractual guarantee for the provision of services, in particular a provision of critical milestone services no later than at a certain point in time. Depending on the structuring of such a guarantee, this can result in a liability without fault in the event of services not provided or not provided in time and thus the breach of the guarantee provided. In such cases, also an exculpation cannot be considered.</span></span></span></p><p><span><span><strong><span lang="EN-US"><span><span>2.4 Contractual clauses on force majeure</span></span></span></strong></span></span></p><p><span><span><span lang="EN-US">But even in case of the apparent breach of guarantees, contractual clauses may possibly still help, which are designed to address exceptional situations such as epidemics or other catastrophes. Many agreements provide for such so-called force majeure clauses. In the event of force majeure, these clauses should exempt the parties from their service obligations partially or entirely, often limited to the duration of the event.</span></span></span></p><p><span><span><span lang="EN-US">Force majeure is an event inflicted from outside which cannot be averted even with the utmost diligence that can reasonably be expected and which cannot be attributed to the spheres of the contracting parties. The consequences of epidemics may lead to the assumption of force majeure in individual regions. Whether and when you are actually exempt from a service obligation - and to which rights your contract partner is entitled in this case - depends, however, on the wording of the specific clause, the applicable law and the details of the case. There are countless modifications for these clauses so that an individual assessment is always required here. It can also make a difference whether such clause is only part of the GTC or whether it was negotiated in an individual contract.</span></span></span></p><p><span><span><span lang="EN-US">Relevant IT contracts should therefore be examined for the existence and the effectiveness of force majeure clauses. However, you should not hastily rely on a force majeure clause under any circumstances.</span></span></span></p><h3><span><span><span lang="EN-US">3. Liability, rescission, termination, contractual adjustments</span></span></span></h3><p><span><span><span lang="EN-US">If you cannot meet your service obligations under an IT contract, this may result in claims for damages of the principal or also in a termination or reversed transaction of the contract. In the worst case, a warning of the principal is not even necessary for this purpose.</span></span></span></p><p><span><span><span lang="EN-US">We therefore strongly recommend that you take all measures available in order to maintain the operating capability of your company. This includes in particular personnel matters as well as preventive measures for the containment of the coronavirus. Please document all measures, decisions and other proceedings such as internal discussions etc. in order to be able to provide evidence in the case of dispute that you are not at fault if you are no longer able to provide a service.</span></span></span></p><p><span><span><span lang="EN-US">In doing so, also caution is recommended: Too far-reaching prevention measures, such as the deliberate decision to no longer execute certain orders temporarily for the welfare of the employees, may lead to an intentional breach of contract in the worst case, whereby you also deprive yourself of all limitations of liability. Preparedness and response measures of a company are one´s own enterpreneurial decisions and do not necessarily lead to the assumption of force majeure. Here, at least an increased need for justification exists.</span></span></span></p><p><span><span><span lang="EN-US">Should it therefore be apparent that certain works can no longer be completed with a good conscience, you should always attempt here to find at first an adequate solution together with your contract partner. In the individual case, even a - mutual - right to contractual adjustments may exist.</span></span></span></p><h3><span><span><span>Our recommendations:</span></span></span></h3><ul><li><span><span><span><span><span><span lang="EN-US">Examine whether a timely provision of services actually has become objectively impossible.</span></span></span></span></span></span></li><li><span><span><span><span><span><span><span><span><span lang="EN-US">Examine your contractual relationships for the existence and the arrangement of<br>- Information requirements<br>- Guarantees<br>- Force majeure clauses<br>- Contractual penalties without fault or other sanctions</span></span></span></span></span></span></span></span></span></li><li><span><span><span><span><span><span><span><span><span lang="EN-US">Inform your contract partners early on threatening failures to provide services and delays.</span></span></span></span></span></span></span></span></span></li><li><span><span><span><span><span><span><span><span><span lang="EN-US">By contacting your principals early, a constructive environment and solutions for both sides can be created.</span></span></span></span></span></span></span></span></span></li><li><span><span><span><span><span><span><span><span><span lang="EN-US">Under any circumstances, do not hastily assume that you are no longer obliged to provide services.</span></span></span></span></span></span></span></span></span></li><li><span><span><span><span><span><span><span><span><span lang="EN-US">Take and document all operational precautionary measures to contain the coronavirus and to maintain your business operations.</span></span></span></span></span></span></span></span></span></li><li><span><span><span><span><span><span><span><span><span lang="EN-US">Always distinguish whether impediments to the provision of services actually originated from force majeure or whether entrepreneurial decisions lead to the impediment to the provision of services.</span></span></span></span></span></span></span></span></span></li><li><span><span><span><span><span><span><span><span><span lang="EN-US">Examine whether for the case of a closure of the company or failures to provide services an insurance exists which covers possible damages on your part.</span></span></span></span></span></span></span></span></span></li></ul><p><a href="https://www.beiten-burkhardt.com/index.php/en/experts/dr-florian-jakel-gottmann" target="_blank" rel="noreferrer">Dr Florian Jäkel-Gottmann</a><br><br><span><span><span><span><span><a href="https://www.beiten-burkhardt.com/en/experts/lennart-kriebel" target="_blank" rel="noreferrer">Lennart Kriebel</a></span></span></span></span></span></p><p><a href="https://www.beiten-burkhardt.com/en/experts/wojtek-ropel" target="_blank" rel="noreferrer"><span><span><span><span><span>Wojtek Ropel</span></span></span></span></span></a></p><p>&nbsp;</p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-2530</guid>
                        <pubDate>Wed, 10 Jul 2019 18:00:00 +0200</pubDate>
                        <title>The International Comparative Legal Guide to: Data Protection 2019 - Germany</title>
                        <link>https://www.advant-beiten.com/en/news/international-comparative-legal-guide-data-protection-2019-germany</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>6th Edition</strong></p><p><em><strong>A practical cross-border insight into data protection law</strong></em></p><p>The ICLG to: Data Protection Laws and Regulations covers relevant legislation and competent authorities, territorial scope, key principles, individual rights, registration formalities, appointment of data protection officer and of processors - in 42 jurisdictions.</p><p>We are happy to contribute to this important publication with a whole chapter written by <a href="https://www.beiten-burkhardt.com/de/experten/dr-axel-von-walter" target="_blank" rel="noreferrer">Dr. Axel von Walter</a>.</p><p>If you are interessted in the whole publication: it is available on the webpage <a href="https://iclg.com/practice-areas/data-protection-laws-and-regulations/germany" target="_blank" rel="noreferrer">ICLG (International Comparative Legal Guides)</a>.</p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-2501</guid>
                        <pubDate>Wed, 15 May 2019 18:00:00 +0200</pubDate>
                        <title>Beyond the buzz? Getting to the crux of legal tech</title>
                        <link>https://www.advant-beiten.com/en/news/beyond-buzz-getting-crux-legal-tech</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>The current (May) issue of fivehundred -&nbsp;the Legal 500 magazine&nbsp;- quotes Dr Axel von Walter a number of times on the 'legal tech' issue. The article outlines the meaning and innovations of legal tech, and professional changes it might bring about. Dr von Walter addresses whether legal tech might even replace lawyers in the future.</p><p>You will find the entire article on the <a href="https://indd.adobe.com/view/f0db10c7-c67b-4ffc-831a-d770a887ee65" target="_blank" rel="noreferrer">Legal 500 website </a>starting on page 91.</p>]]></content:encoded>
                        
                            
                                <category>IT and the Law of Data</category>
                            
                                <category>Digital, Media &amp; Technology</category>
                            
                        
                        
                    </item>
                
            
        </channel>
    </rss>


