IT & Data Law06.07.2026 Newsletter
Focus IT&C - 2nd Quarter of 2026
European digital regulation continues to evolve: with the draft Cloud and AI Development Act, the new AI Omnibus, landmark rulings by the European Court of Justice and the Munich Regional Court I, and the announced data protection reforms, numerous new requirements and opportunities are emerging for businesses. The focus is on digital sovereignty, AI compliance, the handling of data protection rights, liability for AI-generated content and the future shape of data protection law. Find out which developments businesses should be keeping an eye on right now and what is particularly important in practice.
Developments in IT&C law
1. ECJ ruling ‘Brillen Rottler’: Limits on abusive requests for information
3. An overview of the draft European AI and Cloud Computing Act
4. ECJ ruling on the exclusion of evidence and data protection
5. Key amendments to the AI Regulation introduced by the ‘AI Omnibus’
6. Planned data protection reform
1. ECJ ruling ‘Brillen Rottler’: Limits on abusive requests for information
In its judgement of 19 March 2026 (Case C‑526/24 – Brillen Rottler), the European Court of Justice (ECJ) has addressed important questions concerning the right of access under Article 15 of the General Data Protection Regulation (GDPR) and liability under Article 82 of the GDPR.
In practice, it is precisely the handling of the right of access that causes problems for businesses, as processing such requests is time-consuming and, at the same time, it remains largely unclear under what specific conditions businesses may refuse to provide a comprehensive response. In particular, it was previously unclear whether even an initial request for information from a data subject could be classified as ‘excessive’ within the meaning of Article 12(5) of the GDPR. Such cases occur frequently, particularly in the context of strategically motivated requests (“GDPR hopping”).
The proceedings were based on a set of facts in which there was strong evidence that the claimant’s sole intention was to misuse data protection law as a vehicle for asserting claims for damages.
A private individual from Austria initially signed up for a newsletter via the website of Brillen Rottler, an optician based in Arnsberg (Germany). A few days later, she submitted a request for information under Article 15 of the GDPR. Brillen Rottler refused to provide the information, citing an abusive and excessive request. In doing so, the company cited publicly available information indicating that the data subject had followed the same pattern in numerous cases: registration, request for access, followed by a claim for damages.
The data subject continued to pursue their right to access and additionally claimed non-pecuniary damages under Article 82 of the GDPR in the amount of EUR 1,000. Brillen Rottler subsequently brought an action seeking a declaration that no claim for damages existed. The Arnsberg Local Court referred several questions to the CJEU regarding the interpretation of the GDPR, including the possibility of classifying a first request for access as excessive, the significance of the motivation to claim damages, and the scope of Article 82 of the GDPR.
Key points of the judgment
The CJEU held that even a first request for access to data may be excessive and thus abusive. The decisive factor is not the number of individual requests, but their purpose. A request may be excessive if, whilst formally meeting the requirements of Article 15 of the GDPR, it does not serve the purpose of monitoring data processing and verifying its lawfulness, but is designed solely to artificially create the conditions for a subsequent benefit under the GDPR.
At the same time, the CJEU clarified that the controller bears the burden of proof and must substantiate an abusive intent on the basis of all the circumstances of the individual case. In the Court’s view, publicly available information regarding a systematic abusive practice may be taken into account in the assessment.
At the same time, the CJEU clarifies in its judgment the liability under Article 82 of the GDPR. A claim for damages does not require unlawful processing in the strict sense. Even a breach of the right of access under Article 15 of the GDPR may give rise to compensable damage.
Conclusion and Outlook
Firstly, it is to be welcomed that the CJEU has clarified in its judgment that an abusive motivation on the part of the data subject may preclude their right of access, even in the case of an initial request. Data controllers are thus provided with a further tool to defend themselves against abusive, strategically motivated requests for access.
Nevertheless, the liability risk for companies when dealing with requests for access remains high. In practice, it is often extremely difficult to demonstrate the data subject’s underlying motivation in a manner that would stand up in court. If this cannot be done, the company bears the consequences, as it bears the burden of proof. We therefore recommend that the defence of abusive behaviour should only be raised after careful consideration.
Furthermore, companies should review their processes for handling data subjects’ requests to ensure that suspected cases of abuse are documented in a structured manner. The ECJ’s ruling provides greater clarity on dealing with ‘GDPR-hopping’, but does not replace the need for a careful case-by-case assessment.
Marco Degginger
2. Munich Regional Court I: Liability for AI search results – ‘AI overview’ as the search engine’s own content
Generative AI is increasingly finding its way into search engines. Instead of merely displaying links, search engines now provide ‘answers’, often under headings such as ‘AI overview’. The Munich I Regional Court (LG) has now had to rule for the first time on the extent to which a search engine operator is liable for content in such AI-generated overviews that infringes personal rights. In its judgement of 28 May 2026 (Case No. 26 O 869/26), the court clearly defined the search engine operator’s liability and imposed far-reaching obligations to refrain from certain actions upon it.
In addition to the traditional list of results, Google offers an additional format in its internet search engine: a generative AI summarises “representative results” and displays these as an “AI-powered overview”. This overview displays automatically generated texts accompanied by links to third-party websites.
For search queries combining the name of a publishing house and its imprint with terms such as ‘scam’ – some of which were suggested via the autocomplete function – an ‘AI overview’ appeared in which the two publishing houses were linked to scams, subscription traps and dubious business practices. In some cases, the AI overview referred to sources without the links containing any corresponding statements.
The publishing house subsequently took legal action against Google. It considered these (inaccurate) AI-generated statements to be a violation of its corporate personality rights. Google essentially defended itself by arguing that it was merely a search engine operator, automatically displaying third-party content, and was liable, at most, as an indirect infringer under a ‘notice-and-takedown’ model. The AI overview was clearly just a summary of third-party content; moreover, there were numerous negative user reviews and forum posts supporting the statements.
The claimants sought interim relief to prohibit Google from disseminating the aforementioned statements in AI summaries (Sections 823(1) and 1004 of the German Civil Code (BGB), applied by analogy in conjunction with Article 2(1) and Article 19(3) of the German Basic Law (GG)).
The court’s decision
The Regional Court of Munich I essentially ruled in favour of the plaintiffs and prohibited the defendant from disseminating the key, reputation-damaging statements.
The crux of the decision lies in the classification of the “AI-generated summary” as content created by Google itself. Unlike a mere list of results containing links to third-party websites, for which the operator is liable only as an indirect interferer, the AI here formulates an independent response, structures the content and, in some cases, makes new statements, for example by establishing links to other companies. From the perspective of a reasonable user, this is therefore not merely third-party content. The defendant introduced the AI itself, controls the algorithms and must be held responsible for the content. It is therefore liable as a direct infringer (Section 1004 of the German Civil Code (BGB)) and cannot rely on either host provider privileges (Article 6(1) of the German Data Services Act (DSA)) or a purely ‘notice-and-takedown’ model. Even a note stating ‘Created with AI’ does not alter this responsibility.
The ‘AI overview’ is not essential to the functioning of the internet; therefore, stricter duties of scrutiny are reasonable. At the very latest following the specific indications provided by the claimants, such as the letter of warning and the online form, Google should have reviewed the content of the AI response. The court rejected a restriction to ‘obvious’ infringements, as this would otherwise create a loophole in protection.
False statements of fact are impermissible; expressions of opinion lose their protection if they are based on false facts. Among other things, the court prohibited statements alleging that the plaintiffs were ‘known for dubious business practices’ or ‘scams’, were associated with certain companies, lured customers into ‘subscription traps’, continued to demand payment despite payment having already been made, frequently changed names or URLs, failed to unlock paid content, and were unreachable. The defendant was unable to substantiate the truth of these claims; user reviews and forum posts are not sufficient for this purpose. On balance, the plaintiffs’ interest in protection prevails.
Conclusion
The judgement of the Munich I Regional Court is one of the first decisions to clarify liability for AI-generated search results. Although this judgement is not yet final, it may increase the pressure on search engine operators. It sends an important signal that anyone who provides AI-generated answers as an independent source of information must also assume responsibility for their content.
Particularly against the backdrop of the growing importance of AI-generated answers in search engines, this ruling is of considerable practical relevance: users often base their decisions on the AI summaries displayed immediately, without checking the linked sources in detail. Incorrect or inaccurate statements can therefore spread particularly quickly and have a significant impact on the reputation of companies and individuals.
Melissa Irtel
3. An overview of the draft European AI and Cloud Computing Act
With the draft Cloud and AI Development Act (“CADA”), presented on 3 June 2026, the European Commission is laying the next building block for an independent European cloud and AI ecosystem. The aim is to accelerate the expansion of energy-efficient data centres, reduce dependence on non-European hyperscalers and establish a binding sovereignty framework for cloud services in the public sector.
Over 70 per cent of the European cloud market is currently controlled by three non-European providers; the market share of European competitors has almost halved between 2017 and 2022. Against this backdrop, the CADA is intended to create a single market framework that addresses investment, infrastructure and sovereignty in equal measure.
The draft is structured around three key areas of action: research, development and innovation; capacity building; and autonomy. The aim is to at least triple data centre capacity in the EU within the next five to seven years.
Scope of the Sovereignty Framework
At the heart of the CADA, however, is the ‘Union Cloud Computing Sovereignty Framework’ set out in Article 16 et seq. of the CADA. It is aimed at cloud computing service providers wishing to provide services to EU institutions and public bodies. In accordance with NIS2, cloud services are defined as digital services that enable on-demand access to a scalable pool of shared computing resources. This explicitly includes on-demand access to AI systems as a service, but not the AI system or the underlying model itself.
On the demand side, the target audience comprises, in particular, public authorities within the meaning of the Open Data Directive, as well as EU institutions, bodies and agencies that wish to use cloud services for activities in NIS2 sectors and in security-related areas such as national security, internal security, border protection, defence, justice and law enforcement. For these activities, Member States and Union institutions are to carry out risk assessments in future and determine which activities require which level of security.
Private companies will initially only be covered indirectly. Companies in the sectors covered by the NIS2 Directive may voluntarily carry out risk assessments in accordance with Article 29. For particularly critical sectors, however, the Commission may make the carrying out of such assessments and the implementation of risk mitigation measures mandatory. It is therefore foreseeable that operators of critical infrastructure, in particular, will in future assess their cloud service providers against the CADA sovereignty levels, even though the current draft is primarily designed for public procurement.
The framework comprises graduated security levels 1–4, which impose progressively higher requirements on cloud computing services. Once the CADA comes into force, Member States and EU institutions are to define promptly which public tasks are to be assigned to which security level. All procurements for public bodies must be classified at Level 1 as a minimum. Contracting authorities whose activities are classified as relevant to public order may only use services that meet security levels 2 to 4.
The security levels in detail:
Security Level 1: The provider must be established in the EU; the majority of infrastructure and data must be localised within the EU; limited outsourcing to third countries is permitted, subject to strict governance and security requirements.
Security Level 2: Complete localisation of the provider, subcontractors, infrastructure, assets and staff within the EU; a cybersecurity certificate; strict data localisation; and the first comprehensive requirements regarding third-country control and the software supply chain.
Security Level 3: For particularly sensitive applications; additionally, EU citizenship and, where applicable, security clearances for staff, extensive exclusion of third-country control with only very limited exceptions.
Security Level 4: For highly sensitive data; ‘high’ certificate, exclusively EU-based and EU-controlled providers and subcontractors, full data localisation and an absolute ban on third-country control.
Interaction with other EU legal acts
The draft CADA complements existing regimes such as the GDPR, NIS2 and the Data Act, without replacing them. NIS2 and the GDPR remain decisive for cybersecurity and data protection respectively – including incident reporting. The CADA primarily addresses the issues of sovereignty, infrastructure and public procurement. By contrast, the Data Act regulates, in particular, access to data, its use, and cloud switching. With its security levels and the obligation to migrate within twelve months, the CADA requires cloud services to support portability in practice. Specific conflict-of-law or priority rules are not set out in detail in the extracts provided and remain open in this respect.
Expected timetable
The Regulation is due to enter into force one year after its publication. Within this year, Member States must, amongst other things, draw up national strategies for cloud computing and AI, designate competent authorities and identify the first Data Centre Acceleration Zones. Public bodies must carry out their first risk assessments within one year of the regulations becoming applicable and subsequently repeat these every two years. Migrations due to increased risks must be implemented within a maximum of twelve months.
For cloud computing service providers serving the public sector in the EU, the draft CADA marks a paradigm shift: alongside traditional security requirements, there are now detailed sovereignty criteria covering location, ownership, control by third countries and the entire software supply chain.
Hyperscalers with a strong presence in third countries will have to adapt their governance and operating models to achieve higher levels of security. At the same time, European providers are given a clear framework against which to position themselves as a sovereign alternative. The final form of the legislation will depend on the further legislative process. In particular, the specific levels of fines and the practical interplay with the GDPR, NIS2 and the Data Act remain to be seen.
Anselm Auer
4. ECJ ruling on the exclusion of evidence and data protection
On 18 June 2026 (C 484/24), the European Court of Justice (ECJ) handed down an important ruling on the implications of a data protection breach for the admissibility of evidence in civil proceedings. The ruling deals exclusively with the implications of a data protection breach for the court, but also provides insights into the implications for the party concerned.
The judgment was based on a case from Germany in which an employer sued an employee for damages because she had sold company property via eBay. To this end, the employer had apparently (unlawfully) accessed the employee’s private eBay account and submitted evidence obtained from it to the court. The court sought to determine whether the General Data Protection Regulation (GDPR) precluded the use of such evidence.
The ECJ ruled that the correct legal basis for the court is Article 6(1)(c) of the GDPR and not, for example, Article 6(1)(e) of the GDPR. The court has a legal obligation to fulfil by ruling on the admissibility of evidence and, where appropriate, assessing it. The CJEU then went on to rule, having weighed up Articles 7 and 8 of the Charter of Fundamental Rights, that a prior breach of the GDPR does not automatically and in every case lead to a prohibition on the use of evidence, but that this is, in principle, a matter for national case law. The GDPR therefore does not require a prohibition on the use of evidence under national procedural law. German courts may continue, within the framework of existing German supreme court case law, to assess evidence even if it was previously obtained unlawfully by the parties.
Unsurprisingly, the ECJ further ruled that Article 17(3)(e) of the GDPR does not constitute a legal basis for asserting or defending legal claims. However, a legal basis may in principle be found here under Article 6(1)(f) of the GDPR (legitimate interest) or, for sensitive data, under Article 9(2)(f) of the GDPR (which also expressly mentions the courts).
In this respect, interesting conclusions arise for courts and the parties to proceedings: under German case law on procedural law concerning prohibitions on the use of evidence, courts may continue to use personal data obtained in breach of the GDPR and submitted by a party, but must in doing so comply with the principle of data minimisation.
ECJ relaxes requirements for prohibitions on the use of evidence
Whilst, according to previous case law of the Federal Labour Court (BAG), a prohibition on the use of evidence had to be considered in any event where a constitutionally protected legal position – such as the general right of personality – prohibits the perpetuation of the infringement through continued use of the evidence, the ECJ appears to be further relaxing this requirement as well. The ECJ thus holds that courts may admit evidence containing unlawfully processed personal data even where there is no legitimate interest going beyond the mere interest in the evidence itself. However, before disclosing such data to parties or third parties, the court must assess whether the disclosure is limited to what is strictly necessary and, where appropriate, take measures to minimise the interference with the right to data protection, for example through anonymisation.
The courts are not responsible for penalising the parties for committing such infringements.
Conversely, however, it does not follow that the parties – in this case, the employer – are also entitled to collect and submit this data. The ECJ has indicated that the legal basis of legitimate interest cannot apply in cases of unlawful collection and use of personal data (in this instance, there is likely to be no legitimate interest to begin with). Rather, the parties remain liable for unlawfully processing personal data and may themselves be held accountable for this. In the case in question, the employee could be entitled to compensation under Article 82 of the GDPR, or the party could face administrative fines from the supervisory authority under Article 83 of the GDPR.
Winning a civil case on the basis of unlawfully obtained evidence could therefore be a Pyrrhic victory. Companies should carefully consider whether the advantages associated with the unlawful collection and submission of evidence outweigh the potential disadvantages under data protection law. Strategically, however, the submission of evidence obtained in this way may, under certain circumstances, be utilised to settle cases out of court.
We regularly advise companies on internal investigations, in particular on the lawful processing of data during such investigations.
Dr. Jürgen Hartung
Isabel Hexel
5. Key amendments to the AI Regulation introduced by the ‘AI Omnibus’
On 29 June 2026, the Council of the EU adopted the so-called ‘AI Omnibus’ (Digital Omnibus on AI) to simplify and streamline the rules governing artificial intelligence (AI). The European Parliament and the Council had previously reached a political agreement on the legislative package during the trilogue process in early May. The text of the legislation will shortly be published in the Official Journal and will enter into force on 2 August 2026.
The AI Omnibus is an amending act designed to simplify, harmonise and reduce EU regulations on AI, in particular the AI Regulation (AI Reg) (Regulation (EU) 2024/689). In addition, the AI Omnibus postpones key deadlines for high-risk AI and grants companies more time to implement the AI Regulation. The aim is to facilitate investment in European AI applications.
Substantive changes
Changes to data protection law
The AI Omnibus provides for a new legal basis for the processing of sensitive data (Art. 4a AI Regulation, as amended). This allows providers and operators of AI systems and models to process special categories of personal data (Art. 9 GDPR). However, this applies only for the purposes of bias detection and bias correction in high-risk AI systems, subject to strict conditions. This includes, in particular:
- The objective cannot be effectively achieved using other data, such as anonymised or synthetic data.
- Strict data protection and security measures apply, including pseudonymisation.
- Access to the data is strictly limited and is documented to prevent misuse.
- The data must not be disclosed to third parties.
- The data must be erased once the purpose has been fulfilled or the retention period has expired.
- The necessity of the processing and the absence of suitable alternatives must be documented.
The Fundamental Rights Impact Assessment (Fundamental Rights Impact Assessment (FRIA), Art. 27 of the AI Regulation) is being more closely integrated with the Data Protection Impact Assessment (Data Protection Impact Assessment (DPIA), Art. 35 of the GDPR). In future, organisations will be able to utilise existing DPIAs by including references or integrating relevant content into FRIAs. This significantly reduces the documentation burden.
New prohibited practices
The AI Omnibus Directive expands the list of prohibited AI practices set out in the AI Regulation (Article 5 of the AI Regulation). In future, so-called “Nudify apps” and other AI systems designed to generate non-consensual sexual or intimate content (NCII), depictions of sexualised violence, and child sexual abuse material (CSAM) will be expressly prohibited. It is already prohibited to place on the market or put into service AI systems that are either intended to generate such content or do not provide for adequate technical and organisational safeguards. The dissemination of such content is already prohibited under the Digital Services Act.
Changes to regulations on high-risk AI systems
The AI Omnibus is intended to better avoid overlaps between sector-specific regulations and the AI Regulation. Consequently, the Machinery Regulation is excluded from the scope of the high-risk provisions of the AI Regulation (Annex I, Section A) and moved to Annex I, Section B. Such machinery will no longer fall under the AI Regulation, provided that an AI-specific sectoral safety regime exists. This means that (only) if the Commission introduces AI-specific provisions into sectoral legislation by means of delegated acts will the high-risk requirements under the AI Regulation cease to apply. These delegated acts must be applicable by 2 August 2028.
Furthermore, sector-specific AI regulations take precedence (Article 2(13) of the AI Regulation): For other high-risk AI systems in sectors listed in Annex I, Section A – such as toys or lifts – certain obligations under the AI Regulation (Articles 9–15 and 17–25 of the AI Regulation) may be limited if the applicable EU law provides equivalent or higher levels of protection for health, safety and fundamental rights. To this end, the European Commission may adopt delegated acts by 2 August 2027.
Weakening of the AI literacy requirement
The legal obligation for AI providers and operators to ensure that their staff have sufficient AI literacy (AI literacy; Article 4 of the AI Regulation) is being weakened. Instead of a binding obligation, the AI Omnibus Act will in future require companies to actively promote AI literacy amongst their staff. Responsibility for the general promotion of AI literacy is shifted more towards the European Commission and the Member States. Specific training obligations for operators of high-risk applications remain in place.
Relief measures for SMEs and SMCs
The AI Omnibus provides for further relief measures. For small and medium-sized enterprises (SMEs, i.e. up to 249 employees and up to 50 million euros’ annual turnover), the AI Regulation currently provides for relief measures, such as simplified documentation, reduced maximum penalty limits and fees, as well as support measures from Member States. These relief measures will be extended to so-called small mid-cap companies (SMCs, i.e. 249–750 employees or an annual turnover of 50–150 million euros or a balance sheet total of up to 129 million euros).
Changes to the dates of application
The AI Omnibus will enter into force on 2 August 2026. From that date, according to the current version of the AI Regulation, the rules for high-risk AI systems and transparency obligations covered by the substantive amendments in the AI Omnibus are to apply.
Consequently, the AI Omnibus provides for the adjustment of the deadlines and timetables relevant to businesses regarding the application of the requirements and obligations for high-risk AI. These replace the original start date for the high-risk AI obligations set out in the AI Regulation (2 August 2026). This gives businesses considerably more time to implement AI compliance.
2 December 2026:
From 2 December 2026, the obligation for providers to label AI-generated content (Article 50(2) of the AI Regulation) is to apply to products placed on the market before 2 August 2026. The effective date has been brought forward from 2 February 2027. This affects companies that publish AI-generated text, images, videos and audio, or incorporate them into products.
The other key transparency obligations under Article 50 of the AI Regulation will apply as planned from 2 August 2026 and are not affected by the AI Omnibus. This concerns the obligation for providers to inform users about AI interaction (paragraph 1), as well as the obligation for operators to inform data subjects about emotion recognition (paragraph 3) and to label deepfakes and AI-generated texts (paragraph 4).
Furthermore, companies have until this deadline to adapt their AI systems to the new regulations on prohibited AI practices.
2 August 2027:
National authorities must have established AI real-world laboratories by this date.
2 December 2027 (at the latest):
Under the AI Omnibus, obligations for high-risk AI systems (Annex III) will not come into force until this date (rather than 2 August 2026). This applies, for example, to sectors such as critical infrastructure, education and employment.
This deadline is to be linked to the availability of standards or other support instruments from the European Commission. Without such harmonised standards, a conformity assessment under Article 43 of the AI Regulation is not possible. Should the European Commission adopt a decision regarding high-risk AI systems confirming that suitable support measures are in place, these provisions will enter into force six months after its adoption. However, 2 December 2027 is the cut-off date from which the relevant regulations are to apply at the latest.
The European Commission had already published a draft set of guidelines for the classification of high-risk AI systems on 19 May 2026. Technical standards, and in particular a decision confirming their availability, do not yet exist.
2 August 2028 (at the latest):
From 2 August 2028, regulations for AI systems acting as safety components in regulated products (Annex I) – that is, for high-risk AI systems embedded in products – are to apply (instead of 2 August 2026). This applies, for example, to toys, lifts and medical devices.
This deadline is also to be linked to the availability of standards or other support instruments from the European Commission. Twelve months after the adoption of a decision relating to AI systems embedded in products, the relevant regulations are to apply. 2 August 2028 represents the latest possible deadline in this regard.
The European Commission’s draft guidelines for the classification of high-risk AI systems also cover AI systems as set out in Annex I to the AI Regulation.
What does this mean in practice?
With the AI Omnibus, the European Commission aims to facilitate the practical implementation of the AI Regulation and align it more closely with the needs of industry. In particular, the postponement of key compliance obligations for high-risk AI systems gives companies more time to prepare internal processes, governance structures, contracts and technical requirements. The relief measures extended to SMEs, as well as the relaxation of the general AI competence requirement, are also reflections of this approach.
At the same time, the fundamental framework of the AI Regulation remains unchanged. Companies should not view the extended implementation deadlines as a delay, but rather use them as an opportunity to establish a structured and robust AI compliance framework.
Whether the AI Omnibus will actually lead to a noticeable simplification will, however, depend largely on how quickly the guidelines, harmonised standards and other support tools announced by the European Commission are made available. Until then, companies should closely monitor further developments in the European AI regulatory framework.
Valentino Halim
Melissa Irtel
6. Planned data protection reform
The CDU/CSU and the SPD agreed on a comprehensive reform package yesterday in the coalition committee. This includes numerous measures in the areas of taxation, the labour market and reducing red tape. Various initiatives are also planned in the area of data protection, which are intended in particular to ease the burden on businesses.
Specifically, the coalition plans to:
- National data protection is to be simplified. In doing so, full use will be made of all existing leeway provided by the General Data Protection Regulation (GDPR).
- At European level, the coalition intends to campaign for non-commercial activities (such as those carried out by voluntary organisations), small and medium-sized enterprises, and low-risk data processing (for example, simple customer lists in the skilled trades) to be excluded from the scope of the GDPR.
- There are plans to create a Data Code that harmonises and simplifies data law as a uniform set of rules. The aim is both to guarantee data protection and to promote the use of data.
- Data protection procedures are to be streamlined, whilst supervisory structures are to be simplified and consolidated. A greater concentration of responsibilities is envisaged at the Federal Commissioner for Data Protection and Freedom of Information (BfDI). Furthermore, the Data Protection Conference (DSK) is to be enshrined in law to facilitate common standards. However, the specific details remain to be determined.
- In small and medium-sized enterprises, the number of in-house data protection officers is to be reduced.
Assessment
The already discernible trend, whereby data protection is losing its status as a virtually sacrosanct ‘super-fundamental right’, is being further driven forward by the coalition. Following the data protection supervisory authorities’ recent tendency to act with greater restraint in many cases, substantive data protection law is now also to be brought back to a more proportionate level. From a business perspective, this development is generally to be viewed positively. However, many of the announced measures have been under discussion for years and, in my view, do not yet go far enough.
Valentino Halim
Your contacts for IT&C:
Michael Abels, Anselm Auer, Marco Degginger, Dr. Thomas Fischl, Valentino Halim, Dr. Jürgen Hartung, Dr. Marc Hilber, Melissa Irtel, Tobias Kollakowski, Rocco Mondello





