Archive.

News in law & regulation

AI in Companies: Central Legal Aspects

The use of AI systems has become part of everyday business operations in many companies. At the same time, legal questions arise under the AI Act, data protection law, trade secret protection, and corporate governance.

This article outlines the key legal aspects companies should consider when using AI systems and explains why legally compliant AI use usually begins with a clear governance decision.

Read more

SaaS Contracts: Reducing Financial Risks through Swap Clauses

Rigid license agreements often result in unnecessary "shelfware" costs. So-called remix or swap clauses promise relief through mid-term license exchanges.

This article examines the contractual mechanisms of exchange rights and explains how companies can avoid economic disadvantages through precise provisions on valuation and co-termination.

Read more

What are Non-Disclosure Agreements (NDAs) and Why They Matter

A Non-Disclosure Agreement, often referred to as an “NDA,” is a contract in which two or more parties agree to keep certain information confidential.

NDAs are important for protecting trade secrets, sensitive data, or innovative ideas, and they provide legal certainty when sharing information.

Read More

CJEU on non-material damage: shame, distress and loss of control

In its judgment of 4 September 2025 (C-655/23), the CJEU clarified that feelings such as shame, distress and loss of control can constitute compensable non-material damage under Article 82 GDPR.

The ruling confirms that even minor data breaches (for instance mis-sent messages) may give rise to compensation claims. National remedies remain available in parallel, e.g. for injunctive relief.

Read more

Short Briefing – Data Act

The Data Act (Regulation (EU) 2023/2854) obliges, among others, manufacturers, sellers and digital service providers to inform users about data generated by connected products and to grant them rights of access and sharing.

This short briefing summarises key obligations and definitions for connected products and provides a concise overview of user rights, data access and transparency requirements.

Read more

AI Act and CRA: Leveraging Synergies for Cybersecurity Compliance

The EU's AI Act and Cyber Resilience Act (CRA) are closely linked. Together, they form a unified framework for product and data security in the age of artificial intelligence. Companies that understand how both regulations interact can leverage synergies, avoid duplicate assessments, and streamline compliance.

The article explains how Article 12 CRA and Article 15 AI Act interconnect, how cybersecurity obligations are aligned, and when the stricter assessment regime takes precedence.

Read more

Data Act: Model Contractual Terms and Standard Contractual Clauses

Since this still seems to be relatively unknown, here is another note:

In March 2025, an expert group appointed by the European Commission presented Model Contractual Terms (MCTs) and Standard Contractual Clauses (SCCs) (European Commission, Expert Group). These are intended to provide companies in the B2B context with guidance on implementing the EU Data Act.

While the templates are not legally binding, they can help integrate key obligations such as data access, remuneration, protection of trade secrets and switching modalities into contracts even now.

Read more

Data Act: Data Disclosure at Any Price?

Since September 12, 2025, the EU Data Act has been in force. Data holders of data originating from the use of connected products and related services must, in principle, make these data available to users. However, there are exceptions, even if defined very narrowly: for example, in cases of serious risks to safety or health, or to protect trade secrets. For personal data, the GDPR remains fully applicable: if datasets contain personal data, a valid legal basis is still required. SMEs may also benefit from certain exemptions that can provide relief.

The Data Act is very far-reaching and has set out clear mechanisms to make circumvention of disclosure obligations more difficult. A “disclosure at any price” is not intended. Instead, data holders must carefully assess whether they or the data they manage fall under one of the narrowly defined exemption provisions.

AI Act: First obligations for general-purpose AI apply

As of 2 August 2025, the first requirements of the EU AI Act apply, initially for so-called general-purpose AI (GPAI). Providers of these broadly usable AI systems must ensure transparency about training data, technical safeguards and risk management.

The European Commission has published a "Code of Practice" to support industry in meeting AI Act obligations regarding safety, transparency and copyright when developing and using GPAI models.

NIS-2: German government plans broad expansion of IT security duties

The latest draft law implementing the NIS-2 Directive modernises German IT security law. The scope will expand significantly: up from about 4,500 around 29,500 entities are expected to fall under BSI supervision. This includes "important" and "essential" entities across the economy and society.

Affected organisations must register with the BSI, report significant incidents and implement comprehensive technical and organisational measures (such as risk analyses, incident response, training and secure communications).

Data Act: EU launches standardization framework for trusted data use

On July 7, 2025, the European organizations CEN and CENELEC officially accepted the European Commission's standardization mandate to develop a “European Trusted Data Framework.” This framework aims to support the practical implementation of the Data Act, whose first obligations must be applied starting September 12, 2025.

Seven European standardization documents are planned, including four European Standards. The goal is to promote trusted data sharing, technical interoperability, and the creation of common European data spaces.

Contact.

Get in touch

If you have legal questions or would like to arrange an initial consultation, please feel free to get in touch.

Direct contact

Email: info@kanzlei-happel.de
Tel.: +49 (6106) 639 24 25
Consultation via email, phone, video conference, or by appointment.