Personal data that was collected unlawfully is not automatically admissible as evidence. The European Court of Justice has clarified this. The proceedings centered on the question of whether
Effective August 2, 2026, the key transparency requirements of the European AI Act will take effect. Under these requirements, companies will be required in certain cases to disclose whether content has been generated by
Who is responsible under data protection law when advertising is sent through a mailing list provider? Is it the advertising company that defines the target audience, or the mailing list provider that selects the recipients?
Many companies confuse deletion periods with retention periods. Why this is problematic from a data protection perspective, what risks it poses, and how an effective deletion strategy can improve compliance and data security
The European Parliament and the Council have agreed on a series of amendments to the EU AI Regulation (AI Act). The provisional agreement reached as part of the so-called
Since 2016, the BSI has set the German standard for secure cloud services with the „Cloud Computing Compliance Criteria Catalogue” (C5). With C5:2026, the
Sharing participant data with event partners is common practice. Using real-world examples, we highlight the data protection considerations that must be taken into account and provide
Modern transcription systems not only convert speech into text, but also attempt to identify individual speakers. As a result, they are not only directly subject to the requirements of the
With the enactment of the Data Act Implementation Act, the Data Act will soon be effectively enforced in Germany as well. Here are the steps companies should take now to prepare.
The KRITIS umbrella law supplements existing IT security regulations by pursuing an all-hazards approach. In other words, protection against natural hazards, technical faults, sabotage, terrorism and other non-IT-related threats. Here you will find