- Labor law
- Construction and architecture law
- Succession planning law
- Family law
- Film and Broadcasting Law
- Corporate law
- Trade and commercial law
- Real estate law
- International business law
- IT-Compliance
- IT-Law
- Art law
- Trademark and Labeling Law
- Tenancy and residential property law
- Press Law
- Litigation and arbitration
- Insolvency law and corporate restructuring
- Criminal and misdemeanor law
- Copyright and Media Law
- Competition Law
IT-Law
Your contacts for this practice area:
- Roman Ronneburger (software contracts, platform law, open-source compliance, international data transfers, AI in copyright and media law)
- Linda Seiffert (IT contracts, data protection, e-commerce, platform and influencer law)
- Johannes Schleuning (IT contract law, interface with corporate law)
- Alessandra von Piechowski (data protection and AI in the employment relationship, employee data protection)
- In technical cooperation: Robin Data and Prof. Dr. Döring (technical experts)
Over the past two years, the digitalisation of the economy has triggered a regulatory wave that surpasses, in pace, depth and level of detail, everything companies remember from the introduction of the GDPR in 2018. The Cyber Resilience Act, the NIS2 implementation act, DORA, the AI Act, the Data Act, the new Product Liability Directive and the Digital Services Act mesh together, partly overlap, and create a legal framework in which software, data and digital business models can no longer be operated without careful legal support. Anyone who today offers a SaaS application, trains an AI model, runs an online shop or, as a group of companies, organises data traffic to the USA, has to contend with a multitude of parallel bodies of rules whose implementation deadlines follow one another in close succession in the months between September 2025 and August 2027.
SES Berlin has advised companies from Berlin and the entire German-speaking region for more than four decades as a commercial law firm. We combine a commercial-law foundation — corporate law, contract law, employment law, tax law — with technically well-grounded advice in IT and data protection law. We understand software architectures, cloud models and AI pipelines not only in doctrinal terms but also in their business and technical logic. Our clients range from start-ups in Berlin-Mitte to long-established mid-sized companies, listed corporations, platform operators, software manufacturers and research institutions.
In the field of IT law and data protection, we advise on the three major pillars that shape today's digital commercial law: software contracts in all their variants, data protection law with a focus on international data flows — and the newly emerged focus on software compliance, in which the CRA, NIS2, DORA, the AI Act and the Product Liability Directive converge. Added to this are e-commerce law, open-source compliance, telemedia and platform law, and the forward-looking topics surrounding digitalisation and Industry 4.0. On technically complex questions we cooperate with Robin Data and Prof. Dr. Döring as technical experts, thereby combining legal precision with technical depth.
Our IT-law and data-protection advisory focus at a glance
We advise clients on more than fifteen typical constellations of IT and data protection law:
- Drafting, negotiating and reviewing software contracts of every kind, including SaaS, outsourcing, software leasing, software purchase, software development and service-level agreements
- Cloud and hosting contracts, data-centre contracts, contracts with internet service providers and content delivery networks
- Open-source compliance along the software supply chain, including licence analysis for GPL, LGPL, MPL, MIT, Apache, BSD, EPL and SSPL
- Data protection concepts, privacy notices, data processing agreement frameworks and joint controllership under Art. 26 GDPR
- International data transfers, transfer impact assessments and support with the EU-US Data Privacy Framework
- Cyber Resilience Act: conformity assessment, vulnerability management, SBOM and reporting obligations
- NIS2 implementation act: registration, risk management, reporting channels, management liability
- DORA compliance for financial service providers and their ICT third-party providers
- AI Act: risk classification, GPAI obligations, transparency requirements
- Telemedia, platform and DSA law
- E-commerce law, including general terms and conditions, right of withdrawal and price-indication rules
- Structuring influencer marketing on a legally sound basis
- Fine and supervisory proceedings before the BlnBDI and the BfDI
- Employee data protection, rights of access and erasure, company data protection officer
- Training for management, IT, HR and marketing
Software and SaaS contracts
Software is today the backbone of almost every business model. Anyone who purchases, leases, licenses, hosts or develops software operates within a contract type to which the German Civil Code (BGB) devotes no chapter of its own, and which can nonetheless decide the success or failure of a project in a split second. The typical areas of friction are well known from our advisory practice: service descriptions that are not a precise fit, unclear acceptance and escalation rules, deficient service-level definitions, unresolved ownership and usage rights in source code and data, faulty open-source clauses and questionable exit scenarios when switching providers.
We draft and negotiate software contracts in all of their typical variants. In the classic software development contract, we review the specification, milestones, remuneration model, acceptance procedure, warranty rights, chain of rights and the client's duties to cooperate. In customising, we ensure a clean separation between standard software and individual adaptation, because this distinction later determines warranty, maintenance obligations and the protection of the client's investment. With SaaS contracts, the focus is on availability, response and recovery times, contractual penalties, audit rights, data migration and, above all, the legally sound link with data protection law.
Service level agreements are not an annex in our advice but a core element of the contract. We pay attention to realistic and measurable KPIs, to a clean definition of the reference period, to the treatment of maintenance windows, to a pragmatic escalation chain and to contractual penalties that do not become a trap under the German rules on standard terms (Sections 305 et seq. BGB). In outsourcing projects, we combine IT contract-law support with corporate and employment-law advice, because such projects regularly raise questions of business transfers, works-council involvement and co-determination rights.
Contracts with hosting providers, cloud service providers, telecommunications companies and content delivery networks now form a distinct field of contract law. Here, elements of lease, service, works and sales law are mixed, and to these are added data-protection and security obligations under the GDPR, NIS2 and DORA. We review the standard terms of hyperscalers such as Amazon Web Services, Microsoft Azure and Google Cloud Platform just as much as individual contracts with European providers. In particular, we address the CLOUD Act problem and its consequences for third-country transfers under Art. 44 et seq. GDPR together with our US correspondent firms.
Data protection and GDPR advice in Berlin
Since the GDPR became applicable on 25 May 2018, data protection has developed into a cross-cutting theme that is now indispensable to every business process. Fines imposed by European supervisory authorities regularly exceed the hundred-million-euro mark, German authorities are increasingly assertive in their enforcement, and the Berlin Commissioner for Data Protection and Freedom of Information has in recent years established itself as one of the more active supervisory authorities in Germany. Added to this are the EDPB guidelines, the case law of the CJEU — from Schrems II to the more recent jurisprudence on non-material damages under Art. 82 GDPR — and an increasingly active private enforcement route.
We prepare data protection concepts for companies of every size, from the start-up with twelve employees to the internationally active group. The focus is on a workable records-of-processing framework under Art. 30 GDPR, a robust legal-basis matrix under Art. 6 and 9 GDPR, a well-considered process for data-subject rights under Art. 15 to 22 GDPR, an effective data protection impact assessment under Art. 35 GDPR and a contingency plan for data breaches under Art. 33 and 34 GDPR.
Data processing agreements under Art. 28 GDPR are a mainstay of our advice. We prepare model templates, review providers' data processing agreements, negotiate individual terms and, above all, clarify the distinction between processing on behalf of a controller, joint controllership and separate controllership.
On international data transfers, we advise comprehensively on the 2021 Standard Contractual Clauses, on the transfer impact assessment in line with EDPB Recommendations 01/2020, on supplementary measures within the meaning of Schrems II, and on the application of the EU-US Data Privacy Framework, which since the adequacy decision of 10 July 2023 forms the central bridge for transatlantic data flows.
In employee data protection, we advise on all phases of the employment relationship — from applicant management through internal investigations, whistleblower systems, employee monitoring and the introduction of new IT tools, to termination with its typical data protection questions. We work closely with our firm's employment lawyers.
We handle fine proceedings before the BlnBDI, the BfDI and other supervisory authorities from the first hearing through to court proceedings before the administrative court and, where necessary, the Federal Administrative Court.
Software compliance in Berlin: CRA, NIS2, DORA and the AI Act
With the Cyber Resilience Act, the NIS2 implementation act, DORA, the AI Act, the Product Liability Directive and the Data Act, 2025 and 2026 have brought the largest regulatory wave of the digital single market since the GDPR down upon companies. Anyone who manufactures, places on the market, imports, distributes or operationally deploys software must grapple with a web of European regulations and directives. We have built a dedicated advisory practice for this and support companies across all the relevant bodies of rules.
Cyber Resilience Act (CRA)
The Cyber Resilience Act, formally Regulation (EU) 2024/2847, entered into force on 10 December 2024. Most of its substantive obligations apply from 11 December 2027. The central reporting obligation for actively exploited vulnerabilities and serious security incidents already takes effect from 11 September 2026 — a deadline that many companies underestimate.
The CRA covers all products with digital elements whose intended use includes a direct or indirect data connection to a device or network. It therefore covers hardware and software products from the IoT sensor to business software, from the smartwatch to the industrial robot, from the mobile app to the embedded Linux image in an industrial control system. Only a few areas are excluded, such as medical devices, motor vehicles, civil aviation and certain SaaS constellations covered by other sector-specific cybersecurity rules.
Manufacturers must carry out a risk assessment, comply with essential cybersecurity requirements from the design stage (security by design), maintain a Software Bill of Materials (SBOM) and provide free security updates for the support period. They must establish vulnerability management encompassing active detection, remediation and information. The reporting obligations are three-tiered: a 24-hour early warning to the competent CSIRT and ENISA, a 72-hour notification, and a final report no later than 14 days after remediation. Infringements may be sanctioned with fines of up to EUR 15 million or 2.5 per cent of worldwide annual turnover. We support manufacturers, importers and distributors with conformity assessment, technical documentation, vulnerability management and reporting processes.
NIS2 Directive and NIS2 implementation act
The NIS2 Directive (Directive (EU) 2022/2555) has been transposed in Germany through the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG). Around 30,000 companies in 18 sectors are now affected. Classification as an essential or important entity is determined by sector and size. Affected companies must register with the BSI, implement extensive risk-management obligations and follow a 24/72-hour reporting scheme with a final report within one month. Particularly serious is the personal liability of management. Infringements may be sanctioned with fines of up to EUR 10 million or 2 per cent of worldwide annual turnover.
DORA — Digital Operational Resilience Act
Regulation (EU) 2022/2554 (DORA) has applied directly since 17 January 2025. DORA obliges financial entities to maintain comprehensive ICT risk management, to test their digital operational resilience, to operate a standardised reporting system for serious ICT incidents, and to exercise strict third-party management, including the register of information and Art. 30 DORA contract requirements. We support financial service providers and their ICT third-party providers with gap analysis, contract adaptation and threat-led penetration tests (TLPT).
AI Act
Regulation (EU) 2024/1689 (the AI Act) is the world's first comprehensive regulation of AI systems and applies in stages since 1 August 2024. It follows a risk-based approach dividing AI systems into prohibited practices, high-risk AI, AI subject to transparency obligations and minimal-risk AI. Providers of high-risk AI must establish a risk management system, operate data governance, prepare technical documentation, enable human oversight and ensure accuracy, robustness and cybersecurity, followed by conformity assessment and CE marking. For GPAI models, special transparency, documentation and copyright-compliance obligations apply. Fines can reach up to EUR 35 million or 7 per cent of worldwide annual turnover. We advise providers, importers, distributors and deployers along the entire value chain.
New Product Liability Directive (2024/2853)
The new Product Liability Directive (EU) 2024/2853 must be transposed into national law by 9 December 2026. Software is now expressly a product; digital services necessary for the functioning of the product count as a product component; and supplier liability is broadened. Procedural reliefs for injured parties include a duty to disclose evidence, alleviations of the burden of proof and a presumption of defectiveness where product-safety or cybersecurity requirements are obviously infringed. Anyone who commits a CRA infringement therefore risks not only fines but also civil liability. We analyse the implications for manufacturers, software providers and IoT providers.
Data Act (Regulation (EU) 2023/2854)
The Data Act has applied since 12 September 2025 and creates a horizontal framework for access to and use of data from connected products and related services. Manufacturers must enable users, and on their request third parties, to access product-usage data; cloud providers must create switching mechanisms and abolish unreasonable switching charges. We advise manufacturers, data recipients, cloud providers and users on contract drafting, data-access models and the demarcation from the GDPR and the Trade Secrets Act.
Synergies and integrated governance
The greatest challenge lies in exploiting the synergies between the CRA, NIS2, DORA, the AI Act, the GDPR and product liability. An integrated incident-response management can serve reporting obligations under the CRA, NIS2, DORA and Art. 33 GDPR simultaneously; a unified vulnerability and asset management covers CRA obligations and NIS2 risk management; a consolidated supplier due diligence reduces the burden across open-source compliance, NIS2 supply-chain requirements and CRA vulnerability obligations. Together with our clients, we develop an integrated compliance architecture that does not think in silos.
Open-source compliance
Open-source software is today an integral part of practically every software product. Anyone using open source must comply with the licence terms — from the copyleft obligations of the GPL and LGPL, through the attribution requirements of the MIT, BSD and Apache 2.0 licences, to special constellations such as the MPL, the EPL and the SSPL. We analyse software inventories for licence conformity, review SBOMs, advise on compliance processes and provide support in M&A transactions. With the CRA, manufacturers remain responsible for the security of embedded open-source components as well.
Cloud and data transfers to third countries
The use of cloud services from American hyperscalers is indispensable to everyday digital business, yet imposes demanding data protection requirements which, at the latest since the CJEU's Schrems II judgment, stand at the centre of every cloud engagement. We support clients in selecting cloud providers, review standard terms and individual agreements, prepare transfer impact assessments and assist with supplementary technical measures such as encryption, pseudonymisation and tokenisation. The EU-US Data Privacy Framework has, since 10 July 2023, created a new basis for transatlantic data flows.
E-commerce law
Online shops, platforms and marketplaces are a distinct focus of our advice. We prepare tailored terms and conditions, withdrawal notices, privacy notices and legal notices, and advise on the price-indication rules, the cancellation button under Section 312k BGB, the Platform-to-Business Regulation and the extensive obligations arising from the Digital Services Act. Platform operators are subject to enhanced DSA obligations including notice-and-action procedures, transparent moderation rules and risk management for very large online platforms.
Digitalisation and Industry 4.0
The digital transformation of classic industrial companies raises its own legal questions. We draft contracts for the implementation of new technologies — from IoT sensor technology through predictive maintenance to robotic process automation — advise on data-monetisation business models and assist with the contractual structuring of self-learning algorithms, including in the automotive and autonomous-driving field.
Tools for DPO and CISO teams
Data protection officers and chief information security officers face the task of implementing a rapidly growing number of obligations in limited time. We support DPO and CISO teams with detailed templates, checklists and training materials, and offer in-house workshops, webinars and tailored training for management, the data protection team, the IT security team, HR, procurement and sales.
Cyber Resilience Act (CRA): In-depth client information on the new EU cybersecurity law for products with digital elements — What must be done? · FAQ · Regulation text.
IT-Law
Your contacts for this practice area:
- Roman Ronneburger (software contracts, platform law, open-source compliance, international data transfers, AI in copyright and media law)
- Linda Seiffert (IT contracts, data protection, e-commerce, platform and influencer law)
- Johannes Schleuning (IT contract law, interface with corporate law)
- Alessandra von Piechowski (data protection and AI in the employment relationship, employee data protection)
- In technical cooperation: Robin Data and Prof. Dr. Döring (technical experts)
Over the past two years, the digitalisation of the economy has triggered a regulatory wave that surpasses, in pace, depth and level of detail, everything companies remember from the introduction of the GDPR in 2018. The Cyber Resilience Act, the NIS2 implementation act, DORA, the AI Act, the Data Act, the new Product Liability Directive and the Digital Services Act mesh together, partly overlap, and create a legal framework in which software, data and digital business models can no longer be operated without careful legal support. Anyone who today offers a SaaS application, trains an AI model, runs an online shop or, as a group of companies, organises data traffic to the USA, has to contend with a multitude of parallel bodies of rules whose implementation deadlines follow one another in close succession in the months between September 2025 and August 2027.
SES Berlin has advised companies from Berlin and the entire German-speaking region for more than four decades as a commercial law firm. We combine a commercial-law foundation — corporate law, contract law, employment law, tax law — with technically well-grounded advice in IT and data protection law. We understand software architectures, cloud models and AI pipelines not only in doctrinal terms but also in their business and technical logic. Our clients range from start-ups in Berlin-Mitte to long-established mid-sized companies, listed corporations, platform operators, software manufacturers and research institutions.
In the field of IT law and data protection, we advise on the three major pillars that shape today's digital commercial law: software contracts in all their variants, data protection law with a focus on international data flows — and the newly emerged focus on software compliance, in which the CRA, NIS2, DORA, the AI Act and the Product Liability Directive converge. Added to this are e-commerce law, open-source compliance, telemedia and platform law, and the forward-looking topics surrounding digitalisation and Industry 4.0. On technically complex questions we cooperate with Robin Data and Prof. Dr. Döring as technical experts, thereby combining legal precision with technical depth.
Our IT-law and data-protection advisory focus at a glance
We advise clients on more than fifteen typical constellations of IT and data protection law:
- Drafting, negotiating and reviewing software contracts of every kind, including SaaS, outsourcing, software leasing, software purchase, software development and service-level agreements
- Cloud and hosting contracts, data-centre contracts, contracts with internet service providers and content delivery networks
- Open-source compliance along the software supply chain, including licence analysis for GPL, LGPL, MPL, MIT, Apache, BSD, EPL and SSPL
- Data protection concepts, privacy notices, data processing agreement frameworks and joint controllership under Art. 26 GDPR
- International data transfers, transfer impact assessments and support with the EU-US Data Privacy Framework
- Cyber Resilience Act: conformity assessment, vulnerability management, SBOM and reporting obligations
- NIS2 implementation act: registration, risk management, reporting channels, management liability
- DORA compliance for financial service providers and their ICT third-party providers
- AI Act: risk classification, GPAI obligations, transparency requirements
- Telemedia, platform and DSA law
- E-commerce law, including general terms and conditions, right of withdrawal and price-indication rules
- Structuring influencer marketing on a legally sound basis
- Fine and supervisory proceedings before the BlnBDI and the BfDI
- Employee data protection, rights of access and erasure, company data protection officer
- Training for management, IT, HR and marketing
Software and SaaS contracts
Software is today the backbone of almost every business model. Anyone who purchases, leases, licenses, hosts or develops software operates within a contract type to which the German Civil Code (BGB) devotes no chapter of its own, and which can nonetheless decide the success or failure of a project in a split second. The typical areas of friction are well known from our advisory practice: service descriptions that are not a precise fit, unclear acceptance and escalation rules, deficient service-level definitions, unresolved ownership and usage rights in source code and data, faulty open-source clauses and questionable exit scenarios when switching providers.
We draft and negotiate software contracts in all of their typical variants. In the classic software development contract, we review the specification, milestones, remuneration model, acceptance procedure, warranty rights, chain of rights and the client's duties to cooperate. In customising, we ensure a clean separation between standard software and individual adaptation, because this distinction later determines warranty, maintenance obligations and the protection of the client's investment. With SaaS contracts, the focus is on availability, response and recovery times, contractual penalties, audit rights, data migration and, above all, the legally sound link with data protection law.
Service level agreements are not an annex in our advice but a core element of the contract. We pay attention to realistic and measurable KPIs, to a clean definition of the reference period, to the treatment of maintenance windows, to a pragmatic escalation chain and to contractual penalties that do not become a trap under the German rules on standard terms (Sections 305 et seq. BGB). In outsourcing projects, we combine IT contract-law support with corporate and employment-law advice, because such projects regularly raise questions of business transfers, works-council involvement and co-determination rights.
Contracts with hosting providers, cloud service providers, telecommunications companies and content delivery networks now form a distinct field of contract law. Here, elements of lease, service, works and sales law are mixed, and to these are added data-protection and security obligations under the GDPR, NIS2 and DORA. We review the standard terms of hyperscalers such as Amazon Web Services, Microsoft Azure and Google Cloud Platform just as much as individual contracts with European providers. In particular, we address the CLOUD Act problem and its consequences for third-country transfers under Art. 44 et seq. GDPR together with our US correspondent firms.
Data protection and GDPR advice in Berlin
Since the GDPR became applicable on 25 May 2018, data protection has developed into a cross-cutting theme that is now indispensable to every business process. Fines imposed by European supervisory authorities regularly exceed the hundred-million-euro mark, German authorities are increasingly assertive in their enforcement, and the Berlin Commissioner for Data Protection and Freedom of Information has in recent years established itself as one of the more active supervisory authorities in Germany. Added to this are the EDPB guidelines, the case law of the CJEU — from Schrems II to the more recent jurisprudence on non-material damages under Art. 82 GDPR — and an increasingly active private enforcement route.
We prepare data protection concepts for companies of every size, from the start-up with twelve employees to the internationally active group. The focus is on a workable records-of-processing framework under Art. 30 GDPR, a robust legal-basis matrix under Art. 6 and 9 GDPR, a well-considered process for data-subject rights under Art. 15 to 22 GDPR, an effective data protection impact assessment under Art. 35 GDPR and a contingency plan for data breaches under Art. 33 and 34 GDPR.
Data processing agreements under Art. 28 GDPR are a mainstay of our advice. We prepare model templates, review providers' data processing agreements, negotiate individual terms and, above all, clarify the distinction between processing on behalf of a controller, joint controllership and separate controllership.
On international data transfers, we advise comprehensively on the 2021 Standard Contractual Clauses, on the transfer impact assessment in line with EDPB Recommendations 01/2020, on supplementary measures within the meaning of Schrems II, and on the application of the EU-US Data Privacy Framework, which since the adequacy decision of 10 July 2023 forms the central bridge for transatlantic data flows.
In employee data protection, we advise on all phases of the employment relationship — from applicant management through internal investigations, whistleblower systems, employee monitoring and the introduction of new IT tools, to termination with its typical data protection questions. We work closely with our firm's employment lawyers.
We handle fine proceedings before the BlnBDI, the BfDI and other supervisory authorities from the first hearing through to court proceedings before the administrative court and, where necessary, the Federal Administrative Court.
Software compliance in Berlin: CRA, NIS2, DORA and the AI Act
With the Cyber Resilience Act, the NIS2 implementation act, DORA, the AI Act, the Product Liability Directive and the Data Act, 2025 and 2026 have brought the largest regulatory wave of the digital single market since the GDPR down upon companies. Anyone who manufactures, places on the market, imports, distributes or operationally deploys software must grapple with a web of European regulations and directives. We have built a dedicated advisory practice for this and support companies across all the relevant bodies of rules.
Cyber Resilience Act (CRA)
The Cyber Resilience Act, formally Regulation (EU) 2024/2847, entered into force on 10 December 2024. Most of its substantive obligations apply from 11 December 2027. The central reporting obligation for actively exploited vulnerabilities and serious security incidents already takes effect from 11 September 2026 — a deadline that many companies underestimate.
The CRA covers all products with digital elements whose intended use includes a direct or indirect data connection to a device or network. It therefore covers hardware and software products from the IoT sensor to business software, from the smartwatch to the industrial robot, from the mobile app to the embedded Linux image in an industrial control system. Only a few areas are excluded, such as medical devices, motor vehicles, civil aviation and certain SaaS constellations covered by other sector-specific cybersecurity rules.
Manufacturers must carry out a risk assessment, comply with essential cybersecurity requirements from the design stage (security by design), maintain a Software Bill of Materials (SBOM) and provide free security updates for the support period. They must establish vulnerability management encompassing active detection, remediation and information. The reporting obligations are three-tiered: a 24-hour early warning to the competent CSIRT and ENISA, a 72-hour notification, and a final report no later than 14 days after remediation. Infringements may be sanctioned with fines of up to EUR 15 million or 2.5 per cent of worldwide annual turnover. We support manufacturers, importers and distributors with conformity assessment, technical documentation, vulnerability management and reporting processes.
NIS2 Directive and NIS2 implementation act
The NIS2 Directive (Directive (EU) 2022/2555) has been transposed in Germany through the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG). Around 30,000 companies in 18 sectors are now affected. Classification as an essential or important entity is determined by sector and size. Affected companies must register with the BSI, implement extensive risk-management obligations and follow a 24/72-hour reporting scheme with a final report within one month. Particularly serious is the personal liability of management. Infringements may be sanctioned with fines of up to EUR 10 million or 2 per cent of worldwide annual turnover.
DORA — Digital Operational Resilience Act
Regulation (EU) 2022/2554 (DORA) has applied directly since 17 January 2025. DORA obliges financial entities to maintain comprehensive ICT risk management, to test their digital operational resilience, to operate a standardised reporting system for serious ICT incidents, and to exercise strict third-party management, including the register of information and Art. 30 DORA contract requirements. We support financial service providers and their ICT third-party providers with gap analysis, contract adaptation and threat-led penetration tests (TLPT).
AI Act
Regulation (EU) 2024/1689 (the AI Act) is the world's first comprehensive regulation of AI systems and applies in stages since 1 August 2024. It follows a risk-based approach dividing AI systems into prohibited practices, high-risk AI, AI subject to transparency obligations and minimal-risk AI. Providers of high-risk AI must establish a risk management system, operate data governance, prepare technical documentation, enable human oversight and ensure accuracy, robustness and cybersecurity, followed by conformity assessment and CE marking. For GPAI models, special transparency, documentation and copyright-compliance obligations apply. Fines can reach up to EUR 35 million or 7 per cent of worldwide annual turnover. We advise providers, importers, distributors and deployers along the entire value chain.
New Product Liability Directive (2024/2853)
The new Product Liability Directive (EU) 2024/2853 must be transposed into national law by 9 December 2026. Software is now expressly a product; digital services necessary for the functioning of the product count as a product component; and supplier liability is broadened. Procedural reliefs for injured parties include a duty to disclose evidence, alleviations of the burden of proof and a presumption of defectiveness where product-safety or cybersecurity requirements are obviously infringed. Anyone who commits a CRA infringement therefore risks not only fines but also civil liability. We analyse the implications for manufacturers, software providers and IoT providers.
Data Act (Regulation (EU) 2023/2854)
The Data Act has applied since 12 September 2025 and creates a horizontal framework for access to and use of data from connected products and related services. Manufacturers must enable users, and on their request third parties, to access product-usage data; cloud providers must create switching mechanisms and abolish unreasonable switching charges. We advise manufacturers, data recipients, cloud providers and users on contract drafting, data-access models and the demarcation from the GDPR and the Trade Secrets Act.
Synergies and integrated governance
The greatest challenge lies in exploiting the synergies between the CRA, NIS2, DORA, the AI Act, the GDPR and product liability. An integrated incident-response management can serve reporting obligations under the CRA, NIS2, DORA and Art. 33 GDPR simultaneously; a unified vulnerability and asset management covers CRA obligations and NIS2 risk management; a consolidated supplier due diligence reduces the burden across open-source compliance, NIS2 supply-chain requirements and CRA vulnerability obligations. Together with our clients, we develop an integrated compliance architecture that does not think in silos.
Open-source compliance
Open-source software is today an integral part of practically every software product. Anyone using open source must comply with the licence terms — from the copyleft obligations of the GPL and LGPL, through the attribution requirements of the MIT, BSD and Apache 2.0 licences, to special constellations such as the MPL, the EPL and the SSPL. We analyse software inventories for licence conformity, review SBOMs, advise on compliance processes and provide support in M&A transactions. With the CRA, manufacturers remain responsible for the security of embedded open-source components as well.
Cloud and data transfers to third countries
The use of cloud services from American hyperscalers is indispensable to everyday digital business, yet imposes demanding data protection requirements which, at the latest since the CJEU's Schrems II judgment, stand at the centre of every cloud engagement. We support clients in selecting cloud providers, review standard terms and individual agreements, prepare transfer impact assessments and assist with supplementary technical measures such as encryption, pseudonymisation and tokenisation. The EU-US Data Privacy Framework has, since 10 July 2023, created a new basis for transatlantic data flows.
E-commerce law
Online shops, platforms and marketplaces are a distinct focus of our advice. We prepare tailored terms and conditions, withdrawal notices, privacy notices and legal notices, and advise on the price-indication rules, the cancellation button under Section 312k BGB, the Platform-to-Business Regulation and the extensive obligations arising from the Digital Services Act. Platform operators are subject to enhanced DSA obligations including notice-and-action procedures, transparent moderation rules and risk management for very large online platforms.
Digitalisation and Industry 4.0
The digital transformation of classic industrial companies raises its own legal questions. We draft contracts for the implementation of new technologies — from IoT sensor technology through predictive maintenance to robotic process automation — advise on data-monetisation business models and assist with the contractual structuring of self-learning algorithms, including in the automotive and autonomous-driving field.
Tools for DPO and CISO teams
Data protection officers and chief information security officers face the task of implementing a rapidly growing number of obligations in limited time. We support DPO and CISO teams with detailed templates, checklists and training materials, and offer in-house workshops, webinars and tailored training for management, the data protection team, the IT security team, HR, procurement and sales.
Cyber Resilience Act (CRA): In-depth client information on the new EU cybersecurity law for products with digital elements — What must be done? · FAQ · Regulation text.