News
Below you will find articles on data protection, artificial intelligence and IT security. They are published in German.
50by 50 articles
Data protection
Datentransfers in die USA unter Druck – EDSA fordert Überprüfung des Data Privacy Framework
After the Supreme Court ruling on the removal of FTC members, one of the assumptions underpinning the adequacy decision no longer applies. At the end of July 2026 the European Data Protection Board asked the Commission to review it, without calling for a suspension. The Data Privacy Framework continues to apply, but it does not serve as the sole and permanently secured basis.
Read in GermanData protection
Berliner Datenschutzbeauftragte zu Kontrollpflichten des Verantwortlichen bzgl. seiner Auftragsverarbeiter
The Berlin authority reprimanded the Berlin public transport operator for failing to check deletion at a service provider and for reporting an incident late. A data processing agreement alone is therefore not enough, and the Higher Regional Court of Dresden had held the same in 2024. The higher the risk, the tighter the checks, with confirmation of deletion, spot checks and agreed reporting channels.
Read in GermanData protection
Digital Omnibus und § 25 TDDDG: Die Auswirkungen auf Reichweitenmessung
The Commission's proposal moves the rules on access to terminal equipment out of the ePrivacy regime and into the GDPR. A new Art. 88a is intended to allow aggregated audience measurement for a provider's own purposes without consent. For personalised advertising and for tracking across several websites nothing changes.
Read in GermanData protection
EuGH zu Art. 15 DSGVO: Rechtswidrige Auskunftsersuchen bei „DSGVO-Hoppern“
In March 2026 the Court of Justice held that even a first request for access can be excessive. What matters are the purpose and the circumstances, for example deliberately provoking infringements in order to prepare a claim for damages. The company has to set out and prove the abusive intent, which is why refusal remains the exception.
Read in GermanAI law
Einigung zwischen dem Rat der EU und dem EU-Parlament über die Vereinfachung und Straffung der KI-Verordnung im Rahmen des Digitalen Omnibus-Pakets
In May 2026 the Council and the Parliament agreed on amendments to the AI Act. The obligations for high risk systems move to December 2027 and December 2028, while the marking of generated content is brought forward to December 2026. A ban on certain practices and wider relief for smaller companies are added.
Read in GermanE-commerce
Widerrufsbutton
From 19 June 2026, Section 356a BGB requires a withdrawal function in distance selling that is visible throughout the withdrawal period and reachable without a customer account. The label, the confirmation step and the acknowledgement of receipt are prescribed, while the reason for the withdrawal remains voluntary. Only what the withdrawal actually needs may be requested.
Read in GermanData protection
Aufsichtsbehörden erlassen Leitlinien zur Nutzung von Tracking-Pixel in E-Mails
In 2026 the Italian and the French supervisory authorities published guidance on tracking pixels in email and reached the same conclusion. Their use requires consent, because Section 25 TDDDG and its European counterparts apply. The exemption for marketing to existing customers covers sending the message, it does not cover the pixel inside it.
Read in GermanData protection
reCAPTCHA wird Auftragsdatenverarbeiter
From 2 April 2026, Google acts as a processor for reCAPTCHA and no longer as a controller. The operator of the website is the controller from then on, concludes a data processing agreement, updates the privacy notice and settles the legal basis for embedding the service.
Read in GermanData protection
Schwächung des Mitbestimmungsrechts von Betriebsräten in Bezug auf den Datenschutz durch Urteil des LAG Hessen
The Higher Labour Court of Hesse held that Section 87(1) no. 6 BetrVG gives the works council no right of co-determination over compliance with data protection. The employer remains responsible, and the right of co-determination concerns the technical device for monitoring performance and conduct. On that view, data protection can be governed only in a voluntary works agreement.
Read in GermanData protection
Aufsichtsbehördliche Maßnahmen aufgrund rechtsgrundloser Speicherung von E-Mail-Postfächern von Ex-Mitarbeitenden (APD (Datenschutzaufsicht Belgien))
How long may the mailbox of a departed employee stay in operation? The Belgian authority treats one month as the rule and three months as the exception, while two years with a redirect to /dev/null is unlawful. The decision belongs in every offboarding process, together with the idea of using role based addresses.
Read in GermanAI law
KI.WI Stammtisch: Aufnahmen vom 25.11.2025 zum Personenbezug von KI-Modellen und Data Act
At the AI meetup of the economic development agency of the Hannover region, the subject was whether AI models contain personal data and how to handle the conflicting views of the supervisory authorities. Barbara Thiel and Jonathan Stoklas sat on the panel, moderated by Kai Korte. Niklas Krause then outlined the fields of action under the Data Act.
Read in GermanData protection
Europäischer Datenschutzausschuss legt Transparenz- und Informationspflichten der DSGVO als Schwerpunktthema für das Jahr 2026 fest
In 2026 the coordinated enforcement framework of the European Data Protection Board deals with the transparency and information duties of Art. 12 to 14 GDPR. The German supervisory authorities last wrote to named controllers and did not conduct an anonymous survey. What needs review is therefore the privacy notice of the website and the one for employees as well.
Read in GermanData protection
Schadensersatz für Google-Recherche
Researching applicants is permitted under Art. 6(1)(b) GDPR, while the information duty under Art. 14 GDPR is mandatory. For failing to comply, the Higher Labour Court of Düsseldorf awarded 1,000 euros in non material damages, confirmed by the Federal Labour Court in March 2025. A ban on using the evidence does not follow from this.
Read in GermanData protection
Neue Einschätzung des EDSB zur Nutzung von Microsoft 365
The European Data Protection Supervisor had objected to the Commission's use of Microsoft 365 in 2024 and closed the case in July 2025. This was achieved through an amended data processing agreement with purpose limitation, named recipients, defined third countries and a notification of requests for disclosure. That catalogue works as a template for one's own contracts, as a licence it does not.
Read in GermanAI law
Neue Transparenzpflichten für interaktive KI-Systeme
From 2 August 2026, Art. 50 of the AI Act requires a notice that a person is talking to a system and not to a human being. It addresses the provider and not the deployer, which is why the duty belongs in the development stage. The exemption for obvious cases regularly does not apply to chatbots.
Read in GermanAI law
Recht auf Erklärbarkeit von Hochrisiko-KI-Systemen vor dem EuGH
The first request for a preliminary ruling on the AI Act comes from Bulgaria and concerns the right to an explanation under Art. 86(1) of the AI Act. The article considers a disclosure of the algorithm doubtful and relies on the case law on Art. 15(1)(h) GDPR. It even remains open whether the billing algorithm is an AI system at all.
Read in GermanData protection
26. Datenschutzkongress des Handelsblatts in Berlin
lexICT was a partner of the 26th Data Protection Congress held by Euroforum and Handelsblatt. Fabian Schmieder spoke about cyberattacks from the perspective of those affected, Nikolaus Forgó about the state of IT security law.
Read in GermanAI law
KI im Unternehmen: Essentials des KI-Rechts im Handelsblatt
In Handelsblatt, Kai Korte summarised the essentials of AI law, from the risk based approach of the AI Act through data protection to copyright and liability. His practical advice is an AI policy as the first line of defence, before the first purchase and not after the first incident.
Read in GermanData protection
Pressemitteilung: Barbara Thiel wird Of Counsel bei lexICT
Barbara Thiel, for many years the Data Protection Commissioner of Lower Saxony, has supported lexICT GmbH as Of Counsel since November 2024. She advises there on strategic questions of data protection and IT compliance.
Read in GermanData protection
Der Consent Mode v2 von Google Analytics
Consent Mode v2 manages consent more finely and allows a measurement without consent through a ping mechanism. It changes nothing about the need for consent, because loading the script already falls under Section 25(1) TTDSG. The Higher Regional Court of Cologne had held the use of Google Analytics unlawful in November 2023.
Read in GermanAI law
KI und Urheberrecht: Vortrag bei den Computacenter Solution Days
Fabian Schmieder spoke about artificial intelligence and copyright at the Computacenter Solution Days. Two questions from everyday work were at the centre, namely the requirements for a generated newsletter text and the use of generated images without a licence and without naming an author.
Read in GermanAI law
Die Nutzung von künstlicher Intelligenz (KI) im Unternehmen
The information duties and the right to erasure need clarifying before an AI system goes into use in a business. How far do those duties reach when the logic of the system is hard to explain? How can requests for erasure be met once inputs have entered the model? The article answers both and draws the line between controllership, joint controllership and processing on behalf of a controller.
Read in GermanData protection
Was ist eigentlich Profiling?
Profiling under Art. 4(4) GDPR is the automated evaluation of personal aspects. What is protected is less the processing than the decision based on it, see Art. 22 GDPR. The article explains this using the SCHUFA score, in which the Advocate General of the Court of Justice saw a prohibited automated decision.
Read in GermanAI law
11.10.2023: DataTalk: Künstliche Intelligenz – Revolution in Recht und Ethik
In October 2023 lexICT hosted a DataTalk on artificial intelligence, together with Hochschule Hannover, the employers' associations of Lower Saxony and further partners. The panel included the Data Protection Commissioner of Lower Saxony and Fabian Schmieder from our team. The topics were rights in generated content, data protection and the ethical perspective.
Read in GermanData protection
12.10.2023: Forum „Datenrecht„ - Data Act vs. DSGVO – schaffen wir ein innovationsfreundliches Umfeld?
The Forum Datenrecht series started in 2023 at the Institute for Innovation and Digitalisation in Law at the University of Vienna. Its first question concerned the relationship between the Data Act and the GDPR. The series is organised by Žiga Škorjanc from our team.
Read in GermanData protection
17.10.2023: „Hinweisgeberschutz„: Einladung zur Podiumsdiskussion
Austria implemented the whistleblower directive in February 2023, with internal reporting channels from fifty employees upwards. The Austrian Federal Economic Chamber and the Institute for Innovation and Digitalisation in Law discussed it, covering the group exemption, administrative fines and the handling of anonymous reports. The panel was organised by Žiga Škorjanc from our team.
Read in GermanData protection
Erleichterung durch neuen EU-US Angemessenheitsbeschluss
On 10 July 2023 the Commission adopted the adequacy decision for the Data Privacy Framework. Transfers to certified companies in the United States therefore need no additional safeguards. Standard contractual clauses remain available, and actions against the arrangement had already been announced.
Read in GermanData protection
Webinar 5 Jahre DSGVO: Aufnahme verfügbar
The recording of the webinar on the fifth anniversary of the GDPR is available free of charge. It covers case law and supervisory practice, ChatGPT, Microsoft 365 and the protection of whistleblowers.
Read in GermanData protection
5 Jahre DSGVO: Kostenloses Webinar zu Updates und Neuigkeiten
For the fifth anniversary of the GDPR, lexICT hosted a webinar in June 2023. The programme covered case law and supervisory practice, ChatGPT, Microsoft 365 and the protection of whistleblowers. The speakers were Fabian Schmieder, Kai Korte, Žiga Škorjanc and Jonathan Stoklas.
Read in GermanData protection
Welcher Captcha-Dienst ist aus Datenschutz-Sicht empfehlenswert?
Google reCAPTCHA buys its accuracy with canvas fingerprinting and a transfer to the United States. The article compares the service with FriendlyCaptcha and Arkose Labs and explains why a honeypot remains unproblematic under data protection law as an addition. What counts for the choice are the legal basis, the server location and the range of characteristics collected.
Read in GermanData protection
Fortschritt auf dem Hürdenlauf zum sicheren Datenverkehr mit den USA
In February 2023 the European Data Protection Board gave its opinion on the draft adequacy decision for the United States. The new redress mechanism drew praise, its practical handling drew reservations. Still open at the time were the approval of the member states' committee and the scrutiny by the European Parliament.
Read in GermanE-commerce
Update EU-DSA: Der Digital Services Act erreicht seine nächste Phase
The Digital Services Act entered into force in November 2022 and applies in full from 17 February 2024. The article explains which duties depend on the role and the size of a service and why publishing the number of users comes first. Smaller platforms and marketplaces are covered too, not only the very large providers.
Read in GermanData protection
Französische Aufsichtsbehörde verhängt Bußgeld gegen Discord
In 2022 the CNIL fined Discord 800,000 euros. It objected to a missing deletion concept, weak password rules and a default setting that kept microphone and camera running after the application appeared to be closed. On the impact assessment the article disagrees with the authority, because the protection of minors does not form a threshold of its own there.
Read in GermanData protection
Health and Law Network in Hannover
The Health and Law Network started in Hannover in 2022 with the involvement of lexICT. It brings together practitioners from medicine, research and data protection, which is where research data and treatment data meet.
Read in GermanData protection
BGH - Klagebefugnis bei Datenschutzverstößen
May consumer associations and competitors bring data protection infringements before a court? For associations the Court of Justice confirmed this in 2022, even without a mandate from a data subject. Two hearings on the standing of competitors were scheduled at the Federal Court of Justice, and for companies at a competitive disadvantage the choice between a complaint and court action depends on the outcome.
Read in GermanData protection
Rechtswidriges Profiling - Bußgeld gegen Bank
In 2022 the Lower Saxony authority imposed a fine of 900,000 euros on a credit institution that had analysed usage behaviour for advertising purposes. Legitimate interest covers direct marketing, profiling built from large data holdings it does not cover. What tipped the balance was the reasonable expectation of the customers.
Read in GermanData protection
Data Reform Bill 2022 – Die Reform des Datenschutzrechts im UK
In 2022 the British government planned to largely abolish cookie banners, data protection officers, impact assessments and records of processing. For companies with customers in the EU little changes, because the GDPR applies wherever the market is. The adequacy decision for the United Kingdom expires four years after it entered into force and is renewed only if the level of protection remains adequate.
Read in GermanData protection
Generalanwalt des EuGH äußert sich zum Umfang des Auskunftsrechts nach Art. 15 DSGVO
Is it enough to state categories of recipients when granting access? In 2022 the Advocate General said no and denied the controller a choice. If the Court follows that view, the privacy notices under Art. 13 and 14 GDPR would have to be adjusted as well.
Read in GermanData protection
EuGH entscheidet zu den Kündigungsvoraussetzungen für Datenschutzbeauftragte
In 2022 the Court of Justice confirmed that Section 38(2) BDSG may be stricter than the GDPR. Dismissing an internal data protection officer therefore requires serious cause, even where the dismissal has nothing to do with the data protection work. The protection continues for another year after the appointment ends.
Read in GermanData protection
Home Office und mobiles Arbeiten
Working from home moves processing to places the company does not control. The article lists the technical measures that close this gap, from the encrypted connection to the separation of private and business use. What makes them binding is a policy and not a recommendation.
Read in GermanData protection
Kann die Einwilligung Google Analytics retten?
Can consent under Art. 49(1)(a) GDPR support a transfer to Google? The supervisory authorities say no, because the provision is meant to cover occasional transfers only. The article takes the opposite view and shows which requirements such consent would have to meet.
Read in GermanData protection
Vermarktung von Webseiten: Verstößt das TCF 2.0 gegen die DSGVO?
In 2022 the Belgian authority held that the TC String is personal data and that all bodies organised within the TCF are joint controllers. From this follow an agreement under Art. 26 GDPR and joint and several liability under Art. 82(4) GDPR. The article advises advertisers to examine carefully whether they need the TCF at all.
Read in GermanData protection
Einsatz von Google Analytics rechtswidrig – Neue Entscheidung der Österreichischen Datenaufsicht
At the beginning of 2022 the Austrian authority held the use of Google Analytics unlawful, because the standard contractual clauses do not limit access by United States services. The decision does not apply directly in Germany, but comparable proceedings were pending elsewhere. The article recommends dropping the service or obtaining explicit consent.
Read in GermanData protection
Das neue TTDSG: Gesetzliche Regeln für den Einsatz von Cookies und ähnlichen Technologien
The TTDSG entered into force on 1 December 2021 and governs when cookies and comparable techniques require consent. Cookieless methods such as device fingerprinting are covered as well, because the wording of the act is technology neutral. Fines reach up to 300,000 euros, and the sanctions of the GDPR may apply alongside them.
Read in GermanData protection
3G-Testpflicht für Arbeitgeber
At the end of 2021, Section 28b of the Infection Protection Act obliged employers to check the vaccination, recovery or test status of their staff every day. The article shows how that duty could be met with as little data as possible, for example through negative lists instead of copies of the certificates. It also covers the information duty under Art. 13 GDPR, outsourcing the checks and a retention period of no more than six months.
Read in GermanData protection
Kritische Sicherheitslücke bei Microsoft (Hafnium)
The Exchange vulnerability of 2021 showed how closely the technical response and the duty to notify are linked. The article records how differently the supervisory authorities handled notification under Art. 33 GDPR and that the deadline is 72 hours. It closes with a checklist from the assessment through the patches to the notification.
Read in GermanData protection
EuGH erklärt Privacy-Shield Abkommen für unwirksam
Schrems II annulled the adequacy decision on the Privacy Shield in 2020 and placed every transfer to the United States on a new footing. The article sets out the steps for reviewing an existing stock of services from the United States. Its advice is to agree standard contractual clauses or to move to processing inside the EU.
Read in GermanData protection
Datenschutz in Zeiten des Coronavirus
Written in spring 2020, when businesses moved to working from home within days. It covers private contact details of staff, health data and risk areas, informing the workforce about infections, and securing home working and video conferences.
Read in GermanData protection
Bußgeldkonzept der Datenschutzkonferenz
In 2019 the German supervisory authorities disclosed how they calculate fines, namely through a turnover bracket, a daily rate and a factor for severity. The model does not bind courts or authorities in other member states. As an illustration of the order of magnitude, the article cites the fine imposed on a telecommunications provider in December 2019.
Read in GermanData protection
„Cookies“ nur noch mit Einwilligung … oder nicht
The Planet 49 judgment of the Court of Justice from 2019 settled what consent to cookies requires. Pre ticked boxes are not consent, consent can be required even without personal data, and information about lifespan and access has to be given. Cookies that are strictly necessary to provide the service remain exempt.
Read in German
No article for this selection yet.