Your Company and the EU‘s “Digital Strategy”

Your Company and the EU‘s “Digital Strategy”

In February 2020 the European Commission published their “digital strategy” which would mark a “digital decade” and as part of which, a bundle of measures, especially regulations, would follow. The strategy is based on “three pillars”, one of which describes the fair and digital economy.

The following summary creates an overview of these measures, keeping in mind your business interests:

Just the essentials. Straightforward. No detours or digressions. Here:

"Was da ist"

EU Data Act

 

Entered into force on the 11.02.2024

 

Regulatory Content

  • allocation of a right to data as an intellectual property right (“Ownership of Data”)
  • access/usage of Data generated in the EU
  • data access and sharing resulting from the use of connected devices (IoT) by customers or third parties
  • protecting SMEs from unfair contract terms
  • seamless and free switching between different cloud services (multi-cloud)
  • inoperability standard

Affects:

  • All legal entities, which offer or use IoT devices or cloud services
  • “reassessing monetization opportunities”
  • Data usage agreements will need to be concluded

EU Chips Act

 

Entered into force on the 21.09.2021

 

Regulatory Content:

  • strengthening the “semiconductor ecosystem” in the Eu, ensuring supply chain security, and reducing external dependence
  • package of measures to double market share to 20%
  • investment program: mobilizing 43 billion euros

Affects:

  • directly affects any company integrating chips
  • Indirectly affects every company whose software service requires such hardware

Digital Services Act (DSA)

 

Entered into force on the 16.11.2022

 

Regulatory Content:

  • reducing the risk of disinformation (see also Strengthened Code of Practice on Disinformation)
  • protection against illegal content / of business property rights against unfair competition
  • transparency regarding classification, ratings, purchasing behavior and communications on platforms
  • duty to monitor marketplaces: “know your customer”

Affects:

  • online intermediaries and platforms
  • online marketplaces, social networks, content-sharing platforms
  • market and legal positions of SMEs and startups that sell through platforms

Digital Markets Act (DMA)

 

Entered into force on the 01.11.2022

 

Regulatory Content:

  • competition law restrictions on dominant market positions
  • conduct requirements regarding access, preselection, and ranking

Affects:

  • anyone developing data driven (product-) innovations
  • anyone, who requires a large amount of accessible data: software test, AI-training

Data governance Act (DGA)

 

Entered into Force on 23.06.2022

 

Regulatory Content:

  • created cross-sector and cross-border open data space “making data available”
  • regulating data intermediaries to build trust in the exchange of data

Affects:

  • anyone developing data driven (product-) innovations
  • anyone who requires a large amount of accessible data: software test, AI-training

EU AI Act

Entered into force 01.08.2024

Regulatory Content:

  • ranking of AI-systems by risk factor
  • unacceptable, high (human resource management tools), limited (chatbots), and minimal risk
  • oversight by a notified body

Affects:

  • AI developers and users
  • establishing, documentation and maintenance of risk management systems
  • Transparency requirements

Cyber Resilience Act

Entered into force on the 10.12.2024

Regulatory Content:

  • protection of businesses (and others) from products with inadequate security features
  • mandatory cybersecurity requirements
  • manufacturer responsibility throughout the entire product lifecycle
  • market surveillance

Affects:

  • anyone putting cybersecurity products (software or hardware) on the market
  • anyone using such products

“As an aside”

There is noteworthy news regarding GDPR, whereby an adequacy decision relating to the EU-U.S. Data Privacy Framework pursuant to Artikel 45 of the GDPR, which came into force on the 10.07.2023. This decision certifies that the level of protection provided by certified companies is adequate and can therefor serve as the basis for data transfer to the U.S.

Does your company still have doubts about Google Analytics?

Your contacts

Peter Wagner

E peter.wagner@jordan-ra.com
T 0711 255 404-60
F 0711 255 404-70

Dr. Thomas A. Degen

E thomas.degen@jordan-ra.com
T 0711 255 404-60
F 0711 255 404-70

Dr. Hanns-Georg Pipping

E hanns-georg.pipping@jordan-ra.com
T +49 (0)711 255404-60
F +49 (0)711 255404-70



Mathias Lang LL.M.

Fachanwalt für IT-Recht
E mathias.lang@jordan-ra.com
T 0711 255 404-60
F 0711 255 404-70

Tilo Schindele

E tilo.schindele@jordan-ra.com
T +49 (0)711 255404-60
F +49 (0)711 255404-70

Dr. Arnd-Christian Kulow

E arnd.kulow@jordan-ra.com
T +49 (0)711 255404-60
F +49 (0)711 255404-70


Marzia Carla Iosini, LL.M.

E marzia.iosini@jordan-ra.com
T 0711 255 404-60
F 0711 255 404-70

Secretariat

Judith Himmelseher

Geprüfte Rechtsfachwirtin
Assistentin
E judith.himmelseher@jordan-ra.com
T 0711 255 404-60
F 0711 255 404-70

Nadine Schneider

Rechtsanwaltsfachangestellte
Assistentin
E nadine.schneider@jordan-ra.com
T 0711 255 404-60
F 0711 255 404-70

Alice Heger

Geprüfte Rechtsfachwirtin
Assistentin
E alice.heger@jordan-ra.com
T 0711 255 404-60
F 0711 255 404-70