CJEU on the Right of Withdrawal for Streaming Subscriptions: What Providers Need to Review Now

22.07.2026Gernot Fritz, Fabian Duschnig, Laurin Lutz Millions of consumers sign up for streaming subscriptions online. As part of the sign-up process, they are often required to agree that the provider may begin performing the contract immediately and that they will consequently lose their right of withdrawal. Until now, this has been a common way for […]
From Satellites to Data: How the Cyprus Presidency Compromise Redraws the EU Space Act’s Downstream Reach

20.07.2026Gernot Fritz, Amina Kovacevic The EU Space Act has largely been discussed as a regulatory framework for satellites, launches and space infrastructure. The Cyprus Presidency Compromise text, however, places considerably greater emphasis on what those assets ultimately produce: space-based data. This shift matters well beyond the traditional space sector. Satellite-generated information supports communications, Earth observation, […]
AIFMD II in Austria: What the New Framework Means for the Funds Industry and Beyond

16.07.2026 Private credit in Austria just got a dedicated legal home. On 7 July 2026, the Austrian National Council passed the bill transposing AIFMD II into Austrian law. For AIF-managers, the message is clear: the rules have caught up with the market. The question now is how to make the most of them. A Framework […]
Anonymous for whom? The EDPB’s new framework for anonymisation under the GDPR

10.07.2026Gernot Fritz, Tanja Pfleger Anonymisation promises significant advantages. Once information has been successfully anonymised, it no longer qualifies as personal data and falls outside the scope of the GDPR. It may therefore be used, shared and analysed with considerably greater freedom. But when is data truly anonymous? Removing names and other direct identifiers is rarely […]
Parallel, not exclusive: The CJEU clarifies the GDPR system of remedies
06.07.2026Gernot Fritz, Fabian Duschnig The relationship between lodging a complaint with a data protection supervisory authority under Article 77 GDPR and bringing a judicial remedy against a controller under Article 79 GDPR has raised practical questions ever since the GDPR became applicable. Can both routes be pursued at the same time? And may a supervisory […]
The Digital Omnibus on AI has arrived: New timelines, less duplication, more clarity
03.07.2026Gernot Fritz, Tanja Pfleger, Fabian Duschnig On 29 June 2026, the Council of the European Union gave the green light to simplify the AI rules under the Digital Omnibus on AI, also referred to as the Omnibus VII package (press release). This sets the legislative direction: the key application dates for high-risk AI systems will […]
Obtained in Breach of Data Protection Law – Admissible Nonetheless? The CJEU on the GDPR in Civil Proceedings

25.06.2026Gernot Fritz, Tanja Pfleger, Sabine Prossinger In its judgment of 18 June 2026 in Case C-484/24 (NTH Haustechnik), the CJEU issued a highly relevant decision for litigation practice on the interface between data protection law and the use of evidence. At its core, the case concerns a question that repeatedly arises in employment and civil […]
AI in Business Operations: When Data Flows Become a Risk

09.06. 2026Gernot Fritz, Tanja Pfleger Artificial intelligence is no longer a topic for the future. In many companies, AI systems are already answering customer enquiries, summarising documents, searching internal knowledge bases, supporting HR processes or assisting with software development. This brings new efficiency gains – but also new legal and technical attack surfaces. The key […]
EU Space Act vs NIS2: How the compromise text reshapes the cybersecurity architecture

27.05. 2026Gernot Fritz, Amina Kovacevic European space law is currently undergoing a fundamental regulatory shift. This is particularly visible in the area of cybersecurity. While the European Commission’s original proposal for the EU Space Act of 25 June 2025 still placed strong emphasis on a standalone, sector-specific cybersecurity regime for the space sector, the current […]
Who Is Responsible in Space? – Private Space Activities and State Responsibility

13.05. 2026Gernot Fritz In April 2026, space lawyers and diplomats met again in Vienna for the 65th session of the Legal Subcommittee of UNCOPUOS. The setting was familiar: international law, treaty principles and the long-standing question of how to ensure the peaceful and responsible use of outer space. The 65th session took place from 15 […]
Data Protection Supervision 2025: Rising Caseloads and New Responsibilities
11.05. 2026Gernot Fritz, Fabian Duschnig In April 2026, both the Austrian Data Protection Authority (DSB) and the Parliamentary Data Protection Committee (PDK) published their activity reports for 2025. Read together, the two reports point to a development that is more relevant in practice than any individual figure: data protection supervision is becoming broader, more complex […]
AI and Data Protection: Input Data – The Moment of Truth

04.05. 2026Gernot Fritz, Tanja Pfleger Alongside training data, which we discussed in our previous article, one of the key data protection risks of AI systems lies in what users enter into them. Input data is the blind spot of practice. A prompt is written in seconds. A file is uploaded just as quickly. A use […]
Who Is Liable When Things Go Wrong in Outer Space?

30.04.2026 From Gernot Fritz In a previous post, we asked a deceptively simple question: Who owns the Moon? The answer led us into the core principles of space law, in particular the idea that outer space is not subject to national appropriation. But if no one owns space, a more pressing question quickly follows: what […]
AI and Data Protection: Training Data – The Invisible Foundation

28. April 2026Gernot Fritz, Tanja Pfleger The legal risks of AI systems do not arise at the point of use – they arise much earlier. Not at deployment, not at the prompt or output stage, but at a phase that still receives surprisingly little attention in many projects: training. This is where the foundations are […]
Outer Space: More Than a Legal Wild West

27.04.2026Gernot Fritz A satellite drifts out of control and threatens to collide with another object in orbit. A private company launches a constellation of hundreds of satellites, reshaping entire orbital regions. A state conducts a test that generates thousands of debris fragments, affecting missions worldwide. None of this is hypothetical. And yet, when confronted with […]
Who Owns the Moon? – Non-Appropriation, Commercial Use, and the New Space Economy

15.04.2026Gernot Fritz Space law has always been a discipline at the intersection of multiple legal domains. It combines elements of public international law, regulatory governance, contract law, and increasingly also resource and technology law. At the same time, it is one of the most internationally coordinated areas of law, shaped in particular by the five […]
UN Model Clauses on Data Contracts: Contractual Logic for the Data Economy

02.04.2026Gernot Fritz, Amina Kovacevic Data contracts have long become part of commercial reality. Companies procure datasets, obtain access to ongoing data streams, integrate data into platforms, and use it to develop new products, models, and services. However, the legal classification of these constellations remains inconsistent. Depending on their structure, data contracts fall somewhere between licence, […]
Article 17 GDPR and Injunctive Relief: On the Scope of the Right to Erasure

01.04.2026 Gernot Fritz, Fabian Duschnig The right to erasure under Article 17 GDPR is one of the most prominent and practically relevant data subject rights. At the same time, the question has long been raised how far this right extends – in particular, whether it not only covers the deletion of already processed data but […]
AI & Copyright: Why the Debate No Longer Starts with Training Alone

27. March 2026Gernot Fritz, Hannah Kercz, Amina Kovacevic The copyright debate surrounding artificial intelligence has gained significant clarity and intensity over the past two years. What was long treated as a largely theoretical question is now increasingly shaped by case law. Across Europe, the United States, and Asia, more defined legal contours are emerging – […]
Access, Abuse, Damages: CJEU Draws the Line
26.03.2026Gernot Fritz, Tanja Pfleger In its judgment of 19 March 2026 in case C-526/24 (Brillen Rottler), the CJEU addressed key practical questions on the interplay between the right of access, the concept of abuse, and damages under the GDPR. The Court clarified, on the one hand, that controllers may, in exceptional circumstances, rely on the excessive […]