TMT Newsletter | July 2026

Outlook

30.07.2026

Hearing

German Federal Court of Justice: Is it required that a phonogram producer permits the copying and use of a rhythm fragment from a sound recording? The FCJ is expected to focus on the recently specified requirements of the "pastiche" exception within the meaning of Article 5(3)(k) InfoSoc Directive (following CJEU, case C-590/23 ("Pelham II"); I ZR 74/22 ("Metall auf Metall V")).

Hearing

German Federal Court of Justice: Does forwarding private chat messages initially shared among employees to an employer violate Article 6 GDPR, or does the GDPR not apply in this case, Article 2(2)(c) GDPR (I ZR 256/25)?

31.07.2026

Decision

Regional Court of Munich I: Does it violate the right of reproduction and the right of making available to the public (Secs. 16, 19a German Copyright Act) if musical works are used to train an AI system that generates output which sounds similar based on a user prompt (42 O 763/25)?

As a general rule, the CJEU does not hold hearings between 16.07.26 and 31.08.26 (judicial recess).

News

CJEU – On the scope of the hosting provider privilege

A hosting provider acts within the scope of the E-Commerce Directive even where hosted third-party content consists of (unlawful) advertisement for gambling, because the hosting activity itself is not directly connected to gambling within the meaning of Article 1(5)(d) E-Commerce Directive. However, the hosting provider may nevertheless, under certain circumstances, be unable to rely on the liability exemption (Article 14 E-Commerce Directive; now Article 6 DSA) where, under a "commercial partnership agreement", it reviews a third party's content for matters such as originality and quality. This applies regardless of whether the review is automated or conducted by humans (C-421/24).

CJEU – A service provider's app store pre-installation requirements are abusive

A service provider may abuse its dominant market position if it makes device manufacturers' access to its app store conditional on pre-installing other services (Article 102 TFEU, Article 54 TFEU). Such conditions can create a bias in favor of the pre-installed services that is difficult for competitors to counteract. Further, banning the distribution of unauthorized versions of an operating system may also be abusive if it prevents the development and marketing of alternative digital ecosystems. The Commission is not required to prove the exclusion of as-efficient competitors. It is sufficient to conduct an overall assessment of the digital market environment, taking into account network effects, ecosystem lock-ins, and barriers to entry (C-738/22 P).

CJEU – On the international jurisdiction for infringements of personality rights arising from linear TV broadcasts

In principle, claims for infringement of personality rights arising from a cross-border television broadcast must be brought either at the defendant's domicile or at the place where the harmful event occurred (Article 5(3) Brussels I Regulation (44/2001); now: Article 7 No. 2 Brussels Ibis Regulation (1215/2012)). The CJEU does not apply the principles set out for an infringement of personality rights resulting from online content (Cases C-509/09 and C-161/10: possible jurisdiction at the affected person's center of interests). Unlike online content, a television broadcast can be territorially localized. This applies even where a television series can be accessed online, but the person affected is not sufficiently identifiable (C-232/25).

CJEU – On the exemptions under Article 85 GDPR and the concept of "journalistic purposes"

National provisions that exclude online databases containing unedited decisions by criminal courts from the scope of the GDPR while referring affected persons to criminal and civil defamation remedies violate Article 85 GDPR. The GDPR provides specific legal remedies (e.g., the right to lodge a complaint, Article 77 GDPR). While Article 85(2) GDPR allows for exemptions in specific areas, the provision does not cover the GDPR's legal remedies as it does not refer to Chapter VIII of the GDPR. Further, the databases do not serve "journalistic purposes" within the meaning of Article 85(2) GDPR (C-199/24).

CJEU – On the right of withdrawal for streaming subscriptions as a "digital service"

Where a service goes beyond the provision of specific content, it qualifies as a "digital service" (and not as "digital content") within the meaning of Article 2(16), (11) of Directive 2011/83/EU. The CJEU's decision concerned a streaming service for audiovisual content that adapts the content to user behavior and provides recommendations. Consequently, it is not possible to exclude the 14-day right of withdrawal for "digital services" (Article 9, 16(1)(m) of Directive 2011/83/EU). For cases of abusive behavior, the CJEU refers to the consumer's obligation to pay a proportionate amount for the service under Article 14(3) of Directive 2011/83/EU (C-234/25).

CJEU – Effective geo-blocking excludes communication to the public

An uploader does not carry out a communication to the public (cf. Article 3(1) InfoSoc Directive) in the countries where it prevents access through state-of-the-art geo-blocking measures (Article 6(3) InfoSoc Directive). The fact that such a restriction can be circumvented by technical means (e.g., via a VPN) does not automatically render the measure "ineffective". However, where no "effective" technological measures are implemented, there may be communication to the public by the uploader, and not the VPN provider (C-788/24).

CJEU – Publication of anti-doping rule violations may be compatible with the GDPR

The publication of such violations does not, in principle, involve health-related data (Article 9 GDPR). This may be different where the published information (e.g., regarding the substance used) allows conclusions about the athlete's health. Such publication may be necessary and appropriate in the public interest under Article 6(1)(c), (e), and (3), subpara. 2 GDPR. However, national regulations must allow the controller (in this case: a national anti-doping agency) to assess the relevant interests in each individual case. The affected athlete may file a complaint under Article 77 GDPR to prevent the publication (C-474/24).

EGC – App stores on different devices qualify as one intermediation service

The Court's decision confirms that the app store in question qualifies as a core platform service (Article 3(1)(b) DMA). Even if different versions exist for different devices or operating systems, the app store qualifies as one online intermediation service (Article 2 No. 5 DMA). This is based on the app store's common purpose of connecting business users (in this case: software developers) and end users. An appeal to the CJEU is possible (T-1079/23, T-1080/23, T-214/24, not yet final and binding).

EU Commission – On a potential gatekeeper designation based on a qualitative assessment

According to the Commission, two cloud computing services should be designated as gatekeepers within the meaning of Article 3 DMA. Neither meets the quantitative thresholds set out in Article 3(2) DMA. The Commission therefore relies on the qualitative assessment under Article 3(8) DMA, taking into account the service providers’ turnover, operational capacity, investments, AI portfolio, and the size of their ecosystem. The service providers may now submit formal replies (press release of 25.06.26, not yet final and binding).

EU Commission – DMA guidelines issued for service provider regarding interoperability and access to search data 

The service provider must grant competitors' AI assistants equal access to features of its operating system (e.g., voice commands) as it does to its own assistant (Article 6(7), Article 8(2) DMA). It is also required to make certain anonymized search data (e.g., ranking data) from its search engine available to third-party providers under fair, reasonable and non-discriminatory terms (Article 6(11), Article 8(2) DMA). These guidelines are legally binding. The service provider may challenge the guidelines by way of an action for annulment (Article 263 TFEUpress release of 16.07.26).

EU Commission – Fine imposed on service provider for alleged DMA violations

According to the Commission, the service provider gives preferential treatment to its own services – e.g., for shopping or sports results – over those of third parties when operating its search engine. The provider's own services are allegedly ranked more prominently or visually highlighted in the search results (Article 6(5) DMA). The service provider is also accused of preventing app developers in its app store from informing customers about their offers and from entering into contracts with them through distribution channels of their own choosing (Article 5(4) DMA). The service provider may challenge the decision by way of an action for annulment (Article 263 TFEUpress release of 23.07.26, not yet final and binding).

EU Commission – The design of two very large online platforms preliminarily found to be "addictive"

According to the Commission’s preliminary assessment, the design of the services does not comply with the requirements of the DSA. The Commission points to features such as infinite scrolling, autoplay, push notifications, and recommendations. The service provider is also accused of not adequately assessing and effectively mitigating risks to users' physical and mental wellbeing (Article 34(1), subpara. 2, sentence 2, lit. d, Article 35 DSA). The service provider may now submit a formal reply (press release of 10.07.26, not yet final and binding).

EU Commission – Fine imposed on very large online platform for alleged non-compliance with DSA risk management obligations

According to the Commission, the service provider did not properly assess the systemic risk of disseminating illegal content through its service (Article 34(1), subpara. 2, sentence 2, lit. a DSA). The Commission points to insufficient staffing and the use of recommender systems that allegedly intensify the dissemination of such content. In addition, the service provider's risk mitigation measures are deemed inadequate (Article 35(1)(d) DSA). The service provider is now required to submit an action plan (Article 75 DSA; press release of 20.07.26, not yet final and binding).

German Federal Court of Justice – Uniform standard for copyright protection of works of applied art

A modular furniture system can be protected under copyright law (Sec. 2(1) No. 4, (2) German Copyright Act). The criterion of originality must be assessed according to uniform, objective standards for all types of works. This also applies to works of applied art. While recognition within professional circles or the author's creative intent may serve as indicators of copyright protection, they are not decisive for the assessment. An aesthetic effect can only justify copyright protection to the extent that it is based on and expresses an artistic effort (I ZR 96/22; following CJEU, cases C-580/23 and C-795/23; see also the Newsletter of December 2025).

Higher Regional Court of Hamburg – Referral to the CJEU on the admissibility of a model action for a declaratory judgment for GDPR compensation

The court has stayed the proceedings concerning an alleged "data scraping" incident on a provider's service. The CJEU is asked to clarify whether, and under what conditions, an association may assert such claims by means of a model declaratory judgment (Article 80(1), (2), Article 82(1) GDPR). The court is also referring the questions of whether international jurisdiction in such cases is governed by Article 7(2) Brussels Ibis Regulation (1215/2012) or by Article 79(2) GDPR, and whether Article 7(2) Brussels Ibis Regulation permits the bundling of claims for damages that occurred in different places (11 VKI 1/24).

German Federal Network Agency – Design of an online marketplace preliminarily does not meet DSA requirements

The German Federal Network Agency criticizes the service's notice and action mechanism (Article 16 DSA) as not being easily accessible or user-friendly. It also criticizes that the requirements regarding the statement of reasons for measures against users (Article 17 DSA) are not fully met, and that information on trader traceability (Article 30 DSA) is not easy to find and is not presented in a user-friendly manner. The service provider may submit a formal statement (press release of 06.07.26, not yet final and binding).

State Media Authorities – Service providers must comply with media law transparency and equal treatment obligations for "AI Overviews" and "AI chatbots"

The German state media authorities of Hamburg/Schleswig-Holstein and Berlin-Brandenburg have issued orders against service providers regarding their AI services. The authorities take the view that AI-generated answers constitute content of the service providers. They further criticize that this content may not be given prominent placement within media intermediaries. The authorities also consider chatbots to be media intermediaries (Sec. 2(2) No. 16 MStV) that are required to comply with transparency obligations and non-discrimination obligations (Secs. 91-94 MStV). According to the authorities, the DSA liability rules therefore do not apply to these services. The service providers may appeal within the proceedings (press release of 14.07.26, not yet final and binding).