Data Protection and Media Law
21st Century Law

My Services in Detail
IT law, its subfield of data protection, and the related field of media law involve a vast and almost indefinable array of laws, regulations, and other requirements, the scope of which has continued to expand in recent years. Anyone who develops software, distributes digital products, sells via platforms, works with data, or publishes digital content today faces numerous legal issues—and these span multiple areas of law simultaneously.
New regulations don't just affect large technology companies. They impact startups, agencies, software companies, SaaS providers, and online retailers—in other words, anyone whose services are delivered, marketed, or scaled digitally.
I advise founders, agencies, software companies, platform providers, and online retailers in Berlin and beyond. My practice focuses in particular on software, SaaS, cloud, and IT project contracts; artificial intelligence and data-driven products; data protection and international data processing; platforms and account suspensions; IT security and cyber incidents; copyright and licensing, trademarks and digital identifiers, e-commerce and digital products, as well as online advertising and competition law.
The focus is on the legal classification of specific business models and conflicts—taking into account technical processes, economic interdependencies, and the regulatory framework in Germany and the EU.
Below is a list of some of the legal requirements that business owners must address today. I can help you navigate these requirements, among other things.
An Overview of the Topics
- Contract Law
- Copyright
- Trademark Law
- Platforms
- Legislative Reform
- Competition Law
- AI Law
- Privacy Policy
- Cyberattacks
- Criminal Defense
Contract Law – Just Because You Paid for It Doesn’t Mean It Belongs to You
It almost always starts with a contract. In technology projects, the allocation of risk is rarely determined by the scope of work—but rather by usage rights, changes to the scope of work, availability, interfaces, data migration, subcontractors, liability, and the question of what happens when the contract ends.
In practice, services are bundled: development, hosting, maintenance, support, licensing, and ongoing customization together constitute a product. Legally, this results in a mixed contractual relationship. Whether a specific outcome is owed or merely an ongoing service may sound like an academic distinction—but it determines acceptance, the due date for payment, rights in the event of defects, and the terms of termination.
The chain of rights pertaining to the software itself is the most prone to conflict. Section 69b of the German Copyright Act (UrhG) grants the employer property rights to programs written by employees in the course of their duties. This provision does not apply to independent developers, agencies, or other contractors. Furthermore, even full payment for a development project does not mean you have the rights you need for modification, further development, sublicensing, or a future sale of the company. This is usually only realized in the data room during a financing round—that is, when your negotiating position is at its weakest.
With cloud and SaaS contracts, there is the added factor of dependence on the provider. If a service is discontinued, an account is suspended, or an interface is changed, this simultaneously affects contract law, data protection, trade secrets, and technical feasibility. Service levels and credit adjustments cover only a small portion of these issues.
Copyright – Technically possible does not mean legally protected
The same question regarding the chain of rights arises for everything that appears on a website. Software, photos, videos, text, graphics, and database structures may be protected by copyright. For agencies and technology companies, this means two things: Are the rights of use granted without exception across all parties involved—and do they also cover what is actually planned for their use?
Since 2021, the Copyright Service Provider Act has governed the liability of certain service providers for content uploaded by users. It includes blocking mechanisms as well as complaint and dispute resolution procedures. Exemptions apply to young providers: an EU-wide annual turnover of no more than ten million euros and a service that has been available for less than three years.
Case law continues to clarify the scope of software protection. In the “Action Replay II” case (judgment of July 31, 2025, I ZR 157/21), the Federal Court of Justice addressed interventions in the flow of a computer game without modifying its object code or source code. The decision shows that what matters is not whether third-party software is economically affected, but rather the specific forms of expression that are protected.
For companies, the key distinction remains between use that is technically possible and use that is legally sound. This applies to open-source components as well as to stock media, user-generated content, and AI-supported production.
Trademark Law – The Name Was Available Until It Wasn't
When rights involve multiple parties, it’s worth taking a closer look at your own name. An available domain, an available social media handle, and no identical search results do not mean that a name is free to use. Older trademarks, company names, and work titles may conflict with it without being identical.
The financial risk almost always becomes apparent only after the product launch. A rebranding then affects the website, packaging, App Store listings, ongoing campaigns, domains, and search engine rankings all at once. For international operations, national trademarks and EU trademarks with different scopes of protection must also be taken into account.
Even after registration, the process doesn’t end there. A trademark must be used in a way that can be substantiated later. In digital business models, this can quickly become confusing: changing logos, product versions, platform appearances, and country-specific offerings. Which of these are protected is determined in the event of a dispute.
Platforms – When the Sales Channel Disappears Overnight
A brand and a product are of little use if the sales channel through which they are sold breaks down. For many companies, Amazon, app stores, social networks, advertising platforms, or booking portals are the primary sales channels. An account suspension, removed listings, limited visibility, or exclusion from monetization features therefore have an immediate impact on revenue, reach, and customer relationships.
The legal situation is better than most affected individuals assume. The Digital Services Act has been fully in effect since February 2024—with provisions regarding the justification of moderation decisions, internal complaint systems, and transparency. Since May 14, 2024, the Digital Services Act has been supplemented by the Digital Services Act, which establishes German jurisdictions, a coordination office, and a central complaints office.
In addition, there is contract law. On July 29, 2021, the Federal Court of Justice ruled in cases III ZR 179/20 and III ZR 192/20 that the Facebook terms and conditions regarding post deletions and account suspensions, as reviewed at that time, were invalid. Platforms therefore cannot exercise moderation powers without contractual and procedural limits.
And it’s no longer just about blocking access. Since the 2021 amendment to the Act Against Restraints of Competition (GWB), the Federal Cartel Office has been able to take targeted action against companies with significant cross-market influence. In February 2026, it prohibited Amazon from using certain price-control mechanisms and initially recouped 59 million euros in economic benefits. The case involved mechanisms that caused offers from independent sellers to be removed or not displayed in the highlighted Buy Box.
For merchants, this means that platform terms, ranking mechanisms, and price controls are not purely product-related decisions made by the operator. They are open to challenge—under contract law, the DSA, and antitrust abuse regulations.
Legal Reform – Digital Products Have Their Own Contract Law
Anyone who sells to consumers through digital channels is subject to a set of rules that many are not yet aware of. Since 2022, the German Civil Code has included a separate body of contract law for digital products. It applies to consumer contracts for digital content and services—and, under certain conditions, even when consumers provide their data in lieu of payment (Section 327 of the German Civil Code).
For providers of apps, SaaS products, streaming services, and digital subscriptions, this raises questions regarding provision, compliance with contract terms, update obligations, changes during the term of the contract, and legal remedies in the event of defects. The rules also have an impact on the supply chain: Anyone who supplies digital products for another company’s consumer contracts may be affected by Section 327e of the German Civil Code (BGB) without ever having dealt with a consumer themselves.
In addition, there are requirements regarding the conclusion and termination of contracts. For certain continuing contractual relationships that can be entered into online, Section 312k of the German Civil Code (BGB) requires a cancellation button. Price reductions for goods must generally be based on the lowest total price over the preceding 30 days.
In addition, the essential requirements of the Accessibility Enhancement Act have been in effect since June 28, 2025. This applies, among other things, to e-commerce services that are intended to lead to the conclusion of a consumer contract via websites or apps. Accessibility is therefore no longer a matter of goodwill, but rather one of product design, user guidance, and technical implementation.
Competition Law – One Statement, Ten Channels, One Problem
What applies to the contract applies even more so to advertising: It reaches more places than one might realize when writing it. Influencer marketing and native advertising straddle the line between editorial content, personal recommendations, and commercial communication. Since 2022, the UWG has contained an explicit provision in § 5a(4): In the absence of consideration, a commercial purpose benefiting a third-party company generally does not exist—if there is consideration, such a purpose is presumed.
This doesn't just apply to influencers. Agencies, advertising companies, affiliate partners, and platform operators are all caught up in the same campaign processes. Things get complicated when it comes to product shipments, discount codes, editorial-style content, and the distinction between self-promotion and advertising for third parties.
At the same time, the requirements for environmental and sustainability claims are increasing. On June 27, 2024, the Federal Court of Justice ruled in Case I ZR 98/23 (“climate-neutral”) that when an environmental term is ambiguous, its specific meaning must be explained within the advertisement itself. This is particularly problematic for digital campaigns, as the same statement appears simultaneously on product pages, in ads, on social media, in newsletters, in retailer feeds, and through affiliates.
Such a conflict therefore does not end with the removal of an advertisement. Cease-and-desist orders and removal requests can apply to all channels. And warning letters, cease-and-desist declarations, and contractual penalties have economic consequences that extend far beyond the original campaign—often for years.
AI Law – A Lawyer Instead of AuwAIa
AI is now involved in nearly all of the areas mentioned: software development, marketing, customer service, translation, and analytics. This raises four questions for companies that are rarely addressed together. What data and content are even permitted to be entered into a system? What rights apply to the output? What can you promise your customers regarding this? And what is your own role when you customize, further develop, or offer a system under your own brand?
The AI Regulation tiers its obligations based on risk. What a company must do depends on the system, the area of application, and its specific role—which may involve risk management, documentation, transparency, human oversight, or technical controls. The regulations will be phased in over time; the first set of provisions has been in effect since 2025, with another key phase taking effect on August 2, 2026.
Germany has established the relevant responsibilities through the AI Market Surveillance and Innovation Promotion Act. Unless otherwise specified, the Federal Network Agency serves as the market surveillance authority. The Act also establishes a central complaints office, AI real-world labs, and procedures for imposing administrative fines.
In practice, therefore, it is not enough to simply categorize AI as a new tool. What matters is the entire process—from model selection, through training and input data, to integration into products and customer services. Copyright law, data protection, trade secrets, and contract law continue to apply alongside this. And particularly when it comes to AI results, exclusivity, origin, and the chain of title are often less clear-cut than technical availability might suggest.
Data Protection – The Devil Is Still in the Details
There have also been significant developments in data protection, particularly with regard to cloud services and international data transfers. The focus has shifted—away from privacy policies and toward the actual architecture of data processing.
When it comes to cloud, analytics, CRM, and AI services, it matters who has access to the data, which subcontractors are involved—and whether the provider is truly acting solely on your behalf or is also using the data for its own analytics, product improvement, or training purposes. A signed data processing agreement does not answer this question.
International data transfers are constantly evolving. Contractual transfer mechanisms must align with the actual access situation, which is determined by specific details: remote administration, support access, corporate structures, backups, log data, and control over encryption keys. Data protection is thus closely intertwined with cloud architecture, information security, and contract drafting.
At the same time, claims for damages are becoming increasingly significant. In 2024, the Federal Court of Justice emphasized that even a brief loss of control over personal data can constitute non-pecuniary damage. A data breach can therefore trigger a large number of parallel individual claims in addition to proceedings before the regulatory authorities.
Cyberattacks – While IT Is Still Searching, the Deadline Is Running Out
What applies to data flows applies even more so to incidents. Cyberattacks, ransomware, compromised login credentials, and leaks of customer or company data are not purely technical crises. While the cause is still under investigation, legal reporting, documentation, and disclosure requirements are already in effect.
With the BSI Act, which was revised at the end of 2025, Germany has implemented the NIS2 requirements. It covers “particularly important” and “important” entities, requires them to implement risk management measures, and explicitly holds senior management responsible for oversight and training.
For significant security incidents, Section 32 of the BSIG provides for a tiered reporting chain: an initial report within 24 hours, a more detailed report generally within 72 hours, and finally a concluding report. This chain exists in addition to—not in lieu of—the 72-hour deadline under data protection law.
As a result, a single incident can trigger several parallel processes: a technical investigation, a data protection report, a BSIG report, communication with customers and insurers—and, in many cases, a criminal investigation.
Criminal Defense – When an Incident Leads to a Preliminary Investigation
This is where my two areas of expertise intersect. After a ransomware attack, a data breach, or the removal of data by a former employee, it’s no longer just a matter of reporting incidents and filing insurance claims. It’s about filing criminal complaints—against others or against one’s own company—about searches and seizures, and about questioning employees.
Filing a criminal complaint grants the company the state’s investigative powers. At the same time, it relinquishes control over which systems are examined, which employees are questioned, and which related violations come to light in the process. This is a matter of weighing the pros and cons—it is not a given.
Just how closely these procedures are intertwined is illustrated by a rule that hardly anyone is aware of: Under data protection law, a report of a data breach may be used in administrative or criminal proceedings against the person who filed the report only with that person’s consent. Therefore, reporting a breach does not automatically incriminate the reporter—but one must be able to invoke this provision.
How you handle your own documents also requires careful consideration. Whether materials from an internal investigation conducted under legal counsel will be exempt from seizure during a search depends, among other things, on where they are located and who created them. This must be determined before anyone shows up at the door.
You can find out how I handle criminal cases under “Criminal Defense.”
Problems rarely come alone
Developments in recent years point in one direction: Legal requirements are having an increasingly direct impact on product design, technical processes, and architecture. For a growing company, this means that multiple areas of regulation come into play simultaneously.
A SaaS product involves contract law, data protection, IT security, and possibly the AI Regulation. A marketplace involves the Digital Services Act (DSA), consumer law, price disclosure, product safety, and competition law. A marketing campaign raises issues related to trademarks, copyright, data protection, and fair trade. Switching cloud providers is not just about technology and costs, but also involves data export, data processing on behalf of others, rights of use, and trade secrets. And a cyber incident simultaneously triggers reporting obligations, customer claims, insurance issues, and investigative proceedings.
Legal issues therefore rarely arise in isolation. They arise when new technology is introduced, a product is scaled up, content is generated automatically, or data is processed internationally—or when a business model depends on a single platform.
That's why you need to see the big picture and have a lawyer who'll go above and beyond for you if necessary.

My Advice and Offer
In disputes over technology, data, and publications, timing is usually the deciding factor: deadlines are approaching, and the initial response determines what can still be negotiated later. Please send me whatever you have.
You'll receive a prompt assessment of what's at stake and what options are available.
Frequently Asked Questions
Our account has been suspended. How soon do I need to get in touch?
Immediately. Not because the matter is urgent, but because several deadlines are running concurrently: the platform’s internal appeals process, the one-month enforcement period for a preliminary injunction, and the urgency that a court will no longer accept as valid if you’ve been corresponding with support for six weeks.
We've received a cease-and-desist letter. Can't I just sign the cease-and-desist agreement to put an end to this?
You can—but in doing so, you’ll be committing yourself for years to a contractual penalty for every future attributable violation, even accidental ones. That’s the most expensive kind of peace of mind. Send me the warning letter with the deadline before you sign anything.
When do the 72 hours start counting in the event of a data breach?
From the time the breach is known, not from the time the damage is identified. Exactly where the threshold for “knowledge” lies—when only technical anomalies are initially present—has not been definitively clarified; and it is precisely this time period that later determines whether a report was late.
We use AI only as a tool. Does the AI Regulation even apply to us?
Perhaps more than you think. The role isn't determined by how you describe yourself, but by what you do with the system—customization, fine-tuning, or reselling under your own brand can turn a user into a provider.
Go Directly to the Law
- Phone: 030 23258357, Mon–Fri, 2:00–4:00 p.m.
- Email anfrage@rakff.deResponse within 24 hours
- Address: Gneisenaustr. 115, 10961 Berlin; U-Bahn station: Mehringdamm (U6, U7), a one-minute walk

“Freedom is always the freedom of those who think differently.”

Rosa Luxemburg
1871 – 1919
