European Union

On July 9, 2026, the Court of Justice of the European Union (“CJEU” or “Court”) delivered its judgment in Sky Österreich Fernsehen (C-234/25), deciding that a streaming offering constitutes a digital service under the Consumer Rights Directive (Directive 2011/83/EU), rather than digital content, where the trader’s offering is of a dynamic nature and goes beyond the stable or continuous provision of specific content. As a result, providers of such streaming offerings cannot rely on the Consumer Rights Directive’s exception to the right of withdrawal for digital content.

The judgment has broad implications for providers of personalised digital services, as it affects whether consumers can cancel a subscription during the 14-day withdrawal period and, if they do, how much providers may charge for use of the service during that period.

Continue Reading CJEU Decides When Streaming Subscriptions Are Subject to the Right of Withdrawal

On 3 June 2026, the European Commission published several legislative and policy measures wrapped up in one “tech sovereignty” package (see our posts summarising the package as a whole here, and diving deeper into the Cloud and AI Development Act here). But the EU’s tech sovereignty drive has a long history, and is by no means limited to this package.

In this post, we take a closer look at the current and forthcoming EU legislative measures aimed at increasing the resilience of services provided in the EU against external, malicious influence, a key aspect of tech sovereignty. Relevant legislation falls into two broad categories: (1) laws promoting cyber resilience generally, to prevent malicious actors from disrupting services and critical infrastructure; and (2) laws focused on building supply chain resilience and reducing dependencies on certain external actors by building European industrial capacity in key tech sectors.

Continue Reading Looking beyond the tech sovereignty package: how the EU is moving to ensure tech sector resilience

On July 7, 2026, the Irish National Cyber Security Centre (“NCSC”) published guidance for management boards and senior executives of organizations subject to the EU’s Network and Information Security Directive (“NIS2”). Reflecting a central theme of NIS2, the Guidance makes it clear that cybersecurity is no longer solely a technical issue, but a governance and risk-management matter that requires active oversight at “the highest levels of executive management.”  It is a helpful document for organizations that are likely to be subject to NIS2, expect to be supervised in Ireland, and that are considering their governance structures and board-level oversight mechanisms.

Continue Reading Irish NCSC Issues Cyber Governance Guidance for Management Boards Ahead of NIS2 Implementation

On May 26, 2026, the French data protection authority (“CNIL”) published updated versions of its Reference Methodology 001 (“MR-001”, available here in French) and Reference Methodology 003 (“MR-003”, available here in French), two key frameworks governing the processing of personal data in the context of health research.

Continue Reading CNIL Updates Two Standards For Health Research (MR-001 and MR-003)

On May 26, 2026, the Spanish Data Protection Agency (“AEPD”) published details of its decision to fine Amadeus IT Group, S.A. (“Amadeus”), a Madrid-headquartered technology provider for the global travel and tourism industry, EUR 18 million in connection with GDPR violations involving Amadeus’s Global Distribution System (“GDS”). Amadeus voluntarily paid the fine, less a 20% reduction, on May 29, 2025, thereby terminating the proceedings without admitting liability. The fine, one of the largest the AEPD has imposed, highlights the enforcement risks associated with repurposing personal data such as passenger data without appropriate transparency or a valid legal basis under the GDPR.

Continue Reading Amadeus IT Group Receives GDPR Fine

On May 28, 2026, the European Union Agency for Cybersecurity (“ENISA”) published the third edition of its NIS360 report, an annual benchmarking tool that assesses the cybersecurity maturity of entities in the sectors set out in Annex I of the NIS2 Directive (which includes certain entities in the energy, transport, healthcare, digital infrastructure, and space sectors), as well as the relative criticality of the relevant sectors. The NIS360 is designed to support national authorities, policymakers, and other stakeholders in understanding where sectors stand in terms of cybersecurity readiness, including where more support or oversight might be needed.

Continue Reading ENISA’s NIS360 2026 report highlights both the criticality of the European space sector, and flags a persistent cybersecurity maturity gap

On 19 May 2026, the European Commission published its long-awaited draft, non-binding guidelines on the classification of high-risk AI systems (“HRAIs”) under the EU AI Act (the “Guidelines”). Across three documents—covering general principles, high-risk classification in the context of regulated products (Annex I), and high-risk use cases (Annex III)—the Commission sets out its approach to one of the AI Act’s central questions: when does an AI system fall within the high-risk regime (and, just as importantly, when does it not)?

Rather than restating every aspect of the Guidelines, this post highlights a number of interpretative points likely to matter most in practice.

Continue Reading EU AI Act Update: The European Commission Publishes Draft Guidelines on HRAIs

On 7 May 2026, negotiators from the Council of the European Union, the European Parliament, and the European Commission reached a provisional agreement on the terms of the Digital Omnibus on AI, marking the first set of amendments to the EU AI Act since its adoption in June 2024. The final package of amendments reflects a mix of pragmatic timeline extensions, focused simplification measures, and a small number of substantive policy changes.

Continue Reading EU AI Act Update: Timeline Relief, Targeted Simplification, and New Prohibitions

The European Commission has set a clear timeline for rolling out age verification across the EU:

  • by June 30, 2026, Member States are encouraged to submit implementation plans; and
  • by December 31, 2026, at least one EU‑compliant age verification solution should be available in each Member State.

This timeline, set

Continue Reading EU Sets the Clock on Age Verification: Rollout Urged by End‑2026