Categories
Technology- & IT-Law

AI washing in Germany

The term “AI washing” (also known as “AI washing”) refers to a practice whereby companies and organizations describe or market their products, services or projects as artificial intelligence (AI), even though this description is either misleading or greatly exaggerated. This shows that exaggerated advertising of AI products in the course of AI washing can result in tangible criminal liability.

Categories
Liability of the management Technology- & IT-Law

Cybersecurity in Germany: Implementation of the NIS2 Directive in Germany

Implementation of the NIS2 Directive in Germany: There are now draft laws on the implementation of the NIS2 Directive in Germany, and a clear line can be seen. In Germany, the NIS2 Directive is implemented by the “Act on the Implementation of the NIS-2 Directive and on the Regulation of Essential Principles of Information Security Management in the Federal Administration”. It is also known as the “NIS-2 Implementation and Cybersecurity Strengthening Act” or “NIS2UmsuCG” for short.

At the heart of it all is the German “BSI Act”: this law was originally created to regulate the competencies and measures of the Federal Office for Information Security (BSI). However, this law is increasingly being transformed into a set of cyber security regulations. This was already foreseeable with the German IT Security Act and has been enhanced with the IT Security Act 2.0. IT security in Germany – and Europe – is thus being raised to a completely new level and the economy in particular will have to dress warmly.

Note on the current status of the legislative process: The NIS2 Directive must actually be implemented by mid-October. However, draft bills have only been available since May 2024, which already raises doubts as to whether this will happen in time. With this in mind, a paragraph has been added on what delayed implementation means. The article has been updated to the status of the second draft bill (processing status: 24.06.2024).

Categories
Criminal Defense Liability of the management

Breach of a duty to look after assets as a board member of a stock corporation

The German Federal Court of Justice (3 StR 329/21) was able to comment on the breach of a duty to look after assets as a board member of a public limited company. The BGH emphasized that, from a legal point of view, it must be assumed that the management board of a stock corporation must be granted a wide scope of action when managing the business of a company, without which entrepreneurial activity is absolutely inconceivable.

Categories
Technology- & IT-Law

Gaming law – Cheats, bots & Co.: Legal issues surrounding online computer games in Germany

Gaming behavior with regard to computer games on the computer has changed considerably in recent years: Where floppy disks and CDs used to be the norm, sometimes in combination with obscure-looking copy protection measures (I fondly remember the Mix’n’Mojo hub at Monkey Island, which, incidentally, is also available online today), today not only downloads prevail, but also completely new gaming cultures, some of which have shifted entirely to the online realm.

Massively Multiplayer Online Role-Playing Games (MMORPGs) such as World of Warcraft have heralded a real cultural change in this respect – and also completely new legal issues: whereas people used to be most concerned about how best to copy games, today other desires prevail. At a time when accounts cost money and virtual goods have a real market value, cheating in games is viewed very differently. This is also reflected in recent court decisions. Lawyer Jens Ferner, who works in the field of software law, including legal issues relating to online games, provides an overview.

Categories
Technology- & IT-Law

Law on the development of computer games in germany

Computer games and the law in Germany: The world of computer games has developed rapidly in recent decades and is now a major industry that delights millions of people worldwide. However, behind the colorful graphics and exciting stories lies a complex legal landscape that developers, publishers and other parties involved must take into account. The law governing the development of computer games encompasses numerous areas of law, from copyright and media law to data protection and the protection of minors.

Categories
Cybercrime Cybersecurity Liability of the management

Strategies for ransomware negotiation

Is there a strategy for dealing with ransomware? Ransomware is a type of malware that blocks access to the victim’s system or data and demands a ransom to unlock or release it. Negotiations with cybercriminals over such attacks can be complex and risky.

Ransomware attacks are one of the biggest threats to companies worldwide: dealing with such crises correctly, especially negotiating with the attackers, can be crucial to minimizing the damage and regaining control. I am an atypical source of information here because I usually work as a lawyer for the attackers and therefore have completely different insights.

I would like to loosely explore the question of whether there can be fundamental strategic considerations on this topic. And indeed, based on current studies and practical experience, important insights can be gained and mistakes that can occur during negotiations can be avoided.

Categories
Technology- & IT-Law

Software development contract: Contract for the development of software in Germany

A software development contract regulates the relationships and obligations between a client who wishes to have software developed and a software developer or a software development company.

The core of such a contract is to precisely define the specifications and requirements of the software to be developed in order to ensure that the end product meets the client’s expectations. In practice, however, it is precisely this part that is shied away from, firstly because it does not seem practicable, as requirements are always subject to change anyway, and secondly because people shy away from the work involved.

Categories
Cybersecurity Technology- & IT-Law

Contract design for IT security services in Germany

IT security services: IT security is – quite rightly – the dominant topic today and continues to play an increasingly important role in everyday life. The question of how to deal with it when companies engage external service providers to secure their systems is still somewhat out of focus.

This article provides a clear overview of what should be considered when drafting a contract for an IT security service in Germany in order to protect both parties – provider and customer.

Categories
Cybercrime

North Korean group LAZARUS – Security notice on cyber espionage activities

A joint security advisory from the BfV and NIS dated February 19, 2024 provides information on North Korean cyber espionage activities against the defense industry. North Korea focuses on stealing advanced defense technologies to strengthen its military.

The note contains tactics, techniques, procedures (TTPs) and indicators of compromise (IoCs) of the DPRK. It describes two cases of cyberattacks: a supply chain attack on a research center and social engineering attacks by the LAZARUS group. The recommendations emphasize preventive measures and raising awareness of such threats in the defense industry and other sectors.

Categories
Criminal Defense

BFH ruling on international account information

In a recent ruling dated January 23, 2024 (IX R 36/21), the German Federal Fiscal Court (BFH) ruled on the constitutionality of the automatic exchange of financial account information and its compatibility with fundamental rights. This issue has far-reaching implications for taxpayers with accounts abroad.