Technology and IP Quarterly Q3 2026
BAHR
1
Table of Contents Intellectual property rights ..................................................................................................... 4 Digital regulation and data protection ............................................................................... 17 BAHR Technology ................................................................................................................... 35
Editorial team
Eirik Basmo Ellingsen
Jacob A. Møller
Knut Sverre S. Andresen
Anna Medbøe Tamuly
PARTNER
PARTNER
PARTNER
SENIOR ASSOCIATE
eiell@bahr.no
jam@bahr.no
knusa@bahr.no
antam@bahr.no
Morten S. Nadheim
Sindre Dyrhovden
Ingrid Li
Sander Bøe Bertelsen
MANAGING ASSOCIATE
MANAGING ASSOCIATE
ASSOCIATE
ASSOCIATE
monad@bahr.no
sidyr@bahr.com
ingli@bahr.no
saber@bahr.no
2
Introduction This Q3 2026 edition of our Technology and IP Quarterly summarises key legal and regulatory developments in technology and intellectual property. We focus on the most material updates from Norway and the EU during the third quarter of 2026, including regulatory changes, new case law, and other noteworthy developments relevant to businesses operating in innovative and highly regulated markets.
3
Intellectual property rights BAHR’s intellectual property practice covers all areas of contentious and non-contentious intellectual property law. The team has litigated numerous cases and has extensive experience providing legal advice to both domestic and international clients within the fields of patents, trademarks, copyright, design and trade secrets. For more information regarding patent litigation in Norway, we have authored the Norwegian chapter in Lexology In-Depth: Patent Litigation, accessible here. This section will present recent regulatory developments and case law in the field of intellectual property from Norway, the European Union, and other European jurisdictions, offering insights into the latest legal trends and decisions during the third quarter of 2026.
4
Norway Case law Trademark – Likelihood of confusion – the Oslo District Court – TOSL-2025-200735 – 7
September 2026
This case concerned a decision by the Norwegian Board of Appeal for Industrial Property
Rights (“KFIR”), which had invalidated the Norwegian trademark registration of CATL, held by
the Chinese technology company Contemporary Amperex Technology Co., Limited
(“Contemporary”). Caterpillar Inc., which holds earlier registrations for the trademark CAT,
had opposed the registration. KFIR had found, by majority, that there was a likelihood of
confusion between the two marks and declared Contemporary’s trademark registration
invalid. Contemporary brought an action against KFIR before the Oslo District Court arguing
that KFIR's decision was based on an incorrect application of Section 4, first paragraph, of the
Trademarks Act, and must be declared invalid.
The District Court first found that a significant number of the goods covered by the CATL
registration, in particular various types of batteries and battery chargers, were identical to goods covered by Caterpillar's CAT-trademark registrations. This high degree of similarity between the goods lowered the threshold required for similarity between the marks themselves.
On the comparison of the marks, the court found clear visual similarities, since the word CATL contains the entire text of the mark CAT, though the addition of the letter L and Caterpillar's graphic elements created some visual differences. The marks were also found to share
phonetic features, both starting with the same three letters, while conceptually the marks differed since CAT has an obvious meaning in English whereas CATL does not. The court
rejected KFIR's approach of treating CATL as if consumers would break it down into "CAT"
plus an added letter, holding that the average consumer would perceive the short mark as a whole rather than analyzing its individual components.
The court found that a non-negligible part of the relevant public could believe there was a
commercial connection between the two undertakings, and upheld KFIR's decision to invalidate the registration. It was not necessary for the court to consider Caterpillar's
alternative argument that CAT was a well-known mark entitled to extended protection. The applicant was ordered to cover the State's legal costs, and to cover part of Caterpillar's legal costs as intervening party, with the amount reduced to reflect that Caterpillar's costs exceeded what the court considered necessary for a case of this scope. The decision is available to read here.
5
Trademark – Infringement - Ownership over business and social media accounts – The Ringerike og Hallingdal District Court –TROH-2026-25359 – 13 July 2026 The case concerned an application for an interim injunction between Woolf Merino AS
(“Woolf”), a Norwegian company selling wool clothing for the ski and outdoor segment, and
a US-based shareholder who had originally set up Woolf’s Shopify, Google Workspace, Meta,
LinkedIn, YouTube and Klaviyo accounts before the company was incorporated in Norway. The parties disagreed as to who was entitled to control these business and social media
accounts. The shareholder had removed Woolf's access to these accounts, and Woolf sought an interim injunction restoring full and exclusive control. The question of jurisdiction had already been settled by the Court of Appeal, which found that Norwegian courts had
jurisdiction and that Woolf had shown, to a reasonable degree, at least equal rights to the accounts.
The District Court found that although the accounts had been created in the shareholder’s name, the accounts had in substance been set up and financed for Woolf's business. The court found that Woolf held at least a co-ownership interest in the accounts.
However, the court did not find that Woolf was the sole owner of the accounts. Nor did it find that Woolf had a right to exclude the shareholder entirely. The accounts also served Woolf's US subsidiary, which was formally owned and operated by the shareholder alone.
The court found that a basis for interim injunction existed, since the shareholder's takedown request to Shopify had infringed Woolf's Norwegian trademark rights, and since the loss of access to the accounts had cut Woolf off from order processing, pricing and inventory
updates, customer communication and marketing, causing significant harm to its ongoing operations.
Rather than granting Woolf's request for full and exclusive control, the court found that the appropriate solution was to order that both parties be given access to the accounts, in line
with the general co-ownership principle that no co-owner may use a jointly owned asset to an extent, or in a way, that unreasonably harms another co-owner.
Woolf's request for an interim injunction authorising it to instruct the platforms directly,
without any involvement from the shareholder, to transfer full and exclusive ownership and administration rights over the accounts to Woolf, was rejected as falling outside what a
Norwegian court had jurisdiction to grant. The court stated that this would in effect direct third-party platforms that were not parties to the case.
The shareholder was ordered to restore Woolf's access and refrain from further interference, and to pay Woolf's legal costs, as the court found that Woolf had succeeded in substance. The decision is available to read here.
6
7
EU Regulatory updates Design – Phase II of the EU design law reform enters into force – 1 July 2026 On 1 July 2026, the second phase of the most significant reform of EU design law since 2002 took effect. The reform is implemented through Regulation (EU) 2024/2822, amending the Community Design Regulation, and a package of accompanying delegated and implementing regulations. While the first phase of the reform entered into force on 1 May 2025, the provisions requiring secondary legislation, including new categories of protectable designs and new representation requirements, have applied only from 1 July 2026. From 1 July 2026, the scope of registrable designs has been expanded to explicitly cover digital designs, including transitions, animations and other visual effects, as well as graphical user interfaces, graphic works, surface patterns, spatial arrangements and virtual environments. The requirements for how a design must be represented in an application have also changed: the previous limit of seven views per design has been removed, with the exact number and type of views, including for three-dimensional designs, to be determined by secondary legislation. The reform also narrows the "repair clause" exemption for spare parts, which now applies only where the manufacturer or seller has clearly informed the public, either on the part itself or by other means, that the spare part is not an original component. A corresponding repair clause has, for the first time, been introduced into the accompanying recast Design Directive (Directive (EU) 2024/2823), which Member States must transpose into national law by 9 December 2027, with a transitional period until 9 December 2032 for existing national design protection of component parts. As previously reported in our Q3 2025 edition, the EU design regulations themselves are not part of the EEA Agreement and therefore does not apply directly in Norway, but the recast Design Directive, once implemented into national law, is expected to be incorporated into the EEA Agreement and subsequently transposed into the Norwegian Designs Act, as has been the pattern with earlier EU design directives, and reported in our Q2 2026 edition. We will follow the transposition process and report on its implications for Norwegian design law in future editions. Further information on the EU design law is available here.
Case law Trademark – Freedom of expression as “due cause” – Court of Justice of the European Union – Case C-298/23 – 8 September 2026 The case concerned a request for a preliminary ruling from a Belgian court (the Nederlandstalige court in Brussels) in a trademark infringement dispute between Inter IKEA Systems BV and a group of defendants comprising the non-profit association Algemeen Vlaams Belang, acting on behalf of the political party Vlaams Belang and the non-profit
8
association Vrijheidsfonds. The referring court had, however, found the claims admissible only in so far as they related to Vrijheidsfonds. Vrijheidsfonds had used signs closely resembling the IKEA trademarks, including similar typography and color scheme, to promote a plan to reform Belgian asylum and immigration policy on behalf of Vlaams Belang. Under both the EU Trade Mark Regulation and the Trade Mark Directive, the proprietor of a trade mark with a reputation may prohibit a third party's use of an identical or similar sign, unless that use is made with so-called “due cause”. The Belgian court asked the Court of Justice of the European Union (“CJEU”) whether freedom of expression, including the freedom to express political opinions and engage in political parody, can constitute 'due cause' for using a sign identical with, or similar to, a trade mark with a reputation, and if so, what criteria should guide that assessment. The CJEU confirmed that freedom of expression may in principle constitute such “due cause”, but clarified that merely invoking freedom of expression is not sufficient in itself. The third party must show specific grounds connected to the exercise of that freedom which takes precedence over the trademark proprietor's rights and interests. The CJEU set out the criteria relevant to that balancing exercise. First, the national court must examine the third party's intention, verifying that the use was not driven by an intent to free ride on the trademark's reputation or to harm its distinctive character, and that it was carried out in good faith, for example to comment on the mark itself, its proprietor, or its goods or services, or to fuel a debate of public interest. Second, the national court must consider whether the use in question contributes to a genuine debate in the public interest, bearing in mind that political speech enjoys strong protection under the case law on freedom of expression, and whether the expression occurs in a strictly commercial context. Third, the national court must weigh the consequences of the use for the trademark proprietor, including the intensity, scale and methods of the use, the degree of similarity between the sign and the trademark, the extent of the mark's reputation, and whether the use could give the public the impression that the proprietor endorses or supports the political message conveyed, particularly where the proprietor's values are based on political neutrality. Applying these criteria to the facts, the CJEU observed that the word IKEA is an acronym with no independent linguistic meaning that would justify its use by a third party, that it did not appear to have become part of everyday language, and that the campaign did not appear to relate to the IKEA trademarks, their proprietor, or its goods or services as such, but rather merely rode on the coat-tails of those marks' reputation. This is the first time the CJEU has confirmed, in a Grand Chamber ruling, that freedom of expression can qualify as “due cause” under the reputation-based infringement provisions of EU trademark law. The CJEU establishes a structured set of criteria for how that balance must be conducted. The judgment is likely to be a key reference point for future disputes involving political campaigns, satire, and other forms of non-commercial expression that make use of well-known trademarks, and it signals that trademark proprietors cannot rely on their exclusive rights to prevent all unauthorised use in a political or public-interest context, while also making clear that the use of near-identical signs without a genuine link to the mark itself will rarely be protected merely by invoking freedom of expression. The decision and opinion of the Advocate General is available here. 9
Copyright – Communication to the public – Geo-blocking and VPN circumvention – Court of Justice of the European Union – Case C-788/24 – 9 July 2026 The case concerned a request for a preliminary ruling from the Dutch Supreme Court in a copyright dispute between Anne Frank Fonds, a foundation which holds the copyright in Anne Frank's diary and manuscripts (protected in the Netherlands until 2037), on one side, and, on the other, Anne Frank Stichting, the Dutch foundation that runs the Anne Frank House in Amsterdam, together with the Royal Netherlands Academy of Arts and Sciences and an association for research into historical texts, which had jointly published a scholarly online edition of Anne Frank's manuscripts free of charge on a website registered in Belgium. The manuscripts had already become public domain in Belgium and other member states but remained protected in the Netherlands. The website used geo-blocking to prevent access from the Netherlands, though this could be circumvented using a VPN or similar service. Anne Frank Fonds argued that the publication infringed its exclusive right of communication to the public in the Netherlands. The Dutch Supreme Court asked the CJEU, in essence: (i) whether publishing a work online only amounts to a "communication to the public" in a given member state if the publication is directed at the public there; (ii) whether a geo-blocking measure can still limit that public where it can be circumvented using a VPN or similar service; and (iii) if circumvention does result in a "communication to the public" in the blocked state, whether that communication is attributable to the publisher or to the VPN provider. The CJEU first addressed whether the publication amounted to a "communication to the public" in the Netherlands despite the geo-blocking. The CJEU found that, provided the geoblocking measure is effective and state-of-the-art, no communication to the public occurs in the member state where the work remains protected, even though determined users can bypass it using a VPN. On whether geo-blocking can be "effective" within the meaning of the InfoSoc Directive despite the possibility of circumvention using a VPN, the Court held that the mere theoretical possibility of circumventing a technical measure does not, by itself, render that measure ineffective. The CJEU also addressed who can be held responsible where a geo-blocking measure turns out not to be effective. It held that in that situation, responsibility for the resulting unauthorised communication to the public lies with the person who published the work online, not with the provider of the VPN or similar service used to circumvent the measure, since such providers do not themselves give end users access to a protected work and do not play a decisive role in that access, being providers of lawful technical tools that users may legitimately use. This judgment is a significant clarification of how EU copyright law applies to online publication of works with divergent territorial protection status. It confirms that rightsholders and publishers relying on geo-blocking to manage differing national copyright terms can rely on technologically advanced blocking measures without being exposed to liability merely because determined users can circumvent them with a VPN, provided the measure is genuinely effective and not merely a self-declaration mechanism. The ruling also shields VPN providers from being treated as directly responsible for communications to the public that occur through circumvention of another party's technical measures, reinforcing the earlier 10
line of case law distinguishing intermediary tool providers from parties that play a decisive role in granting access to protected content. The decision and opinion of the Advocate General can be read here. Copyright – Formal validity of assignment contracts is a contractual matter – EU Court of Justice C-176/25 The case concerned a dispute between two German online sellers of car accessories. BT had, on several occasions between 2014 and 2018, engaged a Polish photographer to photograph her products for online listings, without any written agreement on the assignment of usage rights or on the applicable law. When a competitor, IU, later used some of the same photographs in her own listings, BT sued for infringement of the exclusive rights of use she claimed had been assigned to her by the photographer. IU challenged BT's standing, arguing that the formal validity of the assignment must be assessed under Polish law pursuant to the Rome I Regulation (as the law of the country where the contract was concluded), and that Polish law's written-form requirement for such assignments had not been met. BT argued instead that the lex loci protectionis under Article 8(1) of the Rome II Regulation, i.e. German law, which imposes no form requirement, should govern. The CJEU held that while an infringement claim brought by an alleged assignee against a third party is a non-contractual matter governed by the lex loci protectionis under Rome II, the separate question of whether the underlying assignment contract is formally valid is a contractual matter that must instead be determined under the Rome I Regulation. The Court reasoned that formal requirements serve to evidence the parties' will to be bound by a contractual obligation and are independent of the tortious liability of the alleged infringer. The Court rejected the European Commission's submission that the assignee's rights-holder status should be treated as a copyright or proprietary-rights matter, finding that the formalvalidity question does not touch the substance of copyright, authorship, or the scope of protection, and so falls outside that categorization even where the outcome affects who ultimately holds the rights. The Court noted that this approach does not conflict with the territoriality principle under the Berne Convention, since national copyright laws continue to govern the protection and infringement analysis regardless of which law governs the contract's formal validity. Norway is not an EU Member State, and neither the Rome I nor the Rome II Regulation is incorporated into the EEA Agreement as such, since private international law generally falls outside the Agreement's scope, save for narrow exceptions. Where Norwegian choice-of-law questions are not settled by statute, Norwegian courts apply unwritten private international law under the "Irma Mignon formula," but the Supreme Court has consistently held that, in the absence of a diverging Norwegian rule, considerations of legal uniformity favor giving weight to the solutions chosen under the Rome I and Rome II Regulations. Recent Supreme Court practice confirms this approach is treated as reflecting current Norwegian law for noncontractual claims generally. Norwegian courts facing a cross-border copyright dispute of this kind would therefore likely look to the CJEU's reasoning in this judgment, distinguishing the contractual question of an assignment's formal validity from the non-contractual lex loci protectionis governing the infringement claim, as persuasive guidance, even though neither regulation binds Norway directly. 11
The decision and opinion of the Advocate General can be read here. Copyright – Social media posts as protected works and the limits of the news-reporting exception – EU Court of Justice C-598/24 – 3 September 2026 The case concerned a Romanian teacher who published a short 22-line text on Facebook expressing that she did not wish to receive gifts from her pupils' parents at the start of the school year. An online newspaper subsequently republished the entire text without her consent, later adding her name and a hyperlink to the Facebook post as the source. She sued for copyright infringement, but the lower Romanian courts dismissed her claim on the basis that the text was not copyright-protected. The referring Romanian Supreme Court asked the CJEU, first, whether such a text could qualify as a protected "work" under Article 2(a) of the InfoSoc Directive (2001/29/EC), and second, whether the exception for reporting of current events under Article 5(3)(c) of that directive precluded a national rule limiting the exception to short excerpts and prohibiting any commercial or economic advantage from the use. On the first question, the Court held that a text published on a social network can qualify as a protected "work" provided it reflects the author's own intellectual creation and personality through free and creative choices – factors such as the text's length, its online publication, or its lack of fit within a predetermined literary genre are irrelevant to that assessment, which is for the national court to make. On the second question, the Court held that Article 5(3)(c) does not preclude a national rule limiting the exception to short excerpts of a protected work, since full reproduction may undermine the work's normal exploitation and unreasonably prejudice the author's legitimate interests, provided the limitation is proportionate and preserves the exception's effectiveness and purpose (safeguarding information and press freedom under Article 11 of the Charter). However, the Court found that a blanket prohibition on deriving any direct or indirect commercial or economic advantage from such use has no basis in the wording of Article 5(3)(c) and undermines the exception's effectiveness, since press organisations legitimately carry out economic activity alongside their function of informing the public – such an unqualified prohibition upsets the balance between the intellectual property right under Article 17 of the Charter and the freedom of expression and of the press under Article 11. The Norwegian Copyright Act implements the InfoSoc Directive and defines a protected work using the same originality standard as EU law, meaning the CJEU's reasoning that social media posts can meet this threshold regardless of length or platform is directly relevant to how Norwegian courts would assess similar content. The decision of the court and opinion of the Advocate General can be found here. Design – Individual character – Reliance on patent illustrations as prior designs – EU General Court – Case T-40/25 – 1 July 2026 This case concerned a decision of the Third Board of Appeal, and the key legal question was whether, in assessing individual character of a registered design, the comparison should be limited strictly to the specific patent drawing relied on as the earlier design, or whether the accompanying patent text and other illustrations could also be taken into account.
12
The applicant argued that the Board of Appeal had erred in comparing the contested design only against the two specific illustrations relied on, rather than against the patent specifications as a whole, including their written description of the invention and their other illustrations. The EU General Court rejected this argument, holding that a patent protects an invention rather than the appearance of a product, and that illustrations in a patent specification may show various embodiments of that invention. It followed that a party seeking a declaration of invalidity based on illustrations found in a patent specification must precisely identify which specific illustrations it relies on as earlier designs, and that only those precisely identified illustrations, not the patent as such or its surrounding text, can be relied on to challenge a design's individual character. The EU General Court dismissed the action in its entirety and upheld EUIPO's decision, without ruling on the substantive question of the contested design's validity, which remains to be assessed by the Cancellation Division following the case's remittal. The applicant was ordered to bear its own costs and to pay those of the intervener, while EUIPO was ordered to bear its own costs. The decision and the opinion of the Advocate General is available here.
13
14
Other jurisdictions European Patent Office Patents – Adaptation of the description to amended claims – Enlarged Board of Appeal of the European Patent Office – G 1/25 – 3 September 2026 The case concerned a referral from a Technical Board of Appeal in opposition-appeal proceedings between Knauf Insulation, the patent proprietor, and Rockwool A/S, the opponent. During the proceedings, the claims had been amended, and the Board hearing the appeal found that this amendment created an inconsistency with parts of the description that had not been correspondingly updated. Since the case law of the Boards of Appeal had developed two conflicting approaches to whether such inconsistencies must be resolved by adapting the description, the Board referred three questions of law to the Enlarged Board of Appeal, asking (i) whether the description must be adapted when a claim amendment creates an inconsistency with it, (ii) which provision of the European Patent Convention requires this, and (iii) whether the same rule applies to patent applications during examination as to granted patents during opposition. The Enlarged Board first answered the third question. It began by considering the relationship between this referral and its earlier landmark decision G 1/24, which had held that the description and drawings must always be consulted when interpreting a claim, not only when the claim wording is unclear when read on its own. The Enlarged Board confirmed that this holistic approach to claim interpretation, in which the claims, description and drawings are read together as a single process, applies equally in opposition and examination proceedings, and is not limited to assessing patentability, so there was no reason to treat the two types of proceedings differently, and therefore answered the third question in the negative: the same rule applies during examination as during opposition. Turning to the first question, and to the two lines of diverging case law, the Enlarged Board declined to follow the more recent line, most fully developed in decision T 56/21. That decision had found that the requirement in Article 84 EPC, that claims be supported by the description, runs only one way, from the description to the claims. On that reading, an inconsistency introduced by amending the claims could never render the patent noncompliant with the Convention. The Enlarged Board held that this reading could not be reconciled with the holistic approach to claim interpretation confirmed in G 1/24, and that the wording of Article 84 EPC does not support treating the description as irrelevant once a claim amendment creates a genuine inconsistency. The Enlarged Board then set out its own definition of a legally relevant inconsistency: it exists where a statement in the description or drawings suggests a reading of a claim that conflicts with the claim's apparent meaning, and this conflict cannot be resolved simply by applying ordinary claim interpretation principles, leaving the skilled person in real doubt about the claim's meaning. Importantly, the Board clarified that an inconsistency is not created merely because the description contains embodiments or teachings that fall outside the amended claims; adaptation of the description is not required purely for the sake of formal tidiness or to remove every trace of unclaimed subject matter. 15
Where such a legally relevant inconsistency does exist, however, the Enlarged Board held that it must be removed, either by amending the claims, by amending the description or drawings, or both, whenever the inconsistency causes non-compliance with specific requirements of the Convention, including sufficiency of disclosure, clarity and support, added subject matter, or the extension of protection after grant. Turning to the second question, the Board found that there is no single provision of the Convention that automatically requires adaptation of the description in every case; instead, the legal basis for requiring an adaptation is whichever specific requirement of the Convention the inconsistency causes to be breached in the circumstances of the individual case. This decision clarifies the case law of the Boards of Appeal on when the description must be amended to be in line with amended claims. The decision is likely to become a key reference point for patent prosecution practice and for claim construction disputes before national courts and the Unified Patent Court applying the corresponding G 1/24 principles. The decision is available here.
16
Digital regulation and data protection At BAHR, we recognise the vital role of data privacy and security in today's digital world. Our team of legal experts is committed to providing clear guidance on regulatory matters to ensure businesses remain compliant and secure. We offer customised solutions to help businesses navigate the complexities of the Norwegian and EU digital regulations. This section will provide updates on the regulatory framework within Norway and the EU, offering insights into recent developments and trends.
17
Norway Regulatory updates New national recommendations on children's screen use On 14 September 2026, the Norwegian Government launched new joint recommendations on screen use for children and young people. The recommendations build on the Directorate of Health's screen guidance launched in January 2026. The updated guidance is notably specific on algorithms, social media, smartphones and digital risks, and explicitly warns about addictive design, harmful content, recruitment into criminal activity and contact risks associated with specific services, including TikTok, YouTube and Snapchat. 1 The recommendations are available here here. On a related note, at the annual Nordic Prime Ministers' summer meeting in Denmark on 20 August 2026, the Nordic prime ministers discussed closer cooperation on protecting children online, alongside common security and defence matters. The leaders exchanged experiences on regulating digital platforms and measures to protect children from harmful content. 2 This signal continued momentum across the Nordic region towards closer alignment on child online safety. The Government wants stricter regulation of smart glasses On 25 August 2026, the Norwegian Minister of Digitalisation and Public Governance announced the establishment of an expert group to advise on the regulation of new and powerful technology. The Minister pointed to a clear trend of AI being combined with cameras and microphones used in items such as glasses and highlighted the need to prevent such equipment from being used to surveil others in public spaces. 3 The initiative follows input from the Norwegian Data Protection Authority (“Datatilsynet”) and the Norwegian Consumer Council. Datatilsynet's Director, Line Coll, welcomed the initiative, stating that it is positive that the Government now wishes to introduce stricter regulation of this type of technology. 4 The expert group is expected to work quickly and put forward alternatives and proposals for the regulation of smart glasses, earbuds and other devices that now come equipped with cameras and built-in AI functionality. The Government will subsequently assess any resulting proposals and circulate them for public consultation. 5 In the meantime, the Minister has encouraged leaders in both the public and private sectors to consider whether the use of smart glasses or similar devices should be permitted on their workplaces.
https://www.regjeringen.no/no/aktuelt/regjeringen-lanserer-nye-anbefalinger-om-skjerm-for-barn-og-unge/id3172523/ https://www.regjeringen.no/no/aktuelt/styrket-nordisk-samarbeid-om-sikkerhet-og-teknologi/id3170958/ 3 https://www.regjeringen.no/no/aktuelt/tung-vil-ha-strengere-regulering-av-smartbriller/id3171263/ 4 https://www.datatilsynet.no/aktuelt/aktuelle-nyheter-2026/regjeringen-vil-ha-strengere-regulering-av-smartbriller/ 5 https://www.regjeringen.no/no/aktuelt/tung-vil-ha-strengere-regulering-av-smartbriller/id3171263/ 1 2
18
Datatilsynet’s annual report to the Storting shows fewer sanctions but rising caseload On 21 August 2026, the Government submitted Meld. St. 13 (2025–2026) to the Norwegian Parliament (the “Storting”), presenting the annual reports of Datatilsynet and the Privacy Appeals Board for 2025. 6 The report shows that Datatilsynet issued 36 decisions on corrective measures or infringement fees in 2025, down from 44 in 2024. According to Datatilsynet, the decline is due to a heavy caseload and a strained resource situation, which has forced the authority to prioritise faster case processing over the more resource-intensive use of sanctions. Of these 36 decisions, only two resulted in infringement fees. Datatilsynet's overall caseload continues to grow sharply with 5,532 new cases registered in 2025, up from 4,736 in 2024. Datatilsynet points to a marked increase in complaints that are wholly or partly AI-generated, which are often extensive and make it more difficult to identify the actual legal issues in a case. On personal data breach notifications, Datatilsynet received 3,016 notifications in 2025, a slight decrease from the record 3,191 in 2024. The most common category remained personal data sent to the wrong recipient, accounting for 39 per cent of notifications, while Datatilsynet also reported a rise in notifications linked to the use of AI tools, including unauthorised recording and transcription of digital meetings. On international cooperation, Datatilsynet remains an active participant in the European Data Protection Board (“EDPB”), attending around 150 meetings in 2025 and contributing in particular to the ongoing work on guidelines for "consent-or-pay" models. Datatilsynet was involved in 381 cross-border cases in 2025 (up from 373 in 2024) and acted as lead authority in 50 of these, a marked increase from 17 the year before, partly driven by a cluster of complaints concerning SATS's practice of photographing all members. The Privacy Appeals Board, which hears appeals against Datatilsynet's decisions, faced a similar surge in its own caseload. The Privacy Appeals Board's actual case-processing time as of year-end was around 16 months, and the Board itself describes the growth in its caseload as unsustainable given current resources. The full report is available here. Nordic ministers urge Commission to hold platforms accountable for digital fraud under the DSA On 14 July 2026, ministers from all five Nordic countries sent a joint letter to the European Commission calling for stricter enforcement of the Digital Services Act (“DSA”) in relation to online fraud. The letter highlights that digital fraud remains a significant and growing problem across the Nordic region and that the largest online platforms have not done enough to prevent and combat it. The letter concludes by stating that the Commission and its services have the Nordic ministers’ full support to pursue action against fraudulent advertising on online platforms in accordance with the DSA, and that full application of the DSA is more needed than ever. 7
6 7
https://www.regjeringen.no/no/dokumenter/meld.-st.-13-20252026/id3170563/?ch=1 https://www.regjeringen.no/no/aktuelt/vil-holde-plattformene-ansvarlige-for-digital-svindel/id3169104/
19
The Nordic ministers also request the Commission to report back on its plans to act under the DSA against fraudulent advertising. The letter is available here. Datatilsynet has updated its guidance on the right of access On 10 July 2026, Datatilsynet published updated guidance on the right of access, following a number of enquiries from individuals. 8 Datatilsynet highlights that the main objective of the right of access is to allow individuals to find out which personal data a business processes about them, why, and how, so that they are able to check whether the business's use of their data is lawful. Datatilsynet points out that the right of access concerns the personal data itself, and not necessarily the documents in which that data is contained. On format, Datatilsynet clarifies that the right to a copy does not necessarily entail a right to a paper copy. As a starting point, if the access request is submitted electronically, the copy should also be provided electronically, and it is for the business itself to determine which electronic form is appropriate in each case, provided the format is easily accessible and understandable to the individual. Finally, Datatilsynet addresses identification requirements, noting that where there is reasonable doubt as to the requester's identity, the business may ask for additional information, but it cannot request more information than is necessary to confirm that identity. The guidance from Datatilsynet is available here.
Case law and sanctions Datatilsynet fines Lab Pharma for unlawful influencer marketing and breach of cooperation obligations On 12 August 2026, Datatilsynet imposed a fine of NOK 205,000 on Lab Pharma AS, ordered the company to cease its use of an influencer's personal data for marketing purposes, and ordered the deletion of the influencer's name and images from its websites. 9 The case arose from a complaint submitted by an influencer whose name, images and endorsements of Lab Pharma's products continued to be used in the company's marketing after the expiry of a collaboration agreement entered into in 2016. Lab Pharma argued that the agreement entitled it to continue using the material and subsequently also sought to rely on legitimate interests under Article 6(1)(f) GDPR. Datatilsynet rejected both arguments, finding that the agreement had expired in 2017 and that the company lacked a valid legal basis for its continued use of the influencer's personal data. The authority therefore concluded that the processing was unlawful and that the data should have been deleted following the influencer's request for erasure. 10
https://www.datatilsynet.no/aktuelt/aktuelle-nyheter-2026/om-retten-til-innsyn/ https://www.datatilsynet.no/contentassets/8c9c5cceb6d14481ad668d222035cf83/2026-08-12-vedtak---lab-pharmaoffentlig.pdf 10 https://www.datatilsynet.no/contentassets/8c9c5cceb6d14481ad668d222035cf83/2026-08-12-vedtak---lab-pharmaoffentlig.pdf, Section 5.2. 8 9
20
The fine itself was imposed for breaches of Article 31 GDPR, which requires controllers to cooperate with supervisory authorities. Datatilsynet found that Lab Pharma had repeatedly obstructed and delayed the investigation by failing to provide requested documentation, missing deadlines and directing threats of legal action and police reports at Datatilsynet and its case handlers in an attempt to have the investigation discontinued. 11 Datatilsynet characterised the conduct as a serious breach of the duty to cooperate. The decision highlights the importance of ensuring that contractual rights to use personal data in marketing remain valid throughout the period of use. It is also a notable example of Datatilsynet imposing sanctions for obstruction of a regulatory investigation, rather than for the underlying GDPR infringements themselves. Datatilsynet launches sector-wide investigation of insurers' use of health data In August 2026, Datatilsynet announced a sector-wide review of the insurance industry focusing on insurers' collection of health data when handling claims under personal insurance policies. 12 The review follows a number of complaints concerning the scope of health information requested from policyholders during claims handling. Datatilsynet has stated that it will examine whether insurers have adequate procedures in place to ensure that no more health data is collected than is necessary for the relevant claim assessment. As part of the review, information requests have been sent to eight major insurance providers operating in Norway. The initiative signals continued regulatory focus on data minimisation and the handling of special category personal data in the insurance sector. Datatilsynet reprimands SATS over compulsory membership photos On 15 July 2026, Datatilsynet reprimanded SATS for breaches of the GDPR concerning its requirement that members provide a photograph to use its fitness facilities. 13 The case was handled as a cross-border case, with Datatilsynet acting as lead supervisory authority and the Swedish, Finnish and Danish data protection authorities as concerned authorities. 14 Datatilsynet found that SATS had relied on the wrong legal basis for its mandatory check-in photo requirement, citing contractual necessity under Article 6(1)(b) when the correct basis was legitimate interest under Article 6(1)(f), and that SATS had failed to give data subjects adequate information about their right to object under Article 21. SATS was also found to have rejected members' objections without demonstrating compelling legitimate grounds to continue the processing. 15 SATS was reprimanded for these breaches, with a compliance deadline of 11 September 2026.
https://www.datatilsynet.no/contentassets/8c9c5cceb6d14481ad668d222035cf83/2026-08-12-vedtak---lab-pharmaoffentlig.pdf, Section 5.3. 12 https://www.datatilsynet.no/aktuelt/aktuelle-nyheter-2026/tilsyn-med-forsikringsbransjen/ 13 https://www.datatilsynet.no/contentassets/eae270ba69d844a3bf87f6a7edbfb4de/vedtak-om-palegg-og-irettesettelse---satsasa.pdf 14 https://www.datatilsynet.no/aktuelt/aktuelle-nyheter-2026/palegg-og-irettesettelse-til-sats/ 15 https://www.datatilsynet.no/contentassets/eae270ba69d844a3bf87f6a7edbfb4de/vedtak-om-palegg-og-irettesettelse---satsasa.pdf 11
21
EU Regulatory updates United States seeks to intervene in X and Musk's DSA fine dispute As reported on our Q4 2025 edition, available here, the European Commission imposed its first fine under the DSA, fining X (formerly Twitter) €120 million for breach of transparency obligations. X Internet and X Holdings, together with Elon Musk personally, then brought separate actions before the General Court of the CJEU (Cases T-114/26 and T-121/26) seeking to annul the European Commission's decision. 16 On 24 September 2026, the United States Department of Justice applied to intervene in both proceedings in support of the applicants. The Department pointed out that the fine had been calculated on a joint and several basis, using the combined worldwide turnover of the entire economic unit surrounding Elon Musk, rather than solely the turnover of the X entity that operated the platform. Assistant Attorney General Brett A. Shumate characterised the Commission's approach as an improper attempt to extend its regulatory reach to American companies operating outside the EU's jurisdiction and indicated that the United States would resist what it described as regulatory overreach directed at American technology and innovation. 17 EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines On 21 September 2026, the EDPB published guidelines on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR, and adopted the final version of its guidelines on the interplay between the DSA and the GDPR. 18 The guidelines on imposing administrative fines set out in detail the assessments supervisory authorities must carry out when deciding whether to impose a fine. They also provide an overview of the corrective powers available to national data protection authorities, including warnings, reprimands, orders, limitations (including bans) and the withdrawal of certification, and explain their purpose, scope and interrelationship. The EDPB has provided 14 practical examples illustrating how authorities may apply the methodology to specific cases. The guidelines are currently open for public consultation, with comments invited until 13 November 2026. The guidelines can be read here. The guidelines on the interplay between the DSA and the GDPR have now been adopted in final form. They are intended to support the consistent application of both instruments, in particular where provisions of the DSA concerning the processing of personal data by intermediary service providers refer to concepts and definitions laid down in the GDPR. The guidelines can be read here.
https://www.google.com/goto?url=CAESgQEB6zswFfleO4TiWECRSVsvZCIUjpGahJdA5o5yqd_suut_Vk5lvcGESAlJce_yWk8IMGlk6 oZBzanlyAotgasd0Rbpiw3GBvesnALj6vkF5YHVCG1y7G8mGSRvggjncRM_yXbIyxYjOINi6WgnchaWUEmm4JuaIPqpTB6MKwuCnfM and https://eur-lex.europa.eu/eli/C/2026/2392/oj/eng 17 https://www.justice.gov/opa/pr/united-states-files-request-intervene-case-brought-x-corp-and-elon-musk-seeking-annul 18 https://www.edpb.europa.eu/news/edpb-harmonises-fining-methodology-and-adopts-final-dsa-gdpr-guidelines_en 16
22
Commission has adopted a proposal for the EU KIDS Act On 17 September 2026, the European Commission (the “Commission”) adopted a proposal for the EU KIDS Act, a regulation aimed at protecting minors online. The proposal introduces harmonised age rules across the EU: children under 13 are prohibited from holding social media accounts, children aged 13 and 14 may only access online social networking services and video-sharing platform services through accounts set up by parents with possibility of parents setting a maximum time limit of one hour. The EU wide minimum age for kids creating their own accounts it set to 15. 19 Under the proposal, enforcement is planned to build on the existing enforcement structures DSA (for online platforms) and the AI Act (AI companions and chatbots). 20 AI Act transparency obligations now in force On 2 August 2026, the transparency obligations set out in Article 50 of the AI Act became applicable in the EU. 21 These obligations apply to both providers and deployers of certain AI systems, regardless of the risk class of the system. Providers of AI systems that interact directly with individuals must ensure that users are informed they are dealing with an AI system, unless this is obvious from the circumstances. Providers of AI systems, including socalled general purpose AI systems, generating synthetic audio, image, video or text content must mark such output in a machine-readable format so that it is detectable as artificially generated or manipulated. Deployers, in turn, must inform individuals when they are exposed to emotion recognition or biometric categorisation systems, clearly label deepfakes, and disclose when AI-generated or AI-manipulated text on matters of public interest is published without substantive human review or editorial control. 22 AI systems placed on the market before 2 August 2026 benefit from a limited grace period until 2 December 2026 for marking obligations. Non-compliance with the transparency obligations may result in fines of up to EUR 15 million or 3 per cent of worldwide annual turnover. 23 As further detailed below, the Commission has published guidelines clarifying the scope and practical application of the Article 50 obligations, complemented by a voluntary Code of Practice on Transparency of AI-Generated Content which provides a recognised path for demonstrating compliance with the AI Act transparency obligations. Throughout the past years, we have monitored and provided regular updates regarding the AI Act. A selection of our previous articles can be accessed here, here and here.
https://digital-strategy.ec.europa.eu/en/library/proposal-eu-kids-act-eu-keeping-internet-digital-spaces-accountable-andtrustworthy and https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1890 20 https://digital-strategy.ec.europa.eu/en/faqs/kids-act-explained 21 Regulation (EU) 2024/1689, available at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02024R168920260727 22 European Commission, Guidelines on transparency obligations for providers and deployers of certain AI systems, available at https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-transparency-obligations. see also Q&A at https://digitalstrategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act 23 https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1714 19
23
EU reinstates temporary Chat Control 1.0 scanning regime until April 2028 On 23 July 2026, the Council of the EU (“Council”) accepted the European Parliament's amendments and gave its final approval to reinstate the temporary derogation from the ePrivacy Directive known as "Chat Control 1.0", extending it until 3 April 2028. 24 Chat Control 1.0 permits (but does not require) providers such as Snapchat, Facebook and Messenger to scan unencrypted communications for known child sexual abuse material. 25 The reinstated version excludes communications to which end-to-end encryption is, has been or will be applied. In furtherance of this, the EU has separately been discussing "Chat Control 2.0", which would take this considerably further by requiring providers to scan communications for known child sexual abuse material, rather than merely permitting it. 26 As reported in our Q3 2025 edition, available here, this has been a controversial proposal, as a particularly controversial point has been the use of scanning messages without previous suspicion, which would include scanning of end-to-end encrypted services, and there is a fear that the proposal might lead to mass surveillance. Datatilsynet is also highly critical of the new proposal. In an article published 31 August 2026, Datatilsynet stated that the Chat Control measures in the proposal go too far, as they would entail mass surveillance of users of digital services. Datatilsynet specifically stress that there exist other measures that do not interfere with privacy to the same degree, and that general surveillance of users of digital services has no place in a democratic state. 27 It remains uncertain exactly what Chat Control 2.0 will entail in practice. EU member states continue to discuss the proposal, and a negotiating meeting between the Council, the Parliament and the Commission is planned for 29 September 2026. 28 If the EU adopts it, most indications are that the regulation will be implemented in Norway through the EEA Agreement. 29 ChatGPT, Reddit and Roblox designated as Very Large Platforms under the Digital Services Act On 31 August 2026, the European Commission designated ChatGPT as a Very Large Online Search Engine ("VLOSE"), and Reddit and Roblox as Very Large Online Platforms ("VLOPs") under the DSA. 30 The designations follow notifications that the services each reach more than 45 million average monthly users in the EU, thereby exceeding the statutory threshold for enhanced supervision. As a result of the designation, the services will be required to comply with the additional obligations applicable to VLOPs and VLOSEs from January 2027. These include obligations to identify, assess and mitigate systemic risks associated with their services, including risks
https://www.consilium.europa.eu/en/press/press-releases/2026/07/23/fighting-child-sexual-abuse-online-interim-measureprotecting-children-now-reinstated/ 25 https://eur-lex.europa.eu/eli/reg/2021/1232/oj/eng 26 https://home-affairs.ec.europa.eu/policies/internal-security/protecting-children-sexual-abuse/legal-framework-protectchildren_en 27 https://www.datatilsynet.no/aktuelt/aktuelle-nyheter-2026/chat-control-gar-for-langt/ 28 https://data.consilium.europa.eu/doc/document/WK-10939-2026-INIT/en/pdf 29 https://www.nrk.no/urix/chat-control_-eu-vil-masseovervake-innbyggerne-1.17983785 30 https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1772 24
24
relating to illegal content, the protection of minors, fundamental rights, public security and electoral processes. The designation is also noteworthy because it confirms the Commission's view that ChatGPT qualifies as a hybrid service that constitutes an online search engine under the DSA. The Commission will be responsible for supervising compliance with the enhanced obligations, working together with the relevant national Digital Services Coordinators. With these additions, a total of 28 services has now been designated as VLOPs or VLOSEs under the DSA. EDPB raises questions following US Supreme Court ruling relevant to EU-US Data
Privacy Framework
On 31 July 2026, EDPB sent a letter to the European Commission expressing concerns regarding the potential implications of the US Supreme Court's judgment in Trump v. Slaughter 31 for the EU-US Data Privacy Framework ("DPF") 32.
The judgment, delivered on 29 June 2026, overturned longstanding precedent concerning the independence of the US Federal Trade Commission ("FTC"), holding that FTC Commissioners are subject to presidential removal powers. The EDPB noted that the existence of independent supervisory authorities is one of the factors considered when assessing whether a third country ensures an adequate level of protection under Article 45 GDPR. In its letter, the EDPB pointed out that the Commission's 2023 adequacy decision for the DPF expressly relied on the independence of US authorities, including the FTC. The EDPB therefore invited the Commission to assess whether the Supreme Court's ruling may have implications for the continued functioning of the adequacy decision and requested that the Commission keep the EDPB informed of any relevant developments. While the EDPB has not suggested that the DPF is no longer valid, the letter highlights the
continued scrutiny of the safeguards underpinning EU-US data transfers. Given the history of the Schrems I 33 and Schrems II 34 judgments, which led to the invalidation of both the Safe Harbour and Privacy Shield frameworks, developments affecting key elements of the
adequacy framework are likely to attract significant attention from both regulators and privacy advocates going forward. Although the DPF currently remains a valid transfer mechanism, the development serves as a reminder of the importance of maintaining
appropriate contingency arrangements, including the ability to rely on alternative transfer mechanisms such as SCCs should the regulatory landscape change.
EU launches AI Gigafactories initiative to expand AI computing capacity On 30 July 2026, the European Commission launched a call for tenders to establish up to seven AI Gigafactories across Europe as part of its broader ambition to strengthen European Supreme Court judgment No. 25-332, https://www.supremecourt.gov/opinions/25pdf/25-332_qn12.pdf Commission Implementing Decision EU 2023/1795, available at: https://eur-lex.europa.eu/legalcontent/EN/TXT/PDF/?uri=CELEX:32023D1795 33 Case C-362/14 (Maximillian Schrems v Data Protection Commissioner), October 6, 2015 34 Case C-311/18 (Data Protection Commissioner v Facebook Ireland Ltd, Maximillian Schrems), July 16, 2020 31 32
25
AI capabilities and technological sovereignty. 35 The initiative is expected to unlock more than EUR 30 billion in combined public and private investment and significantly expand Europe's computing capacity for the training, fine-tuning and deployment of advanced AI models. The AI Gigafactories are intended to provide large-scale AI infrastructure to start-ups, scaleups, industry, academia and public authorities. The programme will be supported by up to EUR 10 billion in public funding, with participating Member States matching EU contributions and substantial private investment expected to follow. The facilities will complement the EU's existing network of AI Factories and are intended to support the development of advanced AI systems on infrastructure operating under European rules and standards. The call closes on 12 November 2026, with the first projects expected to be selected in early 2027 and operations commencing thereafter. The initiative forms part of the EU's broader efforts to strengthen domestic AI infrastructure and reduce dependence on non-European computing capacity. Further amendments to eIDAS On 15 July 2026, the European Commission adopted three amendments to eIDAS. 36 EIDAS is the EU Regulation that established a single framework for electronic identification and trust services across the EU/EEA, ensuring mutual recognition of notified electronic identification schemes and enabling safer, faster and more efficient electronic interactions between businesses, customers and public administrations throughout the European Union. 37 Firstly, Implementing Regulation (EU) 2026/1731 updates the technical standards underpinning the wallets and introduces safeguards for sharing the wallet user's portrait, requiring explicit confirmation before disclosure of biometric data. It also establishes the EU Digital Identity Wallet Trust Mark and requires gatekeepers to give wallet providers free access to relevant operating system, hardware and software features. 38 Secondly, Implementing Regulation (EU) 2026/1730 updates the standards for registering the link between intermediaries and the wallet-relying parties they act for, and introduces a common format and API to improve interoperability between national registers. 39 Lastly, Implementing Regulation (EU) 2026/1735 updates the requirements for issuing and revoking qualified electronic attestations of attributes and introduces new requirements for signing and sealing verification results against authentic sources. 40 Commission presents European technological sovereignty package On 3 June 2026, the European Commission presented the European technological sovereignty package, comprising two legislative proposals — the Chips Act 2.0 and the Cloud and AI Development Act — together with a new EU open source strategy and a Strategic
https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1708 https://eur-lex.europa.eu/eli/reg_impl/2026/1731/oj, https://eur-lex.europa.eu/eli/reg_impl/2026/1730/oj and https://eurlex.europa.eu/eli/reg_impl/2026/1735/oj 37 https://digital-strategy.ec.europa.eu/en/policies/discover-eidas 38 https://europalov.no/rettsakt/eid-digital-lommebok-endringsbestemmelser-om-standarder-tekniske-spesifikasjoner/id-34538 39 https://europalov.no/rettsakt/eid-digital-lommebok-endringsbestemmelser-om-registrering-av-mottakerparter/id-34539 40 https://europalov.no/rettsakt/eidas-forordningen-endringsbestemmelser-om-elektroniske-attester/id-34540 35 36
26
roadmap for digitalisation and AI in energy. 41 The package aims to reduce Europe’s dependence on non-EU suppliers of core digital technologies. 42 The Chips Act 2.0 replaces the original Chips Act and aims to further strengthen Europe’s semiconductor industry. 43 The main objectives of the Chips Act 2.0 are to: 1. Improve conditions for investment and competitiveness 2. Stimulate demand and industrial uptake
3. Support research, innovation and talent development
4. Strengthen supply chain resilience and crisis preparedness
The Act includes specific measures to achieve these objectives. To highlight the importance of the semiconductor industry and the need for the EU to capture a larger share of the opportunities within it, the Commission states that the global semiconductor market is expected to reach €1.37 trillion by 2030, with AI-related components estimated to drive around 70% of that growth. 44 The proposal is available here. The Cloud and AI Development Act aims, among other things, to at least triple EU data centre capacity within five to seven years. 45 In the introductory memorandum, the Commission notes that three non-EU hyperscalers currently hold over 70 per cent of the European cloud market, which entails a number of risks, including that large market incumbents are subject to third-country jurisdictions with extraterritorial laws that may mandate data access and transfer in conflict with EU fundamental rights and data protection frameworks, and that European users are exposed to operational discontinuity risks where unilateral decisions by third-country actors could disrupt service provision. The proposal is available here.
Guidelines When must AI-generated content be disclosed? The Commission publishes AI Act transparency guidelines On 20 July 2026, the Commission published guidelines on the implementation of the transparency obligations under Article 50 of the AI Act, together with a voluntary Code of Practice on transparency of AI-generated content. The guidance is intended to assist providers and deployers of AI systems in complying with the first transparency obligations becoming applicable under the AI Act from 2 August 2026. The guidelines clarify the transparency obligations applicable to a broad range of AI use cases, including AI systems that interact directly with individuals, systems generating or manipulating synthetic content, emotion recognition and biometric categorisation systems, as well as certain deepfakes and AI-generated text published on matters of public interest. A central objective of the transparency regime is to ensure that individuals can recognise when they are interacting with AI or consuming AI-generated or AI-manipulated content. According to the Commission, these requirements are intended to reduce the risks of https://commission.europa.eu/news-and-media/news/strengthening-europes-tech-sovereignty-2026-06-03_en https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1187 43 https://digital-strategy.ec.europa.eu/en/policies/chips-act-2 44 https://digital-strategy.ec.europa.eu/en/policies/chips-act-2 45 https://digital-strategy.ec.europa.eu/en/policies/cloud-and-ai-development-act 41 42
27
deception, manipulation, misinformation and fraud, while helping to preserve trust in AIenabled services and the wider information ecosystem. The guidance confirms that the transparency obligations extend beyond high-risk AI systems and may apply to a wide range of everyday AI applications, including chatbots, AI assistants, AI agents and generative AI tools. It also provides detailed guidance on when deepfakes and certain AI-generated text must be disclosed and clarifies the distinction between obligations applicable to providers and deployers of AI systems. Alongside the guidelines, the Code of Practice provides a practical framework for implementing the transparency requirements, including common approaches to labelling AIgenerated content and a standardised EU transparency icon that may be used when disclosing AI-generated or AI-manipulated content. The Code also sets out practical measures relating to content marking, detection mechanisms and disclosure practices, and is intended to facilitate a consistent approach to compliance across the EU. The full Code of Practice is available here and the Commission Guidelines here. Can publicly available data be used to train AI? EDPB publishes new guidelines on web scraping EDPB has published new draft guidelines on web scraping in the context of generative AI. 46 The guidelines address the GDPR implications of using automated tools to collect data from publicly available websites for the development and training of AI models. They reflect growing regulatory focus on the data collection practices underlying generative AI systems and provide practical guidance on the application of the GDPR in this context. A central message is that publicly accessible personal data remains protected under the GDPR. The EDPB emphasises that web scraping involving personal data constitutes processing subject to the GDPR, regardless of whether the data is publicly available online or whether the scraping is undertaken directly by an organisation or through a third-party service provider. The guidelines further indicate that legitimate interests will often be the most relevant legal basis for web scraping in the context of AI development, subject to a careful balancing assessment that considers, among other things, the nature of the data, the reasonable expectations of individuals, and the safeguards implemented by the controller. The guidelines place particular emphasis on legitimate interests assessments, transparency, data minimisation and data quality. Among other things, the EDPB recommends that controllers carefully define collection criteria, implement measures to limit the collection of unnecessary personal data, and ensure that appropriate technical and organisational safeguards are in place throughout the AI development process. The guidance also highlights the relevance of measures such as filtering, pseudonymisation, anonymisation and, where appropriate, the use of synthetic data. The guidance is particularly relevant for organisations developing, fine-tuning or procuring generative AI solutions that rely on large-scale datasets sourced from the internet. It also provides further clarification on how established GDPR principles apply in the context of AI development and is likely to become an important reference point for assessing the https://www.edpb.europa.eu/public-consultations/guidelines-032026-on-web-scraping-in-the-context-of-generativeai_en#no-back 46
28
lawfulness of AI training datasets and related data collection practices. The draft guidelines are open for public consultation until 30 October 2026. You can read the full EDPB guideline on web scraping here. When is personal data truly anonymous? EDPB publishes new anonymisation guidelines The EDPB has published new draft guidelines on anonymisation, providing long-awaited clarification on when data can be considered truly anonymous and therefore fall outside the scope of the GDPR. 47 The guidelines replace and update the EDPB's previous guidance from 2014, reflecting developments in CJEU case law, data sharing initiatives and advances in AI and data analytics. A key message from the EDPB is that anonymisation remains a high threshold. Removing names or other direct identifiers will often not be sufficient if individuals can still be identified through linking datasets, combining information from different sources, or drawing inferences about specific individuals. To assess whether data is anonymous, the EDPB introduces an updated framework based on three criteria: no record isolation, no linkage and no inference. The guidelines are particularly relevant for organisations seeking to use data for analytics, research, AI development or data sharing initiatives. Notably, the EDPB confirms that whether data is anonymous may depend on the perspective of the relevant recipient or processing entity, reflecting recent developments in CJEU case law. The guidance also provides a clearer methodology for assessing whether anonymisation has been achieved and confirms that successful anonymisation may facilitate the wider use and sharing of data outside the GDPR framework. At the same time, the EDPB emphasises the importance of assessing, documenting and periodically reassessing anonymisation measures and re-identification risks, particularly in light of advances in AI and the increasing availability of external datasets. The guidelines provide welcome clarification on the concept of anonymous data and translate recent CJEU case law, including EDPS v SRB (Case C-413/23 P) 48, into a practical framework for assessing anonymisation. The guidance seeks to facilitate the use and sharing of data while safeguarding individuals' rights, and reflects growing regulatory focus on reidentification risks driven by AI, advanced analytics and the increasing availability of external datasets. The draft guidelines are open for public consultation until 30 October 2026. You can read the full EDPB guideline on anonymisation here. EDPB adopts final guidelines on the use of personal data in blockchain solutions On 7 July 2026, the EDPB adopted the final version of its guidelines on the processing of personal data through blockchain technologies following public consultation. 49 The guidelines provide practical guidance for organisations considering the use of blockchain solutions involving personal data and address how blockchain technology interacts with core GDPR requirements. https://www.edpb.europa.eu/public-consultations/guidelines-022026-on-anonymisation_en#no-back https://infocuria.curia.europa.eu/tabs/document?source=document&docid=303863&doclang=EN 49 https://www.edpb.europa.eu/documents/guideline/guidelines-022025-on-processing-of-personal-data-throughblockchain_en 47 48
29
A central theme of the guidelines is that certain characteristics commonly associated with blockchain technology, including immutability, decentralisation and long-term data storage, may create challenges in relation to key GDPR principles such as data minimisation, storage limitation and data subjects' rights to erasure and rectification. The EDPB therefore emphasises that organisations should carefully assess whether blockchain technology is necessary for the intended purpose and whether less privacy-intrusive alternatives could achieve the same outcome. The EDPB further recommends that personal data should generally not be stored directly on a blockchain. Instead, organisations should consider techniques such as encryption, hashing, cryptographic commitments and off-chain storage. The guidelines also express a preference for permissioned blockchain solutions and highlight the importance of carrying out a Data Protection Impact Assessment ("DPIA") where the use of blockchain is likely to result in a high risk to individuals' rights and freedoms. While the EDPB recognises that blockchain can offer benefits in areas such as digital identity, financial services and digital assets, the guidance makes clear that the use of blockchain does not lessen the obligations imposed by the GDPR. Organisations considering blockchainbased solutions will therefore need to assess privacy and data governance issues at an early stage, particularly where the architecture may limit the ability to modify or delete personal data. You can read the full guideline on the use of personal data in blockchain solutions here.
Case law and sanctions Commission preliminarily finds TikTok in breach of DSA for failing to ensure safe accounts for minors On 24 July 2026, the European Commission sent TikTok preliminary findings indicating that TikTok accounts of minors do not meet the safety standards required under the DSA. On TikTok, minors can choose to set their account as "public", meaning that anyone may view the minor's content. This setting also allows content published by older minors (16-17 years old) to be recommended to any other TikTok user through the “For You Feed”. The Commission also found that even when minors set their accounts to private, their accounts can easily be located through the "following" and "followers" lists of other users, and that their profile photos remain accessible to anyone. According to the Commission, these settings continue to expose minors to risks of unwanted contact, cyberbullying and predatory behaviour. 50 Under the DSA, platforms accessible to minors must ensure a high level of privacy, safety and security on their service, a standard the Commission preliminarily considers TikTok's account settings fail to meet. In line with its Guidelines on the protection of minors, the Commission preliminarily considers that TikTok should adjust the default settings of minors' 'public' accounts so that their content is, by default, visible only to TikTok users the minor has accepted, and that TikTok should refrain from recommending minors' content to other users through the “For You Feed”. TikTok can now examine the files in the Commission's investigation and reply to the findings. The European Board for Digital Services will also be 50
https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1679
30
consulted before the Commission adopts a final decision. These preliminary findings do not prejudge the final outcome of the investigation. 51 Binding specification measures for Google under DMA On 16 July 2026, the European Commission issued two sets of binding specification measures to Google under the Digital Markets Act ("DMA"). The first specification concerns interoperability between Google's Android operating system and third-party AI assistants and is intended to ensure that competitors' Artificial Intelligence (“AI”) services can compete with Google's own AI services, such as Gemini, by having equal access to features on Google's Android devices. The decision will require Google to enable users to activate their preferred AI assistant via voice commands, similar to the "Hey Google" command, and to allow thirdparty AI assistants to perform actions in apps on the user's behalf. The second specification concerns the sharing of Google Search's search data with third-party search engines and is intended to rebalance the playing field by giving third-party search engines access to search data that only Google Search can collect at scale. The decision requires Google to share the same search data it uses to optimise its own search services, subject to anonymisation, and sets out a formula for pricing the shared data and a transparent process for accessing it. 52 The measures are legally binding, and Google must implement them within the timelines set out in the decisions. Search data sharing with eligible providers must begin from January 2027, while the Android interoperability changes must take effect from July 2027. The decisions remain subject to independent judicial scrutiny. 53 Google fined €890 million for breaches of the Digital Markets Act – European Commission On 23 July 2026, the European Commission imposed fines totaling EUR 890 million on Google for two infringements of the Digital Markets Act ("DMA"). 54 The decisions concern Google's treatment of competing services in Google Search and restrictions imposed on app developers using Google Play. The Commission found that Google had breached the DMA's prohibition on selfpreferencing by giving preferential treatment to its own services, including shopping, hotel, transport and sports services, in search results. According to the Commission, Google's own services were systematically displayed more prominently than competing services, including through top placement in search results, enhanced visual presentation and dedicated filtering functions that were not made available to third-party providers. Google was fined EUR 460 million for this infringement. The Commission also found that Google had failed to comply with the DMA's anti-steering obligations applicable to app stores. Under the DMA, app developers must be free to inform users about alternative offers and purchasing options outside the app store. The Commission found that Google prevented developers from freely promoting and directing users to alternative distribution channels, including their own websites and third-party app stores. The Commission further concluded that the fees Google charged developers for purchases made https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1679 https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1634 53 https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1634 54 https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1670 51 52
31
outside Google Play, and the duration for which such fees were levied, exceeded what is permitted under the DMA. Google was fined EUR 430 million in respect of these practices. Google has been ordered to bring the infringements to an end within 60 days or risk periodic penalty payments. The decisions represent one of the most significant enforcement actions under the DMA to date and provide important guidance on how the Commission interprets the DMA's self-preferencing and anti-steering obligations for designated gatekeepers. Google fined €403 million over location data processing practices – Irish Data Protection Commission On 21 September 2026, the Irish Data Protection Commission ("DPC"), acting as lead supervisory authority for Google Ireland Limited, imposed fines totaling EUR 403 million following an investigation into Google's processing of location data between May 2018 and February 2020. 55 The investigation focused on three features: Web & App Activity, Location History, and Location Accuracy. The DPC found that Google had infringed the GDPR's requirements relating to lawfulness, fairness and transparency in its processing of location data. According to the DPC, users were not provided with sufficiently clear information about how their location data was collected and used, including for purposes such as advertising and profiling. The DPC also found that Google had failed to demonstrate compliance with its accountability obligations and had retained location data for longer than necessary. In announcing the decision, the DPC stressed that location data can reveal highly sensitive information about an individual's movements, habits and interests, making transparency and user control particularly important. Google has been ordered to bring its processing operations into compliance within six months. The decision is one of the largest GDPR fines imposed in 2026 and serves as a reminder of the heightened regulatory scrutiny of behavioural tracking, profiling and the use of location data by digital platforms. The DPC has stated that the full decision will be published in due course. Commission fined AliExpress €550 million for breaches of the Digital Services Act On 20 July 2026, the Commission fined AliExpress EUR 550 million for breaches of the DSA. 56 The fine is the largest issued under the DSA to date. The Commission found that AliExpress had failed to (i) diligently assess risks relating to the sale of illegal, unsafe or counterfeit products, and (ii) mitigate identified systemic risks. The Commission highlighted a number of shortcomings, such as failure to allocate sufficient resources for the review of illegal products, detection systems that did not function properly, which resulted in many illegal products circulating on the platform and remaining online for several weeks after being identified, and failure to enforce its penalty policy against traders selling illegal products.
https://www.dataprotection.ie/en/news-media/latest-news/data-protection-commission-fines-google-eu403-millionfollowing-inquiry-googles-processing-location 56 https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1654 55
32
The Commission opened its formal proceedings already in 2024. In June 2025, the Commission accepted and made binding a series of commitments offered by AliExpress, while at the same time issuing its preliminary findings. As next steps, AliExpress must submit an action plan by 20 October 2026 explaining how it will remedy the identified failures.
33
34
“ BAHR distinguishes itself through its exceptional legal expertise, particularly in complex intellectual property matters. Chambers Europe
What makes this practice unique is the combination of deep legal expertise and exceptional technical insight. The team stands out for their ability to understand and articulate complex scientific and engineering concepts with remarkable clarity - an essential skill in patent litigation. They have not only mastered the nuances of both Norwegian and EPO law but also integrated this knowledge into creative, pragmatic strategies that make a tangible difference in the outcome of cases. Legal 500
35
BAHR Technology BAHR’s multi-disciplinary Technology group is tailored to meet the diverse needs of technology companies, covering all areas from litigation and M&A to contracts and regulatory matters. We are dedicated to maintaining in-depth knowledge and active engagement with industries at the cutting edge of technological advancement, delivering market-leading expertise to tackle the legal challenges these sectors face. Our clients benefit from lawyers who not only understand their business but also grasp the commercial opportunities and challenges inherent within their industry.
Contact us
Jacob A. Møller
Eirik Basmo Ellingsen
PARTNER
PARTNER
+47 928 80 017 jam@bahr.no
+47 920 88 112 eiell@bahr.no
36
Notes
37
Technology and IP Quarterly Q3 2026
38
Disclaimer This publication is provided for general information purposes only and does not constitute legal advice. You should not rely upon it as a substitute for specific legal advice tailored to your particular circumstances. If you require legal advice on any matter addressed in this publication, please contact a BAHR partner. BAHR accepts no responsibility for any information contained in this publication that may prove to be inaccurate, incomplete, outdated, or incorrect. BAHR excludes all liability (howsoever caused) to you or any third party for any loss or damage arising from the use of, or reliance upon, this publication. Any use of the information contained herein is entirely at your own risk. 39