Any cloud service provider seeking to offer cloud services to the German public sector will inevitably have to deal with the Supplementary Contractual Conditions for the Procurement of IT Services (Ergänzende Vertragsbedingungen für die Beschaffung von IT-Leistungen – “EVB-IT”). The EVB-IT were developed by the Federal/State/Local Cooperation Committee (Kooperationsausschuss ADV Bund/Länder/Kommunaler Bereich) in cooperation with
DLA Piper
DLA Piper is a global powerhouse law firm with expertise in a variety of areas—ranging from finance to employment to real estate to international trade. Their team of knowledgable attorneys spans 40 countries throughout the Americas, Asia Pacific, Europe, Africa, and the Middle East. Covering multiple practices and geographic regions, their perspectives are consumed worldwide and this has cemented them as a top firm known around the globe. DLA Piper publishes eight different blogs, each with a specific niche.
Latest from DLA Piper - Page 5
EU Commission looks to strengthen EU Cybersecurity Resilience and Capabilities
On 20 January 2026, the European Commission proposed a new cybersecurity package, aimed at strengthening the EU’s cybersecurity resilience and capabilities. The package includes a revised Cybersecurity Act (“CSA”) and targeted amendments to the NIS2 Directive (see our blog post for further information on the amendments to the NIS2 Directive). The revised CSA aims…
UK: Commencement of the data protection provisions in the Data (Use and Access) Act
On 5 February 2026, the main changes to data protection legislation in Part 5 of the Data (Use and Access) Act 2025 (“DUAA”) came into force.
The DUAA was passed and received Royal Assent on 19 June 2025. Although some of the DUUA provisions came into force automatically, many of the reforms need to be…
China: New guidance on data transfer and identification of important data in the automotive sector
On 3 February 2026, the Ministry of Industry and Information Technology (MIIT), the sectoral regulator of the automotive sector, and the Cyberspace Administration of China (CAC), the designated data regulator, together with six other government authorities, published the Guidance for the Secure Cross-Border Transfer of Automotive Data (2026 Edition). This new guidance focuses on the…
EU: NIS2 Update – EU Moves to Harmonise Cyber Controls, Refine Scope, and Add New In-Scope Entities
The NIS2 Directive continues to evolve – and organisations must keep pace. On 20 January 2026, the Commission unveiled a set of targeted amendments to the NIS2 Directive (“the Proposal”), signalling the next phase of its push to modernise and streamline the EU’s cybersecurity legal framework.
Positioned within a broader legislative package, also proposing a…
Supreme Court to Clarify Meaning of “Consumer” Under VPPA
By: Andrew Serwin, Isabelle Ord, Jeffrey DeGroot, Hayley Curry, and Matt Danaher
On January 26, 2026, the U.S. Supreme Court granted certiorari in Salazar v. Paramount Global to clarify the scope of the Video Privacy Protection Act (“VPPA”) and resolve a circuit split on the issue. See Salazar v. Paramount Global, No. 25-459 (S. Ct.).…
From Telecoms to “Digital Networks”: Navigating the EU’s New Digital Networks Act (DNA)
The European Commission has just unveiled its proposal for the Digital Networks Act (DNA). The DNA marks a fundamental shift from regulating traditional “electronic communications” to a broader, cloud-integrated ecosystem of “digital networks”.
In a nutshell: The DNA replaces the fragmented framework of the 2018 Electronic Communications Code (EECC) with a directly applicable Regulation. Unlike…
Australia: Return to Sender ID: Businesses must register “branded identifiers” used in Australian SMS messages
From 1 July 2026, entities that use an alphanumeric sender ID for SMS/MMS messages in Australia must register that ID on the SMS Sender ID Register.
Sender IDs are used to send SMS/MMS messages from a named entity (i.e. a name displayed at the top of a text message to show who the message is…
Why Investors should lean into privacy-centric AI: key takeaways from the ICO’s Agentic AI Guidance
The ICO has, this week, published extensive guidance on its expectations on Agentic AI, ICO tech futures: Agentic AI | ICO. The UK data protection regulator’s core message is clear: the future of the success of this technology is rooted in accountability.
Investor expectations on the realisation of commercial benefits from AI deployment are…
CHINA: new mandatory reports to regulator on children’s data , initial deadline 31 January 2026
All data controllers processing personal data under the age of 14 (“minors”) must now submit an annual report to Chinese data regulator, the Cyberspace Administration of China (“CAC”). For 2025, the report must be submitted by 31 January 2026. There is no volume threshold, meaning that any data controller processing any minors’ data – even…