1. Full Steam Ahead: The European Union’s (EU) Artificial Intelligence (AI) Act in Action — As the EU’s landmark AI Act officially takes effect, 2025 will be a year of implementation challenges and enforcement. Companies deploying AI across the EU will likely navigate strict rules on data usage, transparency, and risk management, especially for high-risk AI systems. Privacy regulators are expected to play a key role in monitoring how personal data is used in AI model training, with potential penalties for noncompliance. The interplay between the AI Act and the General Data Protection Regulation (GDPR) may add complexity, particularly for multinational organizations.
  2. Network and Information Security Directive (NIS2) Matures: A New Era of Cybersecurity Regulation — The EU’s NIS2 Directive will enter its enforcement phase, expanding cybersecurity obligations for critical infrastructure and key sectors. Companies must adapt to stricter breach notification rules, risk management requirements, and supply-chain security mandates. Regulators are expected to focus on cross-border coordination in response to major incidents, with early cases likely setting important precedents. Organizations will likely face increasing scrutiny of their cybersecurity disclosures and incident response protocols.
  3. The Evolution of Data Transfers: Toward a Unified Framework — After years of turbulence, 2025 may mark a turning point for transatlantic and global data flows. The EU-U.S. Data Privacy Framework will face ongoing reviews by the European Data Protection Board (EDPB) and potential legal challenges, but it offers a clearer path forward. Meanwhile, the EU may continue striking adequacy agreements with key trading partners, setting the stage for a harmonized approach to cross-border data transfers. Companies will need robust mechanisms, such as Standard Contractual Clauses and emerging Transfer Impact Assessments (TIAs), to maintain compliance.
  4. Consumer Rights Expand Under the GDPR’s Influence — The GDPR continues to set the global benchmark for privacy laws, and 2025 will see the ripple effect of its influence as EU member states refine their own data protection frameworks. Enhanced consumer rights, such as the right to explanation in algorithmic decision-making and stricter opt-in requirements for data use, are anticipated. Regulators are also likely to target dark patterns and deceptive consent mechanisms, driving companies toward greater transparency in their user interfaces and data practices.
  5. Digital Markets Act Meets GDPR: Privacy in the Platform Economy — The Digital Markets Act (DMA), fully enforceable in 2025, will bring sweeping changes to large online platforms, or “gatekeepers.” Interoperability mandates, restrictions on data combination across services, and limits on targeted advertising will intersect with GDPR compliance. The overlap between DMA and GDPR enforcement will challenge platforms to adapt their practices while balancing privacy obligations. This regulatory synergy may reshape data monetization strategies and set a precedent for digital market governance worldwide.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Dr. Viola Bensinger Dr. Viola Bensinger

Viola Bensinger is Global Co‑Chair of the firm’s Intellectual Property & Technology Practice Group and also chairs the Technology Practice in Germany. Viola advises clients from the technology, media, health care and other innovation-driven industries on digitisation projects, IT outsourcing, cloud computing, e‑commerce…

Viola Bensinger is Global Co‑Chair of the firm’s Intellectual Property & Technology Practice Group and also chairs the Technology Practice in Germany. Viola advises clients from the technology, media, health care and other innovation-driven industries on digitisation projects, IT outsourcing, cloud computing, e‑commerce, electronic payment, data protection, and software licensing.

She has wide-ranging experience in advising media and entertainment clients such as distributors, producers, broadcasters, digital platforms, publishers, and their contracting partners on licensing and distribution, as well as the legal set-up of digital platforms. Viola also advises clients on regulatory issues, especially with regard to broadcasting law, data protection, and AI regulation.

In her litigation practice, Viola represents clients at courts or arbitration panels in contract disputes, copyright and other litigation. For many years, Viola has also gained broad experience in the areas of insolvency and restructuring relating to IP assets and licensing agreements and has advised numerous clients in large-scale insolvency proceedings relating to their German business partners.

Photo of Carsten A. Kociok Carsten A. Kociok

Carsten Kociok is a partner in the Technology, Financial Services and Data Privacy Practice in Berlin and Co-Head of Greenberg Traurig’s global Fintech Group. He advises national and international clients across all industries, including financial services, information technology, artificial intelligence, ecommerce, media, health

Carsten Kociok is a partner in the Technology, Financial Services and Data Privacy Practice in Berlin and Co-Head of Greenberg Traurig’s global Fintech Group. He advises national and international clients across all industries, including financial services, information technology, artificial intelligence, ecommerce, media, health care, telecoms, retail and real estate, on a wide variety of complex commercial and regulatory matters.

Carsten is a leading technology lawyer, ranked consistently in Band 1 for Fintech Legal in Germany since 2020. He has in-depth and wide-ranging experience in the areas of privacy and cybersecurity, payments law, financial services, e-money products, blockchain technology, and financial and banking regulation, as well as in artificial intelligence regulation – including compliance with the EU AI Act – and the integration of AI technologies into existing software systems.

Carsten regularly assists clients in licensing projects and audit proceedings with financial regulators and advises on the contractual and regulatory aspects of developing, implementing and operating financial technology products and transactions.

On the data privacy side, Carsten counsels clients on complex data-driven business models and regulatory matters, including on international data transfers, data privacy compliance, monetization of data, artificial intelligence, litigation, cybersecurity and data breach response.

Carsten regularly lectures and publishes on various FinTech and data privacy topics. Prior to joining the firm, Carsten worked at Olswang Germany for eight years and in the Capital Transaction Practice Group of an international law firm in New York.

Photo of Dr. Philip Radlanski Dr. Philip Radlanski

Philip Radlanski is a Local Partner in the IP & Technology Practice Group. He advises clients ranging from early-stage start-ups to large corporations on matters relating to artificial intelligence (AI), data privacy, and cybersecurity. His work focuses on complex and innovative data-heavy AI

Philip Radlanski is a Local Partner in the IP & Technology Practice Group. He advises clients ranging from early-stage start-ups to large corporations on matters relating to artificial intelligence (AI), data privacy, and cybersecurity. His work focuses on complex and innovative data-heavy AI projects, often with cross-border aspects. He also assists with addressing cybersecurity issues, including data breach incident management and response. He gained strong recognition throughout Europe for his representation in the first German trial against a GDPR fine, in which he was able to achieve a reduction of the multimillion-euro fine by more than 90 percent.

As a driving force behind the firm’s AI practice in Germany, he guides companies through the complex and rapidly evolving regulatory landscape surrounding artificial intelligence — from the EU AI Act and sector-specific requirements to the intersection with data protection and intellectual property law.

With a strong understanding of the technical underpinnings of AI and a practical, business-oriented mindset, Philip is regularly sought after by multinational companies, technology providers, and start-ups developing or deploying AI systems. He advises on all aspects of AI governance — from risk assessments and compliance strategies to drafting internal policies and representing clients before regulatory bodies. Philip also works closely with in-house legal, compliance, and technical teams to promote effective AI oversight, foster privacy-by-design, and drive responsible, future-proof adoption of transformative technologies.

Philip is known for his pragmatic approach, which he was able to further refine through several months of secondments to the legal departments of a leading German internet service provider and an internationally operating online marketplace for food delivery. A further one-year secondment to the Global Privacy & Data Security Group of an international law firm in New York shaped Philip’s understanding of the U.S. market and U.S. clients.

Prior to practicing as an attorney, Philip worked as a research assistant at the University of Regensburg, Germany, and as a visiting tutor at King’s College London, UK. He also worked with the German Federal Film Board, the cybercrime division of the Berlin District Attorney’s Office, and for different international law firms in Berlin, New York, and Sydney.

He is a member of the German Association for the Protection of Intellectual Property and Copyright (GRUR), the International Technology Law Association (ITechLaw), and the Bauhaus Archive.