GA-Alliance

Data Protection & Cybersecurity

GA-Alliance

GA-Alliance specializes in providing expert guidance on privacy, data protection and cybersecurity, assisting clients in navigating complex industry regulations and effectively managing cybersecurity risks.
Our firm boasts the capability to support clients with multi-disciplinary teams comprising both legal professionals and information technology experts.

Personal Data Protection Legal Advice
Our team provides legal advice on personal data protection, assisting clients in interpreting and adhering to national and international privacy regulations.

Our legal services encompass:

  • Privacy audits, gap analysis and risk assessments
  • Creation and implementation of all necessary acts and documents as per applicable regulations
  • Drafting of data protection policies and procedures
  • Assistance in the management of data breaches and notification to the relevant authorities
  • Our professionals also serve as DPOs (Data Protection Officers) for institutional investors and leading companies, both domestically and internationally, spanning diverse sectors.

Cybersecurity Services
We provide specialised legal advice for the prevention and management of cybersecurity incidents, enabling clients to comprehend and mitigate cybersecurity risks to protect their businesses and data.

Our legal services include:

  • Cybersecurity audits and vulnerability assessments
  • Advice in drafting and negotiating cybersecurity contracts
  • Assistance in the management of security incidents and responding to cyber attacks

With our extensive experience and expertise in the fields of data protection and cybersecurity, we deliver comprehensive and reliable legal support to address challenges associated with digital information management and cybersecurity effectively.

Our experts

VIEW MORE

Caricamento..

Insights

GA-Alliance

Knowledge Management

Jul 28 2026

Google for AI interoperability and sharing of Google Search data under the Digital Markets Act

On July 16th, 2026, the EU issued two sets of binding specification measures to Google under the Digital Markets Act.

The aim of the first specification measure is to ensure that competitors' Artificial Intelligence (“AI”) services can compete with Google's own AI services, such as Gemini, by having equal access to features on Google's Android devices.

The aim of the second specification measure is to rebalance the playing field by giving third-party search engines access to search data that only Google Search can collect at scale.  

INDEX

FACTUAL BACKGROUND

Google's relationship with EU competition enforcers did not begin with the Digital Markets Act (“DMA” or the “Act”). By the time the DMA entered into force, the Commission had already spent the better part of a decade building a record of formal antitrust cases against the company, mostly under Article 102 of the Treaty on the Functioning of the European Union which focuses on the prohibition of abuse of a dominant market position. Google has been fined multiple times over its infringements, with record sanctions including €2.42 billion for favouring Google Shopping in 2017 and €4.34 billion for tying Android to Google's own apps and services in 2019. Said records are part of the reason Google was one of the first companies the Commission had in mind when it began designing a faster, more predictable alternative to case-by-case litigation.

That alternative arrived on 6 September 2023, when the Commission formally designated Alphabet, alongside Amazon, Apple, ByteDance, Meta and Microsoft, as a gatekeeper under Article 3 of the DMA.[1]  The designation was not a discretionary judgement call in Google's case as the company comfortably met the quantitative thresholds set out in Article 3(2) of the Act:  EU revenues above €7.5 billion in each of the preceding three years, a core platform service used by more than 45 million monthly active end users and at least 10,000 business users in the EU, and a presence sustained over three consecutive years. These three margins create a rebuttable presumption of gatekeeper status. Eight of Google's services were swept into the designation as core platform services in their own right: Google Search, Google Play, Google Maps, YouTube, the Android operating system, Chrome, Google Shopping and Google's online advertising services. No other gatekeeper was designated for as many services at once, a reflecting the real importance of Google's various products as gateways between European businesses and European consumers.

The designation triggered a compliance rush. Under Article 3(10) of the DMA, gatekeepers have six months from designation to bring their conduct into line with the Regulation's obligations, meaning Google was required to be fully compliant across all eight designated services from 7 March 2024. It is what happened after that date, or, more precisely, what Brussels considers not to have happened adequately, that sets the stage for the specification proceedings. These proceedings were opened in January 2026, with the preliminary findings and proposed measures published in April 2026, and the final decisions announced in July 2026. It is worth noting that specification proceedings clarify how a DMA obligation should be implemented to ensure compliance. Specification proceedings are distinct from non-compliance investigations, and do not aim to assess the gatekeeper's compliance with the DMA. Therefore, they do not provide for the imposition of fines.[2]

Regulation (EU) 2022/1925 (the “Regulation”), otherwise known as the Digital Markets Act, entered into force in November 2022 and became applicable in May 2023, following of years of case-by-case antitrust enforcement, which made the Commission unable to keep up with the fast evolution of digital markets. The Google Shopping case was Exhibit A for that concern: a practice identified as harmful in 2017 was not definitively confirmed as unlawful by the courts until 2024, by which time the market it was meant to protect had moved on. The DMA's premise is that, in markets characterised by strong network effects, data-driven advantages and high switching costs, gatekeeper platforms can occupy positions so entrenched that waiting years for an Article 102 case to run its course effectively cedes the market to them in the meantime.[3]

The Regulation imposes a set of ex-ante, largely self-executing obligations directly on companies that meet the gatekeeper definition. It regulates ten categories of "core platform service" (i.e. online intermediation services, search engines, social networks, video-sharing platforms, messaging services, operating systems, web browsers, virtual assistants, cloud computing and online advertising) and designates as a gatekeeper any undertaking that meets the qualitative test of Article 3(1): significant impact on the internal market, control of an important gateway between business users and consumers, and an entrenched and durable position, or the foreseeable emergence of one.  Article 3(2) attaches quantitative thresholds that create a presumption of gatekeeper status, subject to rebuttal, while Article 3(8) allows the Commission to designate a company even where those thresholds are not met, following a dedicated market investigation.

The DMA sets out both obligations and prohibitions to be respected by the designated gatekeepers. As some may be open to broad interpretative approaches, the Commission may elaborate iterative clarifications. For these, the Commission can open a specification proceeding under Article 8(2) to define compliance in dialogue with the company before, or instead of, moving to a finding of infringement.

Enforcement sits exclusively with the Commission, unlike ordinary EU antitrust law, which is enforced in parallel by national competition authorities; this centralisation was itself designed to guarantee consistent, EU-wide application of rules that, being a Regulation rather than a Directive, apply directly in all Member States without national transposition. Penalties for non-compliance can reach 10% of a company's total worldwide annual turnover, rising to 20% for repeat infringements, with periodic penalty payments available to compel compliance and, for systematic non-compliance, the possibility of behavioural or even structural remedies.

Having taken into consideration the legal background of the DMA, the two decisions of 16 July 2026 are not an isolated phenomenon but a case study on how the DMA is meant to function.

THE SPECIFICATION DECISIONS

The two specification proceedings were both opened on 27 January 2026 and ran in parallel, with the final decisions both concluding on 16 July. The decisions include binding measures.

The decisions are connected, as both are about whether Google's control over a foundational layer, the Android operating system in one case, the unprocessed information on what people search for in the other, can be used to entrench its own position in the market that increasingly matters most, artificial intelligence, at the expense of everyone trying to compete with Gemini or with Search itself.

INTEROPERABILITY WITH GOOGLE ANDROID

The first decision concerns Article 6(7) of the DMA, which requires a gatekeeper to provide business users and third-party providers with free and effective interoperability with the hardware and software features of its operating system, provided that interoperability does not compromise security or the integrity of the device. Applied to Android, this obligation had, until now, produced little practical change: rival AI assistants competing with Google's own Gemini could be installed on Android phones, but they lacked access to system-level features that Gemini enjoyed by default, such as being triggered by a wake word in the way "Hey Google" activates Google's assistant, or being able to act on a user's behalf inside other apps. The Commission found that roughly 60% of EU users on Android devices were, in practice, locked into a lesser experience with any assistant other than Google's own.[4] The decision specifies that Google must give competing AI providers equivalent access: EU users should be able to trigger their assistant of choice by voice, delegate tasks such as booking a taxi, receive suggested replies inside messaging apps, or ask their assistant about a place they recently visited, which are all capabilities so far reserved for Gemini. The decision also builds in safeguards intended to preserve user privacy, device integrity and security while opening up access.

GOOGLE SEARCH DATA

The second decision concerns Article 6(11), which obliges a gatekeeper operating a search engine to give rival search providers access, on fair, reasonable and non-discriminatory terms, to anonymised ranking, query, click and view data that it generates from users' interactions with its own search engine. Google had already made some data available by the March 2024 compliance deadline, but the Commission concluded that the implemented changes were not as effective as mandated by the DMA: the scope of data was too narrow and the anonymisation approach was contested. However,  it was unclear whether AI chatbots with search functionality even qualified as eligible recipients. The new decision resolves each of those points. First, it confirms that AI chatbots offering search-like functionality are entitled to receive the data. Second, it requires Google, once the data is anonymised, to share broadly the same information it uses to optimise its own search results. Third, it lays down a multi-layered anonymisation methodology developed with internal and external privacy experts, designed to align with the draft joint guidelines the Commission and the European Data Protection Board are preparing on how the DMA and the GDPR interact.[5] Google retains the ability to assess, before sharing data with a specific recipient, whether doing so would pose a serious cybersecurity or data-protection risk, and the Commission has left itself room to revisit the anonymisation requirements as the market and independent evaluations develop. The decision also sets a formula for pricing the data and a transparent process for requesting access to it.

IMPORTANCE OF THE DECISIONS: A PATTERN OF ENFORCEMENT

This is not the first time that Google finds itself on the wrong side of an EU procedure over data access, self-preferencing or Android control. Three prior enforcement procedures are worth setting alongside the July 2026 decisions.

The first is the long antitrust history under ordinary competition law, rather than the DMA. The 2017 Google Shopping decision, which fined Google €2.42 billion for systematically favouring its own comparison-shopping service in search results, was upheld in full by the European Court of Justice in September 2024, closing a case that had run for the better part of a decade from opening to final judgment. The 2018 Android decision, which fined Google roughly €4.34 billion (later reduced to about €4.1 billion) for bundling Search and Chrome into Android licences and paying manufacturers to keep rival operating systems off their devices, faced the same sanctioning trend on 2 July 2026, when the Court of Justice dismissed Google's final appeal and made the fine definitive. A third case, the 2019 AdSense decision fining Google €1.49 billion over exclusivity clauses that shut out rival search advertising brokers, took a different path: the General Court annulled it in September 2024, the Commission has appealed to the Court of Justice, and the matter remains pending. Most recently, in September 2025, the Commission fined Google €2.95 billion under ordinary antitrust rules for favouring its own ad exchange within the adtech supply chain.[6][7] Read together, these cases describe a single recurring concern: Google using control over a chokepoint, whether search results, Android licensing or the ad stack, to favour outcomes toward its own products.

The second trend is the DMA's own enforcement record. The Commission opened its first non-compliance investigations under the Act in March 2024, a few weeks after the compliance deadline took effect, targeting Apple's and Google's steering rules and Google's self-preferencing in Search under Article 6(5), among others.[8] On 19 March 2025, the Commission sent Google preliminary findings that its search results continued to give Google's own vertical services, such as Google Shopping, Google Flights and Google Hotels, more favourable formatting and placement than rival comparison services, in a manner it considered incompatible with Article 6(5)'s non-discrimination requirement. That case has moved slowly by the DMA's own fast-track standards[9] and, at the time of writing, a formal non-compliance decision, reportedly to include a substantial fine alongside a parallel finding on Google Play's anti-steering rules, is expected imminently, though the Commission has not yet confirmed either the figure or the date. Whatever the outcome, it would follow the template set by the DMA's first-ever sanctions, issued on 23 April 2025, when the Commission fined Apple €500 million for restricting app developers' ability to steer users to purchase options outside the App Store, and fined Meta €200 million for its "consent-or-pay" advertising model. Those two decisions established that the Commission was prepared to use its fining powers early in the DMA's life, not only its power to specify compliance.

The last trend regards the specification-proceeding mechanism used for the July 2026 decisions themselves. The Commission opened the interoperability and search-data proceedings on 27 January 2026 explicitly to "assist" Google in complying with obligations it had already been subject to for nearly two years, language that reflects the DMA's stated preference for dialogue over immediate punishment. That six-month proceeding produced the binding measures now in force. It is a reminder that specification decisions and non-compliance fines are two different enforcement tracks running in parallel against the same company, over conduct that is, at bottom, the same recurring pattern: gatekeeping a chokepoint in ways that keep rivals a step behind.

The argument can be made that the Commission is working double-time to keep up with the changes pushed by the rapidly growing AI digital infrastructure. This pattern of enforcement, coupled with other groundbreaking efforts (see our previous article on the imposition of AI-related interim measures on Meta in June 2026[10]) show a clear strategized effort on behalf of the Commission to keep up, to regulate and to protect both the AI companies as well as the end consumer.  


[1]  Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital Markets Act), available under the followinglink.

[2] Summary of Commission Decision of 19 March 2025 relating to a decision pursuant to Article 8(2) of Regulation (EU) 2022/1925 (Case DMA.100203 – Article 6(7) – Apple – iOS – SP – Features for Connected Physical Devices) (notified under document number C(2025) 3000), available under the following link.

[3] European Commission, the Digital Markets Act, available under the following link.

[4] European Commission: Commission provides guidance to Google for AI interoperability on Android and sharing of Google Search data under the Digital Markets Act, available under the following link.

[5] Ibid.

[6] This decision is currently being contested by Google.

[7] European Commission, "Commission fines Google €2.95 billion over abusive practices in online advertising technology," Press release IP/25/1992, September 2025, available under the following link.

[8] Digital Markets Act (DMA) portal, "Commission finds Apple and Meta in breach of the Digital Markets Act," 23 April 2025, available under the following link.

[9] The Act was designed to produce findings within roughly a year.

[10] INSERT LINK TO PREVIOUS META ARTICLE

GA-Alliance

Knowledge Management

Jul 27 2026

EU Commission imposes interim measures on Meta

On June 9th, 2026, the EU Commission announced that it is imposing interim measures on Meta while the investigation on a possible abuse of dominance is carried out. The antitrust investigation, opened in December 2025, means to evaluate the legality of Meta’s revised policy which blocks access for AI providers, other than Meta AI, to WhatsApp.[1]

INDEX

FACTUAL BACKGROUND

Meta, formerly known as Facebook, acquired WhatsApp in 2014. The merger was given the greenlight by the EU Commission after an extensive study on possible anticompetitive effects in three different relevant markets: consumer communication services, social networking services, and online advertising. The assessment was based on information and promises shared by Facebook regarding the unlikelihood of automated matching between Facebook users’ accounts and WhatsApp users’ accounts following the merger. Nevertheless, in 2016, WhatsApp announced updates to its terms of service and privacy policy, including the possibility of linking WhatsApp users' phone numbers with Facebook users' identities.[2] The Commission reacted by fining Facebook €110 million for providing misleading information about the takeover after finding that, contrary to Facebook’s statements from 2014, its staff were aware of the possibility of matching the platforms’ accounts and identities.

Facebook infringed Regulation 1/2003 by intentionally or negligently providing the incorrect or misleading information to the Commission. The fine was meant to act as a deterrent proportional to the nature, gravity and duration of the infringement, after taking into consideration all mitigating and aggravating circumstances. It was the Commission’s first ever decision involving the imposition of fines on a company for providing incorrect or misleading information since the entry into force of the 2004 Merger Regulation. There were no other measures taken aside from the fine and the merger continued to set Facebook (now Meta) on the course toward achieving and maintaining a dominant position status. This is the status that proves problematic for the current event.

In October 2025, Meta announced that it would update its WhatsApp Business Terms, effectively banning third-party general purpose Artificial Intelligence (“AI”) assistants from the consumer communication application. The Commission has considered WhatsApp to hold a dominant position in the market since at least January 2023. Therefore, the update to the Terms is considered, at first sight, to be a possible abuse of dominant position, as competing general-purpose AI assistants are precluded from using the platform’s Business Application Programming Interface (“API”).

Starting mid-January 2026, the only AI assistant available on WhatsApp was Meta’s own AI tool (“Meta AI”). The complete exclusion of all competitors was lessened on March 4th, when a revision of the policy accepted third-party general-purpose AI assistants again on the platform, but levied an access fee which is being classified as a practice possibly equivalent to the previous access ban. Teresa Ribera, executive Vice-President of the Directorate-General for Competition, stated that the fees were so elevated that they could not be economically sustained by competitors.

Formal proceedings were opened by the Commission in December 2025. The decision to initiate antitrust proceedings covered the EEA except for Italy, as the Italian National Competition Authority (AGCM) imposed its own interim measures on Meta in December. Shortly after, a Statement of Objections was released, setting out the Commission’s preliminary view that Meta breached EU antitrust rules by excluding third party AI assistants from accessing and interacting with users on WhatsApp.[3] Meta's conduct risks blocking competitors from entering or expanding in the rapidly growing market for AI assistants.

April 2026 marked the expansion of the investigation to Italy, allowing the study to analyze conduct changes since the initiation of proceedings.

Meta’s response denounces the opening of the investigation as they find that the Commission’s approach imposes unfair conditions, allowing "OpenAI and some of the largest companies in the world [to] use the paid-for WhatsApp Business product for free," a Meta spokesperson said in an email.[4] An appeal will be filed by Meta as they find the investigation to be a “regulatory overreach subsidized by many European companies that pay.”

The substantive investigation into the merits of the case is still active and ongoing.

The investigation of case AT.40134 [CD1] is carried out through the lens of the antitrust laws set out in Article 102 TFEU and Article 54 of the EEA Agreement which prohibit the abuse of dominant positions that may affect trade and prevent or restrict competition within the Single Market.

The proceedings are carried out within the rules and limitations set out by Article 11(6) of Council Regulation No. 1/2003 (Cooperation between Commission and National Authorities)[5] and Article 2(1) of Commission Regulation No. 773/2004 (Initiation of Proceedings)[6].

Pursuant to Article 8(1) Regulation 1/2003, interim measures may be imposed in cases of urgency due to the risk of serious and irreparable damage to competition assessed on a basis of a prima facie finding of infringement. Although such measures are always imposed for a limited amount of time, they can be renewed until the end of the investigation (by June 2029 at the latest for the case at hand).

Meta faces a potential fine of up to 10% of its total turnover in the year preceding the alleged infringement if found to have breached the EU antitrust regulation and may also be subject to daily periodic penalty payments not exceeding 5% of the average daily turnover in the business year preceding the infringement if it does not comply without delay.

THE INTERIM MEASURE

The Commission has concluded that interim measures are warranted to prevent serious and irreparable damage to competition in the growing market for general-purpose AI assistants as Meta holds a dominant position in the market for consumer communication applications and is, at first sight, abusing this position by blocking access to the WhatsApp API. The refusal to provide access to an infrastructure developed for and previously open to third parties created an urgent need to prevent damage to the competition structure of the AI assistant market by stalling the growth of smaller players and new entrants that could possibly challenge large incumbents.

The decision orders Meta to re-instate access for third-party general purpose AI assistants to the platform’s Business API and to re-establish the same terms and conditions that were enforced before the policy change in October 2025, when access to the Programming Interface was free of charge. Those terms are meant to be enforced until the Commission adopts a final decision on the case. Compliance must be immediate, as Meta has five days to implement the measure.

Meta may also appeal the decision ordering the interim measures before the EU Courts pursuant to Section 17 of the Commission Antitrust Manual.

IMPORTANCE OF THE DECISION

Although Regulation No. 1/2003 expressly provides for the ability to impose interim measures if, at first sight, there is an infringement of competition law rules, this is only the second decision imposing such measures since 2019. The first and last instance of application of Art. 8(1) was in relation to the Broadcom case (AT.40608). Broadcom was found to have engaged in exclusionary practices and was subject to the first enforcement of interim measures implemented by the Commission. The interim measures decision, which had an implementation duration of three years, was shortly followed by a commitment decision (ex Art. 9 Regulation No. 1/2003) reflecting commitments offered by Broadcom and revised through a market test. Indeed, the commitment decision built on the applied interim measures, extending their effects for an additional seven years. Furthermore, the commitments covered additional areas of the market and more service providers who were in business with Broadcom.[7] Since then, the Commission has only once announced the possible use of interim measures in an investigation on potential competition restrictions on Lufthansa transatlantic routes to and from several airports in the EEA area[8], but it ultimately decided to abandon its request.

We may conclude that interim measures and commitment decisions are connected, as the former appear to suspend problematic behaviors and create incentives for the company under investigation to quickly find a lasting solution to the identified concerns. A commitment decision may also result in the Commission closing the investigation and simply monitoring the status, implementation, and results of said commitments.[9] Although the Commission may, upon request or of its own initiative, reopen the proceedings (e.g. if the undertaking concern acts contrary to their commitments), the prospect of closing the investigation early is a favourable one for the undertakings concerned. No reasonable economic agent wishes to remain involved in an investigation that can span years, under constant hawk-eye monitoring, and possible heavy fines and remedies.

It seems opportune to now start keeping an eye on other future uses of interim measures by the Commission as a tool to push undertakings to step back in line promptly in a way that spares time, money, and other resources that would otherwise be spent on a lengthy investigation. The transition from the monitoring of the implementation of interim measures to the monitoring of commitments is natural and efficient and it is something we are likely to see more of in future antitrust and competition regulation enforcement.


[1] Commission imposes interim measures on Meta to preserve free access to WhatsApp for rival AI assistants. European Commission Press Release, 9 June 2026. Commission imposes interim measures on Meta

[2] Commission Fines Facebook €110 million for providing misleading information about WhatsApp takeover, 18 May 2017. IP_17_1369_EN.pdf

[3] Commission Statement of Objections (Meta), 9 February 2026. AT_41034_606.pdf

[4] EU orders Meta to open WhatsApp to rival AI chatbots, BBC, Tom Singleton, 9 June 2026. EU orders Meta to open WhatsApp to rival AI chatbots

[5] Council Regulation (EC) No 1/2003 of 16 December 2002 on the implementation of the rules on competition laid down in Articles 81 and 82 of the Treaty. http://data.europa.eu/eli/reg/2003/1/2009-07-01

[6] Commission Regulation (EC) No 773/2004 of 7 April 2004 relating to the conduct of proceedings by the Commission pursuant to Articles 81 and 82 of the EC Treaty.  http://data.europa.eu/eli/reg/2004/773/2015-08-06

[7] Ex post evaluation of the implementation and effectiveness of EU antitrust remedies GA-Alliance Report 2025

[8] Case AT.40940 Press Release on Supplementary Statement of Objections to Lufthansa to prevent harm to Frankfurt-New York air passengers, 15 January 2025. Press Release

[9] A First in 20 Years: EU Commission imposes interim measures on Broadcom - Lexology


 [CD1]Exclusion of AI competitors from WhatsApp within the meaning of Article 11(6) of Council Regulation No 1/2003 and Article 2(1) of Commission Regulation No 773/2004

GA-Alliance

Knowledge Management

Mar 13 2026

EU CYBERSECURITY ACT PROPOSAL


Governance, Resilience, and Market Access

INDEX

Download the Client Alert!

Executive summary 

On 20 January 2026, the European Commission presented a comprehensive “Cybersecurity Package”, proposing a targeted revision of the “EU Cybersecurity Act” (originally adopted as Regulation (EU) n. 2019/881) alongside amendments to Directive (EU) n. 2022/2555 (“NIS2 Directive”).

The original 2019 framework established a permanent mandate on the “European Union Agency for Cybersecurity” (“ENISA”) as the Union’s central technical authority and introduced the “EU Common Criteria-based” (“EUCC”)scheme, laying the foundations of the European cybersecurity certification system. 

Since then, the overall set of existing and emerging threats, has evolved considerably. Modern attacks frequently disrupt vital operations and industrial networks, revealing structural flaws in cross-border coordination. 

The 2026 proposal arrives at a critical juncture where cyberattacks no longer target data alone, but increasingly jeopardise critical infrastructure, essential services, as well as global supply chains. These vulnerabilities are compounded by hybrid threats and growing geopolitical dependencies on foreign technologies. 

Consequently, the proposal moves beyond mere technical standards to address systemic bottlenecks, aiming by reinforcing ENISA’s mandate and restructuring the certification architecture to ensure greater uniformity across the internal market. Additionally, it establishes a formal mechanism to manage risks within ICT supply chains, including the identification of high-risk providers and the implementation of safeguards in high-priority sectors.

For businesses, cybersecurity is no longer confined to regulatory compliance. It directly affects market access, contractual stability, investment planning, and long-term competitiveness within the European digital economy. 

The proposal will now follow the ordinary legislative procedure before the European Parliament and the Council of the EU, then entering a phase of interinstitutional negotiation and technical refinement. If adopted, it is likely to redefine both regulatory obligations and competitive dynamics within the European digital market.

Regulatory standstill and outlook 

The proposed reform initiative marks a shift from a predominantly technical compliance regime toward an integrated governance model anchored in institutional consolidation. At its core lies the strengthening of ENISA as the Union’s central technical authority.

By formalising the Agency’s role in drafting candidate schemes and providing structured technical support to national authorities, the European Commission seeks to eliminate the fragmented national practices that have historically undermined mutual recognition across the EU. This approach ensures a uniform interpretation of assurance levels (ranging from “basic” to “high”) while harmonising evaluation methodologies to facilitate a truly smooth internal market. 

The expansion of ENISA’s mandate includes operating a central EU-wide threat repository, issuing strategic early warnings, managing a unified incident reporting platform, and coordinating large-scale cybersecurity exercises across Member States. These functions position ENISA as the European Union’s definitive technical reference body, bridging the gap between high-level policy and real-time operational coordination.

In the meanwhile, the reform seeks to increase the practical relevance of EU certification schemes. Acknowledging that voluntary schemes have had limited adoption, the European Commission is refining procedures and linking certification more closely with other EU product regulations. This strategy eliminates administrative redundancies and prevents the duplication of audit requirements.

Certification development has also been modernised: new procedures incorporate proportionality principles, encourage international cooperation, and set a clear 12-month timeline for ENISA to propose new schemes. By prioritizing global interoperability, the EU intends to reduce compliance burdens for European companies while establishing its certification framework as a leading international standard.

Most significantly, the revision introduces a step change in supply chain security, treating certification as a tool for technological resilience during geopolitical instability. The creation of mechanisms to identify and monitor high-risk suppliers across eighteen critical sectors represents a decisive move against systemic risks. For the first time, the EU framework allows for the potential withdrawal of deployed products if a supplier is reclassified as high-risk, posing operational and financial implications for critical infrastructure and digital services.

 

 

Strategic imperatives and the evolution of digital governance

The proposed reform introduces a comprehensive change in how organisations must operate within the European digital setting, moving from isolated product-focused security to a holistic approach that emphasises organisational maturity.

Companies will be required to implement advanced governance through documented policies, rigorous internal processes, comprehensive control mechanisms, and risk management structures that transcend traditional technical boundaries. As the certification framework expands to encompass cloud services, 5G networks, managed security services, and overall cyber posture, technology providers will face heightened regulatory scrutiny and extended time-to-market cycles, even as their clients benefit from verified security standards. 

Crucially, the introduction of high-risk supplier mechanisms necessitates a proactive approach to supply chain resilience. This forces entities to assess geopolitical dependencies and monitor interconnected infrastructure. Organizations must, therefore, prepare for the potential replacement of hardware and revise contractual frameworks to mitigate the operational shocks of supplier reclassification. 

For small and medium-sized enterprises, this shift creates a dual challenge. Increased reliance on certified vendors may simplify security management while simultaneously driving up procurement costs. Consequently, these firms will require a higher degree of technical due diligence to remain competitive.

On the operational side, the centralisation of reporting through ENISA’s unified platform will significantly intensify obligations for “Security Operations Centres” (“SOCs”). These entities, alongside “Computer Security Incident Response Teams” (“CSIRTs”), must integrate deeply with EU-level reporting systems. While this improves situational awareness across the Union, it also introduces considerable administrative burdens. 

Next steps 

The proposal will follow the ordinary legislative procedure, requiring both the European Parliament and the Council to adopt their respective amendments. Afterwards, it will enter a phase of interinstitutional negotiations and technical refinement, aimed at balancing security measures with the practical needs of the market.

Conclusion 

The proposed reform of the “EU Cybersecurity Act” signals a transition from fragmented technical standards to a unified, geopolitically aware governance model.

  • The consolidation of powers around the European Union Agency for Cybersecurity reduces national divergence and centralises threat reporting and operational coordination at EU level.
  • Certification is now a tool for technological resilience rather than just a quality mark. The power to exclude high-risk suppliers in critical sectors forces a fundamental reassessment of thirdparty dependencies and hardware lifecycles.
  • Closer alignment between certification schemes and horizontal product legislation increases the regulatory weight of EU certificates in determining market access and competitive positioning.
  • Cybersecurity becomes a board-level responsibility, requiring integrated risk management, structured oversight to ensure alignment with enhanced EU-wide reporting obligations.

GA-Alliance

News

Lahore, Jan 30 2026

GA-Alliance lands in Pakistan
Press release

GA-Alliance lands in Pakistan: strategic partnership signed with Axis Law Chambers

MILAN – 29 January 2026

GA-Alliance, a global legal and tax firm with more than 2,600 professionals in 80 countries, announces its entry into the Pakistani market. The strategic partnership with Axis Law Chambers, a leading full‑service law firm in the region, marks a further expansion of GA‑Alliance’s network, which today covers geographies that generate nearly 90% of global GDP.

The agreement strengthens GA‑Alliance’s commitment to its “one‑stop‑shop” strategy. By integrating local expertise with the highest global standards, the Alliance offers clients a single, efficient access point for all legal and tax needs. This model removes the complexities of managing multiple advisers across different jurisdictions, delivering a coordinated and seamless experience that prioritizes clarity and business growth.

Axis Law Chambers brings to the Alliance a reputation for excellence, particularly in high‑value cross‑border mandates and advice on complex regulatory matters. Regularly listed by Chambers and Partners and The Legal 500, Axis Law stands out for its transactional work in corporate matters, mergers and acquisitions (M&A), employment law, intellectual property, foreign investment, public‑private partnerships, corporate governance, antitrust, tax, data protection and sectoral compliance. The firm advises clients in key industries such as energy, oil & gas, mining, healthcare, telecommunications, automotive, financial services, defense, retail, manufacturing, agriculture, media, IT, logistics, real estate and non‑profit organizations.

Axis Law also boasts one of Pakistan’s most authoritative dispute resolution practices, including litigation and international arbitration, with solid experience in proceedings before ICSID (International Centre for Settlement of Investment Disputes, based in Washington, D.C., and part of the World Bank), ICC (International Chamber of Commerce, based in Paris) and LCIA (London Court of International Arbitration, based in London). This depth of expertise ensures GA‑Alliance clients receive top‑level support in the world’s fifth most populous country, one of the most dynamic economies in Asia.

Francesco Sciaudone, Managing Partner of GA‑Alliance, emphasized the strategic importance of the operation: “Our entry into Pakistan through the partnership with Axis Law Chambers is another step that strengthens our global growth path. At GA‑Alliance, the goal is to simplify complexity for our clients. By extending our ‘one‑stop‑shop’ model to an outstanding Pakistani firm, we are increasingly able to offer our clients the ability to operate with confidence in a very large number of markets worldwide. We are not only expanding our geographic presence; we are enhancing a sophisticated ecosystem where international best practices and precision meet local market leadership to meet clients’ needs in a simple, direct and highly efficient way.”


About GA‑Alliance

With more than 2,600 professionals in 80 countries, GA‑Alliance is a global legal and tax firm with deep European roots, combining a strong legal tradition with a broad international presence. Founded on principles of excellence and innovation, GA‑Alliance offers integrated, multidisciplinary expertise and positions itself as a strategic partner to promote sustainable growth in an ever‑evolving regulatory environment.


About Axis Law Chambers

Axis Law Chambers is a leading Pakistani law firm recognized for excellence in corporate and transactional advice and in resolving commercial disputes. With a team of over 30 professionals and seven partners, the firm assists national and multinational clients in high‑impact transactions, regulatory compliance and complex dispute resolution matters, including international arbitrations.

GA-Alliance

News

Jul 15 2025

GA-Alliance Welcomes Salvatore Figliuolo as New Partner

GA-Alliance Launches Cybersecurity and Digital Compliance Practice and Welcomes Salvatore Figliuolo as New Partner

GA-Alliance, the leading law firm renowned for its innovative and client-centric global legal services, is pleased to announce the establishment of a new Cybersecurity and Digital Compliance Desk. This strategic initiative - designed to support public and private clients, both domestically and internationally, in preventing digital risks, managing data, and ensuring compliance with Italian and international regulations - underscores GA's relentless commitment to providing outstanding and thorough legal support to help businesses navigate the raising challenges of the digital era.

The new practice will be led by Mr. Salvatore Figliuolo, an experienced lawyer who will join GA as a new partner. Mr. Figliuolo has gained extensive exposure to technology law and cybersecurity, both in Italy and abroad, coupled with significant managerial roles in Generative AI companies.

GA realizes the importance of moving from a reactive assistance approach to a more proactive approach, aimed at strengthening clients' digital resilience. As a result, the new desk will offer joint legal and technical support, also thanks to the collaboration with Visibily, a managed security service provider (MSSP) company specialized in advanced enterprise solutions. This unique desk will provide integrated legal and technological services including:

  1. Digital risk and vulnerability analysis;
  2. Review and set up of internal policies and data management protocols;
  3. Training and staff awareness on security and privacy issues;
  4. Ongoing assistance during inspections, data breach situations, and digitalization projects;
  5. Management of relationships with authorities (e.g., Police, Data Protection, Cybersecurity, European Authorities).

With this new initiative, GA-Alliance reaffirms its commitment to supporting clients through their digital evolution with a practical, multidisciplinary, and prevention-oriented approach. The team will also leverage the existing expertise within the law firm, particularly in privacy and administrative law.

Francesco Sciaudone, Managing Partner of GA-Alliance, commented: "The arrival of Salvatore Figliuolo and the launch of the Cybersecurity and Digital Compliance desk represent a natural evolution in GA's growth toward a more and more sophisticated professional services market. In an environment where companies are increasingly exposed to digital risks, and to evolving complex regulations, we believe essential being able to offer clients a comprehensive and integrated support – both domestically and internationally – combining legal expertise with technological solutions. The cooperation with a sophisticated technical partner and the synergies among our internal desks further strengthen our ability to support promptly, concretely, and strategically our clients in facing these new digital challenges."

GA-Alliance

Knowledge Management

Jul 23 2024

Eu Alert - Data, IP and Privacy

This newsletter provides a selection of opinions and analysis from our EU legal experts on interesting policy developments, recent case law and new regulatory directions of major industry practices. It is released biweekly and covers areas such as: Competition Law, Sanctions, Trade, Energy, Finance, EU funds, Data IP and Privacy, Life Sciences, Transport and Court of Justice of the European Union news.

The aim is to provide an up–to–date tool for quick and easy consultation on the most current and important topics at EU level.

EUROPEAN COMMISSION (EC)

The European Commission designates adult content platform XNXX as Very Large Online Platform under the Digital Services Act (10.07.2024) – The Commission has formally designated XNXX as a Very Large Online Platform (VLOP) under the Digital Services Act (DSA).Therefore, XNXX will have to comply with the most stringent rules under the DSA within four months of its notification Such obligations include adopting specific measures to empower and protect users online, to prevent minors from accessing pornographic content online, including with age-verification tools, to provide access to publicly available data to researchers, and to publish a repository of ads.

The European Commission publishes the second report on the State of the Digital Decade (02.07.2024) – The European Commission has published the second report on the State of the Digital Decade, providing a comprehensive overview of the progress made in the quest to achieve the digital objectives and targets set for 2030 by the Digital Decade Policy Programme (DDPP). This year, for the first time, the report is accompanied by an analysis of the national Digital Decade strategic roadmaps presented by Member States, detailing the planned national measures, actions and funding to contribute to the EU's digital transformation.

Keep in touch!

Sign up for our newsletters!

Stay up-to-date on domestic and international legislative and tax news
and international, as well as all the Firm’s events and initiatives.

Back
to top