Freitag, 10. Juli 2026
Dr. iur. Servatius von Tatzenberg
Seven articles published, nine sanction annexes amended, two CJEU preliminary rulings and two General Court judgments handed down.
General Court makes Apple's DMA gatekeeper designation stick in T-1079/23
Unter Vorbehalt
The judgment is among the first DMA gatekeeper challenges decided on the merits — the General Court had already partially annulled Meta's designation in T-1078/23 on 3 June. The designation of the App Store and iOS was confirmed on the merits; the iMessage challenge was ruled inadmissible on the ground that the Commission's preliminary classification produced no binding legal effects. Casimir von Firn has the legal analysis in today's article. The practical point for in-house counsel advising on platform strategy: the gatekeeper obligations — sideloading, interoperability, data portability — are now confirmed at the judicial level. If your product distribution or user acquisition depends on iOS, the next question from your board will be what alternative channels you have developed. The Commission's existing investigations into App Store and default browser practices are running on a timeline that an appeal to the CJEU will not pause.
Prognose: Apple will appeal to the CJEU, but the Commission has full enforcement authority in the interim — expect interoperability enforcement action well before any appeal is decided.
EDPB Guidelines 02/2026 — three new anonymisation tests, most corporate data sets fail at least one
Unter Vorbehalt
Dr. iur. Servatius von Tatzenberg's piece today (article) is the most operationally urgent item on the day's list. The EDPB Guidelines 02/2026 apply three concrete tests — singling out, linkability, inference — in a materially more demanding way than the prior guidance. The guidelines were adopted for public consultation on 7 July 2026 and are not yet finalised; the consultation window runs to 30 October 2026. The carve-out most data governance policies rely on ("this dataset is anonymised and therefore outside the GDPR") is now contingent on passing all three. Companies that built AI training pipelines on purportedly anonymised customer data are the most immediately exposed.
The Swiss angle: the DSG does not track EDPB guidelines automatically, but the FDPIC's interpretive practice does — and the next DSG audit cycle will ask these questions. Read this alongside the Vodafone Romania item below: the two stories are the same risk from different directions.
CJEU confirms the RT broadcast ban is a sanctions obligation, not an editorial choice
Unter Vorbehalt
Dr. iur. Servatius von Tatzenberg's piece (article) removes the last defensible ambiguity: cable operators, satellite providers, and streaming platforms cannot frame a decision to carry RT as an editorial policy call. It is a sanctions compliance decision under Article 2f(1) of Regulation (EU) No 833/2014 (as amended by Regulation 2022/350). The CJEU's ruling in C-67/25 arose from German criminal proceedings against individuals operating a non-commercial website — the court held that the term 'operator' in Art. 2f(1) is not limited to commercial actors, so cable, satellite, and streaming platforms are unambiguously within scope. Swiss distributors with EU operations face the same obligation by extension. Read this alongside today's Russia sanctions annex update below — the EU is tightening the perimeter from both ends simultaneously, and the two enforcement tracks (asset freezes and distribution bans) are now judicially confirmed as distinct but parallel obligations.
FINMA's circular-to-ordinance migration reaches liquidity and risk diversification
Unter Vorbehalt
Dr. iur. Servatius von Tatzenberg covers the substance in today's article; the institutional signal is in the method. FINMA is converting guidance that courts have historically treated as persuasive into Verordnung-level rules that sit at the same legal level as the BankV. Deviations that were manageable audit findings become regulatory breaches. We noted in May that FINMA wanted more enforcement instruments without waiting for Parliament — this is one way to get them without a single vote in Bern.
Prognose: Credit risk and market risk circulars are likely next in the migration queue — supervised entities should audit which Rundschreiben their compliance architecture is still treating as soft law.
Ryanair's COVID-aid challenge fails — an amended state-aid scheme is not automatically tainted
Unter Vorbehalt
Casimir von Firn's state-aid piece (article) is useful beyond aviation: an amended state-aid scheme does not inherit the defects of its predecessor if the amendment is proportionate. For Swiss companies receiving Kantonssubventionen that fall within the Bilateral III state-aid perimeter, the Ryanair precedent gives some comfort that proportionate post-approval amendments survive Commission scrutiny. The harder question — which cantonal subsidy arrangements are now within that perimeter — depends on which sector agreement applies and remains largely unsettled.
ANSPDCP v Vodafone Romania — the Romanian DPA shows it can find gaps and fine for them
Unter Vorbehalt
Today's article by Dr. iur. Servatius von Tatzenberg (link) matters partly for the specific violation and partly as enforcement data: ANSPDCP is not the CNIL, but it is no longer a paper tiger. The geographic takeaway for counsel advising on data processing location: the "peripheral DPA" discount is gone. Companies that selected processing jurisdictions partly based on enforcement appetite should revisit that analysis — the EDPB's consistency mechanism has been levelling the field for three years, and this case shows it.
C-277/25 Helpfind — assigning your claim against an EU insurer is enforceable cross-border
Unter Vorbehalt
Casimir von Firn covers the Helpfind ruling (article): assigning a residual motor-accident claim against a motor-vehicle insurer to a third party — a litigation funder, a claims aggregation platform, a specialist — is valid under EU law. The ruling is immediately relevant to cross-border motor claims management and litigation finance structures. For Swiss insurance intermediaries advising on motor-line products: the direct effect is in EU member states, but if your clients hold EU-sited motor policies or cross-border motor-liability exposures, check whether your assignment clauses would survive a challenge before the next policy renewal cycle rather than after a disputed claim.
Russia sanctions annex updated again — Anhang 8 to SR 946.231.176.72
FINMA News
Routine in form, not in frequency: Anhang 8 to the Russia sanctions ordinance is the latest in a sequence that has materially changed the screening perimeter since January. The RT ruling confirmed today means two parallel enforcement tracks are closing simultaneously — asset freezes and distribution bans both judicially confirmed. For compliance teams: if your screening SLA is weekly, document today why you consider that adequate. The enforcement expectation, once articulated, is likely to be continuous. We covered the MAC clause implications of the 20th package in May — see here.
Prognose: At this amendment pace, SECO will be pushed toward a real-time feed integration standard — watch for technical guidance on automated list updates in Q3 2026.
Five sanctions regimes updated in one cycle — Sudan, Taliban, Iran, ISIL, and a sixth
FINMA News
Alongside Russia, FINMA has flagged a sequence of six amendments across the April–June cycle to Sudan (SR 946.231.18), Taliban (SR 946.231.07), ISIL/Al-Kaida (SR 946.231.08), Iran (SR 946.231.143.6), and the Ordinance on Measures Against Hamas and the Palestinian Islamic Jihad (SR 946.231.09, updated 16 June 2026). Six concurrent regime updates is the kind of situation that stress-tests manual compliance processes. There is no statutory answer to the question of what your internal list-refresh SLA should be — which means, in an enforcement conversation, you need a written answer of your own. Write one down before the next cycle arrives.
Parliament pushes cobalt into Swiss responsible business due diligence
SWI swissinfo.ch (en)
A parliamentary push to include cobalt in Switzerland's responsible business due diligence requirements is early in the legislative process, but the direction is set. The EU's CSDDD already reaches cobalt supply chains for Swiss exporters with EU operations — we covered this in May (article). Companies already managing CSDDD exposure can absorb a parallel Swiss requirement at marginal cost. The companies that will be surprised are those that assumed the Swiss legislative calendar gives them another three years of lead time — it does not, because their EU customer contracts already contain the obligation.
Prognose: If cobalt enters the Swiss framework, battery-critical minerals follow — the NUFG's mineral annex will look considerably broader by 2028.
AI at EU borders is a confirmed high-risk Annex III application — the conformity assessment clock is running
SWI swissinfo.ch (en)
The swissinfo feature on AI deployment at Schengen borders is a useful context piece for the Annex III compliance conversation. We covered in May how the Annex III deadline was extended to 2027 for biometric border systems — but the extension compresses the runway, it does not remove the conformity assessment obligation. If your company supplies identity verification, biometric matching, or risk-scoring tools to border agencies or Schengen-adjacent security functions, the notified body relationship needs to start now. A 2027 compliance date assumes a smooth assessment process, not one that begins in late 2026.
Foreign law firms keep closing China offices — a supply-chain risk for your deal team
Law.com International (en)
Hunton Andrews Kurth's China exit is the latest in a series that is no longer a trend but a structural shift. The practical concern for Swiss in-house counsel is not the firm names — it is the availability of English-language PRC law advice on China-adjacent transactions when international firm offices are thinning and Hong Kong is under its own pressure. Building a direct relationship with a Chinese domestic firm takes longer than one transaction cycle. If your company has active China M&A or joint-venture work, start that relationship before you need it.
Sieben Artikel, neun Anhänge, vier Gerichtsentscheide — zwei Vorabentscheidungen des EuGH, zwei Urteile des Gerichts erster Instanz.
Archiv