As we reach the end of the second quarter of 2026, we present a roundup of the most notable news stories, rulings, case law and trends in the technology sector from the past three months. THE CODE, Pérez-Llorca’s technology newsletter, is a joint effort between the firm’s teams in Spain, Portugal, Mexico and Colombia.
EUROPEAN UNION
The Council of the EU adopts the Digital Omnibus on Artificial Intelligence: On 29 June, the Council of the European Union gave its final approval to the Digital Omnibus on AI, which amends the Artificial Intelligence Act (EU) 2024/1689 (the “AI Act”), Regulation (EU) 2018/1139 and Regulation (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence; with the aim of streamlining their application and strengthening legal certainty within the single market.
The most significant changes include: (i) the postponement of the entry into application of the rules on high-risk artificial intelligence systems, which are set at 2 December 2027 for stand-alone systems and 2 August 2028 for those embedded in products; (ii) the introduction of a new explicit ban on AI systems that generate non-consensual sexual content and child sexual abuse material, applicable from December 2026; (iii) the clarification of the AI Office’s remit with regard to general-purpose models; and (iv) a mechanism to prevent overlaps between the requirements of the AI Act and those of sector-specific legislation. You can read the text here.
The European Commission has adopted Delegated Regulation (EU) 2026/881 on the conditions for delaying the dissemination of notifications under the Cyber Resilience Act: The Commission has adopted this delegated regulation, which implements Regulation (EU) 2024/2847 (the “Cyber Resilience Act”) and sets out the conditions under which the computer security incident response team (“CSIRT”) initially receiving the notification of an actively exploited vulnerability or a severe incident in a product with digital components may delay its dissemination to the CSIRTs of other affected Member States. A delay may be granted, for as long as is strictly necessary, in three main cases: (i) where the sensitivity of the notified information means that its disclosure would pose more risks than benefits to security (for example, because it would enable actors with limited resources to exploit the vulnerability, or because the manufacturer is about to release a patch); (ii) where there are reasonable grounds for doubting the recipient CSIRT’s capabilities to ensure the confidentiality of the information; and (iii) where the single reporting platform has been affected by a cyber security incident. The Regulation entered into force on 10 May 2026. You can read the Delegated Regulation here.
Publication of the Code of Practice on Transparency of AI-Generated Content: On 10 June 2026, the European AI Office published the final version of the Code of Practice on marking and labelling AI-generated content, in accordance with Article 50 of the AI Act. The Code sets out a voluntary and practical framework to enable providers and those responsible for the deployment of generative AI systems to comply with the transparency obligations under the AI Act. Its key commitments include: (i) the implementation of a multi-layer marking approach in a machine-readable format to identify content generated or manipulated by AI; (ii) the provision of interoperable detection mechanisms; and (iii) the use of icons to visibly label deepfakes and AI-generated text posts on matters of public interest. You can read the Code of Practice here.
Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law: The Council of Europe has adopted the first legally binding international treaty on artificial intelligence, which is open for signature by its member states, third countries and the European Union. The Convention obliges the parties to ensure that the life cycle of AI systems is compatible with human rights, democracy and the rule of law, by imposing principles of transparency, accountability, non-discrimination and risk management, and by establishing effective remedies for those affected. You can read the Framework Convention here.
Publication of a common European template for data protection impact assessments: The European Data Protection Board has published a common template for data protection impact assessments (“DPIA”), with the aim of standardising the way in which organisations document the risks associated with their processing activities and justify the measures taken. At present, the lack of a standardised model leads to significant disparities between jurisdictions, which complicates compliance in multinational environments. Once the consultation process has been completed, the national data protection authorities will adopt the template as a standard model or as a reference framework with which their own national templates must be compatible. You can read the template here.
Spain
The Spanish High Court overturns the Spanish Data Protection Agency’s guidelines on attendance monitoring using biometric systems: In its judgement of 30 June 2026, the Spanish High Court upheld the appeal lodged by the Spanish Security Association (using the Spanish acronym, “AES”) and declared null and void the approval and publication of the guidance on attendance monitoring using biometric systems published by the Spanish Data Protection Agency (using the Spanish acronym, “AEPD”) in November 2023. The court concluded that the guidance, despite its title, contained binding criteria on the use of biometric data for monitoring employees’ working hours and access, and that, given its content and impact on the market, it should be classified in substance as a circular requiring compliance, subject to the relevant regulatory procedures, which had not been followed. This is the first time the courts have overturned guidelines issued by the AEPD. The judgement is not final and an appeal may be lodged with the Spanish Supreme Court. The AEPD itself stated that it will examine the ruling and its implications, and noted that it had already announced a review of the guidelines, the new version of which is due to be published in autumn 2026. You can read an article on the subject here (only available in Spanish). The guide is also available here (only available in Spanish).
The entry into force of the obligation to block unregistered aliases, as set out in Order TDF/558/2026 of 4 June, has been postponed: The Spanish Ministry for Digital Transformation and the Civil Service has amended Order TDF/149/2025 of 12 February, which set out measures to combat identity theft scams via phone calls and text messages, and which provided for the creation of an Alias Register managed by the National Commission on Markets and Competition (using the Spanish acronym, “CNMC”). This register requires operators to block SMS/MMS/RCS messages that use unregistered aliases or are sent by unauthorised providers.
The amendment postpones the entry into force of this blocking obligation until 15 September 2026, due to the extraordinary technical, operational and coordination challenges posed by the process of bulk uploading aliases in use during the testing period. The aim of the extension is to ensure the successful completion of the registration process and to prevent the undue blocking of legitimate aliases, which could adversely affect organisations sending and citizens receiving essential communications, including those of a healthcare or administrative nature. You can read the Order here (only available in Spanish).
The AEPD and the Belgian Data Protection Authority publish the first joint European recommendations on video games: The AEPD and its Belgian counterpart have published the first document drawn up jointly by European data protection authorities specifically aimed at the video game sector, containing recommendations applicable to developers, studios, publishers, hardware suppliers, digital stores and legal teams advising the sector.
The document identifies three particularly sensitive processing areas: (i) the creation and management of accounts, including registration data, login credentials, payment information and records of parental consent; (ii) telemetry monitoring, which passively and invisibly to the user captures dozens of parameters per second while the game is being played; and (iii) behavioural inference, whereby telemetry data is processed by machine learning models to deduce emotional states, personality traits, spending propensity or indicators of mental health that the user has never explicitly provided. The document also contains annexes which include compliance checklists tailored to each type of operator involved in the video game value chain. You can read the document here (only available in Spanish).
Draft Organic Law on the proper use and governance of artificial intelligence: On 26 May, the Council of Ministers approved and submitted to the Spanish Parliament the Draft Organic Law on the Proper Use and Governance of Artificial Intelligence, which implements the AI Act and adapts it to the Spanish legal system. The regulation aims to establish a national governance framework that complements the European regulatory architecture, setting out the supervisory powers of the Spanish Agency for the Supervision of Artificial Intelligence (using the Spanish acronym, “AESIA”) and the control mechanisms applicable to AI systems deployed in Spain. Its passage through Parliament comes at a time when Spain ranks among the most active European countries in terms of AI regulation, having been the first Member State to set up a dedicated state supervisory agency in this field. You can read the Draft Law here (only available in Spanish).
Draft Organic Law on the Civil Protection of the Rights to Honour, Personal and Family Privacy, and One’s Own Image: On 7 July, the Council of Ministers approved the Draft Organic Law on the Civil Protection of the Rights to Honour, Personal and Family Privacy, and One’s Own Image, thereby initiating its passage through Parliament in the Congress of Deputies. The legislation, which will replace Organic Law 1/1982 of 5 May, adapts the protection of these rights to the digital environment and introduces the following new provisions: (i) it considers the use of a person’s voice or image without their consent for advertising or commercial purposes, through artificial intelligence or similar technologies—including deepfakes—to constitute an unlawful attack, with an exception for public figures in creative, satirical or fictional contexts where the use of the technology is expressly indicated; (ii) it clarifies that sharing images on social media does not authorise third parties to reuse them on other channels, with consent being subject to the purpose, context and reasonable expectations of the data subject; (iii) it extends protection for victims of crime in relation to ‘true crime’ content, raises the age of consent regarding one’s own image to 16, and extends protection to deceased persons; and (iv) it sets out objective criteria for quantifying non-pecuniary damage, excluding symbolic awards, and allows for a request to be made for the conviction to be published in the Official State Gazette (BOE). You can read the briefing about the Draft Law here (only available in Spanish).
Portugal
Implementation of the Digital Services Act in Portugal: On 15 April 2026, Law no. 12-A/2026 was published, transposing the Digital Services Act (“DSA”) into the domestic legal order and entering into force on 20 April 2026. The Law: (i) designates ANACOM as the competent administrative authority and Digital Services Coordinator, assuming the central supervisory role and acting as the single point of contact with the European Commission and the European Board for Digital Services; (ii) confers specific powers on the ERC (Entidade Reguladora para a Comunicação Social) in relation to terms and conditions applicable to minors, advertising transparency, and the protection of minors on online platforms, while the CNPD assumes supervisory responsibility for advertising based on special categories of personal data and advertising targeted at minors; and (iii) establishes a two-tier sanctioning regime, under which decisions of the Coordinator may be challenged before the Tribunal da Concorrência, Regulação e Supervisão, with appeals lying to the Tribunal da Relação de Lisboa. You can read the Law here (only available in Portuguese).
ANACOM public consultations on AI literacy and prohibited practices under the AI Act: Over the second quarter of the year, ANACOM carried out two significant initiatives within the framework of its supervisory functions under the AI Act. First, on 28 April 2026, it approved the launch of a public consultation on organisational guidelines for the implementation of the AI literacy obligation set out in Article 4 of the AI Act, with a deadline for contributions of 1 June 2026. The document establishes a best practices framework, without creating new legal obligations, to support organisations in ensuring that staff involved in the operation and use of AI systems possess an adequate level of knowledge proportionate to their roles. Second, on 16 June 2026, ANACOM launched a public consultation on a draft set of recommendations for the implementation of Article 5 of the AI Act, concerning prohibited practices, with a deadline of 16 July 2026. The document delimits the personal scope of the prohibitions and highlights the advisability of adopting best practices in this area, irrespective of the adjustments introduced by the Digital Omnibus. You can read the public consultation here (only available in Portuguese).
NIS2 transposition in Portugal: On 3 April 2026, Decree-Law no. 125/2025 of 4 December entered into force, approving the new Legal Framework for Cybersecurity and transposing the NIS2 Directive into the Portuguese legal order. In implementation of this framework, the CNCS (Centro Nacional de Cibersegurança) published Regulation no. 756/2026 of 22 June 2026, establishing the applicable operational rules. The principal developments include: (i) the approval of the National Cybersecurity Reference Framework (QNRCS), aligned with international standards including the NIST CSF 2.0 and ISO/IEC 27001:2022; (ii) the establishment of a risk matrix comprising three levels of assurance (basic, substantial, and high) based on sector, size, and the criticality of the services provided; (iii) the operationalisation of the MyCiber electronic platform as a centralised channel for entity registration, notification of cybersecurity officers, and incident reporting; and (iv) the introduction of an obligation to carry out an annual residual risk analysis for essential and important entities. You can read the Decree-Law here (only available in Portuguese).
MiCA implementation in Portugal and new crypto-assets regime in force: On 1 July 2026, Law no. 69/2025 of 22 December fully entered into force in Portugal, transposing the European Regulation on Markets in Crypto-assets (“MiCA”) into the domestic legal order, following the expiry of the transitional period from which operators already registered with the Banco de Portugal had benefited. The new framework rests on a division of supervisory competences between the Banco de Portugal, which oversees the authorisation and prudential supervision of crypto-asset service providers and token issuers, and the CMVM (Comissão do Mercado de Valores Mobiliários), which is responsible for the behavioural supervision of the market, including the prevention of market abuse and the management of conflicts of interest. The sanctioning regime provides for fines of up to €2.5 million for natural persons and up to €5 million for legal persons, with limits rising to 15% of annual turnover in cases of market abuse infringements. You can read the Law here (only available in Portuguese).
LATAM
Mexico
AI-related amendments protecting performers’ image and voice rights: On 14 May 2026, Mexico published amendments to the Federal Labour Act and the Federal Copyright Act, introducing specific protections for artists, performers and voice professionals in connection with artificial intelligence. Employment contracts must expressly state the conditions and remuneration applicable to the use of a performer’s image or voice through AI or other technologies. The amendments extend image and voice protections to AI-generated results and require a prior written agreement for the cloning or impersonation of a performer’s voice or image. They also grant performers the right to authorise or prohibit AI-generated clones or identifiable simulations of their performances, subject to exceptions including parody, satire and creative imitation. Computer programs, including AI programs, remain protected as literary works in both source and object code, except where their purpose is to damage other programs or equipment or to infringe rights protected under copyright law. Major infringements may be punished with fines. You can read the amendments here (only available in Spanish).
Inclusion of ambush marketing as an administrative offence: On 3 April 2026, the Federal Law on the Protection of Industrial Property was amended to expressly penalise conduct that creates a false impression among the public of official sponsorship in relation to major events. The amendment, which came into force on the eve of the 2026 FIFA World Cup, strengthens the protection of organisers and sponsors against campaigns seeking to capitalise on an event’s profile without authorisation. For companies, this means reviewing not only the use of protected trademarks, but also promotions, digital content, activations and initiatives involving influencers that may suggest a commercial association that does not exist. You can read the amendment here (only available in Spanish).
FIFA’s “clean stadiums” policy: During the 2026 FIFA World Cup, the three Mexican host venues temporarily suspended their commercial names to comply with FIFA’s exclusive commercial exploitation rights. Consequently, the Banorte Stadium was renamed “Estadio Ciudad de México”, while the BBVA Stadium and the Akron Stadium were renamed “Estadio Monterrey” and “Estadio Guadalajara”, respectively. The measure also involved removing, covering or limiting the visibility of brands linked to sponsors not associated with the tournament, in order to preserve the commercial exclusivity of the official partners. Beyond its sporting impact, this precedent demonstrates how the hosting of international events can temporarily alter the way in which naming rights, sponsorship, advertising and venue exploitation contracts are executed. For investors, sponsors, owners and operators, this requires anticipating, from the contract negotiation stage, issues such as the temporary suspension of visibility rights, the use of alternative names, the removal of brand assets, the allocation of operating costs and potential compensation for loss of commercial exposure. An appropriate allocation of these risks helps to minimise contingencies, avoid disputes between the parties and protect the economic value of sponsorship agreements in contexts of high international exposure.
Colombia
Law 2573 of 2026, on the protection of victims of identity theft: The Law was enacted on 19 May 2026 and sets out measures, procedures and policies to protect victims of identity theft from negative reports on credit reference agencies and debt collection arising from fraudulent conduct, imposing obligations on telecommunications operators, financial and credit institutions, and other commercial establishments with jurisdiction in this area. The Law introduces key definitions (including cybersecurity, social engineering, and physical and digital identity theft) and requires organisations to adopt identity verification measures, to report victims with the designation “Victim of Identity Theft” without affecting their credit score, to respond to requests within 10 working days, and to immediately suspend the provision of goods, services and debt collection proceedings, including interest, where identity theft is alleged, with the suspension remaining in place until a final court ruling is issued. If fraud is proven, the individual is exempt from all obligations; otherwise, debt recovery resumes with the interest and costs incurred, and may result in liability for making a false report. The Law will come into force six months after its enactment, with the exception of the first and second paragraphs of Article 5, which take effect upon enactment. You can read the Law here (only available in Spanish).
Update to the Information Security and Privacy Model (MSPI) with guidelines on artificial intelligence: The Ministry of Information and Communications Technology has updated the MSPI by publishing technical, organisational and regulatory guidelines for the design, development, implementation, operation and maintenance of artificial intelligence systems in public bodies, in accordance with CONPES 4144 of 2025. The guidelines set out criteria for protecting information, guaranteeing citizens’ privacy and managing the risks associated with the use of AI across the public sector, and include safeguards such as continuous monitoring, anomaly analysis, event correlation and model robustness testing. The document also serves as a reference framework for the private sector and aims to strengthen the country’s technological sovereignty in line with national policy on the responsible adoption of artificial intelligence. You can read the guidelines here (only available in Spanish).
Corporate structure planning as a key factor in M&A transactions involving technology and intellectual property assets: In the context of transactions involving the sale or purchase of companies or assets with a significant intellectual property, industrial property and technology component, it is important not to limit the analysis to the entities directly involved in the transaction, but to extend it to the corporate structure as a whole and to the corporate decisions that the parties intend to take either before or after completion.
Practical experience shows that the lack of a comprehensive approach can lead to operational and legal difficulties, particularly in relation to the ownership and location of trade marks, software licences, databases and other intangible assets. In this regard, the following points should be borne in mind:
In both cases, these decisions must be assessed in conjunction with their tax and regulatory implications, particularly with regard to transfer pricing and the tax costs arising from the relocation of intangible assets within the group.
EUROPEAN UNION
CJEU
‘Pastiche’ exception in the field of copyright and related rights (C-590/23): The CJEU has clarified the scope of the ‘pastiche’ exception provided for in Directive 2001/29, establishing that it may cover the use of copyright-protected fragments, including those obtained through sampling, where the new creation alludes to a pre-existing work, is perceptibly different from it and engages in a recognisable artistic or creative dialogue. The Court states that such dialogue may take the form of a tribute, an overt imitation of style, or a critical or humorous confrontation, but excludes covert imitations and plagiarism. It also points out that it is not necessary to prove the author’s subjective intention to create a pastiche; it is sufficient that this nature is objectively recognisable to those familiar with the original work. With this interpretation, the CJEU seeks to strike a balance between the protection of copyright, freedom of artistic creation and legal certainty; it is for the German court to apply these criteria to the dispute between Kraftwerk and the producers of the track Nur mir. You can read the judgment here.
Exclusion of copies for offline listening from the private copying exception (C-496/24): The CJEU has ruled that copies made for offline streaming on music streaming platforms are not covered by the private copying exception provided for in Article 5(2)(b) of Directive 2001/29. The Court considers that these copies are not the result of an independent act by the user, but are created by the service provider as a necessary condition for granting access to the work, within the framework of a communication to the public authorised by the rights holder. Furthermore, it emphasises that technological protection measures and licensing agreements enable rights holders to retain control over reproduction and to receive the corresponding remuneration; consequently, there is no financial loss that would justify compensation for private copying. Consequently, the contractual remuneration agreed between the parties does not affect the inapplicability of this exception. You can read the judgment here.
Fair compensation for newspaper publishers for the online use of their publications (C-797/23): The CJEU has ruled that Article 15 of Directive (EU) 2019/790 does not preclude national legislation which grants press publishers the right to fair compensation for the online use of their publications and which imposes obligations on digital platforms regarding negotiation, transparency and the exchange of information. The Court also considers it compatible with EU law for a regulatory authority to lay down the criteria for determining this remuneration, to monitor compliance with these obligations and to impose proportionate penalties, provided that publishers retain the freedom to authorise, refuse or permit the use of their content free of charge, and that the remuneration is linked to the actual use of the publications. It also concludes that, although these measures restrict the freedom of enterprise of information society service providers, this restriction is justified by the objectives of protecting intellectual property rights, ensuring the economic sustainability of newspaper publishers and safeguarding media pluralism. You can read the judgment here.
International jurisdiction in claims for infringement of personality rights arising from the broadcast of television and online content (C-232/25): The CJEU has ruled on the applicable international jurisdiction where an infringement of personality rights arises from the broadcast of audiovisual content in several Member States and on the internet. The Court sets out the following rules: (i) in the case of television broadcasts, the courts of each State in which the content was broadcast have jurisdiction only in respect of damage caused within their territory; the court of the victim’s centre of interests does not have jurisdiction to hear the case in respect of the entire loss; (ii) in the case of online publication, the court of the victim’s centre of interests has jurisdiction over the entirety of the damage only if the content allows that person to be identified, directly or indirectly, as an individual; it is not sufficient for the content to refer to a restricted group with which the claimant may be associated; (iii) by contrast, a legal person whose primary purpose is to defend the interests of the group is directly identifiable; consequently, the court of its centre of interests has jurisdiction to hear the entire claim for damages arising from dissemination on the internet; and (iv) courts with limited territorial jurisdiction may hear claims for damages and for non-pecuniary relief in relation to television broadcasts, but cannot order the rectification of content published on the internet, given its ubiquitous nature. You can read the judgment here.
Spain
The primacy of freedom of expression over the right to honour in the context of political debate (Supreme Court Judgment 2431/2026): The Spanish Supreme Court has dismissed the civil liability claim brought by a journalist against the Minister of Transport over statements made on television and posts on social media concerning the conduct of the claimant – a Washington-based correspondent accredited to the White House – in the context of a political debate attracting considerable public attention concerning Spain’s position on the increase in military spending demanded within NATO. The Court holds that the defendant’s right to freedom of expression prevails, having regard to the subject matter under discussion, which is undoubtedly of general and political interest, the public status of the parties, the claimant’s active and voluntary involvement in the dispute, the political and international context in which the statements were made, the existence of a sufficient contextual and factual basis for expressing a critical assessment of the claimant’s conduct, the absence of expressions that are unequivocally defamatory, offensive or unrelated to the existing political debate, and the lack of a real and objectively appreciable risk of an intimidating or dissuasive effect on the exercise of journalistic activity. You can read the judgment here (only available in Spanish).
Sale of forged paintings attributed to well-known artists constitutes fraud rather than an intellectual property offence (Supreme Court Judgment 1730/2026): The Spanish Supreme Court confirmed that the sale of forged paintings falsely attributed to recognised artists constitutes an offence of fraud and not an offence against intellectual property, given the absence of plagiarism. The Court dismissed the appellant’s argument that the defrauded buyers were under a duty to carry out additional checks, such as consulting the artists themselves or official experts or institutions, finding that such a requirement would be unreasonable for buyers acting in good faith when acquiring works at an auction house. You can read the judgment here (only available in Spanish).
Portugal
Ethics Charter of the Procuradoria-Geral da República on the use of artificial intelligence: Following the Guimarães Court of Appeal case covered in the previous edition of THE CODE, in June 2026 the Procuradoria-Geral da República (“PGR”) approved an Ethics Charter for the Use of Artificial Intelligence applicable to the Ministério Público (the Public Prosecution Service). The Charter expressly prohibits the use of AI systems to predict the probability of conviction, estimate the risk of reoffending, or suggest pre-trial measures based on automated profiling, reaffirming that AI may only function as an auxiliary tool. It also prohibits the introduction of identifiable personal data or complete procedural documents into external generative AI platforms, bans the processing of procedural data outside the European Union, and imposes mandatory impact assessments and audits throughout the lifecycle of tools classified as high-risk. You can read the Charter here (only available in Portuguese).
LATAM
Mexico
Supreme Court strengthens telecom operators’ duty of care in SIM-swapping cases: On 8 April 2026, the Mexican Supreme Court decided Direct Amparos 25/2024 and 26/2024, concerning a fraudulent SIM-card replacement that enabled unauthorised access to a user’s digital services, electronic banking and intimate images. The Court held that telecommunications operators have a heightened duty of care when processing personal data and must reliably verify the identity of persons requesting SIM replacements. A mere assertion that identification had been requested, without adequate documentation or supporting evidence, was insufficient to establish due diligence. The Court found that the operator’s negligence could give rise to fault-based civil liability and ordered a fresh assessment of moral damages. It also required the case to be determined from a gender perspective and rejected arguments attributing fault to the victim for storing intimate images on her device. You can read the resolutions here (only available in Spanish).
Colombia
Guidelines on the use of generative artificial intelligence in judicial proceedings (Order of 26 May 2026, Council of State, Third Chamber): The Council of State laid down guidelines on the use of generative artificial intelligence in judicial proceedings, after finding that an extraordinary appeal for the unification of case law had cited judgments that proved to be non-existent. The Order warns of the phenomenon of “hallucinations” in generative AI tools, which can produce legal references that appear authentic but have no real basis, and reiterates that the duty of verification, diligence and procedural good faith rests with the lawyer signing the submission, regardless of the use of such technology. The Chamber further clarified that judges may not delegate to AI either the assessment of evidence or the adoption of decisions, as the exercise of judicial power is non-delegable. You can read the court order here (only available in Spanish).
The right to habeas data in relation to publicly accessible judicial information (Order ATP829-2026, Criminal Cassation Chamber, Supreme Court of Justice, 16 April 2026): The Criminal Cassation Chamber considered a request from a citizen seeking to have negative judicial information against him concealed, anonymised or deleted from the Corporation’s databases. The Court addressed the tension between free access to public information and the protection of the right to habeas data, reiterating the sub-rules established for handling information in freely accessible databases that can be viewed by the public via internet search engines. Among these sub-rules, the Chamber specified that, in non-criminal judgements or orders that expressly refer to convictions, where it is judicially established that the sentence has been served, has become time-barred, or has been extinguished by the death of the convicted person, the names of the convicted persons must be removed from open-access databases, unless the law requires that such information be kept public at all times. The decision consolidates the Court’s case law on the balance between the public nature of judicial proceedings and the right to the protection of personal data in publicly accessible judicial repositories.
New Law
Spain, a magnet for major AI platforms: In recent months, several of the sector’s leading artificial intelligence companies have announced their entry into the Spanish market. Harvey, the US-based legal AI platform, opened an office in Madrid last April. Meanwhile, Legora, the Swedish legal AI company, has announced that it will open an office in the country during the third quarter of 2026. OpenAI has also confirmed that it will open its first office in Madrid during the second half of 2026, driven by year-on-year growth of over 40% in weekly active ChatGPT users in Spain, which ranks among the company’s top five European markets. The convergence of these trends reflects the growing appeal of the Spanish ecosystem for artificial intelligence companies in the legal and business sectors.
AMALIA, the first open-source large-scale language model in Portuguese: On 1 July 2026, the Government officially presented AMALIA (Assistente Multimodal Automático de Linguagem com Inteligência Artificial), described as the first large language model (LLM) developed specifically for European Portuguese and released under an open-source licence. The project is the result of a consortium bringing together researchers from NOVA FCT (scientific coordinator), the Instituto Superior Técnico (IST), the University of Coimbra, the University of Minho, the University of Porto, and the Fundação para a Ciência e a Tecnologia (FCT), involving more than 60 researchers. AMALIA forms part of the national digital sovereignty strategy and is intended to enable the Public Administration, companies, universities, and research centres to develop AI applications tailored to the Portuguese language, legal framework, and cultural context, thereby reducing dependence on foreign proprietary models. The model includes language, multimodal (text and image), and European Portuguese speech-processing versions, with its progressive deployment planned across public administration, education, culture, media, and scientific use cases. You can read about AMALIA’s key features here (only available in Portuguese).
Portugal AI Act Portal: The Digital.gov portal has established a dedicated section on the AI Act, clarifying the phased application timeline and underscoring its directly applicable nature, which requires no transposition into national law. At the institutional level, the ANACOM (Autoridade Nacional de Comunicações) has been designated as the sole market surveillance authority and national point of contact, coordinating 14 sectoral authorities, while the CNPD (Comissão Nacional de Proteção de Dados) assumes responsibilities in the area of data protection. The portal provides risk classifiers, frequently asked questions, compliance documentation templates, and practical reference guides for businesses and public entities.
Latest News
Pérez-Llorcast TechLaw #22
Sports streaming rights: the DAZN revolution
In this episode of “Pérez-Llorcast” TechLaw, Andy Ramos, a partner in Pérez-Llorca’s Intellectual Property and Technology practice, talks to Carlos Osuna, Head of Legal at DAZN, about the role of the law at the heart of a global sports streaming platform. The conversation addresses some of the most significant issues facing the sector: how the sports rights market is structured and operates; the strategic role of legal advice within a company like DAZN; the challenges posed by piracy and how it is tackled; and how relationships with users, telecoms operators and other stakeholders in the ecosystem are managed. This in-depth discussion covers an industry in which broadcasting rights are not just an asset, but a competitive advantage between platforms. Only available in Spanish.
Pérez-Llorcast TechLaw #23
Business, transformation and legal advice at Lactalis
In this episode of “Pérez Llorcast” TechLaw, Sara Molina, a partner in the TechLaw, Innovation and Legal Transformation practice at Pérez-Llorca, talks to María Cobián, General Counsel at Lactalis Spain and Portugal, to gain a deeper insight into the French group’s development and the strategic role played by the legal department in its growth. María looks back on her career within the company, shares her views on how the legal function has evolved, and reflects on the factors that bring the most value to an organisation that is constantly growing – from business acumen to teamwork and collaboration with other departments. The episode also examines Lactalis’s growth, the development of its brands and the key transformation projects the group is driving forward, analysing how the legal department helps to support these processes and tackle any challenges that may arise, with a discussion on business and the role of legal teams within organisations. Only available in Spanish.
Sign up for our newsletter here.