What’s New at Eris Law Advokatbyrå AB
We are pleased to bring you our latest Eris Law newsletter! By subscribing, you will receive our updates directly in your inbox, including key legal insights, regulatory developments, and firm announcements relevant to your business and industry.
Stay informed and up to date with the issues that matter—delivered straight to you.
Subscribe to our newsletter!
GDPR
Amazon’s €746m fine annulled but its violations stand?: Luxembourg’s Administrative Court annulled the €746 million fine imposed on Amazon in 2021 for ad targeting without valid consent, not because Amazon was found innocent, but because of procedural failings by the regulator. The court confirmed that the underlying GDPR violations were real, finding the authority had failed to properly assess whether Amazon’s conduct was intentional or negligent before setting the penalty. The case has been sent back to the CNPD for a full reassessment from scratch. The ruling is a sharp reminder that Europe’s enforcement machinery, while powerful, remains vulnerable to legal challenge on technical grounds and that companies can delay consequences for years through litigation.
Cookie consent is about to get a major rewrite: The Digital Omnibus package still making its way through EU institutions would fundamentally change how cookie consent works across Europe. Under the proposed rules, consent would no longer be required for roughly 60% of cookies, websites would be required to offer a “single-click” reject-all button as easy to find as the accept one, and publishers would be banned from asking again for at least six months after a user declines. Privacy advocates warn the consent exemptions hand the biggest advantage to large ad-tech players, while regulators stress the reforms also strengthen user control in the areas that remain in scope.
Children’s data emerges as the next GDPR enforcement frontier: Regulators across the EU are increasingly treating the processing of minors’ personal data as a standalone enforcement priority. In recent months, major fines have been issued against Reddit and PlayOn for unlawful handling of children’s information, and data protection authorities are signalling that youth privacy will attract the same level of scrutiny historically reserved for big-tech data transfers. With the EU AI Act’s August 2026 compliance deadline approaching, organisations that use AI systems capable of profiling young users face compounding obligations under both frameworks and a regulator that is watching closely.
FINTECH
US Senate passes stablecoin GENIUS Act:The US Senate passed the GENIUS Act with bipartisan support (68–30), creating the first comprehensive federal framework for stablecoin regulation. The law requires issuers to maintain 100% reserve backing with segregated funds, prohibits yield-bearing stablecoins, and brings issuers under anti-money laundering requirements. With the bill now before the House — which has advanced its own parallel stablecoin legislation — the coming reconciliation process will determine whether the US ends up with a workable national standard or a patchwork that leaves the $300 billion stablecoin market in continued legal grey zones. Foreign issuers, including Tether, remain a contested loophole.
Adyen acquires Talon.One in €750m loyalty software bet:Dutch payments giant Adyen has signed a definitive agreement to acquire Berlin-based Talon.One, a provider of customer loyalty and promotions software, for €750 million. The deal — subject to regulatory approval — extends Adyen’s reach beyond transaction processing into the broader customer engagement stack, positioning it to compete for budgets across marketing and commerce rather than just payments infrastructure. The acquisition reflects a broader trend of European fintech platforms expanding vertically as organic growth in core payments compresses margins and investors demand diversified revenue streams.
May 2026 brings 59 regulatory deadlines for the payments industry: According to Vixio’s Horizon Scanning Calendar, payments professionals face 59 regulatory deadlines this month alone — 33 consultation periods closing and 20 pieces of legislation entering into force across five jurisdictions. The density of compliance events is a signal of how structurally demanding the regulatory environment has become for financial services. Among the active developments: Belarus has tightened its regime on unauthorised payment flows, and the EU’s Clarity Act — with stablecoin yield language intact — moved to the full Senate, underscoring that the compliance burden for fintech is no longer a background concern but a core operational cost.
Telecom
Telia trials 5G-by-airship for mission-critical coverage in Lapland: Swedish telecom operator Telia has partnered with Finnish airship company Kelluu to test a novel approach to connectivity in areas with no traditional mobile coverage: attaching a Nokia small cell basestation to a hydrogen-powered autonomous airship and connecting it to Telia’s core network via satellite, providing 5G access to standard handsets on the ground. The trial, conducted at a defense technology event in Lapland, also demonstrated connectivity for drones, autonomous vehicles, and sensors. The approach sidesteps the infrastructure challenges of building towers in remote or conflict-affected terrain and points toward a future where airborne nodes complement ground-based networks in critical or hostile environments.
Europe’s 5G gap widens as operators call for urgent spectrum reform:A new Connect Europe report found that 5G accounts for just 43% of mobile connections in Europe at end-2025 (compared to over 70% in the US and China) and that end-user spend and investment per capita remain substantially below major peers. Twelve of Europe’s largest telecom operators, including Vodafone, Deutsche Telekom, Orange, and TIM, have jointly urged regulators to allocate the entire upper 6GHz band for mobile networks before the US and China lock in advantages for 6G deployment. The EU’s Radio Spectrum Policy Group is expected to issue a draft opinion on the band in June; operators say delay now means irreversible disadvantage later.
Sateliot and Telefónica partner to bring 5G satellite coverage to defense: Spanish LEO satellite operator Sateliot and Telefónica España have agreed to explore 5G satellite connectivity for defense and military applications, combining Sateliot’s satellite capabilities — six spacecraft already in orbit using 3GPP standards, with five more planned in 2026 — with Telefónica’s 5G standalone deployments. The partnership aims to extend terrestrial connectivity into the space domain for critical environments, reinforcing coverage and resilience where ground infrastructure cannot be relied upon. The deal reflects a broader push across Europe to treat satellite-terrestrial integration as a defense-grade capability rather than a civilian convenience.
AI
EU seals last-minute AI Act overhaul in early-hours deal: At 4:30 a.m. on 7 May, EU negotiators struck a political agreement on the AI Omnibus, pressure before the original August 2026 deadline. The deal postpones compliance timelines for high-risk AI systems by up to 16 months, introduces an industrial carve-out for machinery already regulated under separate EU rules, and bans so-called “nudification” apps that generate non-consensual intimate imagery. The agreement also clarifies that the EU AI Office, rather than national authorities, will supervise general-purpose AI models, except in areas such as law enforcement, border control, and financial services.
Colorado rewrites its AI law before the ink is dry: Colorado’s Governor signed Senate Bill 189 on 14 May, replacing the state’s original AI Act — passed just two years ago — with a substantially revised framework now officially titled “automated decision-making technology” regulation. The new law, which takes effect on 1 January 2027, retains protections against algorithmic discrimination in high-stakes areas like employment, housing, and healthcare, but restructures obligations for developers and deployers. Colorado’s willingness to revise its own legislation so quickly reflects just how fast the legal landscape is shifting, even at the state level, as AI capabilities and political pressures evolve simultaneously.
The US has over 1,200 AI bills and no coherent test for any of them: A new analysis from Yale and NYU researchers highlights an accelerating but fragmented US regulatory picture, with state legislatures racing to pass AI laws while federal policy lurches between preemption and inaction. Connecticut, New York, and Texas have each moved significant AI bills this spring, joining Colorado and California’s growing roster of state-level rules. Yet the White House’s December executive order directed the Department of Justice to challenge state laws that conflict with a “minimally burdensome” national standard, creating legal uncertainty for companies trying to build compliance programmes across jurisdictions with no federal anchor in sight.
Cybersecurity
GitHub’s internal repositories breached via poisoned developer tool: GitHub confirmed this week that hacking group TeamPCP gained access to approximately 3,800 of its internal repositories by compromising a widely-used VS Code extension, the Nx Console plugin, through a cascading supply chain attack that began with the TanStack npm package the week prior. The attackers are offering the stolen code for sale at $50,000, threatening to leak it if no buyer materialises. GitHub says it has found no evidence that customer repositories were affected, though its investigation is ongoing. Security researchers note that TeamPCP deployed a self-replicating worm to automate the attack, marking a new level of sophistication in developer-toolchain targeting.
Medtronic confirms data breach as healthcare sector remains under siege: Medical device giant Medtronic confirmed in late April that hackers breached its network and exfiltrated data, with the attack attributed to the ShinyHunters group and involving millions of records. Medtronic says products and patient safety were not compromised, but the breach represents the third significant cyberattack on a medical device manufacturer this year alone, following incidents at UFP Technologies and TriMed. The pattern points to a deliberate focus on the healthcare supply chain, a sector characterised by high data sensitivity, legacy IT infrastructure, and limited tolerance for operational disruption that makes it an attractive ransomware target.
Nine-year-old Linux kernel flaw exposed as a named vulnerability: Researchers publicly disclosed a privilege escalation flaw in the Linux kernel, CVE-2026-46333, nicknamed “ssh-keysign-pwn”, that went undetected for nine years and allows an unprivileged local user to run arbitrary commands as root on default installations of Debian, Fedora, and Ubuntu. The disclosure follows a separately active SharePoint zero-day (CVE-2026-32201) being exploited across enterprise environments, and a critical Android remote debugging vulnerability (CVE-2026-0073) affecting all devices running Android 11 or later. Security teams are navigating an unusually dense patch cycle this month as several high-severity vulnerabilities converge simultaneously.
Intellectual Property
Taylor Swift vs. AI Algorithm: Taylor Swift has filed new trademark applications to protect her voice and likeness, including specific phrases and an image, in response to the rise of AI-generated deepfakes. Experts say these moves reflect growing concern among celebrities that AI tools can easily replicate their identities and spread misleading or harmful content at scale. Swift’s actions could set a precedent, prompting other public figures to seek similar legal protection as existing laws struggle to keep up with advancing AI technology.
Too TASTY to Trademark: The EU General Court upheld the refusal to register “TASTY” as an EU trademark for food and beverages, finding it lacks distinctiveness. It ruled that consumers would see the word as a simple promotional claim about flavor rather than an indicator of commercial origin. The court also clarified that marketing use or branding strategies cannot make such a descriptive term inherently distinctive for trademark protection
CJEU Rewrites the Rules on Private Copying Levies: The CJEU clarified that EU Member States may impose private copying levies on storage media, even when sold to businesses, based on a presumption that private copying occurs. However, this presumption must be rebuttable, meaning users must have access to effective exemption or reimbursement systems when no private copying takes place or the harm is minimal.
Tariffs &Trade War
EU seals trade deal implementation to beat Trump’s July 4 deadline:In a late-night session on 20 May, the European Parliament and the Council of the EU struck a provisional agreement to implement the tariff reductions promised under last summer’s Turnberry trade deal with Washington. Under that accord, the EU agreed to scrap duties on most US industrial goods in exchange for the US capping tariffs on European exports at 15%. With Trump threatening to raise that rate to “much higher” levels unless the EU ratified its side by 4 July, the overnight breakthrough averts immediate escalation though the deal includes a safeguard clause allowing Brussels to suspend its commitments if Washington continues applying above-15% tariffs on EU steel and aluminium through end-2026.
US trade court strikes down Trump’s 10% global tariffs as unlawful: The US Court of International Trade ruled on 7 May that the Trump administration’s 10% universal tariff introduced in February under a 1970s balance-of-payments provision was imposed without legal authority and exceeded the president’s statutory powers. The ruling came after a challenge by small businesses, including toymaker Basic Fun!, which argued the tariffs were an attempt to work around the Supreme Court’s earlier decision striking down IEEPA-based tariffs. The court did not issue a universal injunction requiring refunds, leaving the practical impact uncertain, but the decision adds to growing judicial pressure on the administration’s trade strategy.
Trump tariffs cost the average US household $1,500 in 2026: A Tax Foundation analysis estimates that the cumulative effect of Trump’s remaining tariffs, after court-mandated rollbacks of IEEPA measures but accounting for still-intact Section 232 levies, amounts to an average tax increase of $1,500 per US household in 2026 and will reduce long-run US GDP by approximately 0.3%. With retaliatory tariffs from trading partners affecting $223 billion in US exports, the combined GDP drag reaches 0.5%. The findings land as the administration’s own Beige Book surveys begin noting “an abatement of tariff-related uncertainty,” though economists warn that even reduced uncertainty leaves structural costs in place that consumers are still paying.
Meet The Team

Katarina Bohm Hallkvist
Editor-in-Chief

Andres Alma
Reporteur
