What’s New at Eris Law Advokatbyrå AB
At Eris Law Advokatbyrå AB, we are proud to announce a groundbreaking collaboration with KMA Center AB, designed to redefine how organizations approach information security and regulatory compliance.
This partnership delivers an integrated solution that combines legal expertise and management systems consulting to implement ISO 27001 with DORA or NIS2 – all in a streamlined and time-efficient manner.
Why It Matters:
- Enhanced Value: By synergizing our deep knowledge of legal compliance with KMA Center AB’s unmatched proficiency in management systems, we provide clients with a seamless, comprehensive approach to navigating complex regulatory landscapes.
- Accelerated Implementation: Our integrated model reduces project timelines, ensuring quicker compliance and operational readiness for our clients.
- Holistic Coverage: The partnership leverages an integrated management system approach, combining ISO 27001 with NIS2 or DORA requirements, while seamlessly incorporating ISO 37001 (Anti-Bribery), ISO 9001 (Quality), ISO 45001 (Occupational Health and Safety) and other ISO standards. This unified framework ensures comprehensive risk management across cybersecurity, compliance and operational domains.
This collaboration exemplifies our commitment to innovation, creating tailored solutions that empower our clients to thrive in a world of increasing regulation.
📩 For more details about this partnership and the services offered, contact us at info@erislaw.se.

From left to right: Fredrik Högbom, a Consultant at KMA Center AB, and Ariunzaya Munkhbat, a Cybersecurity Legal Consultant at Eris Law Advokatbyrå AB.
Fintech
Hello Open Finance: Following the European Council’s agreement on the Financial Data and Access Regulation (FIDA) in late 2024, final negotiations are set to begin in early 2025. These negotiations aim to potentially expand open banking concepts to a broader range of financial services. A key focus is to try to reduce the regulatory burden on the financial services sector while promoting growth opportunities.
New Provisions for PSPs offering credit transfers in EU: The Instant Payments Regulation (IPR) requires payment service providers (PSPs) in the euro area to process instant credit transfers in real-time, with funds credited within 10 seconds, starting January 9, 2025, and mandates charges for these services to align with traditional credit transfer fees. PSPs must also enable sending instant payments by October 2025, with further deadlines extending to non-euro area states by 2027, supported by enhanced verification services for accuracy and security. The regulation, hailed as a modernization of EU payments, eliminates delays in accessing funds and has driven infrastructure updates, such as Banque Raiffeisen and Garanti BBVA International adopting advanced payment solutions.
Progress in EU Digital Payments: The European Court of Auditors has released a special report on digital payments in the EU. The report examines the EU’s approach to digital payments, noting that in 2023 alone, digital payments for retail sales in the EU exceeded €1 trillion. Most of these exchanges happened through mobile devices.
GDPR
A New Remedy in the Swedish Data Protection Act and Criminal Data Act: The Swedish government proposes introducing a new remedy in the Data Protection Act and the Criminal Data Act to strengthen the protection of personal data. This remedy would allow individuals to request correction or deletion of their personal data when processed in violation of the law. The proposed changes are expected to take effect on July 1, 2025.
The CJEU decision weighed in on Data Protection Authorities dismissal of complaints from same Data Subject: The CJEU ruled that a DPA cannot dismiss a complaint as ”excessive” under Article 57(4) GDPR solely because the data subject has submitted multiple complaints to the same authority. Each complaint must be considered individually, regardless of the frequency. Rejecting complaints on this basis would undermine the data subject’s rights under GDPR.
Hefty fine for sharing health details with data subject’s employer: The Italian Data Protection Authority (DPA) imposed a €17,000 fine on a health agency for sharing a sick note with the data subject’s employer, which revealed details about the specific hospital wards where the individual was treated, breaching the principle of data minimization. This constitute a breach of a data subject’ sensitive information and violating the principle of data minimization.
Telecom
Nokia plans to deliver cutting edge optical networking tech: TenneT has selected Nokia to provide optical networking technology for eight new 2-gigawatt offshore converter platforms in the Dutch North Sea, aiming to enhance the transmission of renewable energy to the Netherlands. Nokia will deploy its 1830 PSS DWDM solution, supporting long-distance, single-span unrepeatered transmission of up to 400 kilometers, to connect these offshore sites to TenneT’s onshore telecommunications infrastructure. Implementation is set to begin in early 2025, aligning with the initial construction phases of the platforms, with the first expected to be operational by 2029.
Summit on EU Telecom Competitiveness held in Brussels: On January 16, 2025, Ericsson and Nokia, supported by ASML and SAP, hosted the ”New Industrial Ambition for Europe” summit in Brussels to address Europe’s declining competitiveness in technology compared to the U.S. and China. The summit emphasized the urgent need for Europe to implement recommendations from the Draghi and Letta reports, focusing on fostering innovation, incentivizing investment in key technologies, enabling scale, and reducing fragmentation. Key proposals included strengthening R&D and access to capital, reducing and simplifying regulations to create a digital single market, setting clear targets for 5G deployment, fully implementing the 5G Security Toolbox, and reforming competition guidelines to support market consolidation.
The first EU 5G cross-border highway: Orange, O₂ Telefónica, Vantage Towers, TOTEM, and the Saarland University of Applied Sciences (htw saar) have announced a collaboration to establish Europe’s first cross-border 5G highway corridor, named ”5G Autobahn to Autoroute” (5G A2A). This 60-kilometer corridor will connect Metz in France to Saarbrücken in Germany, with construction set to begin in early 2025 and completion expected by the end of 2027. The project aims to enhance 5G connectivity for cross-border travelers and facilitate industrial trials, including cooperative lane changing, collision anticipation, and testing of partially autonomous vehicles.
AI
Nordic Council of Ministers Approves Funding for AI Center: The Nordic Council of Ministers will allocate 5 million Danish kroner annually from 2025 to 2027 to establish a Nordic AI center, led by AI Sweden. This initiative aims to boost AI adoption, attract investment, and enhance the Nordic region’s influence in AI development. Formal funding approval is pending, with a report on financing to follow.
AI tool can give ministers ‘vibe check’ on whether MPs will like policies: A new AI tool, Parlex, helps UK ministers assess the political climate by predicting MPs’ reactions to policies, acting as a ”vibe check.” It analyzes MPs’ past contributions to forecast support or opposition, helping policymakers navigate potential challenges. Parlex is one of several AI tools being developed within the government to improve decision-making and efficiency.
Sweden among seven countries to host Europe’s first AI factories: Sweden is one of seven countries chosen to host Europe’s first AI factories as part of the EuroHPC Joint Undertaking. The Swedish AI Factory, MIMER, will serve as a national platform for AI research, offering advanced computing resources for innovation. Managed by NAISS at Linköping University, MIMER aims to boost Sweden’s leadership in AI development and international collaborations.
Cybersecurity
FI: DORA Reporting Requirements: The Financial Supervisory Authority (FI) has launched a webpage detailing the new reporting requirements under the DORA regulation, effective from Jan 17, 2025. The page provides information on reporting serious ICT-related incidents and cyber threats, as well as annual information register reporting. Updated guidelines on group or entity-level reporting and reporting formats are also included.
Global Cybersecurity Outlook 2025: The World Economic Forum’s Global Cybersecurity Outlook 2025, created with Accenture, highlights the increasing complexity of the cybersecurity landscape due to geopolitical tensions, emerging technologies, and supply chain interdependencies. The report emphasizes the growing cyber inequity, with small organizations and developing regions facing greater challenges in cyber resilience. The Outlook also highlights new risks rising from rapid AI adoption.
EU Action Plan to Enhance Healthcare Cybersecurity: The EU Agency for Cybersecurity (ENISA) supports the new EU Action Plan for bolstering the cybersecurity of hospitals and healthcare providers, a priority aligned with the European Commission’s 2024-2029 mandate. Key initiatives include the establishment of a pan-European Cybersecurity Support Centre, guidance development for good practices, regulatory mapping tools, and early warning systems for cyber threats in the health sector, to be implemented collaboratively by 2026.
Upcoming Events
- AI World Congress 2025
Dates : June 18-19, 2025 (In-Person)
Time : 9:00 am
Location : London
Registration : https://aiconference.london/register/
- Space show 2025
Dates : 19 – 20 MARCH 2025
Time : 9:30 am
Location : London
- British Legal Technology Forum
Dates : 11 MARCH 2025
Time : 10 am onwards
Location : London
Registration : https://bigevent.io/legal-tech-conferences/
Meet The Team

Katarina Bohm Hallkvist
Editor-in-Chief

Andres Alma
Reporteur

Reet Singh
Reporteur

Ariunzaya Munkhbat
Reporteur