US Supreme Court kippt FTC-Unabhängigkeit: Rechtsgrundlage des EU-US Data Privacy Framework weiter erschüttert

US Supreme Court kippt FTC-Unabhängigkeit: Rechtsgrundlage des EU-US Data Privacy Framework weiter erschüttert Der US Supreme Court hat am 29. Juni 2026 im Verfahren Trump v. Slaughter mit 6:3-Mehrheit entschieden, dass die gesetzlichen Abberufungsschutzregelungen für Kommissare der Federal Trade Commission (FTC) gegen die verfassungsmäßige Gewaltenteilung verstoßen. Die FTC ist damit keine unabhängige Behörde mehr, sondern […]

CLOUD Act, FISA and Co.: When EU Data Centers Fail to Protect European Data

Storing corporate data in European data centers operated by U.S. providers does not rule out access by U.S. authorities. A legal opinion by the University of Cologne, commissioned by the German Federal Ministry of the Interior and published in December 2025, confirms that U.S. authorities have extensive access to cloud data stored in Europe.

Phishing via a legitimate Microsoft address: Power BI abuse and GDPR obligations for companies

Since January 2026, a sophisticated phishing campaign has been active in which attackers send deceptive emails using the legitimate Microsoft sender address no-reply-powerbi@microsoft.com . This is technically possible due to a legitimate feature of Microsoft Power BI: when creating a dashboard, any external email address can be added as a subscriber, and the content of the automatically sent notification can be freely configured.

How secure is encrypted data if the key is stored in the cloud?

A report published by Forbes in January 2026 provides the first public evidence that Microsoft has handed over BitLocker recovery keys to the FBI. This was made technically possible by the default configuration of modern Windows versions, which automatically upload recovery keys to the Microsoft cloud. For companies in the DACH region, this results in an immediate need for review: