News

Online platform liability and algorithms: how the CJEU’s 16 June 2026 ruling strengthens trademark owners

Introduction

The use of an algorithm does not, by itself, make an online platform liable for user-generated content. But for trademark owners, the CJEU’s judgment of 16 June 2026 changes the picture: platforms can no longer rely on automation alone to keep liability at arm’s length. The decisive question is the degree of control that the algorithm enables the platform to exercise over that content. Where automated processing remains technical and merely facilitates access to information, the hosting liability exemption may continue to apply. Where the algorithm determines, in the interests of the provider or its service, which information is disseminated, under what conditions and in what order of priority, the provider may instead be regarded as exercising control over that information.

This is the major contribution of the judgment delivered by the Court of Justice of the European Union on 16 June 2026 in joined cases C-188/24 WebGroup Czech Republic and NKL Associates and C-190/24 Coyote System.

Key points for businesses

A platform whose algorithm decides which content is published, promoted or demoted exercises control over that content and may lose the protective status of a hosting provider.

Losing that status does not automatically establish liability, but it removes the obstacle that has so far blocked many trademark enforcement actions.

Businesses should now document how the algorithm works — ranking, promotion, sponsored placement — as carefully as the infringing content itself.

Platform liability and algorithms under the Digital Services Act

Hosting protection is a conditional safe harbour, not blanket immunity

Article 6 of the Digital Services Act (DSA) provides a conditional exemption for hosting services. In broad terms, providers are protected in respect of information stored at a user's request where they lack actual knowledge of illegal activity or illegal content and, once they obtain the relevant knowledge or awareness, act expeditiously to remove or disable access to it.

A crucial distinction must nevertheless be drawn between losing an exemption and actually being liable. Recital 17 of the DSA states that the liability exemptions determine when an intermediary cannot be held liable; they do not create a positive legal basis for liability. Whether liability exists must still be determined under the relevant provisions of EU or national law, including rules on intellectual property infringement, unfair competition or civil liability.

In other words, losing the safe harbour does not automatically mean losing the case.

Using an algorithm does not automatically remove hosting protection

The DSA expressly contemplates automated processing. Recital 22 specifies that automatic indexing, search functions or recommendations based on users' profiles or preferences are not, by themselves, sufficient to establish specific knowledge of illegal activity or content.

Article 7 also protects diligent “Good Samaritan” initiatives: intermediary service providers do not lose the liability exemptions solely because they voluntarily investigate, detect or remove illegal content in good faith.

CJEU judgment of June 16, 2026: when does algorithmic control cause the loss of hosting status?

Coyote System places the algorithm at the heart of the legal classification

Case C-190/24 concerned Coyote's geolocation-based driving assistance service. Users could report road events and certain information was processed and redistributed through an algorithm. Article L. 130-11 of the French Highway Code (Code de la route) permits the authorities, in specific public-order and public-security circumstances, to prohibit temporarily the rebroadcasting of user-generated information concerning certain roadside checks. The French Conseil d'État referred questions concerning the compatibility of that mechanism with EU law to the CJEU.

Among other issues, the Court therefore had to consider whether the operator could rely on the legal regime applicable to hosting providers and on the prohibition against imposing a general monitoring obligation.

Knowledge and control are autonomous alternatives

An operator can therefore control stored information without any employee actually seeing that information. The fact that the intervention occurs automatically is not decisive when the provider itself has predetermined, through its algorithm, how the content will be disseminated.

According to the Court, where an algorithm determines, in the interests of the operator or its service, whether particular information is disseminated, the conditions governing dissemination, how the information is presented, and its order of priority, the operator exercises control over that information. Under the e-Commerce Directive framework examined in the judgment, such an operator can no longer be classified as a hosting provider, it being for the referring court to carry out the necessary verifications.

From technical indexing to editorial control: where is the boundary?

Not every automated classification becomes an editorial intervention. The analysis accompanying the judgment distinguishes simple categorisation and indexing intended to improve accessibility from processing that materially affects the information itself, by modifying some of it and deleting other parts. When a system decides that some information should be promoted, confirmed, hidden, modified or eliminated according to criteria programmed by the operator, the legal analysis changes.

Accordingly, labels such as “recommendation engine”, “personalisation”, “smart ranking” or “automated moderation” are not decisive. The actual function and effects of the system matter more than its commercial description.

This approach closely reflects recital 18 of the DSA, according to which the liability exemptions should not apply where, instead of providing the service neutrally through merely technical and automatic processing, the intermediary plays an active role giving it knowledge of or control over the information.

The June 2026 judgment formally interprets the earlier e-Commerce Directive rather than Article 6 of the DSA itself. Its reasoning should therefore not be presented as a direct interpretation of the DSA. It nevertheless provides a particularly significant framework for assessing algorithmic control under the current EU regime.

What are the consequences for marketplaces, social networks and IP rights holders?

Marketplaces and social networks: algorithm design becomes a direct liability issue

For a marketplace dealing with counterfeit products or a social network disseminating content that infringes trademarks, copyright, or designs, the analysis should no longer be limited to notice-and-takedown procedures.

Relevant issues may include:

  • the criteria determining the visibility of a listing or item of content;
  • promotion and demotion mechanisms;
  • whether commissions, conversion rates or advertising revenues influence rankings;
  • automated suppression or concealment rules;
  • the settings that allow the platform to favour certain content; and
  • documentation explaining the purpose and operation of the system.

No general monitoring obligation does not mean no targeted monitoring

Article 8 of the DSA continues to prohibit the imposition of a general monitoring obligation on intermediary service providers. That principle does not, however, prevent appropriately targeted injunctions.

The June 2026 judgment confirms that measures relating to sufficiently circumscribed information may be implemented through automated tools without requiring the provider to carry out an autonomous assessment of all stored content.

For IP rights holders, this distinction may be strategically significant. The more objectively and precisely the infringing content or conduct can be defined, the stronger the basis may be for considering an appropriately targeted technological measure.

Trademark owners: how to enforce more effectively against an online platform

The practical significance of the judgment is substantial for businesses: it becomes considerably harder for a platform to claim neutrality where its algorithm amplifies listings or content infringing trademark rights. Trademark owners gain an argument they can deploy immediately, in negotiation as much as in litigation. Their strategy need no longer be limited to showing that a sufficiently precise notice was submitted: where the facts support it, they may also document how the platform selects, ranks, recommends, promotes or maintains the visibility of the disputed content. Such evidence may be used to challenge the purely neutral character of the service and, where appropriate, the availability of the hosting exemption, without automatically establishing the platform’s liability.

In practice, trademark owners should preserve dated evidence capable of showing that intervention: screenshots, ranking positions, sponsored labels, associated recommendations, repeated display of the same listing, or changes in visibility following a defined search. This material can supplement takedown notices by identifying not only the unlawful content itself but also the observed mechanisms that increase its exposure, and may support a suitably circumscribed request for measures or an injunction where the relevant legal conditions are met.

In litigation, available information concerning recommender systems and applicable evidential mechanisms may also help establish the platform’s actual role. The judgment of 16 June 2026 therefore does not create a new autonomous basis of liability for trademark owners, but it meaningfully broadens the evidential and legal arguments that may be used to organise the enforcement of their rights.

Conclusion

The CJEU judgment of 16 June 2026 marks an important development. Automation does not necessarily mean neutrality. A provider may exercise control precisely because it designed the algorithm that determines whether, how and in what order user-generated information reaches the public, even where no human operator sees the individual content concerned. For trademark owners, this is a concrete step forward: documenting a platform’s active role becomes an effective way to strengthen targeted takedown or injunction requests and, where the facts support it, to defeat the hosting liability exemption. Building that analysis into the evidence file from the outset is now a brand-strategy question as much as a litigation one.

Dreyfus & Associés assists its clients in managing complex intellectual property cases, offering personalized advice and comprehensive operational support for the complete protection of intellectual property.

Dreyfus & Associés works in partnership with a global network of attorneys specializing in Intellectual Property.

Nathalie Dreyfus with the support of the entire Dreyfus team

FAQ

Who must show that an algorithm gives the platform control over user content?

The classification depends on the evidence before the court. In practice, a party challenging the availability of the hosting exemption will need to substantiate how the system operates or what effects it produces, for instance by reference to evidence relating to ranking, visibility or the conditions of dissemination.

Can a platform rely on trade secret protection to refuse all information about its algorithm?

No. Trade secret protection may keep certain technical information out of the public domain, but it does not necessarily prevent scrutiny of the system in litigation. Courts can reconcile evidential needs with confidentiality through proportionate protective measures.

Does outsourcing an algorithm to a third-party provider shield the platform from legal risk?

Not necessarily. The analysis focuses on the role actually performed by the platform within the service, not simply on who developed the tool. Outsourcing therefore does not remove potential control where the platform sets the objectives, chooses key parameters or benefits from the resulting selection.

Can the same platform qualify as a hosting provider for some features but not for others?

Yes. The classification should be assessed by reference to the particular service and the role performed for the feature at issue. A platform may merely store some user content while playing a more active role in a separate promotion, advertising or selection service. A functional analysis should therefore be preferred to the automatic attribution of a single status to the platform as a whole.

What evidence should a rights holder preserve before challenging algorithmic treatment?

Dated evidence should be retained so that the observed experience can be reconstructed: screenshots, URLs, search terms, ranking positions, sponsored labels, recommendations, relevant account settings, notices and platform responses. Repeated comparative tests may help distinguish an isolated result from a recurring mechanism.

Can a platform's terms of service transfer all responsibility for content to its users?

No. Terms of service can impose obligations on users and allocate certain contractual risks, but they cannot disapply mandatory rules governing the platform itself. Legal classification depends on the platform's actual role and the operation of the service.

This publication is intended for general public guidance and to highlight issues. It is not intended to apply to specific circumstances or to constitute legal advice.

Read More

Are French courts bound by a UDRP decision ? Lessons from the Paris Court of Appeal decision of February 20, 2026

Introduction

A UDRP decision ordering the transfer of a domain name does not, by itself, bind a French court subsequently asked to rule on a dispute concerning that domain name or its use. The Paris Court of Appeal decision of February 20, 2026 (Paris Court of Appeal, February 20, 2026, Case No. 24/17961) provides a clear illustration: a WIPO administrative panel had ordered the transfer of <banque-delubac.com>, while the French courts later assessed the disputed uses independently under French trademark law.

This autonomy follows from the nature of the UDRP itself. It is an extrajudicial mechanism embedded in the contractual domain-name registration system, not a court judgment with res judicata effect. Paragraph 4(k) of the UDRP expressly preserves the parties’ ability to submit the dispute to a competent court for independent resolution. The Delubac decision therefore illustrates why domain-name recovery strategy can coordinate extrajudicial and judicial remedies without treating their legal tests as interchangeable.

For more information on UDRP procedures, we invite you to consult our previously published article: " What is the UDRP? A Comprehensive Guide to Protecting Your Domain Names ".

Facts: domain names used as platforms for criticism

Banque Delubac, the owner of trademarks incorporating the DELUBAC sign and long-standing domain names, was confronted with the registration, by a former employee, of several domain names reproducing or evoking its name, including <banque-delubac.com>, <affaires-delubac.com> and <harcelement-ambiance.com>. The related websites published testimonials, critical material or links to press articles concerning the bank.

The bank considered that this use infringed its trademark rights and damaged its reputation. The bank sought the removal of certain websites, the transfer of the domain names and damages. Under paragraph 4(i) of the UDRP, however, the remedies available in UDRP proceedings are limited to the cancellation or transfer of the domain name. The disputed pages, by contrast, presented themselves as informational or criticism websites and stated that they were not official bank websites and did not sell goods or services.

Proceedings and claims: UDRP and court litigation

The WIPO UDRP proceeding

The bank filed a UDRP complaint concerning <banque-delubac.com> and <affaires-delubac.com>. In its decision of January 1, 2024 (Decision of the Administrative Panel Banque Delubac Et Cie v. Samir Laroussi, Case No. D2023-4523), the WIPO Administrative Panel distinguished between the two names. It ordered the transfer of <banque-delubac.com>, finding in particular that combining “banque” with DELUBAC did not clearly signal a criticism website and could reinforce the appearance of an association with the bank. By contrast, transfer of <affaires-delubac.com> was denied, as the wording and non-commercial context supported a different assessment. In this case, the Panel considered that the addition of the term “affaires” suggested that the website had a critical purpose and, given its genuinely non-commercial nature, the Respondent could rely on a legitimate interest based on the exercise of the right to criticism and freedom of expression.

The claims before the French courts

In parallel, the bank had brought proceedings before the Paris Judicial Court. After its main claims were dismissed, it appealed, arguing in particular that the domain names and website content interfered with its trademark rights, including the reputation claimed for its trademark, and harmed its image. It also relied on the WIPO decision as part of its argument on the likelihood of confusion and sought compensation for the damage it claimed to have suffered.

An important procedural point should be clarified: before the Court of Appeal, no new request for the cancellation or transfer of <banque-delubac.com> was made. The Court was therefore not called upon to rule on the merits of the transfer ordered by WIPO, and its judgment does not formally “reverse” the UDRP decision.

Decision: an independent assessment under French law

The Paris Court of Appeal upheld the judgment and dismissed the bank’s claims. As regards the alleged infringement of the well-known trademark, it recalled that the legal regime relied upon requires the use of an identical or similar sign in the course of trade in relation to identical or similar goods or services (article L.713-5 of the French Intellectual Property Code). The disputed websites were not being used to identify or market competing goods or services; they mainly published testimonials or press material.

The Court also noted that the websites expressly stated that they were unofficial and sold no goods or services. In those circumstances, the operation of <banque-delubac.com> and <affaires-delubac.com> could not establish the alleged trademark infringement. <harcelement-ambiance.com>, which did not reproduce the DELUBAC sign and was likewise not used in the course of trade, could not support that claim either.

The key point is therefore not a direct conflict between WIPO and the Court, but the fact that they were answering different legal questions:

  • The WIPO Administrative Panel was required to assess, under the specific criteria of the UDRP, whether the conditions for ordering the transfer of the domain names were met.
  • The Court of Appeal, for its part, had to determine whether the disputed use infringed the rights asserted by the bank under French trademark law.

For further insight into the relationship between UDRP proceedings and actions before national courts, we invite you to consult our previously published article: “A judgment of the Paris Court of Appeal of 8 November 2016 confirms the independence of national courts from WIPO decisions.

Significance of the decision: judicial independence from domain name procedures

UDRP panels and national courts apply different legal tests

The UDRP requires the complainant to establish three cumulative elements:

  • The domain name is identical or confusingly similar to a trademark in which the complainant has rights,
  • The domain name holder has no rights or legitimate interests in respect of the domain name,
  • The domain name has been registered and is being used in bad faith.

The French courts are not required to mechanically reassess these three criteria. They rule on the legal grounds submitted to them, in light of the specific requirements of French law.

The fact that different conclusions may be reached does not therefore necessarily mean that one of the decision-makers was wrong. Rather, it reflects the fact that the legal characterization of a given conduct depends on the applicable legal framework, the precise nature of the claims brought, and the evidence submitted. The two bodies may therefore reach different assessments in relation to the same domain name without their decisions being legally contradictory: they do not rule on the same legal basis, apply the same criteria, or exercise the same powers.

A UDRP decision may inform the judicial analysis, but it does not automatically determine the outcome of court proceedings.

For further information regarding the requirement of registration and use in bad faith, please see our article on: " How does the bad faith duplicate between registration and bad faith use? "

The decision highlights the need to coordinate UDRP and litigation strategies

For trademark owners, a domain-name procedure should not be selected in isolation from potential litigation. Before filing a complaint, the desired outcome should first be identified – rapid transfer, cessation of use, damages or action against unlawful content – together with the legal bases that might later be relied upon in court. For a broader overview of the available mechanisms, see our Complete Guide 2026: Domain Name Disputes – UDRP, SYRELI and International Alternatives.

SYRELI and PARL Expert operate differently but remain subject to judicial review

For .fr domain names, SYRELI and PARL Expert are administered within the Afnic framework and do not follow the UDRP regime. However, Article L. 45-6 of the French Postal and Electronic Communications Code expressly provides that decisions taken by the registry may be challenged before the judicial courts. An extrajudicial or administrative decision therefore does not remove the possibility of judicial review.

Conclusion

The Paris Court of Appeal decision of February 20, 2026 confirms a central point in domain-name litigation: a UDRP decision does not, by itself, determine the outcome of proceedings before the French courts. The UDRP and national litigation may concern the same factual situation while applying different legal tests, causes of action and remedies.

For trademark owners, this autonomy calls for a coordinated approach: identify the precise use made of the domain name, distinguish cybersquatting from criticism, confusion and commercial activity, select the procedure that matches the desired result, and anticipate from the outset the possibility of court proceedings.

Dreyfus Law Firm assists its clients in managing complex intellectual property cases, offering personalized advice and comprehensive operational support for the complete protection of intellectual property.

Dreyfus Law Firm works in partnership with a global network of attorneys specializing in Intellectual Property.

Nathalie Dreyfus, with the assistance of the entire Dreyfus team.

Q&A

What evidentiary weight can a UDRP decision have before a French court?

It may be submitted as part of the evidential record and may document the chronology, the parties’ positions or the analysis conducted under the Policy. The court remains free to assess its weight and must decide the claims before it under the applicable law. The UDRP decision does not acquire the authority of a French judicial decision merely because it has been issued.

What happens when a domain-name registrant brings court proceedings after a UDRP transfer decision?

Paragraph 4(k) contains a mechanism under which implementation of the transfer may be deferred where the registrant provides, within the period specified by the Policy, evidence that qualifying court proceedings have been commenced. Timing is therefore critical: proceedings initiated too late may not prevent the registrar from technically implementing the panel decision.

Which other legal grounds may be relevant when a non-commercial criticism site falls outside trademark infringement?

The answer depends on the content and context. Depending on the facts, relevant issues may include defamation and press-law rules, unfair competition or denigration where an economic activity is involved, confidentiality, trade secrets, privacy, or rules governing manifestly unlawful content. Each cause of action has its own requirements, limitation periods and evidential rules.

How should a rights holder choose between UDRP, SYRELI/PARL Expert and court proceedings when several routes appear available?

The starting point is the remedy sought, the domain-name extension and the nature of the alleged abuse. An extrajudicial procedure may be appropriate for a rapid transfer or cancellation, while court proceedings may be necessary for damages, broader injunctions or disputes concerning website content. Evidence and the risk of parallel proceedings should also be assessed before the first filing.

Does a “not an official website” disclaimer remove all legal risk associated with a disputed domain name?

Such a statement is one contextual factor, but its weight depends on the overall impression created for internet users. The domain name itself, website presentation, content, redirections, commercial activity and the registrant’s conduct remain relevant. A disclaimer of affiliation therefore cannot be assessed in isolation.

This publication is intended for general public guidance and to highlight issues. It is not intended to apply to specific circumstances or to constitute legal advice.

Read More

What new identification requirements will apply to .ru, .рф and .su domain names from September 1, 2026?

Introduction

As of September 1, 2026, domain names ending in .ru, .рф and .su will be subject to enhanced identification requirements through ESIA, Russia’s public identification and authentication system. ESIA operates through “Gosuslugi”, the official Russian government services portal. In practice, the domain name holder will need to have a Gosuslugi account, either personal or corporate depending on the holder’s status, containing identity information that has already been verified. This information will allow the registrar to confirm that the individual or company requesting the registration, renewal or certain changes to the domain name is indeed the declared holder. Federal Law No. 569-FZ of December 29, 2025 introduced this principle into Article 14.2 of Russian Federal Law No. 149-FZ.

What changes for Russian domain names on September 1, 2026?

ESIA becomes a gateway for essential domain operations

Guidance published by the Coordination Center for TLD .RU/.РФ states that registration and renewal will require ESIA identification from September 1, 2026. Current operational guidance also covers actions such as registrant or registrar changes, delegation and certain data updates.

Existing domains may continue to work, but not indefinitely

The Coordination Center explains that a domain already registered may remain in use until the end of its current registration term. If the administrator cannot complete the required identification, however, renewal becomes impossible. After expiry and the applicable priority renewal period, the registration may be cancelled and the name may become available again. For a domain name incorporating the name of a brand owner, that creates a direct risk of third-party acquisition and cybersquatting.

Why are foreign registrants particularly exposed?

The main obstacle is practical access to Gosuslugi

The reform does not amount to a general ban on foreign ownership. The difficulty is obtaining an ESIA identity that can be used by the registrar. A foreign company with an accredited Russian branch or representative office may, subject to local requirements, create an organisation account. A foreign company with no accredited presence does not have the same route. Economic ownership of the domain may therefore remain clear while the registrant lacks the regulatory ability to perform the operation needed to keep it.

What should companies do before September 1, 2026?

1. Audit the portfolio and registered holders

It should be verified for each domain:

  • the registrar,
  • registrant,
  • expiration date,
  • DNS settings,
  • email configuration,
  • redirects,
  • connection with the group’s trademarks.

The objective is to quickly identify domain names whose holders may face difficulties in complying with the new identification requirements, particularly where they are registered in the name of a foreign company without effective access to ESIA, a former employee, or a service provider.

To learn more about domain name audits, we invite you to consult our previously published article: ” Domain name audit: securing and maximizing your digital portfolio “.

2. Secure an appropriate continuity solution

If the group has a Russian entity eligible for ESIA, a restructuring of the domain name ownership may be considered before the new framework applies. Where no such presence exists, a local trustee arrangement may be considered where available and lawful, but the agreement should address:

  • DNS control,
  • renewal duties,
  • transfer restrictions,
  • re-transfer,
  • provider failure.

For secondary domains, a controlled migration to an international extension may be more proportionate.

How should the reform fit into an IP strategy?

Domain continuity should be assessed together with trademark strategy. Losing control of a .ru name may affect the website, email, campaigns and user trust. We therefore recommend coordinating legal, trademark and IT teams and strengthening domain name monitoring against cybersquatting.

For a broader approach to protecting your brand in relation to domain names, we invite you to consult our previously published article: “Domain names: registration, monitoring and disputes – how to protect your brand in the digital space”.

Conclusion

Russia’s September 1, 2026 reform requires holders of .ru, .рф and .su domain names to verify without delay whether they can satisfy ESIA identification. For foreign businesses, the priority is to preserve continuity before renewal or another operation is blocked. A targeted audit, secure registrant structure and, where necessary, a transfer or migration plan can reduce the risk of losing the name to a third party.

Dreyfus Law Firm assists its clients in managing complex intellectual property cases, offering personalized advice and comprehensive operational support for the complete protection of intellectual property.

Dreyfus Law Firm works in partnership with a global network of attorneys specializing in Intellectual Property.

Nathalie Dreyfus, with the assistance of the entire Dreyfus team.

Q&A

Does failure to complete identification result in the immediate deletion of the domain name?

No. Failure to complete the required identification will, in particular, prevent renewal of the domain name. Deletion will occur at a later stage, after the domain has expired and the priority renewal period has elapsed.

Can a trademark owner act if a third party registers a released .ru domain?

Loss of the domain does not extinguish earlier trademark rights. Enforcement may remain possible depending on applicable law, the third party’s use and the circumstances of acquisition. Recovering a released domain is nevertheless more uncertain than preventing the loss before expiry.

Should Cyrillic variants of a Latin-character trademark be monitored?

Such monitoring is particularly relevant where Russia remains an important market for the company. Transliteration, phonetic equivalents and visually similar variants may create confusion, particularly under .рф. Effective monitoring should therefore go beyond exact matches and include plausible linguistic variants.

Does a foreign company with no presence in Russia necessarily need to use a trustee to retain its .ru, .рф and .su domain names?

Using a trustee is one possible solution where a company does not have a Russian entity eligible for ESIA, but it is not the only option. Depending on the importance and use of the domain name, migration to an international extension may also be considered. The appropriate solution should therefore be assessed on a case-by-case basis, taking into account the need to retain the domain name and the practical constraints associated with its management.

How should a company choose between transferring a domain name to a Russian entity, using a local trustee, and migrating to another extension?

The choice will mainly depend on the group’s structure and the strategic importance of the domain name. Where an ESIA-eligible Russian entity exists, a restructuring of the registrant arrangement may be considered. Otherwise, a local trustee may provide a continuity solution, subject to appropriate contractual safeguards. For secondary domain names, a gradual migration to an international extension may be more proportionate.

This publication is intended for general public guidance and to highlight issues. It is not intended to apply to specific circumstances or to constitute legal advice.

Read More

What should you do if you receive a cease and desist letter concerning a photograph published on a website?

Introduction

Receiving a cease and desist letter concerning a photograph published on a website calls for a prompt response, but not an automatic payment.

Claims sent by photographers, press agencies and image-enforcement companies commonly contain screenshots, a file reference, a quantified demand and a short deadline. None of those features establishes, by itself, copyright infringement or the amount of compensation that may ultimately be recoverable.

What should you do immediately after receiving a copyright demand for a photograph?

The first task is to secure the evidence. Keep the notice and all attachments, take dated screenshots of the relevant webpage, establish when the photograph was uploaded, identify where the file came from and retain invoices, licences and correspondence with any web agency or content provider involved.

The image may then be removed as a precaution where appropriate. Removal can prevent further disputed use, but it does not erase a possible past infringement. On a general note, removing an image does not, on its own, resolve a claim concerning previous use.

Care should also be taken not to turn a sensible precaution into an admission. A statement such as “we acknowledge that we used the photograph without permission” should not be made before the legal and factual position has been established.

How can you determine whether the copyright claim is justified?

Is the photograph actually protected by copyright?

The French Intellectual Property Code expressly includes photographic works among works capable of copyright protection. Copyright protection nevertheless requires originality: the photograph must embody the author’s own intellectual creation through free and creative choices reflecting his or her personality.

  • In Painer case of Ddecember 1, 2011 (C-145/10), referred to choices that may arise when preparing the photograph, framing and taking the shot, arranging the subject and lighting, and processing the resulting image.
  • In the joined Mio cases of December 4, 2025 (C-580/23 and C795/23), the CJEU reiterated more generally that choices imposed by technical or other constraints are not free and creative and that originality ultimately requires the author’s personality to be expressed in the work.

The assessment must therefore be made image by image.

In a decision ruled in June 25, 2025 (n°24/02278), the Nancy Judicial Court examined , an AFP photograph of a French driving licence for which staging, framing and lighting choices were relied upon; originality was not established in the circumstances. By contrast, in a case ruled in December 11, 2025, the Strasbourg Judicial Court recognised the originality of a photograph depicting a sommelier pouring wine, taking into account the particular visual and compositional choices made.

Professional quality alone therefore neither proves nor disproves copyright protection.

Can the claimant prove that it owns or controls the relevant rights?

The second verification concerns the chain of rights. Before considering any payment, it is necessary to verify that the person or entity making the claim actually holds the rights they are asserting.

In particular, the following must be examined:

  • who is the author of the photograph and, if applicable, who currently holds the economic rights to it;
  • whether the rights have been assigned or licensed to an agency, and under what contract;
  • which rights have actually been transferred, in particular the rights of reproduction and public performance;
  • the scope of this transfer, particularly with regard to the media, uses, territories, and duration involved;
  • when the claim is made by a company specializing in debt collection, the existence and scope of the mandate authorizing it to act or to claim compensation on behalf of the rights holder.

Article L131-3 of the French Intellectual Property Code provides, in relation to copyright assignments, that each transferred right must be identified in the contract and its scope of exploitation defined by reference to matters including purpose, territory and duration.

A screen short showing evidence that a photograph appeared on a website does not itself prove every link in the claimant's chain of title.

Was the use already authorised?

Next, you must precisely identify the source from which the image was obtained and the circumstances under which it was added to the website: purchased from a photo library, downloaded from a free image bank, provided by a communications agency, an employee, a service provider, or a business partner, or retrieved from a search engine.

An image found through Google is not automatically free to use. Under Article L. 122-4 of the French Intellectual Property Code, reproduction or communication of a protected work without the consent of the author or relevant right holder is, in principle, unlawful.

When a photograph has been provided or selected by a service provider, the contract entered into with that provider must also be reviewed. A warranty clause regarding intellectual property rights may allow for legal action against the service provider if the image was used without sufficient rights.

Is the amount claimed legally justified?

The amount stated in a letter must also be analysed rather than treated as an automatically binding tariff.

Under Article L. 331-1-3 of the French Intellectual Property Code, damages for infringement are assessed by reference to matters including negative economic consequences, moral harm and profits or investment savings obtained through the infringement. At the injured party's request, the court may alternatively award a lump sum exceeding the royalties that would have been payable for authorised use, without excluding compensation for moral harm.

How should a company respond to an image-rights claimant?

The appropriate response depends on the facts established following an analysis of the complaint, the ownership of the rights asserted, and the circumstances under which the photograph was used:

  • The agency does not sufficiently demonstrate its rights to the photograph: ask it to provide evidence of ownership of the rights and, if applicable, the originality of the photograph;
  • A license authorized the use of the image: submit documents proving that the disputed use was indeed covered by that license;
  • The use was likely unauthorized, but the amount claimed appears excessive or insufficiently justified: request a detailed breakdown of the calculation and consider negotiating based on standard licensing terms and the specific circumstances of the use;
  • A summons has already been served: immediately forward the summons to an attorney to prepare a defense and meet the procedural deadlines.

What rights should be checked when a person appears in a photograph?

Where an identifiable person appears in a photograph, it is also necessary to verify the conditions under which their image may be used. A photograph that makes it possible to identify an individual may constitute personal data within the meaning of the GDPR. Copyright in the photograph, the image rights of the person depicted, and personal data protection are, however, distinct legal regimes and must be assessed separately.

Conclusion

When a company receives a cease and desist letter concerning a photograph published on a website, it should secure the evidence and then determine, in sequence, whether the photograph is protected, whether the claimant can establish its rights, whether the use was authorised and whether the amount claimed is properly substantiated. This structured approach makes it possible to distinguish a legitimate claim requiring resolution from one that should be challenged or renegotiated.

For further analysis of copyright, our expertise in copyright and IP infringement disputes combines legal analysis, evidence strategy and pre-litigation negotiations.

Dreyfus Law Firm assists its clients in managing complex intellectual property cases, offering personalized advice and comprehensive operational support for the complete protection of intellectual property.

Dreyfus Law Firm works in partnership with a global network of attorneys specializing in Intellectual Property.

Nathalie Dreyfus with the support of the entire Dreyfus team

Q&A

Does modifying or cropping a photograph remove copyright protection?No. Cropping a photograph, changing its colours, adding text or incorporating it into a montage does not remove the rights attached to the original work. Such alterations may even raise an additional issue concerning respect for the integrity of the work.

Does non-commercial use of a photograph exclude any risk of copyright infringement?No. The absence of a commercial purpose does not make the use of a protected photograph automatically lawful. It may, however, be taken into account when assessing the context of the use and, depending on the circumstances, when evaluating the damage allegedly suffered.

What should be done if the claim concerns several photographs?Each photograph should be assessed separately. Originality, ownership of rights, conditions of use and the alleged damage may differ from one image to another. A global claim therefore does not relieve the claimant from substantiating its allegations in respect of each photograph concerned.

Can an old publication still give rise to a claim?Yes. The fact that a photograph was published several years ago does not, in itself, exclude the possibility of legal action. It is necessary to examine the date of the alleged acts, whether the use continued over time, when the rights holder became aware of them, and the applicable limitation rules.

Can a photograph purchased from an image bank still give rise to a claim?Yes. Purchasing an image is not sufficient if the actual use exceeds the scope of the licence acquired. The authorised media, duration, number of users, commercial restrictions and any limitations relating to advertising or social media should therefore be carefully checked.

This publication is intended for general public guidance and to highlight issues. It is not intended to apply to specific circumstances or to constitute legal advice.

Read More

ICANN’s 2026 new gTLD round: What does it mean for your online trademark protection?

Introduction

On August 12, 2026, ICANN closed the application window for its new Generic Top-Level Domain (gTLD) Program, the “2026 Round”. More than 1,600 applications were filed, confirming strong appetite for new internet naming spaces fourteen years after the previous 2012 round. For businesses and intellectual property rights holders, this new wave of extensions represents both a strategic opportunity and a potential source of new online infringement and cybersquatting risks.

A landmark round: more than 1,600 applications filed

A fifteen-week filing window

Opened on April 30, 2026, the application window closed on August 12, 2026 after fifteen weeks, with a significant surge of filings in the final days. More than 1,100 primary applications also included requests for replacement strings, an option available under the program in certain circumstances. These figures remain provisional: they will only be finalized once ICANN receives the required evaluation fees, due by August 19, 2026 (or seven days after an invoice is issued, whichever is later).

Concrete example: the previous 2012 round resulted in more than 1,200 new gTLDs being delegated, including brand extensions (.microsoft, .sky), geographic extensions (.africa, .berlin) and generic extensions (.bank, .eco). The 2026 Round is expected to be of comparable scale, with an unprecedented linguistic dimension.

For a detailed analysis of how the new gTLD program has evolved since the 2012 round, please see our previously published article: " The new gTLD program: What has changed since 2012? ".

An unprecedented opening to non-latin scripts

A notable feature of this round is that ICANN is, for the first time at this scale, accepting applications in 27 non-Latin scripts, including Arabic, Chinese, Devanagari and Thai. This linguistic expansion aims to make the domain name system more accessible to the billions of internet users who do not rely on Latin-based scripts. The base application fee stands at US$227,000, an amount that can rise significantly depending on the specialized evaluation requirements applicable to each type of string.

Key milestones: from reveal day to delegation

Once applications closed, several stages structure the evaluation process, up to the effective delegation of the new extensions.

Stage Deadline
Application window closes August 12, 2026
Evaluation fee payment No later than August 19, 2026
Administrative review of applications Ongoing
Reveal Day (publication of applications) No later than 9 weeks after closure
Announcement of the detailed timeline Mid-September 2026
Objection filing period Second half of 2026

Reveal Day, the publication of applications received, is a pivotal moment for rights holders, as it will disclose both the strings applied for and any conflicts between identical or similar applications.

Contention and objection procedures

Where several applicants seek an identical or overly similar string, ICANN provides contention-resolution mechanisms, including auctions, while prohibiting any private settlement between applicants. In addition, the World Intellectual Property Organization (WIPO) Arbitration and Mediation Center has been appointed as the exclusive provider for two pre-delegation, rights-based objection procedures: the Legal Rights Objection (LRO) and the String Confusion Objection (SCO). WIPO already administered 69 LRO cases during the 2012 round, making it the reference forum for trademark owners seeking to challenge an application that infringes their rights.

For further insight into the objection mechanisms and dispute resolution providers for the new round, please see our previously published article: " ICANN appoints dispute resolution service providers for the next round of new gTLDs: what businesses need to know ".

What risks and opportunities for trademark owners?

Increased risks of cybersquatting and trademark infringement

The opening of new extensions, particularly in non-Latin scripts, multiplies the possible combinations built around a given trademark. A rights holder may therefore face applications reproducing or evoking its mark in a language or script it had not previously monitored. Typical client scenario: a globally known luxury or cosmetics brand could discover, on Reveal Day, that a string closely resembling its name has been applied for by an unaffiliated third party, in a script it had not anticipated.

Strategic opportunities not to be overlooked

Conversely, this round is an opportunity for some companies to apply for their own brand extension (“.brand”), following the example of .airbus or .bnpparibas, in order to gain full control over the naming space associated with their identity. A .brand extension notably allows a company to be exempted from certain Sunrise obligations while retaining control of the registry.

For a more detailed analysis of the strategic issues surrounding “.brand” extensions, please see our article: " .brand extension: A complete guide for companies ahead of the ICANN 2026 wave ".

Practical roadmap

  • Monitor the Reveal Day publication to identify any string conflicting with your rights
  • Check that your trademarks are recorded with the Trademark Clearinghouse (TMCH) to benefit from protection mechanisms (Sunrise, Claims)
  • Assess, with your counsel, whether to file a Legal Rights Objection (LRO) with WIPO within the applicable deadlines
  • Anticipate a possible contention procedure if several applications target a string identical to your rights
  • Update your domain name monitoring strategy (including UDRP practice) to cover the forthcoming new extensions

For further information on domain name monitoring and the prevention of cybersquatting, please see our article: " Domain name monitoring: protecting your trademark against cybersquatting ".

Conclusion

The 2026 gTLD Round marks a major milestone in the evolution of the domain name system, with more than 1,600 applications filed and an unprecedented opening to non-Latin scripts. For trademark owners, the challenge is twofold: anticipating the risks of conflicts and cybersquatting linked to these new extensions, while exploring the strategic opportunities they offer. Do not wait for Reveal Day to act: our teams are available to assess the impact of this 2026 gTLD round on your rights and to build a tailored protection strategy with you.

Key takeaways: more than 1,600 applications filed; Reveal Day expected within 9 weeks; WIPO is the exclusive provider for LRO and SCO objections; the Trademark Clearinghouse remains the key tool for preventive trademark protection.

Dreyfus Law Firm assists its clients in managing complex intellectual property cases, offering personalized advice and comprehensive operational support for the complete protection of intellectual property.

Dreyfus Law Firm works in partnership with a global network of attorneys specializing in Intellectual Property.

Nathalie Dreyfus, with the support of the entire Dreyfus team

Q&A

Is a “.brand” extension reserved for large multinationals?

Not by rule, but its cost (application fees starting at US$227,000, plus annual registry operating costs) puts it out of reach for most companies in practice; smaller businesses can sometimes access similar benefits through a shared technical registry partner.

Can a company that did not apply in 2026 still get its own extension later?

There is no guarantee in the short term: ICANN let fourteen years pass between the 2012 and 2026 rounds, with no commitment on when the next cycle will open. Interested companies should monitor ICANN's announcements and plan well in advance.

What happens if a trademark is not recorded with the Trademark Clearinghouse when a new extension launches?

The rights holder loses the benefit of the Sunrise period, which allows registering a matching domain name before the extension opens to the public, and must instead monitor for potentially infringing registrations after the fact, with a higher risk of having to litigate.

Can a small business file a Legal Rights Objection on its own, or is legal representation required?

WIPO's procedure does not require representation by a lawyer, but the technical nature of the arguments involved (proving prior rights, likelihood of confusion, absence of the applicant's legitimate interest) makes specialized counsel strongly advisable.

Can a contention (auction) outcome be appealed?

Legal Rights Objection determinations can be challenged under WIPO's appellate rules applicable to the 2026 Round, in effect since January 1, 2026; by contrast, the outcome of a contention auction between competing applicants is generally not subject to such an appeal.

What is the difference between a String Confusion Objection and an ordinary trademark opposition before the USPTO or EUIPO?

A String Confusion Objection only addresses confusion between two candidate strings before delegation, whereas a trademark opposition concerns the registration of a mark itself and can be filed at any point in that mark's life.

In practice, how long does it take from filing an application to a new extension actually going live?

Experience from the 2012 round shows this varies widely: uncontested extensions were delegated in a little over a year, while those subject to objections or contention procedures sometimes took several additional years.

Read More

Nathalie Dreyfus recognized for trademark law expertise at the Advisory Excellence Awards 2026

Dreyfus & Associés is pleased to announce that Nathalie Dreyfus has been recognized at the Advisory Excellence Awards 2026. She has received the title “Trademark Law Expert of the Year” for France, highlighting her expertise in trademark law.

Nathalie Dreyfus, “Trademark Law Expert of the Year” for France at the Advisory Excellence Awards 2026.
Nathalie Dreyfus, “Trademark Law Expert of the Year”, France, Advisory Excellence Awards 2026.

A distinction in trademark law for France

This recognition forms part of the Annual 2026 Awards organized by Advisory Excellence. It distinguishes Nathalie Dreyfus as “Trademark Law Expert of the Year” for France.

Advisory Excellence is an international network presenting legal and advisory professionals by country and area of expertise. Nathalie Dreyfus’s profile on Advisory Excellence notably outlines her work in trademark law, intellectual property portfolio management and the protection of digital assets.

Supporting clients from trademark protection to enforcement

A French and European trademark attorney, Nathalie Dreyfus founded Dreyfus & Associés in 2004. Together with her teams, she assists companies and their advisers with protecting, managing and enforcing their rights in France and internationally.

This trademark law practice addresses practical issues: preparing a name or product for launch, aligning protection with the relevant markets, organizing a portfolio of rights and responding to infringement. Each decision must take into account the company’s business, its development plans and the risks identified.

Before a filing or launch, clearance searches help identify earlier rights that could create an obstacle. Their analysis informs the choice of a sign and the development of an appropriate protection strategy.

Over time, trademark and domain name monitoring helps identify filings or uses that may infringe the company’s rights. The firm also assists with opposition proceedings, disputes and online trademark enforcement, in coordination with its clients’ legal advisers.

This connection between trademark strategy and the digital environment is central to our work. It allows industrial property rights, domain names and the use of distinctive signs on online platforms to be considered together.

Sharing this recognition with our clients and partners

We welcome this distinction with gratitude and thank our clients, partners and correspondents for the trust they place in us. It is also an opportunity to acknowledge the daily commitment of the firm’s teams to handling matters carefully and maintaining high-quality exchanges with companies and their advisers.

Our commitment continues with the same standards: understanding the issues specific to each project, providing rigorous analysis and developing intellectual property strategies tailored to our clients’ needs.

To discuss the protection, management or enforcement of your trademarks, contact Dreyfus & Associés.

Dreyfus & Associés law firm partners with a global network of lawyers specializing in intellectual property.

Read More

Video games, esports and alternative dispute resolution: join the WIPO and Dreyfus & Associés webinar

WIPO and Dreyfus webinar on video games, esports and alternative dispute resolution, October 7, 2026, featuring Nathalie Dreyfus and Milena Dreyfus.

The global video game market is experiencing sustained growth and is expected to reach USD 198 billion by 2027. Esports is following the same trajectory, with the global market already valued at nearly USD 1.4 billion in 2022. This economic expansion is accompanied by a growing number of stakeholders, business models and contractual relationships surrounding games, competitions, streaming, licensing, sponsorship and intellectual property rights. In an international sector driven by game launches, updates, tournaments and competitive seasons, a dispute can therefore have immediate consequences for the commercial exploitation of a title or the organization of an event, making access to fast, specialized dispute resolution mechanisms tailored to the constraints of the industry particularly important.

Against this backdrop, the WIPO Arbitration and Mediation Center and Dreyfus & Associés are jointly organizing, on Wednesday, October 7, 2026, from 10:00 a.m. to 12:00 p.m. CEST, a free webinar dedicated to alternative dispute resolution in the video game and esports industry. Nathalie Dreyfus and Milena Dreyfus will present the main types of disputes encountered in this sector and examine how mediation, arbitration and domain name dispute resolution procedures can provide effective tools for resolving conflicts involving, in particular, intellectual property, contracts, trademarks, digital content and domain names.

Why video games and esports require tailored dispute resolution mechanisms

A game, platform or tournament rarely depends on a single right or agreement. Software code, engines, graphics, music, characters, databases, trademarks, online identifiers and user-generated content may each be governed by different legal regimes. These assets are connected through contracts between studios, publishers, technical providers, players, teams, organizers, broadcasters, sponsors and platforms. Effective copyright protection therefore requires more than ownership in principle. It also requires a clear chain of title, consistent licensing terms and evidence showing how each contribution may be used.

Esports add a particularly strong time constraint. A challenge concerning player eligibility, tournament rules, streaming rights or a sponsorship obligation may lose much of its practical value if it is resolved after the competition. Stakeholders need to identify the appropriate mechanism quickly, preserve evidence, ensure that each party can present its case and obtain an outcome that remains relevant to the operational calendar.

Which disputes may affect studios, teams, platforms and sponsors?

Licensing, copyright and technology

Disputes may concern the territorial scope of a license, reuse of a character, integration of third-party software, remuneration of a creator, exploitation of music or ownership of work delivered by a contractor. In these matters, assignment clauses, version histories, technical documentation and preserved communications are often decisive. The procedure must enable a decision-maker familiar with industry practices to consider contractual and technical evidence without losing sight of the commercial timetable.

Trademarks, domain names and digital identities

Domain names are also a significant source of disputes in the video game and esports sectors, particularly in cases of cybersquatting or typosquatting targeting the name of a game, studio, team or competition. Such practices may also be used to operate fake ticketing or streaming websites, or even phishing schemes, especially in the run-up to a game launch or tournament. In response to these infringements, alternative dispute resolution mechanisms, such as domain name dispute resolution procedures administered by WIPO, can provide a targeted and appropriate way to address the dispute.

Player agreements, sponsorship, broadcasting and integrity

Relationships between players, clubs, leagues, organizers and commercial partners raise specific issues: duration and termination, image rights, exclusivity, revenue sharing, attendance obligations, broadcasting, disciplinary sanctions and allegations of match manipulation. Private regulations often sit alongside national law, while the relevant relationships may be cross-border. Clear provisions on governing law, procedure and decision-making authority reduce uncertainty when a dispute occurs.

Mediation, arbitration and expert determination: complementary tools

Mediation to preserve a relationship and build an agreement

In the video game and esports sectors, mediation can be particularly appropriate where a dispute arises between parties that are expected to continue working together, for example, a studio and a publisher, a team and a sponsor, or an organizer and a broadcaster. It allows the parties to seek a rapid, negotiated and confidential solution, while preserving their business relationship and taking into account the operational constraints and tight timelines specific to the sector.

Arbitration to obtain a binding decision

Arbitration allows a dispute to be decided by one or more arbitrators selected for their experience. The parties may adapt the language, seat, timetable and certain procedural stages. This flexibility is valuable when technical expertise, multiple agreements or confidential information are central to the case. The resulting award is intended to bind the parties and, depending on the circumstances, may benefit from an international enforcement framework that is more suitable than parallel national proceedings.

Expert determination for a focused issue

Expert determination addresses a defined question, such as conformity of a deliverable, calculation of royalties, compliance with a performance threshold, valuation of an asset or a technical assessment. It may remove a specific obstacle without opening a wider dispute. Its effectiveness depends on the wording of the clause, the expert’s mandate and whether the conclusion is contractually binding.

IGET and WIPO services for video games and esports

The WIPO Arbitration and Mediation Center offers mechanisms that are particularly well suited to the specific constraints of the video game and esports sectors. Mediation, arbitration and expert determination can notably be used to address international, technical or sensitive disputes within a confidential framework and with the support of professionals familiar with the specific features of the industry.

The webinar will also present the International Games and Esports Tribunal (IGET), a joint initiative of ESIC and the WIPO AMC specifically designed for disputes arising in the video game and esports sectors. IGET can notably handle commercial, intellectual property and integrity-related disputes, providing a single framework for parties that may be established in several different jurisdictions.

What participants will gain from the webinar

  • an overview of the video game and esports industries and their most frequent disputes;
  • an explanation of mediation, arbitration and expert determination;
  • an introduction to WIPO services and IGET;
  • practical examples involving domain names and trademark protection;
  • recommendations on dispute resolution clauses and contractual best practices;
  • a question and answer session for participants.

Nathalie Dreyfus and Milena Dreyfus: complementary perspectives

Nathalie Dreyfus, Industrial Property Attorney, founder of the firm, WIPO expert and court-appointed expert accredited by the French Court of Cassation, has many years of experience in trademark strategies, domain names and the resolution of international disputes. Her experience enables her to combine asset protection, risk assessment and the choice of a dispute resolution procedure proportionate to the economic stakes involved.

Milena Dreyfus, IP/IT lawyer with particular expertise in domain names and cybersecurity, works on intellectual property and digital law issues that shape innovative projects. Her contribution provides an approach directly connected to contracts, technological uses and the operational risks specific to digital environments.

Practical example: protecting an international release without losing the timetable

Consider a studio preparing the international release of a game. A few weeks before launch, a third party registers several domain names similar to its trademark and reproduces elements of the campaign, while a business partner challenges the territorial scope of its license. A coordinated response preserves digital evidence, reviews the chain of contracts, prioritizes territories, starts a domain name recovery procedure and structures negotiations with the partner. If the contract provides for it, mediation or arbitration can address the licensing dispute. The objective is to maintain enforceable rights, limit public confusion and preserve the release whenever the legal conditions allow it.

Who should attend?

The webinar is intended for independent studios and publishers, tournament organizers, professional teams and players, platforms, broadcasters and technical providers, as well as sponsors, investors, lawyers and in-house legal teams. It will be particularly useful for professionals who draft or negotiate licenses, production agreements, sponsorship arrangements, tournament rules or dispute resolution clauses.

Practical information

  • Date: Wednesday, October 7, 2026
  • Time: 10:00 a.m. to 12:00 p.m. CEST
  • Format: online
  • Attendance: free, registration required
  • Organized by: WIPO Arbitration and Mediation Center and Dreyfus & Associés
  • Dreyfus panelists: Nathalie Dreyfus and Milena Dreyfus

Register for the webinar

Reserve your place for October 7, 2026. Attendance is free and registration is required. Open the registration form

Frequently asked questions

Should parties wait for a dispute before choosing mediation or arbitration?

No. The best time to organize dispute resolution is during contract negotiations. A clause may provide for an initial discussion period, followed by mediation and, if no agreement is reached, arbitration. It should identify the institution, language, seat, number of arbitrators and, where relevant, an expedited procedure. An unclear clause may create an additional dispute about jurisdiction or procedure.

Which video game disputes are best suited to mediation?

Mediation is useful when the parties need to preserve a relationship, redefine a license, arrange a technical transition or build an outcome that a court or tribunal could not impose in the same terms. It may also take place while another procedure is pending. Its suitability depends on urgency, the balance between the parties, the available evidence and a genuine willingness to negotiate.

Does every domain name dispute fall under the UDRP?

No. The UDRP addresses defined forms of abusive registration and requires specific conditions to be established. The domain name, extension, registrant, use, prior rights and remedy sought must all be assessed. A national procedure, negotiation or court action may be more appropriate. The objective is to select the route that offers the best balance between speed, cost, evidence and the scope of the outcome.

How can confidentiality be protected in a sensitive dispute?

Confidentiality should be addressed in the contract, the applicable rules and, where necessary, specific undertakings governing documents, hearings and the decision. Parties should also secure access to data, limit recipients and define retention arrangements. These safeguards are important when a matter involves source code, a product roadmap, commercial data or information about a security vulnerability.

Why choose Dreyfus & Associés?

Dreyfus & Associés advises businesses on the protection, enforcement and strategic use of trademarks, copyright, domain names and digital assets in France and internationally. This cross-disciplinary perspective is particularly relevant to video games and esports, where a project combines brand identity, creative content, technology, contracts and global exploitation. To review a clause, assess a trademark or domain name strategy, or prepare an alternative dispute resolution matter, contact Dreyfus & Associés for an initial confidential discussion.

Anticipating disputes to protect the project

In video games and esports, the value of an asset depends both on its protection and on the ability to respond when exploitation is threatened. A suitable clause, well-preserved evidence and a coherent dispute resolution mechanism can reduce uncertainty and protect the business timetable. The webinar on October 7, 2026 will give participants practical reference points for selecting the appropriate route and integrating dispute resolution into their intellectual property strategy.

Dreyfus & Associés law firm partners with a global network of lawyers specializing in Intellectual Property.

Read More

EU Digital Services Act: what compliance priorities must companies secure in 2026?

Introduction

Adopted in 2022 and fully effective as of February 17, 2024, the Digital Services Act (DSA) established a harmonized European framework aimed at increasing the accountability of digital intermediaries, better regulating the dissemination of illegal content, products and services, and strengthening the protection of users online.

In 2026, its implementation will enter a particularly practical phase: following an initial period focused on compliance, European authorities are now stepping up their oversight and expect operators to demonstrate the actual effectiveness of the measures they have put in place.

Evolution of the Digital Services Act

Following the widespread implementation of the DSA in February 2024, European authorities have gradually stepped up their effective compliance with the obligations imposed on digital platforms and intermediaries. The challenge for companies is no longer merely to have formally implemented the measures required by the regulation, but to be able to demonstrate that they are effectively implemented, that they enable the identification and mitigation of the risks addressed by the DSA, and that they produce, in practice, the expected compliance results

This shift is reflected in particular by several proceedings and measures adopted by the European Commission against major digital platforms.

In July 2026, the European Commission fined AliExpress 550 million euros for failures in assessing and mitigating risks associated with the sale of illegal, dangerous, or counterfeit products. It also issued preliminary objections to TikTok regarding the default security settings for minors’ accounts and accepted an action plan from X focusing, in particular, on its advertising registry and researchers’ access to data.

The message to operators is clear: automation, the scale of the service, and technical complexity do not exempt companies from identifying risks or demonstrating the effectiveness of corrective measures. The DSA thus becomes a governance issue shared by the legal, compliance, product, IT, and intellectual property departments.

Which companies fall within the scope of the Digital Services Act?

Classification must be carried out service by service

The DSA provides for several levels of classification depending on the nature and role of the digital service in question. In particular, it distinguishes between simple transport, caching, and hosting services. Among hosting services, some may also be classified as online platforms and, when they enable businesses to enter into distance contracts with consumers, as online marketplaces.

The applicable obligations increase progressively depending on the classification chosen. Additional requirements also apply to very large online platforms and very large search engines, VLOPs and VLOSEs, with at least 45 million average monthly active users in the Union.

A single digital product may offer multiple features that fall under different classifications. A SaaS application, for example, may include a private hosting space, a public forum, and a marketplace offering modules developed by third parties. Each feature must therefore be examined separately to precisely identify the applicable obligations.

Non-EU providers may be directly subject to the DSA

The absence of an EU subsidiary does not exclude the Regulation. The DSA applies where a provider offers services to recipients in the Union and maintains a substantial connection with the EU market.

Relevant indicators may include the language used, euro pricing, payment methods, targeted advertising, the size of the European customer base, delivery arrangements and availability through localised app stores. Mere technical accessibility from the EU is not sufficient.

A covered provider with no EU establishment must appoint a DSA legal representative in a Member State where it offers services. This mandate remains legally distinct from the representative required under Article 27 GDPR, even where both roles are entrusted to the same service provider.

In France, Arcom acts as the Digital Services coordinator for Internet services. It operates alongside the DGCCRF and the CNIL under the French Law of May 21, 2024 on securing and regulating the digital environment.

Which DSA obligations must become operational controls?

Notice, action and redress

Article 16 requires hosting providers to operate accessible and sufficiently precise notice-and-action mechanisms. A properly substantiated notice may give the provider actual knowledge of the alleged illegality.

The provider must then assess the report diligently, document its reasoning and explain any restriction imposed. Online platforms must also provide an internal complaints-handling system and inform users about available out-of-court dispute-settlement procedures.

For intellectual property claims, the reporting form should identify:

  • the intellectual property right concerned;
  • the rights holder or authorised representative;
  • the exact URL of the disputed content or listing;
  • the evidence supporting the alleged infringement;
  • the reporting party’s good-faith statement.

Fully automated removal may disregard licences, exceptions or territorial limitations. Conversely, failure to act on a properly substantiated notice may undermine the hosting provider’s conditional liability protection.

Transparency, advertising and recommender systems

Terms and conditions must clearly explain content restrictions, automated moderation tools and the role of human review.

Platforms must also:

  • identify advertisements and the relevant advertiser;
  • disclose the main advertising-targeting parameters;
  • explain the principal parameters of recommender systems;
  • submit statements of reasons to the EU transparency database.

Harmonised transparency-reporting templates have been mandatory since the second half of 2025. The Arcom professional guidance on the DSA explains the reporting and registration framework applicable in France.

VLOPs and VLOSEs must also perform systemic-risk assessments, implement mitigation measures, undergo independent audits and maintain advertising repositories. Since 29 October 2025, the EU data-access framework has allowed vetted researchers to request access to certain internal platform data relevant to systemic risks.

Safety and privacy for minors by default

Article 28 requires platforms accessible to minors to ensure a high level of privacy, safety and security. The Commission’s July 2025 guidelines clarify expectations concerning age assurance, protective default settings, recommender systems, unwanted contact, addictive design and harmful commercial practices.

A contractual age restriction of thirteen or sixteen is not sufficient where no credible mechanism makes it effective. Regulators may consider the actual audience, the information available to the provider, the content offered and the effectiveness of age-assurance measures.

How should companies build a defensible DSA roadmap?

It is recommended for companies to:

  • map every functionality and third-party content flow concerned by the DSA;
  • determine whether the service falls within the territorial scope of the DSA and document the number of active users in the European Union
  • test notices, response times, statements of reasons and appeals;
  • audit traders and controls addressing counterfeit or unsafe products;
  • Incorporate requirements related to minors, advertising, and recommendation systems from the very beginning of service design

retain decision logs, metrics and evidence required by regulators.

Conclusion

The update of the EU Digital Services Act in 2026 confirms that compliance is now measured through system quality, decision traceability and the practical effectiveness of safeguards. Platforms, marketplaces, hosting providers and community services should treat the DSA as a continuous programme coordinated with the GDPR, consumer law and intellectual property enforcement.

Dreyfus Law Firm assists its clients in managing complex intellectual property cases, offering personalized advice and comprehensive operational support for the complete protection of intellectual property.

Dreyfus Law Firm works in partnership with a global network of attorneys specializing in Intellectual Property.

Nathalie Dreyfus, with the support of the entire Dreyfus team

Q&A

Does the DSA apply to companies outside the European Union?

Yes. It may apply where they offer services to recipients in the Union and maintain a substantial connection with the EU market. A provider with no EU establishment must generally appoint an EU legal representative.

Do all online businesses have the same DSA obligations?

No. Duties depend on the service category, functionality, size and whether the service facilitates transactions between professional traders and consumers.

Must a platform remove every reported item immediately?

No. A sufficiently precise notice must be assessed promptly, objectively and proportionately. The DSA does not require automatic removal merely because content has been challenged.

What are the maximum DSA penalties?

An infringement may lead to a fine of up to 6% of annual worldwide turnover. Separate fines and periodic penalty payments may apply to inaccurate information or failure to comply with a regulatory decision.

Does the DSA replace the GDPR?

No. The two regulations apply cumulatively. The GDPR governs personal-data processing, while the DSA regulates intermediary services, content moderation, advertising, recommender systems and certain systemic risks.

How does the DSA support anti-counterfeiting enforcement?

It strengthens notice mechanisms, requires the traceability of professional traders on marketplaces and obliges the largest platforms to assess and mitigate risks involving illegal or counterfeit products.

This publication is intended for general public guidance and to highlight issues. It is not intended to apply to specific circumstances or to constitute legal advice.

Read More

Is your organization equipped with the right cybersecurity policies?

Introduction

Cyberattacks no longer target IT systems alone: they also reach intellectual property assets, trade secrets, customer files and trademark databases. Facing this growing threat, French and European lawmakers have built, over recent years, a demanding framework: the GDPR, the NIS2 Directive, and the recommendations issued by the CNIL and ANSSI. Yet many companies still do not know whether these obligations apply to them, and above all what they must concretely put in place. This article reviews the cybersecurity policies to adopt, the measures authorities expect, and the reporting deadlines that apply in the event of an incident.

A legal framework that depends on the company's status

The intensity of cybersecurity obligations depends primarily on the status of the organization concerned. French law broadly distinguishes between two categories of actors.

Entities of essential importance

Certain organizations engaged in critical activities are subject to enhanced cybersecurity requirements.

  • Operators of vital importance are designated from among those entities whose unavailability or destruction could seriously affect the nation’s security, economy, defense, or the lives of its citizens.
  • Essential service operators, on the other hand, are identified when an incident affecting their networks or information systems could seriously disrupt the provision of a service essential to the functioning of society or the economy.

These operators must, in particular, implement measures related to security governance, the protection of systems and access, the detection and handling of incidents, as well as business continuity and crisis management. They may also be subject to specific obligations to report incidents to ANSSI.

Data controllers and processors

For any organisation, public or private, that processes personal data, article 32 of the GDPR requires the pseudonymisation and encryption of personal data, the ability to ensure the ongoing confidentiality, integrity and availability of processing systems, the ability to restore access to data in the event of a technical incident, and a process for regularly testing and evaluating security measures. These same requirements are echoed and detailed by the CNIL.

Summary table of obligations by company status

Company status Reporting authority Deadline Reference text
Operator of vital importance (OIV) ANSSI Without delay / per sector-specific order Defence Code, article L1332-7
Operator of essential services (OES) ANSSI Without delay NIS Directive, French transposition
Data controller / processor CNIL 72 hours maximum, where feasible GDPR, articles 33 and 34
Essential and important entities (upcoming) ANSSI 24 hours (early warning) then 72 hours Directive (EU) 2022/2555 (NIS2)

The security measures authorities expect from companies

The CNIL and the ANSSI have published practical guidance. The reported incidents show that effective protection depends as much on the implementation of appropriate technical measures as it does on internal organization and staff awareness.

The essential baseline

  • keep software and systems up to date in order to promptly address known vulnerabilities;
  • require strong and unique credentials for each user account;
  • strengthen the security of professional email accounts;
  • regularly raise employees’ awareness of the main cybersecurity risks and fraud attempts;
  • implement frequent backups, ensuring that at least one copy is kept isolated from systems accessible online.

Advanced protective measures

  • implement multi-factor authentication for sensitive access, particularly remote access;
  • assign individual accounts to employees, partners, and service providers in order to avoid credential sharing;
  • restrict network access to devices that have been previously authorized or authenticated;
  • deploy monitoring mechanisms to quickly detect unusual behavior or connections.

Documenting every incident: an obligation too often overlooked

The GDPR requires data controllers to keep a record of every data breach, its effects and the remedial measures taken (articles 33(5) and 34). This record allows supervisory authorities to verify compliance in the event of an audit. Processors, for their part, must assist the controller and keep appropriate internal documentation. The law does not set a precise retention period: in practice, the record should be kept for as long as the legal risk exists.

Reporting a breach or incident: to whom, and within what deadlines?

To the CNIL, for personal data

Three types of incidents must be reported: a confidentiality breach (unauthorised disclosure of or access to data), an availability breach (loss or destruction of data), and an integrity breach (unauthorised alteration of data). Notification must occur within 72 hours of the company becoming aware of the breach, where feasible, via the CNIL's online notification service.

To ANSSI, for entities of essential importance

Operators of vital importance must report any incident affecting their vital information systems, following the procedures set out in the relevant sector-specific order (OIV incident reporting form).

Operators of essential services must, in turn, report any incident likely to have a significant impact on the continuity of their services (OES incident reporting form).

Shorter deadlines ahead under the NIS2 Directive

Directive (EU) 2022/2555, known as NIS2, not yet transposed into French law at the time of writing, requires essential and important entities to submit an initial notification, known as an 'early warning', without undue delay and within 24 hours of becoming aware of a significant incident, followed by a full notification within 72 hours. These timelines may be further specified by the national implementing measures.

Checklist: the first 5 actions in the event of an incident

  • Qualify the incident: does it affect confidentiality, availability or integrity of the data?
  • Identify whether the company is a controller, a processor, an OIV or an OES.
  • Start the clock: 24 hours (NIS2 early warning) or 72 hours (GDPR).
  • Document the facts, effects and remedial measures in a dedicated register.
  • Notify the competent authority using the appropriate form, then inform data subjects if the risk is high.

Informing data subjects and the public

Where a personal data breach is likely to result in a high risk to the rights and freedoms of individuals, the company must also inform the data subjects directly, unless the CNIL considers that appropriate measures have rendered the data unintelligible to any unauthorised third party. This communication may take several forms: direct messaging (email, SMS), a prominent website banner or notification, postal mail, or an announcement in the print media.

Conclusion

Putting the right cybersecurity policies in place is no longer optional: depending on its status, a company is subject to the GDPR, to reinforced sector-specific obligations, or soon to the NIS2 Directive. The essential measures remain within reach of any organisation, regardless of size. In the event of an incident, how quickly it is qualified and reported largely determines the scale of the legal and reputational consequences.

Dreyfus Law Firm assists its clients in managing complex intellectual property matters by providing tailored advice and comprehensive operational support to ensure the full protection of intellectual property rights.

Dreyfus Law Firm works in partnership with a global network of intellectual property attorneys.

Nathalie Dreyfus, with the assistance of the entire Dreyfus team.

Q&A

What happens if a company fails to report a breach on time?

It may face CNIL fines of up to €20 million or 4% of global annual turnover, in addition to potential compensation claims from affected individuals.

Do these obligations apply to small businesses too?

Yes. The size of a company does not exempt it from its obligations under the GDPR where it processes personal data. However, certain enhanced obligations depend on the nature of its activities, the types of processing carried out, or the status of the organization.

Is appointing a Data Protection Officer mandatory?

The appointment is mandatory for public authorities and bodies, for organizations whose core activities involve regular and systematic monitoring of individuals on a large scale, and for those that process sensitive data or data relating to criminal convictions and offences on a large scale.

Does the 72-hour deadline still apply if the incident occurs at a service provider or processor?

Yes, the processor must alert the controller without undue delay upon becoming aware of the incident, so the controller can still meet the CNIL notification deadline.

Does missing the 72-hour deadline automatically trigger a penalty?

No, the CNIL assesses the circumstances of each case; a justified and documented delay is treated differently from a complete failure to notify.

Should a company maintain an out-of-hours on-call rotation to meet these deadlines?

It is not an explicit legal requirement, but it is strongly advisable in practice, since regulatory deadlines run continuously, including weekends and public holidays.

This publication is intended for general public guidance and to highlight issues. It is not intended to apply to specific circumstances or to constitute legal advice.

Read More

Collective trademark or guarantee trademark: which should you choose to protect a shared sign?

Introduction

A collective trademark or guarantee trademark should be selected according to the legal promise made to the public. Where the sign tells consumers that an operator belongs to an organised group, the collective trademark is generally appropriate. Where it indicates that goods or services satisfy defined characteristics controlled by a proprietor that remains independent from supplying them, the French guarantee trademark is the relevant tool. This classification determines who may file, how the regulations of use must be drafted, how authorised users are supervised and, ultimately, whether the right remains defensible. The French trademark reform introduced by Ordinance No. 2019-1169 of November 13, 2019, which entered into force on December 15, 2019, notably overhauled the collective trademark regime by expressly distinguishing certification trademarks from collective trademarks, each of which is now governed by a separate legal framework. The chosen status must be expressly indicated at the time of filing. It is therefore important to determine the intended function of the sign in advance, before defining its name, logo or governing regulations.

What is the difference between a collective trademark and a guarantee trademark?

A collective trademark identifies membership of an organised group

Article L. 715-6 of the French Intellectual Property Code defines a collective trademark as a trademark distinguishing the goods or services of persons authorised to use it under its regulations of use. Its core function is therefore to indicate a collective commercial origin: the user belongs to the association, network or group that owns the trademark. The regulations may impose strict membership and use requirements, but the trademark is not primarily designed to certify an objectively defined level of quality.

A guarantee trademark attests to controlled characteristics

Under Article L. 715-1 of the French Intellectual Property Code, a French guarantee trademark distinguishes goods or services whose material, method of manufacture or performance, quality, accuracy or other characteristics are guaranteed. The proprietor must remain neutral and may not carry on a business supplying goods or services of the same kind as those guaranteed. The 2019 reform deliberately replaced the former French expression “collective certification trademark” with “guarantee trademark” to avoid confusion with conformity certification under French law.

Which practical test should be applied before filing?

  • “This operator belongs to our network”: a collective trademark will usually reflect the intended function.
  • “This product or service complies with a verified standard”: a guarantee trademark will generally be more coherent.
  • The future proprietor itself supplies the same type of goods or services: a guarantee trademark is legally unsuitable.

Who may own and use these trademarks?

A collective trademark requires a legally organised collective

Article L. 715-7 of the French Intellectual Property Code limits ownership to associations or groups with legal personality representing manufacturers, producers, service providers or traders, and to legal persons governed by public law. A standalone trading company does not become eligible merely because it wishes to let several commercial partners use the same sign.

A guarantee-trademark proprietor must remain independent over time

Any natural or legal person, including a public-law entity, may apply for a French guarantee trademark provided that it does not supply goods or services of the same kind as those guaranteed. The requirement continues after registration: losing that neutrality may expose the trademark to revocation. The proprietor does not necessarily have to be an accredited certification body, accreditation information is required where the applicable legislation makes the corresponding certification mandatory. The INPI expressly distinguishes guarantee, control and collective membership.

How should legally robust regulations of use be drafted?

The regulations of use are both the legal charter for the sign and the operational benchmark for control. Articles R. 715-1 and R. 715-2 require both categories to identify:

  • the proprietor,
  • representation of the trademark,
  • goods and services,
  • authorised users,
  • conditions of use,
  • sanctions.

A collective trademark must also state the purpose of the group, its representative bodies and, where relevant, membership conditions. A guarantee trademark must describe the guaranteed characteristics, verification method, monitoring of use and any legally required accreditation data.

In practice, we seek a genuine mirror effect between the sign, the specification of goods and services and the regulations. A sign suggesting a “label” or certification without a coherent control mechanism may mislead the public. Conversely, rules drafted with excessive technical detail can freeze the scheme and generate repeated non-compliance. They should be precise enough to audit, operational enough to enforce and flexible enough to evolve. Later amendments must be notified to the INPI, and the proprietor must take reasonable measures against non-compliant use if the right is to remain secure.

How can a filing be secured in France and the European Union?

The legal classification should be settled before filing. Beyond the special regulations, the sign must also meet the ordinary validity requirements for trademarks. We therefore recommend a prior-rights review and an accurate goods-and-services strategy. Our trademark law page sets out the principal checks to carry out before registration.

At EU level, the functional counterpart of the French guarantee trademark is the European Union certification trademark. The EUIPO also imposes a neutrality requirement and specifies that an EU certification trademark cannot certify the geographical origin of goods or services. Regulations of use must be filed within two months of the application. An EU filing therefore requires a fresh review of the sign, proprietor, certification scheme and any potential conflict with protected designations of origin or geographical indications.

Before filing, we verify five points:

Conclusion

Choosing between a collective trademark and a guarantee trademark means choosing a governance architecture. The first federates members around a collective commercial origin; the second gives credibility to a promise concerning verifiable characteristics under the responsibility of an independent proprietor. Accurate classification, workable regulations of use and genuine supervision are the three conditions that turn the sign into a durable asset rather than a source of legal vulnerability.

Dreyfus Law Firm assists its clients in managing complex intellectual property cases, offering personalized advice and comprehensive operational support for the complete protection of intellectual property.

Dreyfus Law Firm works in partnership with a global network of attorneys specializing in Intellectual Property.

Nathalie Dreyfus, with the assistance of the entire Dreyfus team.

Q&A

Can a collective trademark or guarantee trademark be assigned to a third party?

An assignment is possible only if the assignee satisfies the statutory eligibility rules for the relevant category. A guarantee-trademark assignee must in particular remain independent from the supply of the guaranteed goods or services, while a collective-trademark assignee must have the legal status required to own that type of trademark.

What should be done when a former member continues to use a collective trademark?

The regulations of use, evidence that membership has ended and the manner in which the sign continues to be used should be reviewed immediately. Depending on the circumstances, a cease-and-desist letter, the contractual or regulatory sanctions provided for by the scheme, and trademark enforcement may be appropriate.

Can a French guarantee trademark be extended unchanged as an EU certification trademark?

Automatic transposition is risky. The EUIPO applies its own substantive requirements, including the exclusion of geographical origin from the certification function. The sign, specification, proprietor’s status and regulations of use should therefore be re-audited before an EU application is filed.

Can a collective trademark contain a geographical indication?

The answer depends on the territory and the function of the sign. EU trademark law provides a specific route for certain geographical indications in collective trademarks, whereas the French 2019 reform did not adopt the corresponding derogation from the distinctiveness requirement. Existing PDO and PGI rights must in all cases be cleared before filing.

How often should the regulations of use be audited?

No single statutory timetable replaces a risk-based review. An audit is particularly appropriate when new users join, the technical standard changes, control procedures are modified, territorial protection is extended or the proprietor changes its own commercial activities.

This publication is intended for general public guidance and to highlight issues. It is not intended to apply to specific circumstances or to constitute legal advice.

Read More