The European Union offers one of the world's most comprehensive frameworks for protecting data as an asset, layering copyright, a sui generis database right, harmonized trade secret protection, contract law, and extensive data regulation. The Database Directive (96/9/EC) grants copyright to databases whose selection or arrangement is the author's own intellectual creation and — the most extensive such regime among surveyed jurisdictions — a sui generis right protecting substantial investment in obtaining, verifying, or presenting data, which can be transferred or licensed for a period of 15 years.
CJEU case law defines the contours of both rights. Football Dataco v. Yahoo! and Infopaq require personal creative judgment for copyright, excluding purely machine-generated databases, while British Horseracing Board v. William Hill and Fixtures Marketing v. OPAP confine sui generis protection to investment in structuring the database rather than creating its contents. CV-Online Latvia v. Melons confirmed that systematic scraping can infringe. The Trade Secrets Directive (2016/943) harmonizes protection of confidential business information across Member States, making enforcement more predictable.
Recent legislation extends the regime to AI and non-personal data. The Digital Single Market Directive permits text and data mining for scientific research and, subject to opt-out, for commercial purposes — applied in Kneschke v. LAION to the compilation of AI training datasets (affirmed OLG Hamburg, 10 Dec 2025; BGH appeal pending). The GDPR governs personal data, the Data Act and Data Governance Act address non-personal data sharing and portability, and the AI Act will impose documentation, transparency, and data governance duties on high-risk systems from 2 December 2027 / 2 August 2028 (Reg (EU) 2026/1744), including requirements that training data be relevant, sufficiently representative, and as far as possible free of errors, with bias examined and mitigated.
Key takeaways
- The EU's sui generis database right protects substantial investment for 15 years regardless of originality — the broadest and most litigated such right among surveyed jurisdictions (the UK retains a parallel right post-Brexit; Mexico grants five years for non-original databases).
- Sui generis protection covers investment in structuring a database, not in generating its underlying content, so owners should document curation and verification efforts.
- The Trade Secrets Directive harmonizes protection across Member States, but cross-border enforcement still runs through national procedural rules.
- Text and data mining exceptions under the DSM Directive permit AI training on protected material unless rights holders opt out of commercial use.
- Businesses should combine sui generis rights with contracts, technical barriers, and trade secret strategies, as scraping and AI-training litigation remains unsettled.
Primary legal instruments
AI-assisted summary of the report, editorially reviewed before publication · AI transparency
Protection mechanisms
Report-derived analysis per mechanism. The report text is fixed; committee members with contributor access can revise the rating (with an audit trail) and add notes below each block.
Recent Developments
Live updates contributed by committee members and the AI research bot — separate from the fixed report content above.
Digital Omnibus on AI adopted: Parliament and Council rewrite AI Act deadlines and transparency rules
The European Parliament approved the Digital Omnibus on AI on 16 June 2026 (with Council final sign-off on 29 June), amending the AI Act before its high-risk regime took effect. The regulation pushes high-risk obligations to December 2027 for standalone systems and August 2028 for embedded systems, sets a December 2026 deadline for machine-readable labelling of AI-generated content, bans nudification and CSAM-generating tools, and allows processing of personal data for AI bias detection and correction under safeguards. These changes reset the compliance timeline for organisations governing AI training and output data in the EU.
CJEU Grand Chamber hears first generative-AI copyright case, Like Company v Google (C-250/25)
On 10 March 2026 the CJEU's Grand Chamber heard its first case squarely addressing generative AI and EU copyright law, a Hungarian referral by news publisher Like Company against Google over its Gemini chatbot. The questions ask whether training an LLM on press content is an act of reproduction, whether the text-and-data-mining exception in the DSM Directive covers such training, and whether chatbot outputs reproducing press publications infringe publishers' rights. The European Copyright Society filed an opinion urging the Court to rule cautiously given the reference's imprecise description of how LLMs work, and a judgment is expected toward late 2026.
EDPB and EDPS issue Joint Opinion on Digital Omnibus reshaping EU data legislation and AI training rules
The EDPB and EDPS published a Joint Opinion on the Commission's Digital Omnibus package, which proposes folding the Data Governance Act and Open Data Directive into the Data Act and amending the GDPR, including provisions easing the use of personal data for AI development. The regulators back consolidation of the data acquis and a derogation for incidental processing of sensitive data in AI systems, but strongly object to narrowing the definition of personal data, warning it departs from CJEU case law. The opinion is a key signal for how the restructuring of EU data-sharing and AI-training law will be negotiated.