Articles (by year)
Journal Articles
A question of strategic legislation: Can the EU deal with cybersecurity issues in space? Journal Article
In: Telecommunications Policy, vol. 49, no. 5, pp. 102954, 2025, ISSN: 0308-5961.
Democratic legitimacy of AI in judicial decision-making Journal Article
In: AI & Society, 2025, ISSN: 0951-5666.
The AI Act and a (sorely missing!) right to AI individualization; Why are we building Skynet? Journal Article
In: European Law Blog, 2024.
Five years after the annus mirabilis for EU data protection: Where we stand and the outlook ahead Journal Article
In: Technology and Communications Law - DITE, pp. 35–47, 2024.
Codes of conduct in German employment relationships – A measure to adequately implementing compliance and data protection? Journal Article
In: European Business Law Review, pp. 157–182, 2024, ISSN: 0959-6941.
Does the future hold more rights or more proportionality? Journal Article
In: European Data Protection Law Review, vol. 9, no. 4, pp. 393–398, 2023, ISSN: 23642831 2364284X.
In: Computer Law & Security Review, vol. 51, pp. 105869, 2023, ISSN: 2212-473X.
The (new) role of states in a ‘States-As-Platforms’ approach Journal Article
In: 2023.
Il caso Clearview Ai: uno stress test per il Regolamento generale per la protezione dei dati e la proposta di Regolamento sull'intelligenza artificiale in relazione alle nuove sfide poste dal riconoscimento facciale Journal Article
In: Ciberspazio e diritto: rivista internazionale di informatica giuridica, pp. 43–58, 2023, ISSN: 2281-1028.
Surveillance in schools across Europe: A new phenomenon in light of the COVID-19 pandemic? The cases of Greece and France Journal Article
In: European Journal of Educational Research, vol. 11, no. 2, pp. 1219–1229, 2022.
Cybersecurity as praxis and as a state: The EU law path towards acknowledgement of a new right to cybersecurity? Journal Article
In: Computer Law & Security Review, vol. 44, pp. 1–14, 2022, (Open Access).
States as platforms following the new EU regulations on online platforms Journal Article
In: European View, vol. 21, no. 2, pp. 214–222, 2022.
The cybersecurity obligations of states perceived as platforms: Are current European national cybersecurity strategies enough? Journal Article
In: Applied Cybersecurity & Internet Governance (ACIG), vol. 1, no. 1, pp. 1–12, 2022.
The regulation of digital Technologies in the EU: The law-making phenomena of “act-ification”, “GDPR mimesis” and “EU law brutality” Journal Article
In: Technology and Regulation, vol. 2022, pp. 48–60, 2022.
In: Computer Law & Security Review, vol. 40, pp. 1–12, 2021, ISSN: 2212-473X.
Digitalisation of water services and the water sector cyber threat landscape: Is the EU regulatory framework adequate? Journal Article
In: Journal of Water Law, vol. 27, no. 4, pp. 119–133, 2021.
In: Computer Law & Security Review, vol. 41, pp. 1–12, 2021, ISSN: 2212-473X.
The act-ification of EU law: The (long-overdue) move towards eponymous EU legislation Journal Article
In: European Law Blog, 2021.
Post GDPR EU laws and their GDPR mimesis. DGA, DSA, DMA and the EU regulation of AI Journal Article
In: European Law Blog, 2021.
EU lawmaking in the Artificial Intelligent Age: Act-ification, GDPR mimesis, and regulatory brutality Journal Article
In: European Law Blog, 2021.
EU sanctions against cyber-attacks and defense rights: Wanna Cry? Journal Article
In: European Law Blog, 2020.
In: Computer Law & Security Review, vol. 36, 2020, ISSN: 2212-473X.
Data protection and the EPPO Journal Article
In: New Journal of European Criminal Law, vol. 10, no. 1, pp. 34–43, 2019, (Open Access).
The new EU cybersecurity framework: The NIS Directive, ENISA's role and the General Data Protection Regulation Journal Article
In: Computer Law & Security Review, vol. 35, no. 6, 2019, ISSN: 2212-473X.
The right to data portability in the GDPR: Towards user-centric interoperability of digital services Journal Article
In: Computer Law & Security Review, vol. 34, no. 2, pp. 193–203, 2018, (Open Access).
Structuring modern life running on software. Recognizing (some) computer programs as new “digital persons” Journal Article
In: Computer Law & Security Review, vol. 34, no. 4, pp. 732–738, 2018, ISSN: 2212-473X.
The rich UK contribution to the field of EU data protection: Let's not go for “third country” status after Brexit Journal Article
In: Computer Law & Security Review, vol. 33, no. 3, pp. 354–360, 2017, ISSN: 2212-473X.
The new General Data Protection Regulation: Still a sound system for the protection of individuals? Journal Article
In: Computer Law & Security Review, vol. 32, no. 2, pp. 179–194, 2016, ISSN: 0267-3649.
The new Police and Criminal Justice Data Protection Directive: A first analysis Journal Article
In: New Journal of European Criminal Law, vol. 7, no. 1, pp. 7–19, 2016.
The cloud computing standard ISO/IEC 27018 through the lens of the EU legislation on data protection Journal Article
In: Computer Law & Security Review, vol. 32, no. 1, pp. 16–30, 2016, ISSN: 2212-473X.
The future of privacy certification in Europe: An exploration of options under article 42 of the GDPR Journal Article
In: International Review of Law, Computers & Technology, vol. 30, no. 3, pp. 248–270, 2016, ISSN: 1360-0869, (doi: 10.1080/13600869.2016.1189737).
In: New Journal of European Criminal Law, vol. 6, no. 2, pp. 160–165, 2015, ISSN: 2032-2844.
Google Spain: Addressing critiques and misunderstandings one year later Journal Article
In: Maastricht Journal of European and Comparative Law, vol. 22, no. 4, pp. 624–638, 2015.
The Council of Europe Data Protection Convention reform: Analysis of the new text and critical comment on its global ambition Journal Article
In: Computer Law & Security Review, vol. 30, no. 6, pp. 633–642, 2014, ISSN: 02673649.
Three scenarios for international governance of data privacy: Towards an international data privacy organization, preferably a UN agency? Journal Article
In: I/S: A Journal of Law and Policy for the Information Society, vol. 9, no. 2, pp. 271–327, 2013.
The proposed Regulation and the construction of a principles-driven system for individual data protection Journal Article
In: Innovation: The European Journal of Social Science Research, vol. 26, no. 1-2, pp. 133–144, 2013, ISSN: 1351-1610 1469-8412.
The proposed data protection Regulation replacing Directive 95/46/EC: A sound system for the protection of individuals Journal Article
In: Computer Law & Security Review, vol. 28, no. 2, pp. 130–142, 2012, ISSN: 02673649.
The police and criminal justice data protection directive: Comment and analysis Journal Article
In: Computers and Law - UK Society for Computers & Law, vol. 22, no. 6, pp. 21, 2012, ISSN: 0140-3249.
Legal challenges posed by online aggregation of museum content: The cases of Europeana and the Google Art Project Journal Article
In: SCRIPTed, vol. 9, no. 3, pp. 314–339, 2012.
The amended EU law on ePrivacy and electronic communications after its 2011 implentation; New rules on data protection, spam, data breaches and protection of intellectual property rights Journal Article
In: UIC John Marshall Journal of Information Technology & Privacy Law, vol. 29, no. 1, pp. 29–74, 2011, ISSN: 1078-4128.
The EU PNR framework decision proposal: Towards completion of the PNR processing scene in Europe Journal Article
In: Computer Law & Security Review, vol. 26, no. 4, pp. 368–376, 2010, ISSN: 02673649.
In: Computer Law & Security Review, vol. 25, no. 5, pp. 403–414, 2009, ISSN: 02673649.
The PNR Agreement and transatlantic anti-terrorism cooperation: No firm human rights framework on either side of the Atlantic Journal Article
In: Common Market Law Review, vol. 46, no. 3, pp. 885–919, 2009, ISSN: 0165-0750.
The agreement on Passenger-Data Transfer (PNR) and the EU-US cooperation in data communication Journal Article
In: International Migration, vol. 46, no. 2, pp. 187–197, 2008, ISSN: 0020-7985.
A data protection approach to data matching operations among public bodies Journal Article
In: International Journal of Law and Information Technology, vol. 9, no. 1, pp. 39–64, 2001, ISSN: 1464-3693.
Book chapters
Book Chapters
In: gen. Döhmann, Indra Spiecker; Mendes, Laura Schertel; Campos, Ricardo (Ed.): Digital constitutionalism, pp. 365–382, Nomos, Baden Baden, 2025.
States as information platforms: A political theory of information Book Chapter
In: Matsumi, Hideyuki; Hallinan, Dara; Dimitrova, Diana; Kosta, Eleni; Hert, Paul De (Ed.): Data protection and privacy, Volume 16: Ideas that drive our digital world, pp. 187–209, Bloomsbury Publishing, London, 2024.
Spiros Simitis – his legacy: Europeanisation and internationalisation Book Chapter
In: gen. Döhmann, Indra Spiecker; Weiss, Manfred (Ed.): Spiros Simitis – sein Vermächtnis, pp. 91–106, Nomos, Baden Baden, 2024.
The Right to be Forgotten Book Chapter
In: Comandé, Giovanni (Ed.): Elgar Encyclopedia of Law and Data Science, pp. 175–181, Elgar, London, 2022.
The need to introduce a new individual right to cybersecurity Book Chapter
In: Martino, Luigi; Gamal, Nadia (Ed.): European cybersecurity in context: A policy-oriented comparative analysis, pp. 77–83, ELF, Brussels, 2022.
The proposed ePrivacy regulation: The Commission‘s and the Parliament‘s draft s at a crossroads? Book Chapter
In: Hallinan, Dara; Leenes, Ronald; Gutwirth, Serge; Hert, Paul De (Ed.): Data Protection and Privacy - Data Protection and Democracy, pp. 267–298, Hart, London, 2020.
Should we be afraid of fake news? Book Chapter
In: Terzis, Georgios; Kloza, Dariusz; Kuzelewska, Elzbieta; Trottier, Daniel (Ed.): Disinformation and digital media as a challenge for democracy, Cambridge, Amsterdam, 2020.
In: Servent, Ariadne Ripoll; Trauner, Florian (Ed.): The Routledge Handbook of Justice and Home Affairs Research, pp. 169–179, Routledge, 2017.
In: Svantesson, Dan; Kloza, Dariusz (Ed.): Trans-atlantic data privacy relations as a challenge for democracy, pp. 521–533, Intersentia, Cambridge, 2017.
Data protection: The EU institutions’ battle over data processing vs individual rights Book Chapter
In: Trauner, Florian; Servent, Ariadne Ripoll (Ed.): The EU institutions’ battle over data processing vs individual rights, pp. 178–197, Routledge, London, 2015.
The EDPS as a unique stakeholder in the European data protection landscape, fulfilling the explicit and non-explicit expectations Book Chapter
In: Hijmans, Hielke; Kranenborg, Herke (Ed.): Data protection anno 2014: How to restore trust? Contributions in honour of Peter Hustinx, European Data Protection Supervisor (2004-2014), pp. 237–252, Intersentia, Brussels, 2014, ISBN: 978-1-78068-213-6.
Intellectual property rights: The security perspective Book Chapter
In: Jahankhani, Hamid (Ed.): Handbook of electronic security and digital forensics, pp. 477–495, World Scientific, London, 2010, ISBN: 9812837035.
Cyberspace and cybercrime Book Chapter
In: Jahankhani, Hamid (Ed.): Handbook of electronic security and digital forensics, pp. 455–475, World Scientific, London, 2010, ISBN: 9812837035.
Data protection in the third pillar: Cautious pessimism Book Chapter
In: Maik, Martin (Ed.): Crime, rights and the EU: The future of police and judicial cooperation, pp. 121–194, Justice, London, 2008, ISBN: 978-0-907247-44-9.
Legal issues for Digital Rights Management: The future Book Chapter
In: Drossos, Lambros; Tsolis, Dimitrios; Sioutas, Spyros; Papatheodorou, Theodore (Ed.): Digital Rights Management for E-Commerce Systems, IGI Global, London, 2008, ISBN: 1605661198.