Influencer marketing has evolved from a trend into a well-established tool within brands’ digital strategies. In 2023, online investment in this area grew by 23.9%, prompting a thorough review of the applicable regulatory framework. In this context, the new Code of Conduct for Advertising Through Influencers represents a significant update from previous versions, incorporating both obligations and recommendations for companies, agencies, and influencers.
The new Code expands its scope to include new stakeholders, such as “users of particular significance” as defined in the General Law on Audiovisual Communication, and incorporates requirements stemming from the Digital Services Regulation. In addition, it incorporates the interpretive doctrine established by the Advertising Board over the past five years, which provides greater clarity and legal certainty to the sector.
Its main objective is to ensure that advertising by influencers is identifiable, transparent, and responsible, thereby preventing disguised advertising. Unlike the previous version, it eliminates the requirement for editorial control as a condition for classifying content as advertising. Now, only two elements need to be present: the content must have a clear advertising purpose, and it must be disseminated as part of a collaboration involving some form of compensation.
Companies that partner with influencers should pay special attention to two key aspects:
Although the legal framework is uniform, its practical application varies by social media platform. The Code recommends using the specific features offered by platforms to indicate that content is advertising. For example:
However, these functions are not uniform, which leads to differences in how the requirements are met. It is essential that the disclosure be clear, immediately apparent, and appear at the beginning of the message, ensuring that it is not hidden among hashtags or requires additional action on the user’s part to be seen.
Following the entry into force of the new Code, it is essential that agreements with influencers include clear provisions to ensure compliance with legal and self-regulatory obligations:
These clauses not only reduce legal risks, but also protect the brand's reputation and enhance transparency for consumers.
The Code clearly and fairly defines the division of liability between the company and the influencer. All parties may be held liable in the event of a breach, although the company may be exempt from liability if it demonstrates that the violation was a one-time, clear-cut action by the influencer that contravened specific instructions.
When advertising content is disseminated solely at the influencer’s initiative, without any involvement or intervention by the company, responsibility lies solely with the influencer or their agents.
This new framework provides greater legal certainty for companies by precisely defining the circumstances under which they may be held liable. However, it requires rigorous oversight of partnerships to mitigate risks.
Cristina Espín, Senior Associate in the Legal Department (Business and Contracts) at Elzaburu.
Artificial intelligence (AI) is no longer just a technological experiment; it has become part of the day-to-day work of legal professionals. From searching for case law to analyzing contracts, AI-based tools have been integrated into law firms’ work, changing the way information is organized and legal advice is provided. But their adoption forces us to rethink what it means today to practice law with rigor, transparency, and efficiency.
The Madrid Bar Association has developed an ICAM Guide to Best Practices for the Use of Artificial Intelligence in the Legal Profession, which we summarize in this article and which can help us use artificial intelligence responsibly in the legal field.
The first mistake is to delegate tasks to AI without understanding how it works. Before implementing any tool, it is necessary to understand what it does, what its limitations are, and in which scenarios this technology truly adds value. Tech literacy has become an essential skill for the modern lawyer: knowing what biases a model may carry, how its results are trained, and what risks its use entails.
Not everything can or should be automated. AI has already proven useful in tasks such as document classification and summarizing legal texts. However, other activities—such as interpreting regulations or defining a litigation strategy—require human judgment and should not be outsourced to an algorithm. The golden rule: use technology to gain agility, without compromising the quality of legal advice or client confidentiality.
Today's lawyers need to be proficient in both legal and technical language. This involves training teams, establishing usage protocols, and fostering a culture in which AI is viewed as a support tool, not a replacement. It is about combining legal precision with technical expertise to build client trust.
Integrating AI into a law firm requires defining responsibilities and controls. Which tools are authorized? Who audits their results? How is the traceability of information ensured? Answering these questions is not a mere bureaucratic formality, but a measure to protect the firm’s professional standing and reputation. A mistake in this area not only creates legal risks but can also seriously undermine the firm’s credibility.
The European Artificial Intelligence Regulation (AI Act) marks a turning point. It establishes risk categories, requires transparency, and mandates that decisions made by AI systems be documented. For law firms, this means auditing tools, assessing risks, and recognizing that the responsible management of technology is part of professional diligence.
The impact of AI is not limited to internal practices; it also shapes what clients demand. Companies across all sectors use it in hiring, recruitment, and data management processes. Lawyers must translate technological risks into legal risks and ensure that solutions are explainable and auditable. This role goes beyond mere compliance: it is about preserving trust and reputation.
Speed must not come at the expense of rigor. Every decision regarding the use of AI must be documented and communicated honestly. Professional ethics, in this context, are demonstrated both in the arguments presented and in the way technological tools are used.
Artificial intelligence is no longer a “possible future,” but a reality in law firms. Its responsible use requires knowledge, prudence, and strategic vision. Rather than a threat, it is an opportunity: the opportunity to modernize the practice of law without compromising the values that have always defined the profession.
Mabel Klimt, managing partner.
For the first time, the U.S. Copyright Office (USCO) has recognized copyright protection for an image generated by artificial intelligence. The work, titled *A Single Piece of Cheese*, marks a milestone in the history of intellectual property and sparks a debate about the future of copyright in the age of AI.
Kent Keirsey, CEO of Invoke—the platform used to generate the image— announced this historic achievement on his social media accounts:
"We have played a small role in the history of U.S. copyright by securing the first copyright for a single image created exclusively with AI-generated content."
This case is significant because, until now, the U.S. Copyright Office had refused to register works generated by artificial intelligence, citing the lack of human involvement in the creative process.
The key to legal recognition in this case lies in human intervention within the creative process. Specifically, the selection, coordination, and arrangement of AI-generated elements have been recognized, demonstrating a level of involvement that has transformed the work into something distinctly human.
The creation of "A Single Piece of Cheese " was not limited to simply having an AI automatically generate the image. Using the Invoke platform, the original image was modified and retouched through the following process:
It was this series of artistic interventions that led the USCO to reconsider the protection of the work in January 2025 (following the rejection of the application in September 2024).
The U.S. Copyright Office (USCO) has previously reviewed copyright applications related to works created using artificial intelligence, although with different results than in this case:
Jason Allen used the Midjourney tool to create the work *Théâtre D’Opéra Spatial* (2022), but his application was rejected because he failed to demonstrate a sufficient level of human involvement.
In 2023, Kris Kashtanova was granted rights recognition for the story and visual composition of her graphic novel *Zarya of the Dawn*, but not for the AI-generated illustrations.
That same year, in the Rose Enigma case, protection was granted only to the portion based on a prior hand-drawn sketch by Kashtanova, while the elements added by artificial intelligence were excluded from protection.
In all of these examples, the USCO reaffirmed that artificial intelligence cannot be considered an author in its own right and that protection is granted only when there is clear and significant human involvement in the creation of the work.
In the European Union, there is still no official ruling by courts or intellectual property registries recognizing copyright in works generated by artificial intelligence. However, the recognition of copyright in A Single Piece of Cheese marks a turning point in the relationship between AI and intellectual property.
In this context, it is likely that European case law will, in the future, gradually define the interpretive criteria for determining the minimum level of human involvement required for a work generated by AI to be protected.
At ELZABURU, specialists in intellectual property, we closely monitor these developments and are ready to advise creators and companies on protecting their rights in the digital environment. Contact us for more information on how to protect your creations under current law.
Agustín Alguacil, Associate in the Legal at Elzaburu.
In an effort by lawmakers to bring Spain’s legal framework up to date with the new dynamics of the audiovisual market—which has been significantly affected by technological advancements and the emergence of new players— Royal Decree 444/2024 (“RD”) came into effect on May 2; it was approved on April 30 by the Council of Ministers and regulates the requirements for determining who qualifies as a “user of special relevance” on video-sharing platforms, also known as influencers.
The regulation also aims to align with Directive (EU) 2018/1808, which, while not explicitly including influencers, gave Member States the freedom to regulate this category, recognizing their growing importance in the dissemination of audiovisual and advertising content. This inclusion seeks to ensure, among other things, the protection of users—especially minors—from content that is potentially harmful and could affect their physical, mental, or moral development.
Specifically, the Royal Decree states that individuals or legal entities that use video-sharing services and meet the requirements set forth in Article 94.2 of Law 13/2022 of July 7, the General Law on Audiovisual Communication, are considered users of particular significance; therefore, the rights and obligations under this regulation apply to these entities.
Among the criteria for being considered a user of special significance are, first, that annual gross income be equal to or greater than 300,000 euros in the previous calendar year, derived exclusively from the users’ activity across all video-sharing services on the platforms they use. Additionally, they must have a substantial audience on the platforms, a requirement that is deemed met when, in the previous calendar year, they reached 1 million followers on a single video-sharing platform or 2 million followers across all platforms, and the user has posted or shared 24 or more videos per year.
These users must register with the State Registry of Audiovisual Communication Service Providers within two months of the Royal Decree taking effect. In this way, their obligations are brought into line with those of other audiovisual operators.
In summary, the Royal Decree is an important step toward modern regulation of the audiovisual market in our country, addressing the challenges and opportunities presented by the digital age and ensuring that both new and traditional market players fulfill their responsibilities by protecting the general public from content that promotes violence, pornography, terrorism, or hate, complying with regulations on the broadcast of commercial audiovisual material they advertise, and ensuring the protection of minors and limiting their exposure to content that could negatively affect their physical, moral, or mental development.
Inés de Casas, Senior Associate at ELZABURU
The European Data Protection Board has finally weighed in on the controversy surroundingthe“pay or OK” policyintroduced in Europe last yearbyMeta, the company that owns Facebook and Instagram.
The Committee, known by the acronym EDPB, concludes that the procedure used by the tech giant in an attempt to comply with the General Data Protection Regulation (GDPR) is invalid.
First of all, it should be clear that this is neither a court decision nor new legislation, nor is it a binding resolution. What the EDPB has issued is an opinion in which, at the request of several European data protection authorities, it provides its interpretation of how “pay or ok” fits within data protection legislation.
However, the impact could be significant, especially for large platforms that, until recently, allowed access to their content completely free of charge. This is because, in practice, the EDPB report establishes as a general rule that paying a fee (whether a one-time payment or a subscription) cannot be offered as the sole alternative to cookies.
Thus, platforms that maintain the pure “pay or ok” model, without additional options, will be required to demonstrate that the system they have adopted does not force their users to accept cookies, but rather that users consent to them of their own free will—and this, given the assumptions contained in the EDPB’s opinion, is extremely complicated, if not impossible.
It is not new legislation, but the ruling must be taken into consideration
It is important to note that the EDPB is not issuing a ruling specifically and individually regarding Meta, even though that is the case underlying its opinion; however, this opinion must be taken into account not only by Meta but by all major web platforms.
Cookie legislation requires that cookies that are not strictly necessary for the website to function must be expressly consented to by users in order to be enabled. Among these cookies are behavioral advertising cookies, which are used to profile users in order to later target them with advertisements. And the consent that users provide must be given of their own free will.
A large part of the business of major platforms is based on selling brands the ability to target their advertising at users who, based on their profile, are more likely to purchase their products or services. But profiling as invasive as that carried out by many platforms—whether through cookies or any other system—requires user consent, and the EDPB understands, in essence, that if the only alternative to such consent is to pay a fee, it must be presumed that the consent is not freely given—especially if the fee is disproportionate and if the platform had previously offered its content or services for free for a long time.
Furthermore, it should be noted that the “pay or ok” approach also violates one of the conditions for valid consent, namely that consent must be specific to the particular data processing in question. If users’ consent is required both to track and profile them and to subsequently serve them advertisements, both types of consent should be requested separately rather than as a single, blanket consent, as is the case with Meta’s “pay or ok” system and others.
Among the possible solutions, the Committee suggests using “random” advertising
If Meta wanted to comply with the EDPB’s interpretation, it seems clear that it should avoid offering payment as the only alternative to profiling and behavioral advertising. The EDPB itself suggests, in addition to setting non-excessive amounts for the payment option, that companies also offer the alternative of “random” advertising or advertising that is less invasive of users’ privacy.
For example, by letting users themselves select, from a closed list of options, their interests or the topics for which they would like to see promotions and advertisements.
One possible solution would be for users to be able to choose from several options, such as: a) an ad-free payment plan, b) a free plan with ads tailored to the user’s preferences, c) a free plan with “random” ads without any profiling, and d) a free plan with behavioral advertising cookies.
Each of these options could entail some differences in terms of service provision or platform use, but in essence they should be equivalent so that the user does not feel compelled to choose just one of them, as doing so would otherwise cause unjustified or disproportionate harm. Furthermore, for any other cookies that also require user consent, such consent should be obtained separately.
However, the platforms—which understand their business and their users—will likely find other solutions or different models that are in line with the EDPB’s position. In some cases, it may be sufficient to lower the price charged, while in others, it may be necessary to adopt alternatives accompanied by some form of compensation or additional benefit for the user. However, the latter must be evaluated very carefully, bearing in mind that the EDPB also states that personal data cannot be used as a bargaining chip.
The Committee provides guidance on evaluating the criteria for informed, specific, and unambiguous consent that major online platforms must take into account when implementing “consent or pay” models
In addition to this opinion, the EDPB also announced that it will develop guidelines on “consent or compensation” models with a broader scope and will collaborate with stakeholders on these upcoming guidelines.
Ruth Benito, Of Counsel for Data Protection and Privacy at ELZABURU
The recent class-action lawsuit filed againstGitHub,Microsoft,OpenAI, and OpenAI Codex, seeking $9 billion, is evidence of a problem that was bound to arise for#artificialintelligence: its development may infringe on#copyright, and great care must be taken.
The lawsuit in question challenges the legality of using GitHub repositories to train GitHub Copilot, a service that auto-completes programming code using artificial intelligence. The lawsuit, filed by Matthew Butterick, alleges that 11 open-source licenses and copyrights have been infringed.
The fact is that training AI systems requires feeding them enormous databases (such as those found on GitHub) to develop the large language models (LLMs) that power this technology.
In the case at hand, we are dealing with a large database containing#opensource code. This code, used to train AI, may be copyleft—with viral licenses—or under permissive licenses—which are less open. In any case, they require respect for copyright.
This may require anyone who uses open-source code to disclose its use, attribute it to the author, and comply with the terms of the license, which, among other things, may require keeping the code open source for extended or modified versions of it or for any code into which it is integrated as a component.
Well, this is not the case with the GitHub Copilot service, which would not only violate those rights and terms but would also encourage copyright infringement among its users, since they are unaware that the code snippets used to autocomplete their own code belong to someone else. Thus, they may even be creating commercial code without having true freedom to use the code provided by GitHub Copilot for this purpose.
AI systems from other companies, such as Google and Facebook, are being developed in the same way. And they are not only using programming code to power this technology, but also other types of copyrighted texts, such as literary works, journalistic texts, music, etc.
For this reason, many experts are questioning whether the use of such works to fuel the development of this technology is valid and what measures need to be taken to ensure that it is. Of course, human inspiration draws from sources and not from nothing, and it is legitimate for AI to do the same; but what measures need to be taken to ensure that AI does not generate content that infringes copyright after reading those sources?
At the very least, this will force companies that use GitHub Copilot and other similar tools to conduct thorough code audits. Otherwise, they risk having all their work rendered commercially unusable, among other things.
Alberto López Cazalilla, attorney at ELZABURU
Last Monday, the U.S. Supreme Court agreed to hear a lawsuit against Google LLC that essentially seeks to establish a uniform legal standard regarding the U.S. Communications Decency Act (CDA): whether Section 230 protects the “recommendations” made by platforms such as YouTube, or whether that protection is limited to traditional editorial functions[1].
This has to do with the origin of the lawsuit and the lack of consistency in case law. Regarding the former, the González family lost their 23-year-old daughter, Nohemi González, in November 2015 during the jihadist attack at the Bataclan concert hall in Paris. In the lawsuit, the González family argues that the automated recommendation algorithms used by YouTube were a necessary vehicle for the radicalization of terrorists who later joined the jihad; that is, YouTube’s (and therefore Google’s) recommendation system had helped ISIS grow and recruit followers, which, in the court’s words:
The application of Article 230 to these recommendations eliminates any civil liability incentives for interactive computer services to avoid recommending such harmful materials, and denies redress to victims who might have been able to prove that such recommendations caused their injuries or the death of their loved ones[2].
Why is this important? Because it would mark—since the CDA took effect in the 1990s—the first precedent for limiting the protection granted to Internet service providers with respect to user-generated content.
Section 230 prohibits courts from accepting lawsuits that seek to hold a service provider liable for performing tasks that traditionally fall to publishers, such as deciding what to publish, remove, postpone, or alter.
Examples of cases dismissed under the CDA include Zeran v. American Online, Reno v. ACLU, and others. Since the CDA took effect, the courts have consistently ruled in favor of granting protection to Internet service providers, citing the protection of freedom of speech and information online, as enshrined in the First Amendment to the U.S. Constitution.
The family questions whether the protection afforded by that provision is limited to the traditional functions of a publisher, or whether it also includes the auto-recommendation features of these algorithm-driven systems.
There could be two solutions to this: either establish that such providers will be liable for the recommendations made by their algorithms when the content of those recommendations is defamatory, abusive, or a threat to public safety; or exclude recommendations made by autonomous algorithms from Section 230, given that the platform itself would be directly suggesting content hosted on its servers to the user, who otherwise would not have accessed it, and would therefore be acknowledging“de facto”that it is aware of the content. In both cases, without the help of the platform’s recommendation system, the user would not have accessed the content, which, in the eyes of the González family, was key to the radicalization of the individuals who carried out the Paris attacks.
While it is difficult to predict a possible outcome, the Supreme Court will likely uphold the current line of case law, including “recommendations” within the exemptions of Section 230. It will argue that it is protecting freedom of speech and the press, as enshrined in the First Amendment, and that the question is not sufficiently defined to hold internet service providers liable for what is published on their platforms or to limit any rights in that manner.
However, it is interesting to note the shift in the interpretation of privacy and liability in the United States, which is moving toward positions closer to the approach taken by the European Union.
Various courts have ruled in favor of establishing liability for content posted by users (Force v. Facebook and Dyroff v. Ultimate Software Group, Inc.), aligning with European positions, where if a platform receives notice that defamatory, harassing, or similar content exists, and fails to remove it, it will be held liable for its inaction, as provided for in Directive 2000/31/EC on Electronic Commerce[3], which distinguishes between different service providers—active and passive—and the liability associated with each role. With the adoption on April 23, 2022, of the proposed Digital Services Regulation[4], which amends the E-Commerce Directive and will take effect on January 1, 2024, the liability of these providers increases, bringing the regulations in line with new technologies.
We will have to wait for the U.S. Supreme Court's ruling to confirm whether there will be a change of course—with the greater security for citizens that this would entail—or whether everything will remain the same, and American citizens will continue to live in the Wild West of the internet.
Author: Jaume Mourisco Ayuso.
We live in a society that is constantly changing and evolving, and as such, on December 29, 2021, the Council of Ministers approved the preliminary draft bill amending Law 23/2011, of June 29, on legal deposit, to enable more effective preservation of national publications and optimize the management of preservation centers.

Before we begin, it is important to note that the Legal Deposit system is the regulation that requires copies of all types of published works—whether in physical or online format—to be submitted to the preservation centers of the Autonomous Communities and to the National Library of Spain. Both of these institutions are responsible for preserving Spain’s bibliographic and documentary heritage, as well as its digital heritage, including online publications, websites, and electronic books and journals.
The draft bill includes the following new provisions: First, publishers will be able to submit digital files prior to digitization, in addition to or in lieu of printed files, provided that the materials in question are books, newspapers, and/or magazines. This is intended to facilitate the preservation of and access to these documents, thereby avoiding the need to digitize these copies in the future.
In addition, the possibility of requesting prints on demand—a service that was previously unavailable—has been added, and both the Spanish Film Archive and the film archives of the autonomous communities are now recognized as centers for the preservation of Spain’s film heritage, with the objectives of recovering, researching, and preserving Spain’s film heritage, as well as promoting it.
Similarly, new types of documents are included, such as video games, commercial catalogs from bookstores, publishers, and auction houses, as well as bookmarks, among others. With regard to video games, it is worth noting that this represents a major change, since under the previous legislation they were classified as audiovisual documents, whereas now they will have their own section to ensure the deposit of the complete edition of this type of document.
Finally, among the amendments is the elimination of microforms—which are no longer published—as well as all types of advertising publications, which, as noted in the preliminary draft, lack heritage value. Additionally, the responsibility for high-level inspection—which, in accordance with the doctrine of the Constitutional Court, had previously fallen to the National Library of Spain— is also eliminated.
This text also incorporates the changes resulting from Royal Decree 635/2015, dated July 10, which regulates the legal deposit of online publications and facilitates the preservation of digital heritage.
Finally, it should be noted that this project was developed in collaboration with the autonomous communities, the Federation of Spanish Publishers’ Associations, the Spanish Video Game Association (AEVI), and the Spanish Reproduction Rights Center (CEDRO), with the aim of adapting to changes in the publishing sector, as well as enabling more effective compliance with the preservation of the national publishing heritage and the optimization of the management of preservation centers.
Authors: Mabel Klimt and Paula Bellés
On November 2, the government approved Royal Decree-Law 24/2021, which transposes, among other things, Directive 2019/790 on copyright in the digital single market (the DAMUD Directive).
The purpose of these regulations is to provide digital content with greater opportunities to compete in a single digital market.
Notable among the new features are the following:

Other significant amendments to the Intellectual Property Law introduced by Royal Decree-Law include:
Authors: Mabel Klimt, Javier Fernández-Lasquetty, Claudia Fernández, and Clara Collado
This past February marked the one-year anniversary of the enactment of Law 1/2019, dated February 20, on Trade Secrets. The preamble states that organizations use confidentiality as a tool for managing business competitiveness, facilitating public-private knowledge transfer, and fostering innovation in research, with the aim of protecting information that encompasses not only technical or scientific knowledge but also business data relating to customers and suppliers, business plans, and market studies or strategies.
However, innovative companies are increasingly exposed to unfair practices aimed at the misappropriation of trade secrets, such as theft, unauthorized copying, industrial espionage, or breaches of confidentiality requirements. Globalization, increasing outsourcing, longer supply chains, and greater use of information and communication technologies all contribute to an increased risk of such practices.
Criminal law scholars have always agreed that the most serious violations of industrial or trade secrets should also be subject to criminal penalties, in line with neighboring countries. Currently, corporate espionage is criminalized under Article 278 of the Penal Code.
The wave of technological innovation has emboldened certain threat actors, who are capable of wiping out large amounts of a company’s data in seconds, exposing businesses to a greater risk of being hacked by competitors, foreign governments, and hacktivist groups. State-sponsored corporate espionage is a reality and is on the rise in a globalized, cyber-driven economy.
However, many companies will not realize the true value of their confidential information until it is stolen, which can have devastating consequences. Even the intelligence services of EU member states acknowledge that they are “groping in the dark” when it comes to cases of economic espionage. A key reason for the lack of data on the cybertheft of trade secrets is that many intrusions go undetected.
According to ECIPE (February 2018), the negative impact on the EU resulting from the cybertheft of trade secrets amounts to approximately 60,000 million euros in lost economic growth, which translates into a loss of competitiveness and jobs and a reduction in R&D investment. More specifically, 289,000 jobs may have been at risk in 2018, and that number is projected to rise to one million jobs by 2025. Cyber theft of trade secrets affects SMEs more than large companies, due to their limited budgets, a lack of awareness that they are targets of espionage, and a shortage of qualified IT professionals.
We found a surprising 64% increase in security incidents attributed to competing companies, some of which may be backed by governments. When carrying out attacks, competitors often combine sophisticated high-tech techniques with other methods such as recruiting employees from the target company, bribery, extortion, and the promise of a new job. The rise in cybercrimes attributed to states and competitors coincides with an increase in the number of thefts of intellectual property and other sensitive information.
One of the most significant current conflicts in the field of technology and security worldwide is the Huawei case, with the U.S. accusing the company of industrial espionage, among other crimes. The issue has many facets, ranging from industrial espionage involving the use of foreign equipment to the advent of new technologies such as 5G and the trade war between China and the U.S.
Chinese talent programs —which recruit experts from companies and universities around the world with various incentives to work in China—have been under FBI scrutiny since 2015 due to the threats they pose to U.S. companies and universities.
Reluctance to award projects to Chinese companies out of fear of espionage has also reached Europe. The EU is the top destination for Chinese companies. In 2017 alone, they invested more than 35 billion euros in Europe, with nearly 60% of that capital going toward infrastructure and communications. This has led several countries to view the influx of Chinese public capital into strategic companies with particular concern and to fear that these acquisitions could result in a transfer of technology to Beijing.
Cyberspionage as a common practice of certain governments is recognized by the National Cryptology Center and, similarly, by the 2019 National Cybersecurity Strategy.
These attacks are typically directed against industrial sectors and critical and strategic infrastructure around the world with the aim of gaining geopolitical advantages, state and/or corporate secrets, intellectual or industrial property, as well as data and information from strategic sectors.
The volume of trade secrets stored electronically, coupled with the rise in cyber intrusions, has created a perfect storm for economic espionage. The more technologically advanced a country is, the greater the risk that its companies will suffer attacks of this kind. Consequently, companies will find themselves embroiled in commercial and technological wars not only with other companies but also among states themselves. Hence, it is of the utmost importance to have effective and swift criminal responses to corporate espionage.
Author: Juan José Caselles