Vintage black and white photograph of a crowded market auction with buyers raising money, symbolising traditional monetary claims and exchange

E-Money vs. Crypto: From Contractual Claim to Statutory Redemption Rights

Under EMD2, e-money holders possess contractual claims arising from account agreements. MiCAR introduces a fundamentally different architecture for e-money tokens: a legal right to reimbursement that exists by operation of law, regardless of whether the holder ever contracted with the issuer. This essay examines Case C-661/22 and Article 49 MiCAR to explain why this distinction matters.
Hands holding an open leather wallet with banknotes and a personal photograph, symbolising direct control over assets without third-party intermediaries—the physical equivalent of a self-hosted crypto wallet.

Self-hosted wallets under EU Law: Compliance through Intermediation

The Markets in Crypto-Assets Regulation sets licensing rules for crypto-asset service providers, but it doesn't say what happens when these middlemen deal with self-hosted wallets. The Transfer of Funds Regulation, also known as Regulation 2023/1113, answers this question about information that goes along with transfers of money and some crypto-assets. This essay looks at how the TFR sets up a framework of stricter due diligence instead of a ban. For transactions over € 1.000, it requires CASPs to check wallet ownership and add blockchain monitoring capabilities. It follows the EBA's Travel Rule Guidelines, the person-to-person exclusion in Article 2(4), and the Commission's job in Article 37 to figure out if more restrictions are needed by June 2026. As self-hosted wallets turn into gated endpoints instead of alternative pathways, lawyers and compliance experts all over Europe need to know how this framework changes the line between regulated intermediation and self-custody.

Το Chat Control δεν πέθανε, απλώς ιδιωτικοποιήθηκε!

Στις 26 Νοέμβριου 2025, το Συμβούλιο της ΕΕ ενέκρινε διαπραγματευτική θέση για το Chat Control που τα ΜΜΕ παρουσίασαν ως «οπισθοχώρηση». Η πραγματικότητα είναι διαμετρικά διαφορετική: η «εθελοντική» σάρωση νομιμοποιεί μαζική επιτήρηση χωρίς δικαστική εντολή, εισάγει υποχρεωτική ταυτοποίηση ηλικίας που τερματίζει την ανώνυμη επικοινωνία, και απειλεί με ψηφιακό αποκλεισμό των εφήβων. Παρά την κατακραυγή 700+ επιστημόνων και την απόφαση Podchasov του ΕΔΑΔ που καταδικάζει τέτοιες πρακτικές, η ΕΕ επιμένει σε μια πρόταση που ο καθηγητής Matthew Green χαρακτήρισε «το πιο τρομακτικό πράγμα που έχω δει ποτέ»

Ενημερωμένη Συνεισφορά μου στο DataGuidance: Παραβιάσεις Δεδομένων στην Κύπρο – Εξελίξεις 2025.

Ενημερωμένη ανάλυση για την πλατφόρμα OneTrust DataGuidance σχετικά με τις παραβιάσεις δεδομένων στην Κύπρο το 2025. Εξετάζεται η σύγκλιση GDPR με NIS2 και DORA, η ειδική Κυπριακή εξαίρεση του Άρθρου 12 του Νόμου 125(I)/2018, και πέντε πρόσφατες αποφάσεις της Επιτρόπου Προστασίας Δεδομένων που διαμορφώνουν την πρακτική εφαρμογή του νομοθετικού πλαισίου.
Branding image of the Law Office of Panayotis Yannakas, featuring a pen and notebook symbolizing legal writing and innovation

Clients Cloud Portal for My Law Office

Meet the Clients Cloud Portal. Υour encrypted workspace for exchanging large files, court bundles, and evidence without email limits. Self-register, drag-and-drop uploads, and get notifications when new documents arrive. Permissions keep access restricted; an activity record preserves the audit trail. Built on HTTPS/TLS and consistent with legal-sector guidance on secure communications.

Do We Possess Our Cache Files?

The controversy over cache files in criminal law reveals a deeper challenge: should automated digital traces count as possession? From child exploitation to terrorism cases, courts struggle to balance strict liability with the principle that culpability requires knowledge and control.
Cyberpunk digital illustration of DAC7 tax directive with neon accents and futuristic circuitry.

DAC7 and the Digital Platform Economy: When Tax Transparency Meets Market Reality

The EU’s DAC7 Directive reshapes tax transparency in the platform economy. What began as targeted gig-economy oversight now extends to almost every digital marketplace transaction—rental, goods, and services alike. Platforms must collect, verify, and report seller data under complex OECD XML rules, facing cross-border inconsistencies and high compliance costs. The result: greater fiscal transparency, but also higher barriers for start-ups and unintended advantages for incumbents.
ICANN has announced an important change to its Registration Data Policy that could affect who is legally recognized as the owner of your domain name. The update takes effect August 21, 2025, and it changes the rules for determining domain ownership.

ICANN: Κρίσιμες αλλαγές στην κυριότητα των Domain Names από 21 Αυγούστου 2025

Από τις 21 Αυγούστου 2025, ο ICANN εφαρμόζει νέους κανόνες που αλλάζουν ριζικά τον προσδιορισμό της κυριότητας των domain names. Εάν το πεδίο «Organization» περιέχει εταιρική επωνυμία, η εταιρεία θα θεωρείται αυτόματα ο νόμιμος κάτοχος του domain, ανεξάρτητα από το όνομα του φυσικού προσώπου που το καταχώρισε.
Samsung executives holding EU RED Cybersecurity Certification framed documents, depicted in cyberpunk neon style — symbolic critique of EU RED Regulation and its impact on openness and innovation

EU Radio Equipment Directive: Balancing Security and Openness

The EU’s Radio Equipment Directive has shifted from a radio-focused safety law into a full-scale cybersecurity regime. From August 1 2025, manufacturers face strict new requirements under the EN 18031 standards—transforming how connected devices handle security, privacy, and fraud prevention. But the same rules also fuel controversy over bootloader locks, innovation barriers, and conflicts with Right to Repair and platform-openness goals.
Dystopian street scene showing futuristic consent terminals outside shops with queuing frustrated people, representing how cookie consent systems became surveillance infrastructure.

The Consent Paradox: How EU Regulations Enabled Corporate Data Harvesting

The European Union's cookie consent rules & guidelines, designed to protect user privacy, have paradoxically created a sophisticated surveillance infrastructure controlled by eight to ten Consent Management Platform companies. This legal essay examines how GDPR compliance requirements enabled corporate data harvesting on an unprecedented scale, with academic studies showing 85% of consent interfaces violate basic privacy requirements while websites using professional consent systems deploy 6.9 times more tracking technologies than those with basic implementations. Rather than protecting European citizens from surveillance capitalism, these regulations have institutionalized "consent theater" that legitimizes expanded data collection under the guise of user choice.