An IT contract proves itself only once a project becomes difficult. We draft contracts that still hold at that point – and set out the new obligations for the use of technology.
Software is commissioned, customised, maintained and eventually replaced. We draft and negotiate the contracts behind that, and represent clients in disputes when a project fails. Alongside this, the legal framework for the use of technology is new: since 2 August 2026 the AI Act has required transparency in the use of artificial intelligence, and the NISG 2026 brings several thousand Austrian companies under binding cybersecurity obligations for the first time. We advise companies in Salzburg and beyond on all legal aspects of information technology.
Our services in IT law
- IT and software contracts: software development and customisation, maintenance and support, service-level agreements, cloud and SaaS contracts, acceptance.
- Failed IT projects: preserving the evidence, grace periods and contract termination, out-of-court settlement and litigation.
- IT service providers: selection and contractual arrangements, processor agreements under Article 28 DSGVO, provisions for changing provider and for the end of the contract.
- AI Act: determining your position as provider or deployer, labelling under Article 50 KI-VO, a training concept under Article 4 KI-VO, an internal AI policy including an approved list of permitted tools.
- AI and content: labelling of AI-generated content, action against deepfakes, copyright review of inputs and outputs.
- NIS-2 and IT security: assessing whether the NISG 2026 covers you, registration, obligations of the management bodies, reporting procedures for security incidents.
- Web and e-commerce: mandatory disclosures on the website and social media channels, terms and conditions for the web shop, cookie consent, digital services supplied to consumers.
- Domains: disputes over domains and online signs, at the interface with trade mark law.
IT contracts and projects
Software development, customisation, maintenance, cloud and SaaS: IT contracts govern long-term relationships, and their weaknesses only show once something goes wrong. We therefore focus on the points that are fought over later – a verifiable service description, a structured acceptance procedure with clear consequences, service levels with measurable values, rights to customisations and data, and an orderly end of the contract in which data and access credentials come back.
In failed IT projects, the evidence comes first: who asked for what and when, what was delivered, which defects were notified at what point? We secure that basis, clarify who must answer for what, and conduct the dispute out of court or before the courts, where a settlement no longer holds. Selecting and contracting IT service providers includes the processor agreement under Article 28 DSGVO as soon as personal data is processed on your behalf – as part of the contract package, not a loose annex; the data protection details are covered by our data protection law practice.
AI in the company: labelling, training, clear roles
The AI Act – Regulation (EU) 2024/1689 – becomes applicable in stages, and the stages that matter most to ordinary businesses have been reached. Since February 2025, certain practices such as manipulative techniques and social scoring have been prohibited, and Article 4 KI-VO obliges companies to ensure sufficient AI literacy among their staff; this training obligation applies to every company that uses AI systems. Since 2 August 2026 the transparency obligations of Article 50 KI-VO apply in addition: anyone using a chatbot in customer contact must disclose that a machine is answering, unless that is obvious. AI-generated or AI-manipulated content, in particular deepfakes, is subject to a labelling obligation.
Which obligations apply to a company depends on its role: providers develop AI systems or place them on the market under their own name; deployers use them under their own authority. Most of our clients are deployers – for them the set of duties is manageable: labelling, training and an internal AI policy with an approved list of permitted tools, so that it is clear what staff may use and what not. The strict obligations for high-risk systems have been postponed – to the end of 2027 for stand-alone systems under Annex III, later for AI embedded in products. Anyone developing or planning to deploy such systems should use the lead time now.
AI-generated content and third-party rights
Labelling is not the end of it: AI-generated content regularly touches the rights of others. Deepfakes can violate the right to one's own image and the protection of personality; against them, civil claims for injunctive relief and removal are available, independently of the AI Act. Entering third-party works raises the copyright question of whether that is permissible; the outputs raise the reverse question of whether they enjoy any protection at all – on the current understanding they do not where the human creative contribution is missing. Much of this has not yet been decided by the supreme courts. We therefore say openly what is settled and what is not, and design processes so that they hold up whichever way the questions are resolved.
IT security and reporting obligations: the NISG 2026
With the NISG 2026, Austria implements the NIS-2 Directive and extends its scope from around one hundred operators of critical infrastructure to several thousand companies in 18 sectors – depending on the sector, from 50 employees or EUR 10 million in turnover. The first obligation is self-registration: companies within scope must come forward themselves and may not wait to be contacted by an authority. The Act expressly places responsibility on the management bodies – they must approve the risk-management measures, oversee their implementation and undergo training themselves; delegating to the IT department does not relieve them. Significant security incidents require an initial report within 24 hours, with follow-up reports thereafter. This must be distinguished from notifying a data breach under the GDPR – that remains a matter of data protection law; the same incident can trigger both obligations, with different deadlines and different addressees.
Website, web shop and digital offerings
The online presence is the most visible point of attack. The mandatory disclosures under the E-Commerce Act and the Media Act apply to the website just as they do to business channels on Instagram or YouTube; missing disclosures are subject to administrative fines and are quickly remedied. In a web shop, terms and conditions, consumer information duties and the right of withdrawal come on top; for digital services supplied to consumers, so does the law of warranty, including the duty to provide updates. For the cookie banner the rule is: consent must be freely given, and declining must be as easy as consenting – an equivalent reject option on the first layer is the benchmark.
Where we start
Some matters begin with a draft contract to be reviewed, others with a project that is not delivering, others again with the question of which of the new obligations apply to the company at all. In all three cases the starting point is the same: a sober assessment, and from it a list of concrete steps with clear responsibilities – workable in day-to-day operations, supported by our firm in Salzburg. Arrange an appointment.