The European Commission’s €550 Million Fine Against AliExpress: A Turning Point for Trade Mark Enforcement Under the Digital Services Act

On 20 July 2026 the European Commission fined AliExpress €550 million for breaching several obligations of the Digital Services Act — the first enforcement action of this magnitude under the Regulation. The size of the penalty is not what matters most. The Commission is not sanctioning the presence of counterfeit goods on the marketplace, but the inadequacy of the risk governance built around it: an assessment that underestimated the risks while overestimating the platform’s own controls, moderation and detection systems below the level of protection required, and human resources out of proportion to the risks identified. Articles 34 and 35 impose on very large online platforms an enhanced obligation of means, not a guarantee of result. For rights holders, this article argues, trade mark protection shifts from a reactive logic of notice and takedown to the prevention of systemic risks.

Brexit and GDPR

The United Kingdom left the European Union on 31 January 2020; Nominet, the .UK registry, published guidance on what this means for data protection. During the transition period, the GDPR and the Data Protection Act 2018 continue to apply unchanged. From 31 December 2020, the United Kingdom becomes a third country: personal data received before that date must continue to enjoy protection essentially equivalent to European standards, and transfers from the Union will depend on an adequacy decision, which the European Commission will only grant after assessing the British regime. Pending that decision, businesses — registrars and registries included, WHOIS data being personal data — must rely on the GDPR's cross-border transfer mechanisms. The article advises companies handling UK-related domain name and customer data to map their data flows now rather than wait for the cliff edge.

25 February 2020
Initially published on iptwins.com

DNS Abuse: How Can Domain Names Linked to the Same Actor Be Connected?

On 18 August 2026, ICANN published for public comment the Initial Report of its DNS Abuse Mitigation Policy Development Process (PDP 1). Among its proposals are Associated Domain Checks: when a registrar acts on an abuse report, it should also examine the other domain names held by the same customer. In its comments of 25 September 2026, the WIPO Arbitration and Mediation Center supports the approach but points out its main limitation: the checks stop at the edge of a single registrar's portfolio. Bad actors know this and spread their registrations across several registrars, which hampers consolidated UDRP proceedings. WIPO suggests exploring cross-registrar mechanisms without saying which data could link the names. The article argues that payment data, pseudonymised, could serve as that common denominator, while acknowledging its limits (prepaid cards, fraud, multiple payment methods): an indicator rather than proof. It marks a shift from a one-domain, one-investigation logic to a network approach.

28 September 2026
Initially published on iptwins.com

DNS and Web3: How Can We Avoid Importing Cryptosquatting into the DNS?

The DNS and blockchain-based alternative naming systems are converging, with projects such as .BLOCKCHAIN and the .ROBOT cryptoTLD seeking to operate the same string in both worlds. In August 2026, ICANN's Technical Study Group released an Initial Report on integrating gTLDs with alternative naming systems, built on a "string + controller" principle: the same name must remain under the same control across systems, with its status kept in sync. In September 2026, the SSAC supported this synchronisation but noted that applying the UDRP and the URS becomes difficult when a registrant exists only in an alternative system, without conventional registration data. The WIPO Arbitration and Mediation Center warns that cybersquatting is already widespread in these systems: mapping names automatically into the DNS would import existing infringements. Trademark owners therefore need functionally equivalent protection mechanisms, including a way to prevent infringing names from being activated, as initiatives like Unstoppable Domains joining GlobalBlock have begun to show.

24 September 2026
Initially published on iptwins.com

Article Information

Author

Emmanuel Gillet

Publication Date

28 July 2026

Jurisdiction

Related Decision(s)

Please select listing to show.

Filter articles

Filter for Topics
Filter for Industries
Filter for Jurisdictions