• Latest
  • Trending
Risks when using and offering no-code platforms as SaaS

Risks when using and offering no-code platforms as SaaS

10. July 2023
BGH considers Uber Black to be anti-competitive

Distance learning, coaching and synchronous online formats

2. March 2026
Media outlets consider influencers law pointless

Manipulated QR codes and quishing

27. February 2026
AI agents as autonomous contractual partners?

AI agents as autonomous contractual partners?

26. February 2026
Platform cooperatives as a financing and business model

AI training data as an asset: accounting, IP strategy and exit factor

25. February 2026
Streaming setup, influencers and contract law

Influencers: when marketing suddenly becomes commercial agency law

18. February 2026
Insolvency administrator and access to tax office data?

NRW audits influencers – and suddenly normal rules apply?

12. February 2026
iStock 1405433207 scaled

Legal pitfalls in revenue-based financing for start-ups

12. February 2026
Streaming setup, influencers and contract law

Streaming setup, influencers and contract law

9. February 2026
Platform cooperatives as a financing and business model

Platform cooperatives as a financing and business model

8. February 2026
Frankfurt district court a.M. softens influencer jurisdiction

VAT on donations, gifts and “support” from influencers?

5. February 2026
Chamber Court on obligations to injuntture in the case of acts of third parties

Jurisdiction in the contract: one word too many, one word too few

4. February 2026
New info on the status of the State Media Treaty

Customer hotline and support in SaaS

2. February 2026
BGH considers Uber Black to be anti-competitive

BGH: FRAND objection fails due to lack of willingness to license

28. January 2026
marianregel

InformationCheck.de is live: side project for source-based classification of social media claims

22. January 2026
DPMA

Paid mods, fan guidelines and EULA: when monetization is possible

21. January 2026
Is an 8 year old allowed to be an Esport player?

LOI, term sheet, MoU, often binding for startups?

20. January 2026
What actually is an IP? In the games, music and film industry!

Freelancer paid, but still not getting rights?

19. January 2026
Affiliate links for streamers and influencers

Comparison sites as an SEO trick

16. January 2026
Reverse vesting

Vesting, good leavers, bad leavers – why a lack of regulations costs startups dearly

15. January 2026
ai generated g63ed67bf8 1280

AI guideline for agencies and external service providers

14. January 2026
  • Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Kurzberatung
Rechtsanwalt Marian Härtel - ITMediaLaw

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Rechtsanwalt Marian Härtel - ITMediaLaw

Risks when using and offering no-code platforms as SaaS

10. July 2023
in Blockchain and web law, Law on the Internet
Reading Time: 6 mins read
0 0
A A
0
security ga1c47328d 1280

At first glance, the title of this blog post might seem like a winner in the contest for most anglicisms in a sentence. But behind the apparent “denglish” lies an extremely relevant topic: no-code platforms.

Content Hide
1. Security risks when using no-code platforms
2. Risks for no-code platform providers
3. Short excursion: code generation by AI?
4. Conclusion
4.1. Author: Marian Härtel
Key Facts
  • No-code platforms are indispensable for companies to optimize business processes and expand their digital presence.
  • The use of no-code platforms harbors security risks, as users often do not have the technical knowledge.
  • A lack of understanding of API integration can lead to GDPR and information security issues.
  • Poorly formulated general terms and conditions can get providers of no-code platforms into legal trouble.
  • The legal aspects include data protection law, IT security law, contract law and liability law.
  • Artificial intelligence (AI) for code generation raises new questions about liability and responsibility.
  • A better understanding of the risks enables the use of no-code platforms without jeopardizing security.

In the increasingly digitalized world, no-code platforms have become an indispensable tool for companies looking to optimize their business processes and expand their digital presence. They are the invisible heroes of digital transformation, making it possible to create and manage applications without writing a single line of code. This reduces the need for specialized developers and opens the door to a world where anyone can become a builder of their own digital solutions.

But as with any superhero, there is a flip side. Despite their advantages, no-code platforms also carry risks, both for users and for the providers of these services. It’s like suddenly having superpowers but not knowing exactly how to control them. This blog post highlights the security risks associated with using widgets and features from no-code platforms. It also discusses the potential problems that providers may face as a result of poorly worded general terms and conditions (GTCs). Because as with any great power, great responsibility comes into play. And in the world of no-code platforms, it’s no different.

Security risks when using no-code platforms

One of the main problems with using no-code platforms is the security risk. Although these platforms allow users to create applications without programming knowledge, it also means that they may not have the technical knowledge to understand the security risks associated with using certain widgets and features.

For example, some widgets could have security vulnerabilities that could be exploited by hackers to access sensitive data. In addition, some features, if not properly configured, could result in confidential information being inadvertently made publicly available. Therefore, it is essential for users of no-code platforms to be aware of the potential security risks and take appropriate measures to protect their data.

Another problem that is often overlooked is the connection of third-party APIs. Many no-code platforms allow the integration of third-party APIs to extend the functionality of the applications created. While this may appear to be an advantage at first glance, it also carries risks. When programming your own APIs, you can always look into your own code and understand exactly when, where, and what data is being tapped via a third-party API. However, this is often not possible with no-code platforms.

This lack of transparency can quickly lead to problems with the General Data Protection Regulation (GDPR) and information security. It is often unknown how exactly (and in case of doubt whether correctly) the API is integrated on the platform and whether the data is “encrypted in transit”, for example. Most no-code platforms are also silent about this, which in turn could be a problem for their own privacy policies.

In addition, a bug in the programming of the no-code platform, which became known to hackers, could provide them with access to thousands of users of the platform. Failure to take your own precautions could result in a massive data leak. Therefore, it is essential to take appropriate measures to protect the data and ensure compliance with the GDPR and security standards.

Risks for no-code platform providers

For providers of no-code platforms, poorly worded general terms and conditions (GTC) can lead to significant legal problems. The GTC are an integral part of the contract between the Provider and the User and define the conditions under which the Service may be used. If these conditions are not clearly and precisely formulated, the provider could be held liable for damages resulting from the use of its platform.

Of course, the issues mentioned in the previous section can present extensive challenges for the platform. Questions like: Where is data stored? What happens if hackers can penetrate the platform? Are individual instances compartmentalized for individual customers? Does a bug in a widget or feature affect all customers? These and many other issues must be considered in the GTC.

In addition, providers could have information obligations when errors occur that require the customer to make adjustments. You could also be responsible for IT security at the client and may need to educate clients about IT security.

For example, if a user suffers a breach of the General Data Protection Regulation (GDPR) due to a security vulnerability in a widget or feature provided by the platform, the provider could be held legally responsible for such incidents if its TOS do not explicitly exclude liability.

The creation of T&Cs for no-code platforms can therefore be very complicated and should only be carried out by experienced lawyers with IT expertise. They must be able to understand the technical aspects of the platform and translate the potential risks and responsibilities involved into clear and concise legal terms.

The legal aspects of using no-code platforms are diverse and complex. They cover not only data protection law, but also IT security law, contract law and liability law. Each of these areas of law has its own rules and regulations that must be followed.

In the area of data protection law, the GDPR is the central set of rules governing the processing of personal data in the EU. It sets strict requirements for data processing security and requires no-code platform providers to take appropriate technical and organizational measures to protect their users’ data.

In the area of IT security law, there are a number of laws and standards that impose requirements on the security of IT systems. These include, for example, the Federal Data Protection Act (BDSG), the IT Security Act (IT-SiG) and ISO 27001. These laws and standards may impose different requirements depending on the type of platform and the specific circumstances of the data processing.

In contract law, the GTC must be designed in such a way that they clearly and precisely regulate the rights and obligations of the parties. They must also comply with the requirements of the German Civil Code (BGB) and the Unfair Competition Act (UWG).

In liability law, the GTC must adequately regulate the provider’s liability for damages resulting from the use of its platform. They must also take into account the requirements of the Product Liability Act (ProdHaftG) and the German Civil Code (BGB).

The creation of T&Cs for no-code platforms therefore requires a deep understanding of these different areas of law and the ability to translate this knowledge into clear and concise legal terms. It is therefore essential that providers of no-code platforms hire experienced lawyers with IT expertise to draft and review their T&Cs.

Short excursion: code generation by AI?

An interesting side issue in the discussion of no-code platforms is the increasing ability of artificial intelligence (AI) to generate code. A prominent example of this is ChatGPT, an AI from OpenAI that is capable of generating human-like text while also generating code. Although ChatGPT is not a classic no-code platform, its use raises similar issues of liability and responsibility.

If ChatGPT is used for code generation and this code contains errors or leads to undesired results, who is responsible? Is it the employee who uses ChatGPT for code generation? Is it the employer who enables or even encourages the use of ChatGPT? Or could it even be ChatGPT itself or its developer, OpenAI?

The answer to these questions is not simple and depends on many factors, including the exact circumstances of code generation and the applicable legal framework. In general, however, one could argue that the employee using ChatGPT has some responsibility to review and validate the generated code. After all, it is his decision to use the AI to generate code, and he should be able to understand and check the generated code for errors.

Employers may also bear some responsibility, especially if they encourage or mandate the use of AI tools such as ChatGPT. It could be required to provide appropriate training and support to ensure that its employees can use AI tools safely and effectively.

The issue of ChatGPT or OpenAI liability is more complex and depends on the specific legal framework. In some jurisdictions, it might be possible for an AI developer to be liable for errors or damages caused by its AI. However, in other jurisdictions, this might not be the case, especially if AI is considered a “tool” that is controlled and directed by the user.

These issues show that the increasing prevalence of AI and no-code platforms presents new and complex legal challenges. It is therefore important that both providers and users of these technologies are aware of the potential risks and take appropriate measures to manage these risks.

Conclusion

While no-code platforms offer significant benefits, such as accelerating digital transformation and democratizing application development, it is imperative that both users and vendors are aware of the associated risks.

Users need to be aware of the security risks associated with the use of widgets and features. These include potential security vulnerabilities that could be exploited by hackers, as well as the risks associated with connecting third-party APIs. It is important that users educate themselves and take appropriate measures to protect their data and ensure compliance with the General Data Protection Regulation (GDPR).

For their part, providers of no-code platforms must ensure that their general terms and conditions (GTC) are clearly and precisely worded in order to avoid legal problems. They must also implement the technical and organizational measures necessary to ensure the security of their platforms and compliance with the relevant laws and standards, such as the German Federal Data Protection Act (BDSG), the IT Security Act (IT-SiG) and ISO 27001.

In addition, the increasing ability of artificial intelligence (AI) to generate code shows that the lines between code and no-code are becoming increasingly blurred. This raises new issues of liability and responsibility that must be considered by both users and providers of these technologies.

By better understanding these risks and implementing appropriate safeguards, the benefits of no-code platforms can be realized without compromising security or risking legal issues. It is an exciting time for digital transformation, but as with any technological innovation, it is important that we take the risks as seriously as the opportunities.

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Tags: Artificial intelligenceChatGPTHaftungPrivacySicherheit

Weitere spannende Blogposts

Avoid legal pitfalls when founding an online start-up

Avoid legal pitfalls when founding an online start-up
10. October 2024

Founding an online start-up requires not only entrepreneurial skill, but also a solid legal foundation. Company founders are confronted with...

Read moreDetails

Obsolete CMS does not lead to fault liability

copyright
20. February 2019

The issue of disruptive liability often makes lawyers frighten enough, because it is a very German legal construct that has...

Read moreDetails

MiCar is partly there

a0f26104d9663e140f79896d2d5ee77a
4. July 2024

When the Markets in Crypto-Assets Regulation (MiCAR) comes into force on June 30, 2024, a new era for stablecoins in...

Read moreDetails

IGD waives claims arising from data protection

abmahnung
7. November 2022

Actually, the topic IGD Interessengemeinschaft Datenschutz e.V. has already been dealt with sufficiently. I have reported on this here and...

Read moreDetails

What should be considered when running sweepstakes on social media?

What should be considered when running sweepstakes on social media?
7. November 2022

Sweepstakes on social media are a great way to build customer loyalty or even to grow your own social media...

Read moreDetails

Copyright in the digital world: What’s next for AI image generators?

Copyright in the digital world: What’s next for AI image generators?
17. January 2023

Introduction The use of AI image generators has become an increasingly important factor in copyright law in recent years. This...

Read moreDetails

Q&A: Legal requirements for a player transfer in esports.

Q&A: Legal requirements for a player transfer in esports.
7. November 2022

Recently I wrote a few key points about what you might have to consider when signing a contract for a...

Read moreDetails

Block social media accounts for hate speech?

medienrecht
7. November 2022

The Koblenz Regional Court had to rule on so-called hate speech in social media and on the effectiveness of the...

Read moreDetails

Legal aspects of the use of AI in marketing

Legal aspects of the use of AI in marketing
11. August 2023

In recent years, artificial intelligence (AI) has emerged as a transformative technology across numerous industries, with the marketing sector standing...

Read moreDetails
BGH considers Uber Black to be anti-competitive
Law and Esport

Distance learning, coaching and synchronous online formats

2. March 2026

The Distance Learning Protection Act (FernUSG) has been experiencing a renaissance for some time now. What for decades was considered...

Read moreDetails
Media outlets consider influencers law pointless

Manipulated QR codes and quishing

27. February 2026
AI agents as autonomous contractual partners?

AI agents as autonomous contractual partners?

26. February 2026
Platform cooperatives as a financing and business model

AI training data as an asset: accounting, IP strategy and exit factor

25. February 2026
Streaming setup, influencers and contract law

Influencers: when marketing suddenly becomes commercial agency law

18. February 2026

Podcastfolge

238a909c26a0302cbd4792cbd18e4922

Global challenges for start-ups – A legal guide

10. October 2024

This informative podcast offers a comprehensive insight into the legal challenges faced by start-ups when expanding internationally. The experienced lawyer...

Read moreDetails
75df8eaa33cd7d3975a96b022c65c6e4

Life as an IT lawyer, work-life balance, family and my career

26. September 2024
da884f9e2769f2f96d6b74255be62c27

The role of the IT lawyer

5. September 2024
fcb134a2b3cfec5d256cf9742ecef1cd

The unconventional lawyer: a nerd in the service of the law

26. September 2024
8315f1ef298eb54dfeed2f5e55c8b9da 1

First test episode of the ITMediaLaw Podcast

26. August 2024

Video

My transparent billing

My transparent billing

10. February 2025

In this video, I talk a bit about transparent billing and how I communicate what it costs to work with...

Read moreDetails
Fascination between law and technology

Fascination between law and technology

10. February 2025
My two biggest challenges are?

My two biggest challenges are?

10. February 2025
What really makes me happy

What really makes me happy

10. February 2025
What I love about my job!

What I love about my job!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung