Brussels Tries to Fix the GDPR Without Making It Worse
Brussels has spent years proving that the easiest way to “fix” the General Data Protection Regulation (GDPR) is to give more power to the institutions that made it unworkable. The Digital Omnibus initially looked ready to continue that tradition. Now, somewhat improbably, several EU governments appear determined to try actual reform instead.
Ireland assumed the rotating presidency of the Council of the European Union from Cyprus for the second half of the year and declined to recycle Cyprus’ flawed draft. Instead, it reopened negotiations over the European Commission’s proposal on pseudonymization, cookie consent, and the use of data for artificial intelligence (AI).
Serious reform will still face resistance in the European Parliament. A joint draft report from its industry and civil-liberties committees leaves the Commission’s most contested GDPR proposals untouched for now. But the co-rapporteurs’ public statements—and the flood of amendments filed since—show that the legislation remains very much in play.
The European Data Protection Board (EDPB) has also weighed in. Although it does not make EU law, it exerts considerable influence over national governments. Its new guidelines distinguishing personal from anonymous data accept, for the first time, the Commission’s central point: whether data is personal should depend on the entity holding or using it, not on whether anyone, anywhere, could identify the person concerned.
The guidelines also show why procedural reform may matter even more. As usual, the EDPB could not quite bring itself to offer guidance useful for much beyond increasing lawyers’ billable hours.