Ten Years of GDPR: Keeping Pace with a Changing Digital World

27 April marked ten years since the General Data Protection Regulation (GDPR) was published. This legislation has been central to shaping how personal data is used and protected across Europe, providing a strong foundation for trust in the digital economy.

With significant advances in technology, including AI, there is a need to ensure that GDPR remains fit for a new era of innovation. The GDPR has established an influential framework for data governance at both EU and global levels, strengthening understanding of data processing and promoting responsible data management. Nevertheless, its complexity has presented notable challenges for citizens, organizations, and regulators, underscoring the importance of efforts to enhance its effectiveness going forward.

The 2024 Draghi report on European Competitiveness clearly made the case: complexity and fragmentation in the implementation of the GDPR across the EU is curtailing EU-based companies’ ability to compete globally, especially on AI and new technologies. This calls for an ambitious approach. As EU policymakers advance a much-needed regulatory simplification agenda in the digital sphere, making the GDPR work better must be a key priority.

The Commission’s Digital Omnibus proposal contains several targeted adjustments to that effect. For example, expansive and conflicting interpretations of the concept of personal data over time have created uncertainty in the market and significantly chilled innovation, even where data protection risks are minimal. The proposed clarification of the definition of personal data codifies the Court of Justice of the EU’s jurisprudence into clear operational criteria, by confirming that data qualifies as personal only where a controller can reasonably identify an individual using means available in practice. This will help companies innovate with confidence while upholding the risk-based approach at the core of the GDPR.

Similarly, the Digital Omnibus offers important clarifications to make the GDPR fit for the AI age. For example, the proposed amendments to Article 9 of the GDPR will allow AI innovators to process special categories of personal data (such as gender) under strong safeguards to ensure accurate and unbiased AI systems. In addition, by confirming that legitimate interest may serve as a lawful basis for the training and operation of AI systems, the proposal codifies the European Data Protection Board’s opinion into biding law, thus providing stable legal certainty for innovators.

As Europe seeks to strengthen its global AI leadership under the AI Continent Action plan, maintaining these amendments in the legislative process will be fundamental. The ball is now in the court of the EU co-legislators to swiftly adopt and pass these much-needed adjustments to the framework. Unfortunately, early compromise texts from the Council of the EU have sought to delete or restrict these crucial measures, without which the proposal would be ineffective.

As GDPR turns 10, EU lawmakers must take a bold and forward-looking approach: recognizing where the framework needs to be clarified and promote consistent application while continuing to uphold strong data protection safeguards. Passing targeted updates through the Digital Omnibus can help ensure the GDPR continues to protect individuals while enabling responsible data use and innovation. Maintaining this balance will be essential to supporting Europe’s competitiveness in the global digital economy.

Tags: Data & Privacy

Related