Site navigation

Is the EU’s Plan to Simplify GDPR a Good One?

Tom Quinn

,

GDPR
The EU’s drive for a ‘simpler digital framework’ is facing backlash, with civil society groups warning against any weakening of GDPR.

Dozens of civil society organisations have banded together to oppose European Commission plans to ‘simplify’ the General Data Protection Regulation (GDPR), claiming that the law should be treated as a cornerstone of the EU’s digital rulebook.

In an open letter to EU commissioners, a coalition of 108 civil society groups, academics, companies and other experts warned that although proposals to amend GDPR to support small and medium-sized companies were ‘good in theory’, any attempt to change the law could roll back key accountability safeguards.

According to the letter, signed by a host of organisations including European Digital Rights, Amnesty International, Open Rights Group, European Digital Rights, Noyb, and even Mozilla, risk ‘missing the mark of genuine simplification’, with the GDPR, once reopened, becoming vulnerable to broader deregulatory demands.

At a practical level, the signatories said that the changes might allow some companies to avoid keeping records of data processing, even when handling special categories of data, purely based on staff headcount or turnover.

“This shift undermines what is often called the GDPR’s ‘risk-based approach’, a mechanism for calibrating obligations according to the potential harm to people’s rights and freedoms, not company size,” reads the letter.

“More fundamentally, it could erode the Regulation’s original foundation as a rights-based instrument grounded in the recognition of personal data protection as a fundamental right. 

“Data rights do not become less important when the controller is smaller, and people’s vulnerability to harm does not shrink accordingly.”

The coalition’s concerns stem from the EU Commission’s desire for a ‘simpler and faster’ Europe, which includes the broad goal of simplifying the EU digital framework, including regulatory burdens it views as holding back European competitiveness.

In March, the EU Commissioner for Justice and the Rule of Law, Michael McGrath, stoked fears that this zeal for reform would target GDPR rules, considered among the toughest privacy and security laws in the world, with penalties for breaching it reaching into the tens of millions of euros.

During a livestreamed interview, McGrath confirmed that the Commission would look to change the law, in a bid to reduce the record-keeping burden placed on SMEs and organisations with under 500 employees.

While the proposed GDPR changes were welcomed in some quarters, with, for example, the Centre for European Policy Studies saying that in its current form the law has become a ‘roadblock to digital progress, stifling innovation, impeding AI development’, many have been left concerned that loosening the EU’s digital protections will undermine corporate accountability.

According to the open letter from EU civil groups, the danger in reopening GDPR goes further, and would send a signal that rights-based regulation is negotiable under pressure.


Recommended reading


“While competitiveness is important, using it to justify exemptions from core protections sends a worrying message: that people’s rights are expendable when economic interests are at stake,” reads the open letter.  

“Once reopened, the GDPR could become vulnerable to broader deregulatory demands. Many such pressures are already visible, including calls to weaken rules on consent with no effective safeguards for users, or legitimise invasive uses of personal data for AI training.”

To maintain GDPR as a meaningful enforcement measure, the coalition is calling on the EU Commission to reject any reopening of the regulation and reaffirm its integrity as a foundation of EU digital law, and resist external and internal pressures to make amendments in the name of competitiveness or trade interests.

Don’t Miss Scotland’s Biggest Tech Event!

Join us at DIGIT Expo West on 5th June at the SEC Glasgow. Get leading industry insights across AI, Cyber Security, and Data, and grow your network at Scotland’s largest gathering of tech leaders – with 1500+ attendees, 50+ speakers, and 50+ exhibitors.

Register your FREE place now at www.digitexpowest.com

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data