Saturday

8th May 2021

EU's landmark GDPR failing to live up to full potential

  • The commission noted data-protection authorities based in Ireland and Luxembourg - European HQss to Google, Facebook, Twitter and Amazon - need a substantial boost in resources (Photo: Descrier)

A two-year review of the EU data protection regulation (GDPR) published by the European Commission on Wednesday (24 June) revealed that its application and enforcement both remain problematic.

"The GDPR is the perfect example of how the European Union, based on a fundamental rights' approach, empowers its citizens and gives businesses opportunities to make the most of the digital revolution," said the EU commissioner for values and transparency, Věra Jourová.

Read and decide

Join EUobserver today

Become an expert on Europe

Get instant access to all articles — and 20 years of archives. 14-day free trial.

... or subscribe as a group

"But we all must continue the work to make GDPR live up to its full potential," she added.

Since its adoption in 2018, GDPR has largely been considered one of the major successes of the EU for being in the vanguard of online protection of fundamental rights in the bloc and globally.

However, the law has been misused to silence journalists and civil society organisations.

It has also proved to be complicated, as well as time- and cost-consuming for small and medium enterprises, and there is legal uncertainty linked to some of the new technologies.

Additionally, the commission's report also identified fragmentation in national legislation, and a lack of cooperation between different data protection authorities, which have created challenges for cross-border investigations.

Such multi-state investigations require that a lead authority drives the investigation in cooperation with other authorities - this system is based on the so-called "one-stop-shop" mechanism which is supposed to serve both people and companies.

However, the legal services of the European Council have previously criticised the "one-stop-shop" system, back in 2013, for undermining citizens' human rights.

Moreover, only five EU countries - the Czech Republic, Denmark, Hungary, the UK, and Luxembourg (which has yet to resolve any major case) - are considered to have enough resources for such cooperative tasks.

Earlier this year, the Hamburg data protection authority described the system as "cumbersome, time-consuming and ineffective".

Google, Facebook, Twitter and Amazon HQs?

The commission's two-year review also indicates that the authorities based in Ireland and Luxembourg, European headquarters to Google, Facebook, Twitter and Amazon, need a substantial boost in resources.

"Given that the largest big tech multinationals are established in Ireland and Luxembourg, the data protection authorities of these countries act as lead authorities in many important cross-border cases and may need larger resources than their population would otherwise suggest," reads the report.

However, according to a separate report published by NGO Access Now, "the fact that Ireland is currently leading a large number of GDPR complaints is not only an administrative issue but also potentially a political one" since tech giants have arguably gained an unprecedented level of influence in policy debates in Ireland - including data protection enforcement.

The Irish watchdog opened cases against Facebook, the Facebook-owned Instagram and WhatsApp apps, as well as Twitter and Apple - among others.

Meanwhile, a report of the regulatory activities under GDPR of the Irish watchdog indicates that "the workload will continue to increase and the coronavirus crisis is likely to have implications for future funding".

GDPR has increased awareness about the protection of personal data, both within and outside of the EU - about 69 percent of people in the bloc have heard about GDPR, according to a recent survey from the EU Agency of Fundamental Rights.

However, businesses stressed the need for legal certainty on how to implement new technologies in a way that is compatible with the GDPR so that they can continue to invest in innovation.

Members of the EU's expert group on GDPR consider that the exact impact of the GDPR on future innovation is hard to estimate - since this also depends on how EU data protection rules apply to new technologies, such as facial recognition technologies, blockchain or AI.

"The two-year review shines an unflattering light on many of these shortcomings, yet the commission seems determined to double down by layering on even more rules," said Eline Chivot, a policy analyst from Center for Data Innovation, referring to the upcoming regulatory framework for AI and an extension of the right to data portability.

"Make no mistake: that would come at the cost of EU's economic competitiveness in the years ahead," she added.

"Policymakers should fix the GDPR's many shortcomings before creating even more rules. Otherwise, the EU will tie the hands of companies that could help its economy compete in the global economy," she also said.

Podcast

Data and Dystopia

Despite concerns about civil liberties and activities of companies like Clearview AI and Palantir, EU authorities are shaping a new industrial policy around artificial intelligence.

EU data protection rules abused to censor media

This week the EU's data protection rules (known as the GDPR) are two-years old. While the controversial GDPR was intended to offer greater privacy rights, it has also been abused by some authorities to muzzle a free press.

Interview

2013: Snowden was 'wake-up call' for GDPR

The contentious negotiations on the EU's data protection rules (GDPR), very much influenced by intense lobbying from the US, radically changed after whistleblower Edward Snowden revealed in 2013 that US intelligence services were collecting worldwide user-data.

News in Brief

  1. Report: Czech minister plotted to bury evidence on Russian attack
  2. Putin promotes Russia's 'Kalashnikov-like' vaccine
  3. Coronavirus: Indian variant clusters found across England
  4. UN report encourages EU methane cuts
  5. EU court upholds ban on bee-harming pesticides
  6. Israeli tourists welcomed back by EU
  7. EU duped into funding terrorist group, Israel says
  8. Brussels prepares portfolio of potential Covid-19 treatments

Stakeholders' Highlights

  1. Nordic Council of MinistersNordic Council enters into formal relations with European Parliament
  2. Nordic Council of MinistersWomen more active in violent extremist circles than first assumed
  3. Nordic Council of MinistersDigitalisation can help us pick up the green pace
  4. Nordic Council of MinistersCOVID19 is a wake-up call in the fight against antibiotic resistance
  5. Nordic Council of MinistersThe Nordic Region can and should play a leading role in Europe’s digital development
  6. Nordic Council of MinistersNordic Council to host EU webinars on energy, digitalisation and antibiotic resistance

Latest News

  1. EU ambassadors flock to Red Square for Putin's parade
  2. MEPs win battle for bigger citizens' voice at Conference
  3. Hungary gags EU ministers on China
  4. Poland and Hungary push back on 'gender equality' pre-summit
  5. EU preparing to send soldiers to Mozambique
  6. EU now 'open' to vaccine waiver, after Biden U-turn
  7. EU mulls using new 'peace' fund to help Libyan coast guard
  8. Poland 'breaks EU law' over judges, EU court opinion says

Join EUobserver

Support quality EU news

Join us