Technology · Digital regulation
EU Commission prepares GDPR rewrite to accelerate AI development
Draft documents reveal far-reaching changes to privacy law including new exceptions for AI training on sensitive personal data and a redefinition of what counts as personal information.
The European Commission is preparing to rewrite the General Data Protection Regulation, the legal framework that has governed personal data across the European Union since 2018. Draft documents obtained by POLITICO show the executive plans to introduce new exceptions for artificial intelligence developers, redefine what constitutes personal data, and weaken consent requirements for online tracking. The changes form part of a "digital omnibus" simplification package due to be unveiled on 19 November, which the Commission describes as targeted technical adjustments but which privacy advocates and several member states regard as a fundamental dismantling of the EU's privacy architecture.
The digital omnibus and the competitiveness imperative
The omnibus package arrives against a backdrop of mounting anxiety over Europe's economic competitiveness. Former Italian prime minister Mario Draghi, in his landmark competitiveness report published last year, explicitly named the GDPR as a barrier to European innovation in artificial intelligence. The argument, echoed by industry lobbyists, is that strict privacy rules prevent European companies from accessing the vast data sets needed to train competitive AI models, while their American counterparts operate without an equivalent federal privacy law. The Commission has been signalling for months that simplification of the digital rulebook is a priority, but officials insisted until now that the underlying principles of the GDPR would remain untouched.
That assurance has not survived contact with the draft text. The proposals would create explicit legal grounds for AI companies to process special categories of data, information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, and data concerning a person's sex life or sexual orientation. Under the current regulation, processing such data is prohibited unless one of a narrow set of exceptions applies. The Commission's draft would add AI development to that list, provided certain safeguards are met. The text also proposes reframing the definition of special category data itself, potentially narrowing the scope of what receives enhanced protection.
Redefining personal data and the pseudonymisation question
A second major change concerns the definition of personal data. The GDPR currently applies to any information relating to an identified or identifiable natural person. The Commission wants to clarify that pseudonymised data, where direct identifiers have been replaced with codes or keys, might not always fall within the regulation's scope. This reflects a ruling earlier this year from the Court of Justice of the European Union, which held that data can be considered anonymous in the hands of a party that lacks the means to re-identify individuals, even if another party holds the key. Critics argue the legislative proposal goes further than the court judgment, creating a loophole that would allow companies to claim pseudonymisation while retaining re-identification capabilities.
The third pillar of the GDPR changes targets the much-maligned cookie banner regime. The draft would insert a provision into the regulation giving website and app operators additional legal bases for tracking users beyond explicit consent. Since the ePrivacy Directive was last updated in 2009, the consent requirement has produced the ubiquitous pop-up banners that users routinely click through without reading. The Commission's approach would legitimise alternative grounds such as legitimate interest, a concept already present in the GDPR but contested in the context of behavioural advertising and analytics. Privacy campaigners warn this would effectively nullify the consent model that underpins current tracking rules.
Regulatory friction and the Big Tech precedent
European privacy regulators have become a significant obstacle to AI deployment by major technology platforms. The Irish Data Protection Commission, lead supervisor for many US tech giants under the GDPR's one-stop-shop mechanism, has forced Meta, X and LinkedIn to delay or modify AI rollouts in Europe. Google faced an inquiry from the same regulator and was previously required to pause the release of its Bard chatbot. Italy's Garante per la Protezione dei Dati Personali imposed temporary blocks on OpenAI's ChatGPT and the Chinese model DeepSeek over privacy concerns. These interventions have reinforced the industry narrative that European regulation is stifling innovation, a narrative the Commission now appears to be adopting.
The GDPR's original negotiation between 2012 and 2016 triggered one of the most intense lobbying campaigns in Brussels history. Since the regulation took effect in 2018, the EU has avoided reopening the text, fearing a repeat of that battle. The Commission's current approach, embedding GDPR amendments within a broader omnibus simplification package, is seen by critics as an attempt to bypass the scrutiny a standalone revision would attract. Public consultation on the digital omnibus closed in October, a fraction of the time typically afforded to major legislative initiatives. The Commission has not prepared impact assessments, arguing the changes are merely technical and targeted.
Member states split along predictable and surprising lines
Documents seen by POLITICO reveal a sharp divide among national governments. Estonia, France, Austria and Slovenia have declared firm opposition to any rewrite of the GDPR. France's position is notable given President Emmanuel Macron's frequent calls for European technological sovereignty; Paris appears to calculate that weakening privacy standards would damage the EU's regulatory credibility without guaranteeing competitive AI champions. Austria and Slovenia have historically aligned with stronger data protection positions. Estonia's opposition is more surprising for a country that brands itself as a digital pioneer, but Tallinn has consistently argued that legal certainty matters more than deregulation.
Germany, traditionally among the most privacy-conscious member states, has broken ranks to push for substantial changes. Berlin's shift reflects pressure from its industrial base, where companies such as Siemens, SAP and the automotive sector are investing heavily in AI-driven manufacturing and services. The German government argues that legal clarity for AI training data is essential to prevent European firms from falling behind. This puts the Federal Ministry for Digital and Transport at odds with the Federal Commissioner for Data Protection and Freedom of Information, who has warned against diluting fundamental rights. The internal German debate mirrors the wider European tension between industrial policy and civil liberties.
Parliamentary battle lines take shape
In the European Parliament, the dividing lines cut across political groups. Markéta Gregorová, a Czech Greens MEP, said she was "surprised and concerned" that the GDPR was being reopened. She warned that Europeans' fundamental rights "must carry more weight than financial interests." Her position reflects a broader scepticism among Greens and left-leaning MEPs about the omnibus approach. On the other side, Aura Salla, a Finnish centre-right MEP who previously led Meta's Brussels lobbying office, said she would "warmly" welcome the proposal "if done correctly," arguing it could bring legal certainty for AI companies. Salla emphasised that the Commission must "ensure it is European researchers and companies, not just third country giants that gain a competitive edge from our own rules." Her intervention highlights the revolving door between Big Tech lobbying and parliamentary politics, a dynamic that privacy advocates cite as evidence of regulatory capture.
Civil society sounds the alarm
Max Schrems, founder of the Austrian privacy group Noyb and the litigant behind the Schrems I and II judgments that invalidated two EU-US data transfer agreements, described the Commission's approach as "secretly trying to overrun everyone else in Brussels." He characterised the omnibus process as a "poorly drafted 'quick shot' in a highly complex and sensitive area" that "disregards every rule on good lawmaking, with terrible results." Schrems's intervention carries weight because his litigation has repeatedly forced the EU to confront the gap between its privacy rhetoric and the reality of US surveillance law. Noyb has already signalled it will challenge any weakening of the GDPR in court, potentially tying the changes up in litigation for years.
Jan Philipp Albrecht, the Green MEP who served as rapporteur for the GDPR during its parliamentary passage, put the stakes in constitutional terms: "Is this the end of data protection and privacy as we have signed it into the EU treaty and fundamental rights charter? The Commission should be fully aware that this is undermining European standards dramatically." Albrecht's question goes to the heart of the EU's legal order. The GDPR was not adopted as an ordinary regulation but as a measure implementing a treaty-based fundamental right. Amending it through a simplification package, a procedural vehicle designed for removing contradictions and redundancies across multiple acts, raises questions about whether the Commission is exceeding its mandate.
The legislative road ahead
Once the Commission publishes its formal proposal on 19 November, the ordinary legislative procedure begins. The Council of the EU and the European Parliament must agree on a common text. Given the opposition from at least four member states and the likely resistance from Greens, Socialists and parts of the liberal Renew group in Parliament, the Commission will need to build a qualified majority in the Council, 55% of member states representing 65% of the EU population, and a simple majority in Parliament. The German-French split complicates the traditional motor of EU lawmaking. If Paris holds its ground, Berlin will need to assemble a coalition of northern and eastern member states, many of which share Germany's industrial priorities but may balk at weakening a regulation their citizens value.
The Parliament's internal dynamics are equally uncertain. The centre-right European People's Party, the largest group, has not declared a unified position. Its MEPs include both digital single market enthusiasts and defenders of the GDPR's consumer protections. The Socialists and Democrats are likely to oppose but contain members from industrial regions who fear job losses. The hard right, including Patriots for Europe and European Conservatives and Reformists, may support deregulation on principle but oppose any measure that strengthens EU-level regulation. Aura Salla's EPP colleagues will face pressure from national parties not to be seen dismantling privacy rights ahead of national elections in several member states in 2026 and 2027.
Sources
People mentioned
Jan Philipp Albrecht
Organisations
European Commission · European Parliament · Irish Data Protection Commission · Noyb