Brussels has spent years proving that the easiest way to “fix” the General Data Protection Regulation (GDPR) is to give more power to the institutions that made it unworkable. The Digital Omnibus initially looked ready to continue that tradition. Now, somewhat improbably, several EU governments appear determined to try actual reform instead.
Ireland assumed the rotating presidency of the Council of the European Union from Cyprus for the second half of the year and declined to recycle Cyprus’ flawed draft. Instead, it reopened negotiations over the European Commission’s proposal on pseudonymization, cookie consent, and the use of data for artificial intelligence (AI).
Serious reform will still face resistance in the European Parliament. A joint draft report from its industry and civil-liberties committees leaves the Commission’s most contested GDPR proposals untouched for now. But the co-rapporteurs’ public statements—and the flood of amendments filed since—show that the legislation remains very much in play.
The European Data Protection Board (EDPB) has also weighed in. Although it does not make EU law, it exerts considerable influence over national governments. Its new guidelines distinguishing personal from anonymous data accept, for the first time, the Commission’s central point: whether data is personal should depend on the entity holding or using it, not on whether anyone, anywhere, could identify the person concerned.
The guidelines also show why procedural reform may matter even more. As usual, the EDPB could not quite bring itself to offer guidance useful for much beyond increasing lawyers’ billable hours.
The Reform Fight Takes Shape
The reform effort is now moving on four fronts, with the Council showing unexpected signs of ambition, Parliament preparing for a fight, the EDPB conceding a key point while muddying the details, and a separate AI measure quietly becoming law.
The Council Hits Reset
The Cypriot presidency of the Council of the European Union tried to secure agreement among national governments on a common position that could have left the GDPR worse off than no reform at all. One week before its term ended, Cyprus circulated another compromise draft, following the version I discussed previously.
It failed. Several governments reportedly objected, including Denmark, Germany, Italy, Poland, and Sweden. The precise reasons remain unclear, but reports suggest that these countries thought the draft did too little to simplify the GDPR. If so, there may still be hope for the reform process.
Ireland, which now holds the rotating Council presidency, chose not to carry over the Cypriot text. Instead, it sent national governments a questionnaire reopening debate over cookie exemptions, pseudonymization, AI data processing, and reductions in compliance burdens.
Parliament Prepares for Battle
The European Parliament’s lead negotiators published their draft report in late June. Two committees share responsibility for the legislation: the Committee on Industry, Research and Energy, led by Aura Salla of the European People’s Party, and the Committee on Civil Liberties, Justice and Home Affairs, led by Marina Kaljurand of the Socialists and Democrats. The Legal Affairs Committee and the Internal Market and Consumer Protection Committee also have advisory roles and have produced draft opinions.
The joint report reflects what Salla and Kaljurand could agree on quickly. It therefore leaves the most contentious questions untouched, including the European Commission’s proposed clarification of “personal data.”
That restraint will not last. Parliament members have already filed a large number of amendments, and both Salla and Kaljurand have indicated that they will seek changes on issues omitted from the draft, including the definition of personal data.
The EDPB Concedes—Then Complicates
The EDPB has published new guidelines on anonymization that bear directly on the Commission’s proposal. Most notably, it finally accepted that whether information counts as anonymous—and therefore falls outside the GDPR—depends on the position of the entity processing it. This is the entity-relative view.
That is broadly the clarification the Commission proposes for Article 4, which defines personal data. But the EDPB wrapped that central point in broader, vaguer qualifications than the Commission likely would have adopted. I will return to those complications shortly.
The ‘AI Omnibus’ Takes Effect
Meanwhile, a less controversial companion measure concerning the EU AI Act entered into force this week. This “AI Omnibus” postponed several compliance deadlines, prohibited AI-generated child sexual-abuse material and nonconsensual intimate imagery, and expanded the legal basis for using sensitive personal data to detect bias in AI systems.
Where the GDPR Reform Fight Gets Real
The next stage of the fight will turn less on abstract definitions than on whether the final law gives businesses rules they can actually use. The debate now centers on three familiar trouble spots: what counts as personal data, how cookie consent should work, and whether the GDPR will leave room for AI development.
The Definition Fight Is Mostly Symbolic
Reports from the final weeks of negotiations under the Cypriot presidency suggest that several national governments oppose the European Commission’s proposed clarification of “personal data” in Article 4 of the GDPR. The proposal also faces resistance in the European Parliament.
I support the clarification, but its practical importance is easy to overstate. The EDPB has now formally accepted the entity-relative view: whether information counts as personal data depends on the position of the entity processing it.
Some will argue that any amendment to Article 4 should include qualifications like those in the EDPB’s anonymization guidelines. Others will say that, because the EDPB has already accepted the entity-relative view, no legislative change is needed.
That argument gives the EDPB too much credit. Its guidelines offer little operational clarity and often seem designed to make implementation difficult unless one simply assumes that all data is always personal. The more consequential reforms are therefore procedural: the Commission’s proposal would let the Commission, rather than the EDPB, adopt legally binding implementing acts that define concepts such as pseudonymization and personal data.
Those powers should be stronger. As drafted, compliance with a Commission implementing act would count only as “an element” in the legal analysis. It should instead create a robust presumption of compliance.
Guidance That Actually Guides
What matters most is whether organizations handling EU data can determine which concrete safeguards place information outside the GDPR because it no longer qualifies as personal data. The EDPB’s anonymization guidelines once again show that the board is institutionally ill-suited to provide that kind of practical direction.
Substance alone is not enough. The guidance must also carry enough legal force to create a strong presumption that those who follow it are acting lawfully. Polish member of the European Parliament Piotr Müller has proposed an amendment moving in that direction—Amendment 398.
The joint industry and civil-liberties committee draft does not yet revise the relevant provision, Article 41a. Its broader thrust, along with many of the amendments filed in Parliament, instead points toward preserving or even expanding the EDPB’s role. Brussels may yet respond to unworkable guidance by giving its authors more authority. That would be very on-brand.
Cookies: Pick Your Poison
The weakest part of the Commission’s proposal concerns cookie consent under Article 5 of the ePrivacy Directive. National governments were understandably unimpressed, and the Cypriot presidency reportedly removed the provision from its final draft.
Ireland has reopened the question, at least in part. It reportedly asked governments whether the law should expand the list of activities that do not require consent, though it is unclear whether the questionnaire also addressed consent managed through browser settings.
The joint committee draft leaves the Commission’s proposal intact. Other parliamentary amendments cover nearly every imaginable option: replacing the ePrivacy rule with ordinary GDPR standards, adding more exemptions, narrowing the proposed exemptions, deleting browser-level consent, or expanding it. The one thing Parliament appears to agree on is that cookie banners have not yet consumed enough legislative attention.
AI Rules Back in Play
The Commission’s proposal contains two provisions of particular importance to AI. Article 88c would clarify that legitimate interests may provide a lawful basis for developing and operating AI systems. Article 9(2)(k) would create a limited exception for sensitive personal data that appears incidentally in AI training datasets.
In my early June comments, I noted that, in the Council drafts, “Article 88c has disappeared from the operative text, but much of its substance survives in Recital 33a,” while “Article 9(2)(k) survived, albeit in narrowed form.” Under the Irish presidency, both issues appear to be back on the table.
As with cookie consent, the joint committee draft proposes no changes to these provisions. Other amendments run in opposite directions, with some seeking to delete the AI provisions and others seeking to broaden them.
I am watching Article 9(2)(k) particularly closely because it may be the Commission’s most immediately consequential reform. As I wrote in the International Center for Law & Economics’ (ICLE) March comments:
Article 9(2)(k) addresses a practical constraint of large-scale AI training: special categories of personal data will inevitably appear in training datasets despite efforts to exclude them. … Perfect ex ante filtering is technically impossible. … Without Article 9(2)(k), controllers face a binary choice: guarantee perfect exclusion of special-category data or abandon AI training in the EU.
Now Comes the Brussels Waiting Game
The European Parliament’s July 15 amendment deadline produced more than 1,000 proposed changes, so the initial joint committee report settles very little. The lead negotiators will spend the autumn bargaining over compromise amendments while awaiting a targeted impact assessment. At this pace, Parliament is unlikely to adopt its negotiating position before February 2027.
The EDPB’s consultation on its anonymization guidelines closes Oct. 30. That process may clarify the board’s position, though recent history counsels against expecting clarity to arrive unaccompanied by qualifications.
The Council may move faster. Ireland now has six months to do what Cyprus could not: secure an agreed position among national governments. Much will depend on how it uses the responses to its questionnaire. The next compromise text should show whether Ireland is serious about simplifying the GDPR—or merely preparing a more elegant route back to the same thicket.
