EC’s plan to reform AI and GDPR rules have experts seriously concerned

Last week the European Commission announced plans to change its landmark General Data Protection Regulation (GDPR) legislation and the rules about scraping data for AI training, and added a sweetener with an idea for eliminating the loathed cookie permissions pop-up.

“We are harmonising, clarifying and simplifying a number of GDPR provisions without touching core GDPR principles and requirements and without undermining the protection of individuals, in line with the GDPR risk-based approach,” an EC spokesperson told TechFinitive.

The agency claims the changes could save businesses €150 billion a year by setting up a European Business Wallet to simplify interactions between member countries.

Before we dig deeper, here are four of the key changes in the proposed “Data Union Strategy“:

  • A proposed “digital omnibus” rule change that will delay the full personal privacy protections contained in its AI Act by 16 months, potentially into late 2027, and narrow the definition of what constitutes personal data.
  • Ease the GDPR rules on smaller businesses to harvest data for AI training “for purposes of a legitimate interest,” and decide new guidelines as to what that constitutes.
  • Reduce the obligations for companies on data reporting under GDPR rules in favour of a single scheme.
  • Ease the rules on allowing or denying cookie data collection by allowing a browser tool to remind users of their settings every six months, rather than doing it every time you visit a site.

Digging deeper behind the proposed GDPR changes

Scrutiny is required any time a regulator says it wants to streamline a process for business, since such changes seldom benefit individual users. And the proposed rules – which are currently under discussion and need to be agreed by a majority of member states – may be modified further.

The European tech industry pressure group the Computer & Communications Industry Association certainly likes the proposals.

“While the Commission has made progress on AI and should be commended for acknowledging the damage of regulatory overreach, significant gaps in the AI Act remain,” said its Head of Policy Alexandre Roure.

“Across Europe, AI developers and deployers need clarity, and they need it fast. We therefore urge co-legislators to support the Commission by speeding up the legislative process.”

Rob Jones, Director of Research at the International Association of Privacy Professionals, told us that while the cookie changes are bound to be popular, the rest of the proposals are far more worrying.

“At the time Cambridge Analytica was a smaller business, for example,” he said. “In the omnibus bill the definition of personal data is becoming a bit too permissive and too relative, and could that give some easy, easy outs for companies to ‘say, it’s not personal data and the GDPR doesn’t apply anymore’.”

One of the most worrying areas, said Jones, is the definition of personal information. While the core GDPR principle of blocking the use of directly identifiable personal information still remains in place, the easing of the definitions would allow data brokers to cross-reference inputs and make people much more identifiable, he suggested.

The squishiness of legitimate interest

“Legitimate interest has been the squishiest legal justification in EU law for a while,” Calli Schroeder, Global Privacy Counsel for the Electronic Privacy Information Center, told us.

“There is some enforcement precedent stopping the more egregious misuses and we can highlight that as precedent, but AI companies will likely argue that their use is different than those cases, which will at least slow down meaningful stops to bad practices.”

She added: “This is further complicated by the proposed change to the GDPR that would explicitly allow AI to train on personal data as a legitimate interest. I genuinely have no idea how they think this is a minor change, it changes the entire meaning of the term.”

However, there’s a lot of horse trading to go on between member states. France and Italy seem keen on the changes; indeed, it was a report by one of Italy’s many former Prime Ministers Mario Draghi that kicked off the current proposals. Proposals supported by the current EC President Ursula von der Leyen.

Germany appears to be on the fence, in part due to its citizens being massively against using their personal data to train AI, and Irish eyes aren’t necessarily smiling at the changes. But the Emerald Isle is trying to develop its position as an AI titan, so may well be tempted to support an easing of regulation in order to grow this business.

An international view of GDPR

All this is occurring as the US administration is looking to block any regulation of the AI industry; an industry that includes major donors to the Republican Party. A rider slipped into the annual National Defense Authorization Act would allow the federal government to block individual states from regulating AI companies, but a proposed ten-year moratorium on regulations was blocked in July. This latest attempt to destroy regulations has caused a huge protest by US state legislators.

There are also more global considerations. Many countries, particularly in Africa and Asia, have adopted GDPR-style regulations using the EU’s rules as a template. Rob Jones warns that if the EC’s revisions pass as proposed it could lead these countries to abandon such plans on the basis that if the creators give up on them then why should they persist?

Then we come to the proposed €150 billion annual savings. The EC spokespeople we spoke to didn’t quantify how that figure was reached, and it seems remarkably high. One suspects it’s an eye-catching justification and – since the mathematical workings have not been produced – it should be treated with more than a pinch of salt.

Iain Thomson
Iain Thomson

In over 30 years as a tech journalist, Iain Thomson has worked for PC Magazine, PC Advisor, V3.co.uk, and was a cofounder of IT Pro. In the last 15 years worked for The Register he wrote over 5,000 news, analysis and feature articles for the site, and is also a regular guest and occasional host on The Week in Tech (TWiT) podcast. He is now a freelance tech reporter based in San Francisco.