Thursday, November 20, 2025

Europe Scaling Back GDPR and AI Laws

Robert Hart and Dominic Preston (Hacker News, MacRumors):

Under intense pressure from industry and the US government, Brussels is stripping protections from its flagship General Data Protection Regulation (GDPR) — including simplifying its infamous cookie permission pop-ups — and relaxing or delaying landmark AI rules in an effort to cut red tape and revive sluggish economic growth.

The changes, proposed by the European Commission, the bloc’s executive branch, changes core elements of the GDPR, making it easier for companies to share anonymized and pseudonymized personal datasets. They would allow AI companies to legally use personal data to train AI models, so long as that training complies with other GDPR requirements.

The proposal also waters down a key part of Europe’s sweeping artificial intelligence rules, the AI Act, which came into force in 2024 but had many elements that would only come into effect later. The change extends the grace period for rules governing high-risk AI systems that pose “serious risks” to health, safety, or fundamental rights, which were due to come into effect next summer. The rules will now only apply once it’s confirmed that “the needed standards and support tools are available” to AI companies.

Update (2025-11-21): noyb (via endl):

As gradually leaked the last days by various news outlets, the EU Commission has secretly set in motion a potentially massive reform of the GDPR. If internal drafts become reality, this would have significant impact on people's fundamental right to privacy and data protection. The reform would be part of the so-called "Digital Omnibus" which was supposed to only bring targeted adjustments to simplify compliance for businesses. Now, the Commission proposes changes to core elements like the definition of "personal data" and all data subject's rights under the GDPR. The leaked draft also suggests to give AI companies (like Google, Meta or OpenAI) a blank check to suck up European's personal data. In addition, the special protection of sensitive data like health data, political views or sexual orientation would be significantly reduced. Also, remote access to personal data on PCs or smart phones without consent of the user would be enabled. Many elements of the envisaged reform would overturn CJEU case law, violate European Conventions and the European Charter of Fundamental Rights.

See also: AFP.

Update (2025-11-25): M.G. Siegler:

Sure, it’s a few seconds here and there, but those add up in aggregate. And I, like everyone who lives in Europe, am doing it many, many times a day. Every day. And some have been doing this for over 15 years now…

And it’s actually worse than tedious or time-wasting, it actually does the exact opposite of what the intent was: to make people more mindful of their privacy and give them more control. No one reads these anymore, no one.

Nick Heer:

If you are annoyed about cookie banners, get ready to have that dialled back — maybe, a bit. The proposed changes will allow users to set their cookie preference in their web browser. But media companies will be free to ignore those automatic signals and ask for your permission to set cookies anyway. Also, the circumstances under which consent is not required will be broadened, but websites will still need to ask before using cookies for targeted advertising. Oh, and consent is still required by laws elsewhere and, until policies are harmonized around the world, consent banners are here to stay. Even if everyone copies the proposed changes for the E.U., you will still see a lot of these banners if you spend a lot of time reading news.

Previously:

Update (2026-08-26): John Gruber:

The GDPR went into effect 10 years ago. By their inaction, they obviously think it’s working just fine. I think they look at the situation and realize, with satisfaction, that every time any website presents a cookie-permission dickover, that dickover effectively has a “Brought to you by the European Commission” badge on it. They were here, they did something, and everyone around the world sees the fruits of the GDPR cookie regulations every time they open their web browser. Job well done.

Previously:

Update (2026-08-28): Nick Heer:

This time, though, the Commission said it was trying to make cookie consents less prevalent by allowing, for example, simple statistical cookies without any consent, and it was going to give users an option to decline tracking universally. When I looked into the changes in November, it seemed like this signal could be ignored by publishers and media companies who would be free to ask for consent anyway. As of May, it seemed this proposal was moving forward by requiring consent management platforms to respond to browser signals. By summer, however, things had changed.

[…]

Privacy-defending organizations are understandably not impressed. They have launched Kill the Cookie Banner to drum up support for legal recognition of a browser signal. In the U.S., five state governments say the Global Privacy Control must be respected. At a browser level, it is only implemented in Brave, DuckDuckGo, and Firefox, but it seems that Apple is working to add it to Safari, and it seems it is being actively worked on for Chromium, too. The European Commission should throw its weight behind this control, too.

6 Comments RSS · Twitter · Mastodon


Horrible proposal, but it's just a proposal for now. Anyone ca. make one. If you're in the EU, fight this. The watering down is already bad enough but enabling AI companies unfettered training on personal data (even if people don't want them to) is a disgraceful violation of privacy


Ban third party trackers
Ban moving first party data to third party hosted services


"If you are annoyed about cookie banners"

It's odd that people's solution to "websites steal so much of my data that they need huge modal disclaimers" isn't "maybe they shouldn't steal my data", but "let's get rid of the disclaimers."


> By their inaction, they obviously think it’s working just fine

Websites are disclosing how they violate your privacy; many have a simple opt-out button, and tracking in Europe has actually decreased[1]. People have better access to their own data; data security practices at corporations have improved as a direct result of the GDPR.

[1]: https://www.sciencedirect.com/science/article/pii/S0167811625000229

Is it perfect? No. Has it had a positive impact? Yes.

I'm so tired of Gruber's bullshit. He's obviously not an idiot, but his recent posts have generally been such clear instances of motivated reasoning that I'm getting to a point where I just don't want to hear anything from him anymore. And he doesn't seem to be able to see it himself; for example, he thinks if Anthropic's watermarking hadn't been motivated by the EU, he would have had the exact same overreaction to it.

It's all so dumb and black-and-white and one-dimensional. I miss when he wrote insightful posts on iTunes' design and stuff like that. Or maybe he's always been like that, and I have changed.


@Plume I like how people now have access to their data. But the cookie banners are just awful, including on the paper the you linked to above. I still get a constant stream of them on my desktop and also on my phone. I would gladly go back to the status quo ante with more tracking and no banners.


> But the cookie banners are just awful, including on the paper the you linked to above

Funny. I didn't see a banner because I have an extension that dismisses them, so I get both less tracking and no banners.

Leave a Comment