GDPR 2.0: Regulation for competitive Europe?
To say that the Omnibus IV amendments to GDPR were disappointing would be an understatement.
After the Draghi report, many hoped the EU would take concrete steps to ease the regulatory burden on SMEs arising from GDPR. Instead, the proposed amendment feels like a symbolic concession which changes little in practice.
Of course, there are still ongoing debates about whether and how to revise GDPR’s “one-size-fits-all” model, but the prevailing sentiment seems to be for #NoReopening.
Additionally, the planned procedural regulation for cross-EU GDPR enforcement risks making matters worse. Max Schrems has already said that “this regulation adds tons of extra steps and extra paperwork to the existing procedures. Authorities and businesses will have more work with GDPR procedures – not less.”
Similarly, the Czech Data Protection Authority warned in its 2024 Annual Report that new procedural demands would paradoxically weaken data subjects’ rights, given limited staff, technical and administrative resources.
And to add fuel to the fire, there are more and more overlapping EU regulations which continue to pile up — just think about cyber incident reporting obligations.