Cybersecurity Policy Report, EU Privacy Advocates Decry Proposed Changes to GDPR, (Nov 12, 2025)
A European Commission proposal to redefine what constitutes “personal data” would gut the robust personal privacy protections offered by the European Union’s General Data Protection Regulation (GDPR), according to three digital rights groups.
“We are particularly worried about the consequences of re-defining what constitutes ‘personal data’ by introducing a ‘subjective’ approach depending on the specific controllers’ capability to identify the person and by potentially excluding ‘pseudonymous’ data from the scope of the GDPR,” the groups said in a letter to EC leaders.
“One consequence of this change could be that the GDPR no longer applies to so-called user IDs which are the basis for the highly problematic data processing of the online advertising and data broker industry,” they said.
“Another huge limitation of protection could occur from the envisaged reduction of scope of ‘sensitive’ data (like political opinions, sexual orientation, trade union membership, health information etc.),” the groups noted.
“The GDPR would only apply to sensitive data ‘directly revealed’ instead of ‘inferred’ as currently defined. The drastic and absurd consequence could be that people who do not want to disclose their personal situation would lose all protections yet those who communicate about such sensitive information would be protected,” they said.
The changes being contemplated by the EC are part of a “digital omnibus” package that aims to simplify and reconcile a variety of EU laws pertaining to artificial intelligence, privacy, and other technology issues.
A leaked version of the legislative package, which will be officially unveiled on Nov. 19, has been met with dismay by some privacy and civil liberties advocates (CPR, Nov. 10).
“We agree that the digital acquis should be consistent and that its application should be coordinated. However, the legislative changes now contemplated go far beyond mere simplification. They would deregulate core elements of the GDPR, the e-Privacy framework and AI Act, significantly reducing established protections,” the groups warned.
“Recent data broker scandals across Europe and beyond have exposed how personal data including sensitive information such as location and behavioural profiles, continues to be traded and exploited at scale,” they observed.
“These cases demonstrate that the problem is not excessive regulation, but the lack of consistent enforcement, guidance and harmonisation. Instead of weakening safeguards, the EU should strengthen oversight and ensure that regulators have the tools and resources to make existing rules work in practice,” they said.
The letter was sent by European Digital Rights, the Irish Council for Civil Liberties, and the European Center for Digital Rights to Henna Virkkunen, the EC’s executive vice president–tech sovereignty, security, and democracy; and Michael McGrath, the EC’s commissioner–democracy, justice, the rule of law, and consumer protection.
News: InternationalLegislation DataPrivacy GDPR