Holding the Line: Preserving the Core Features of the EU’s GDPR
Adopted nearly ten years ago, the General Data Protection Regulation set an international precedent and baseline for how personal data should be handled in an increasingly digital environment. Now, the very spine around which the GDPR’s safeguards are organised – the definition of personal data – is being called into question, threatening the reach and applicability of the privacy-preserving legal framework that socialised the very concept of the “Brussels effect”.
Today, on European Data Protection Day, we urge decision makers to reflect on the implications of the Digital Omnibus proposal and to strive to protect the high standards of data protection that the GDPR has long guaranteed.
The Digital Omnibus Proposal
Presented by the European Commission in November 2025, the Digital Omnibus proposal is a wide-ranging document bundling together proposed modifications to a range of existing laws governing the digital space under the guise of simplification, including the GDPR. Many of the suggested changes go far beyond “technical amendments”, prompting outcry from civil society advocates who have challenged the legitimacy and scope of the proposal, with many calling for an outright rejection of the changes to GDPR.
It is easy to see why. While the proposed modifications to the GDPR are harmful and wide-ranging, one core modification threatens the essence of the law as a whole: redrawing the boundaries of the definition of personal data, and in so doing drastically reducing the scope of application of the GDPR.
Watering Down Decades-Old Concept
In its current version, GDPR defines “personal data” simply and objectively as “any information relating to an identified or identifiable person”. The Digital Omnibus keeps this phrase, but suggests additions which have the effect of relativising what should be considered personal data: if an entity handles information for which it cannot identify the person to whom that information relates to, that information would no longer be considered personal data for that particular entity. The change paves the way for companies to choose to act outside of the scope of the GDPR when they consider they do not hold the means of identifying an individual. Worse yet, the changes would allow entities to use and exchange information that would have formerly been categorised as personal data without safeguards, irrespective of whether such information would become identifiable upon reaching said third party. A stark example puts these implications into perspective: EU-based entities could freely share information with foreign actors outside of the scope of GDPR’s cross-border transfer safeguards – which would no longer apply –, even if such actors could in fact connect the information to living individuals.
The new definition is stated to seek alignment with EU-level jurisprudence – yet several academics have underscored that the proposed definition at best oversimplifies the body of judicial decisions interpreting the concept of personal data, and outright conflicts with them at worst.
The implications of the change are significant. First, they overlook the crucial role of the GDPR in operationalising a fundamental right in the EU: the right to personal data protection recognised in the Charter of Fundamental Rights and the Treaty on the Functioning of the European Union. Changing the foundations of GDPR means drastically altering how that right is interpreted, protected and enforced – and narrowing down the definition of personal data risks contravening the European Commission’s legal duty to uphold fundamental rights in legislation.
An altered definition would result in an EU framework that is out of step with regional approaches. Convention 108 – an international treaty regulating the processing of personal data dating from 1981– endorses a definition of personal data that is almost identical to the GDPR’s in its current form. Changing the GDPR’s definition of personal data would set a lower bar and paradoxically result in a weakened data protection framework for the only regional bloc that has made the protection of personal data a fundamental right.
An Unfortunate Domino Effect
Any conversation weakening the reach of the GDPR threatens the EU digital rulebook as a whole. Instruments such as the Digital Services Act (DSA), Regulation on the Targeting and Transparency of Political Advertising, and the Artificial Intelligence Act all rest on the foundation laid by the GDPR.
The ban on the use of personal data to target ads to minors and the requirement to offer profiling-free recommender systems – core victories of the DSA – are reliant on the definition of personal data, and the connected definition of profiling set by the GDPR. Many of the AI Act’s core provisions, including on its prohibited practices, similarly echo the definition of profiling contained in the GDPR. One of the last remaining safeguards against the proliferation of dangerous AI systems following a related proposal to change the AI Act — the AI Act Omnibus which revisits the EU’s flagship AI law – is also impacted by the GDPR’s change in definition because it relies on the existence of profiling. If the concept of personal data as we know it is gone, profiling – defined as the automated processing of personal data – also loses its meaning, weakening laws that were developed to build on the strong privacy imperative enshrined in the GDPR.
Far from achieving its simplification goal, the Digital Omnibus opens a Pandora’s box requiring re-assessing the meaning and effectiveness of core provisions agreed by the institutions at the conclusion of lengthy and fraught negotiations. At a time when the European Commission is acting swiftly to protect the digital space, these changes both threaten to undermine the current momentum and hinder the robust implementation of much-needed guardrails.
Conclusion
European Data Protection Day exists as a celebration of privacy and data protection. Against the current deregulatory context, it should also provide an opportunity for reflection on the strengths of the current data protection framework, the importance of a robust GDPR, and the fundamental rights leadership the EU can realistically claim to hold in an increasingly polarised world.
We call on the co-legislators to uphold the EU’s privacy-preserving legacy and hold firm on protecting the definition of the GDPR.
Potential Avenues for Redress for AI-related Harms under EU Equality and Non-Discrimination law: A Visual Explanation
In this third instalment of the series, we look at the opportunities afforded by EU equality and non-discrimination law in providing redress for AI-related harms.
General-purpose AI Code of Practice Implementation: A Rights Blindspot
CDT Europe's analysis of the entry into application of the European Commission’s enforcement powers towards general-purpose AI (GPAI) models, detailed and operationalised in the GPAI Code of Practice.
As Brussels starts emptying for the summer, the risks of frontier AI models continue to capture the attention of policymakers as a key chapter of the AI Act becomes enforceable, and disclosure rules around the use of AI systems and AI-generated content are further clarified.
CDT Europe’s Feedback on the Draft Guidelines for the Classification of High-Risk AI Systems under the AI Act
CDT Europe responded to the European Commission’s consultation on the draft guidelines for the classification of high-risk artificial intelligence systems.