Back to blog

EU Rejects Easier GDPR Rules for AI

Based on research by NOYB

schremspersonal datadata protectionaigdpr

The European Data Protection Board and the European Data Protection Supervisor have issued a stark warning against the European Commission’s proposed Digital Omnibus reforms. In a joint opinion, these independent authorities rejected key attempts to narrow the definition of personal data and restrict user rights, signaling that the current regulatory trajectory is facing significant pushback. For Swedish technology leaders, this is not just bureaucratic noise; it confirms that the push to loosen GDPR constraints for the sake of AI competitiveness is far from settled and likely to remain contentious.

The core of the controversy lies in the Commission’s attempt to redefine what constitutes personal data under Article 4(1) GDPR and to limit the right of access under Article 12(5). The authorities argue that these changes would effectively allow companies to escape GDPR obligations by reclassifying data as non-personal or pseudonymized without sufficient safeguards. Furthermore, while the proposal suggests using legitimate interest for AI training, the authorities note that Article 88c fails to provide clarity, leaving companies to perform complex three-step tests to ensure compliance. This ambiguity means that relying on these proposed changes for AI development is currently a legal gamble, not a safe harbor.

The practical implication for Swedish CTOs and CISOs is that you cannot assume a lighter regulatory burden is coming. The authorities’ rejection of these simplifications means that the status quo remains the safest legal baseline. Attempting to exploit the proposed loopholes for AI training or data processing could expose your organization to severe compliance gaps and enforcement actions. The authorities explicitly warned that such changes primarily benefit large US tech firms and law firms specializing in loopholes, rather than reducing administrative overhead for normal EU businesses. If the Commission tries to push these narrow definitions through, expect heightened scrutiny from Swedish and EU regulators who are now explicitly aligned against them.

This regulatory standoff reinforces the strategic imperative for data sovereignty. When the legal definition of personal data is under threat and the rules for AI training remain ambiguous, the only way to guarantee compliance is to keep control of your data infrastructure. Processing data locally within the EU or Sweden minimizes exposure to these shifting regulatory sands and ensures that you remain within the clear protections of the current GDPR framework. As the battle over the Digital Omnibus continues, the companies that prioritize local, compliant data processing will be the ones insulated from the chaos of legislative uncertainty.