Draft proposals obtained by POLITICO show EU is breaking sacred privacy regime to placate industry [politico.eu]:
European Union officials are ready to sacrifice some of their most prized privacy rules for the sake of AI, as they seek to turbocharge business in Europe by slashing red tape.
The European Commission will unveil a "digital omnibus" package later this month to simplify many of its tech laws. The executive has insisted that it is only trimming excess fat through "targeted" amendments, but draft documents obtained by POLITICO [politico.eu] show that officials are planning far-reaching changes to the General Data Protection Regulation (GDPR) to the benefit of artificial intelligence developers.
The proposed overhaul will come as a boon to businesses working with AI, as Europe scrambles to stay economically competitive on the world stage.
But touching the flagship privacy law — seen as the "third rail" of EU tech policy — is expected to trigger a massive political and lobbying storm in Brussels.
"Is this the end of data protection and privacy as we have signed it into the EU treaty and fundamental rights charter?" said German politician Jan Philipp Albrecht, who as a former European Parliament member was one of the chief architects of the GDPR. "The Commission should be fully aware that this is undermining European standards dramatically."
Brussels' shift on privacy comes as it frets over Europe's waning economic power. Former Italian Prime Minister Mario Draghi namechecked the General Data Protection Regulation as holding back European innovation on artificial intelligence in his landmark competitiveness report [politico.eu] last year.
[...] In past months, Commission officials have sought to preempt worries [youtube.com] that it was overhauling the privacy rulebook. It insisted that its simplification proposals wouldn't touch the underlying principles of the GDPR.
Now that draft plans are out, civil society campaigners have begun sounding the alarm.
The Commission is "secretly trying to overrun everyone else in Brussels," said Max Schrems, founder of Austrian privacy group Noyb — and Europe's infamous privacy campaigner [politico.eu] who was behind court cases that brought down major data transfer deals with the United States in the past. "This disregards every rule on good lawmaking, with terrible results," he said.
One line of attack from privacy groups is to poke holes in what they say is a rushed omnibus process. While the GDPR took years to negotiate, public consultation on the digital omnibus only ended in October. The Commission has not prepared impact assessments to accompany its proposals, as it says the changes are only targeted and technical.
The Commission's tunnel vision on the AI race has resulted in a "poorly drafted 'quick shot' in a highly complex and sensitive area," said Schrems.
[...] Draft changes would create new exceptions for AI companies that would allow them to legally process special categories of data (like a person's religious or political beliefs, ethnicity or health data) to train and operate their tech. The Commission is also planning to reframe the definition of such special category data, which are afforded extra protections under the privacy rules.
Officials also want to redefine what constitutes as personal data, saying that pseudonymized data (where personal details have been obscured so a person can't be identified) might not always be subject to the GDPR's protections, a change that reflects a recent ruling [europa.eu] from the EU's top court.
Finally, it wants to reform Europe's pesky cookie banner rules by inserting a provision into the GDPR that would give website and app owners more legal grounds to justify tracking users beyond simply obtaining their consent.