The Looming Overhaul of EU Data Rules
The landscape of European data privacy faces a seismic shift as the European Commission moves to introduce legislation designed to bolster the continent's AI competitiveness. A central feature of this proposal involves amendments to the General Data Protection Regulation (GDPR), specifically targeting how personal data is utilized for AI development. Under the draft language, processing personal data would be considered a 'legitimate interest' whenever it is deemed necessary for the technical operation or development of an AI model. This change is being positioned by proponents as a necessary step to lighten regulatory burdens and foster innovation among European tech firms and international players alike.
However, the move has triggered an immediate and fierce backlash from the non-profit organization noyb (None of Your Business). Led by privacy activist Max Schrems, the organization—which previously dismantled two major transatlantic data transfer pacts—argues that these proposed adjustments, currently categorized under draft references like Article 88bis, effectively signal an abandonment of the foundational principles that have defined European privacy standards for years.
The 'Digital Expropriation' Argument
At the heart of noyb's criticism is the belief that the new rules allow Big Tech companies to repurpose decades of personal data without explicit user consent. The campaign group contends that by framing AI training as a 'legitimate interest,' the European Commission is creating an automatic override that supersedes the fundamental rights of individual citizens. This, according to Schrems, constitutes a 'digital expropriation' of data, potentially allowing companies to ingest everything from historical social media activity to personal chat logs into AI systems, regardless of whether the users ever engaged with those platforms as customers.
The group asserts that the legislative push prioritizes the commercial interests of major AI developers—such as OpenAI, Google, and other global tech conglomerates—over the privacy of the European populace. By removing the requirement for user consent, the proposed framework arguably shifts the power dynamic heavily in favor of AI companies, setting the stage for what many civil liberty advocates fear will be a widespread, irreversible consolidation of personal information for model training purposes.
Why It Matters: The Conflict Between AI and Privacy
- Regulatory Erosion: Critics fear that weakening GDPR standards for AI sets a dangerous precedent that could lead to the degradation of privacy protections across all digital sectors.
- Legal Uncertainty: By pushing legislation that may fundamentally conflict with existing EU fundamental rights, the Commission risks future intervention from the Court of Justice of the European Union (CJEU).
- Corporate Power: The shift highlights the growing tension between government-led initiatives to promote economic growth through AI and the established commitment to individual digital autonomy.
A Return to the Courts
The path forward remains fraught with legal ambiguity. While the European Commission aims to streamline regulation to enhance competitiveness, the European Parliament's stance remains fragmented. Max Schrems has signaled that if the legislature fails to maintain a sense of proportion, the battle will inevitably move back to the courtroom. Given noyb’s track record in the 'Schrems I' and 'Schrems II' cases—which successfully invalidated major EU-US data pacts—their threat to challenge these AI-focused amendments carries significant weight.
Ultimately, the confrontation suggests that the promise of 'regulatory simplification' for AI may come at the cost of long-term legal stability. If the proposed rules are eventually found to be incompatible with European fundamental rights, the industry could face years of litigation, potentially creating even more confusion for the very companies the legislation intended to support.









