Blog

A serious target for improving EU regulation: GDPR enforcement
In recent months, we’ve been hearing about the European Commission’s call for simplification of regulations—an agenda championed by President Ursula von der Leyen. She rightly noted that businesses are overwhelmed by regulations that are “too complex and costly to comply with.
The New French Way of AI Policy: Should Europe Follow?
The vibe in Paris around the AI Action Summit feels strikingly different from Brussels. It’s not even the call to pivot away from over-regulation (you can hear that in Brussels). The difference is that, refreshingly, the call seems earnest (in Brussels it very much isn’t).
The EDPB’s AI Opinion Shows the Need for GDPR Enforcement Reform
Just before Christmas, the EU’s data protection authorities (DPAs)—working together as the EU Data Protection Board (EDPB)—issued the hotly anticipated Opinion on AI models and EU privacy law. As it turned out, the excitement about the Opinion was unjustified.
Apple and EU DMA: a road to leave the EU?
Several recent news items on Apple’s and the EU Digital Markets Act prompted me to update my thoughts on Apple’s struggles with the European Commission and with other software developers. For my previous update, with links to earlier texts, see DMA workshops and privacy.
AI hallucinations, EU GDPR, and the importance of cautious optimism
The EU’s data protection law, the GDPR, requires accuracy in processing personal data. However, generative AI—like large language models (LLM)—may “hallucinate” or reflect information that is false but widely spread. On one hand, inaccuracy may seem like an inherent feature of the technology.
The GDPR and GenAI — Part 1: Lawful Bases
The recent official publication of the EU Artificial Intelligence Act has left several fundamental debates on the legal status of AI in Europe unresolved. Two significant potential legal obstacles to AI development and use remain inadequately addressed: intellectual property and personal data protection laws.
Should the GDPR Prohibit AI? Notes on EU’s AI & GDPR stakeholder event
The European Data Protection Board’s (EDPB) Nov. 5 stakeholder consultation on AI models and data protection—organized to gather input for an upcoming Irish Data Protection Commission opinion under Article 64(2) of the General Data Protection Regulation (GDPR)—showcased significant lingering disagreement on how the GDPR should apply to AI.
Cookies and Google’s privacy-competition dillema
[First published on Truth on the Market on 12 August 2024] Google recently announced that it has changed its plans to phase out third-party cookies in the Chrome web browser. The company had previously planned to disable third-party cookies in Chrome, a change supported by many in the privacy-stakeholder community, but which was met with criticism from the adtech industry and competition lawyers.
AI and EU privacy law: June 2024 state of play
Despite the official publication of the EU Artificial Intelligence Act, debates on the legal status of AI in Europe continue. Two significant potential legal obstacles for AI development and use remain inadequately addressed: intellectual property and privacy laws.
Pay or OK: what is an “appropriate fee”? (July update)
The “pay or OK” debate in the EU continues, and it is still unclear what its outcome will be, for Meta and everyone else. Today, the European Commission announced their preliminary finding that Meta’s approach is not compliant with the law.