Editorial by Prof Dr Hielke Hijmans[1]

  1. Introduction

    As the CJEU recently confirmed in its judgment in Commission/Hungary, the fundamental values “enshrined in Article 2 TEU are, per se, legally binding, and therefore there is an obligation, on the Member States and institutions of the Union, to respect, maintain and promote those values”.[1]

    In order to fulfil this obligation, the Union and the Member States must have the necessary competences and powers. In the digital domain, where power has shifted towards tech giants,[2] there is a specific need for effective competences to ensure that these fundamental values, and in particular the rule of law, are upheld. 

    At the same time, there is ample discussion on EU legislation in the digital age. A common narrative is that detailed regulatory frameworks hamper innovation in the EU, its competitiveness and – possibly most importantly – the digital sovereignty of the Union.[3] The Draghi report suggests that fragmentation of data laws harms competitiveness and slows down data‑driven innovation[4].

    The Digital Omnibus is driven by the concern that the accumulation of rules has an adverse effect on competitiveness.[5]  Consequently, simplification is needed. Maintaining the fundamental values of the Union is not the objective, but rather a precondition.[6] 

    Obviously, simplification and protection of values and individuals are not mutually exclusive. On the contrary, simplification – for instance by countering fragmentation of the law – may lead to better protection.

    This editorial argues that it is urgent to assess whether the enforcement mechanisms in EU data law are sufficiently effective and strengthen these mechanisms where needed, in order to ensure protection of individuals under the rule of law in the digital domain, as envisaged – e.g.- by data protection law, and by doing so fulfil the obligation mentioned by the CJEU in Commission/Hungary.  

    Where do we stand?

    Under the regime of the GDPR, a lot has been achieved since its entry into application on 25 May 2018.[7] The awareness of the relevance of data protection rights has significantly changed; enforcement, mainly by national supervisory authorities, has become a reality, whereas the abundant case law of the CJEU and the numerous papers of the EDPB led to greater European consistency.  

    At the European level, the biggest challenge is probably the one stop shop mechanism with

    one lead national authority in cross-border cases taking decisions based on (intensive) cooperation between various supervisory authorities. One flaw of this mechanism – in essence, the cooperation took place at too advanced a stage of an enforcement procedure – was identified;  the EU legislator acted quickly to remedy this by adopting the GDPR Procedural Regulation.[8]

    It is beyond doubt that the one stop shop mechanism was successful.[9] However, several structural issues remain:

    • Most tech giants have their main EU establishment in Ireland; as a result, the Irish authority is de facto acting as the European supervisor; other authorities are dependent on this authority to ensure that their citizens are being protected. I very much admire the Irish authority, but in the long term this does not seem a tenable situation.
    • The model has not been copied in any other EU (data) law, possibly because of doubts on the effectiveness of the model, but in any event leading to fragmentation because other regulatory structures are not aligned with the GDPR.

    To make things worse: the one stop shop mechanism has not been replaced by another uniform enforcement mechanism. The legislator has instead created a patchwork of supervision arrangements across EU digital laws.[10]

    What is at stake?

    We live in challenging and volatile times. First, our democracies are fundamentally changing, also with the rise of extremist political parties, as illustrated by this week’s votes for the AfD in Saxony Anhalt;  second, the world has become increasingly polarized, with competing digital empires[11] and where the digital sovereignty of the EU and its Member States has a become a major concern;[12] third, artificial intelligence poses a challenge for our human dignity, as outlined by Pope Leo XIV in Magnifica humanitas: On Safeguarding the Human Person in the Time of Artificial Intelligence.

    The GDPR and the various acts of the Digital Rulebook have been adopted to ensure the respect of the rule of law in the digital domain, be it for the protection of rights of citizens or – think about the DMA – for more economic objectives such as fair competition. This is the regulatory EU approach identified by Anu Bradford.[13] This includes a key role for European legal instruments with strong public enforcement by independent authorities both at EU and national levels, always operating under EU law and ultimately subject to review by the CJEU.

    In a recent editorial, entitled In courts we trust: the guardians of European values[14], Koen Lenaerts tells that until recent it was self-evident that “national governments would encourage their citizens to trust the courts as the ultimate arbiters of any legal dispute, including in situations when the court ruling opposed the political majority of the day.” He then explains that today this picture is different.

    This shift of reality not only affects courts but also other branches of government responsible for the protection of the fundamental values of the Union. The rule of law and European leadership are no longer self-evident, partly due to a lack of trust in (European) public intervention in today’s challenging and volatile times.

    The supervision of the digital domain is assigned to authorities with specific mandates based on their expertise. These authorities have the power to make far reaching decisions. Their interventions are justified by their independence from day to day political tendencies.

    However, expertise and independence are not sufficient as such.

    Authorities need to be effective, or, in other words, they need to deliver, not only to ensure that the rule of law is upheld in the digital domain with quite often globally operating economic entities, but also to ensure the credibility of the EU interventions.

    I can also state it differently: this is an area where the EU not only has the competence to act in accordance with Article 5 TEU (principles of conferral, subsidiarity and proportionality), but also the obligation to act in the most effective manner in order to protect the fundamental values of the Union.

    In my view, this is what is at stake: how to design a legal framework in which the supervision by the authorities is best organised. The legal framework should obviously protect the independence of the authorities.  Here I see a parallel with judicial independence which is, as Lenaerts underlines, a prerequisite for the effective judicial protection of EU rights.[15]

    In addition, the legal framework should ensure that the authorities can operate in the most effective manner.  This is the main challenge for the EU legislator at this moment. 

    What is done and what needs to be done

    There is a lot of debate on law in the digital age. As the Digital Omnibus shows, the focus of the EU legislator is predominantly on simplification of substantive provisions in the law.

    This does not mean that there is no interest in better enforcement. In 2022, the EDPB identified the need for additional procedural rules – leading to Regulation 2025/2518 – and also asked attention for “the overall regulatory architecture that is being developed for the digital market (Data Act, DMA, DSA, AI Act, DGA). A clear distribution of competences among the regulators will need to be ensured, as well as efficient cooperation.”[16] In July 2026, the EDPB was more precise, calling for a legal basis for cross-regulatory information sharing.[17]

    In my view, such a legal basis is indeed needed as short term solution. However, what is missing is a fundamental debate on the desired architecture of the enforcement of digital laws in the EU, with the aim of – where needed (re-)designing the architecture, to fulfil the obligation to respect, maintain and promote the fundamental values of the Union, also on a longer term. Obviously, this does not mean abandoning what already has been achieved (the ‘acquis’).

    A fundamental debate, some suggestions

    First, it should be considered whether the scale of digitization requires that in large scale cases effective GDPR enforcement should better take place at EU level. During the legislative preparation of the GDPR, a deliberate choice was made for national enforcement, with the one stop shop and consistency mechanisms as safeguards for harmonized approaches. This choice was based on the principle of proximity, where individuals have the possibility to contact their local supervisory authority and receive an answer.[18] There are reasons to reconsider this choice:

    • Equality of arms: whereas many big enterprises operate EU wide, public enforcement should take place at the same level.
    • De facto, GDPR enforcement against most of the giant tech players centralized, in Ireland, but not with sufficient democratic legitimacy.
    • Other digital acts are (partly) enforced at central EU level, the GDPR risks becoming less relevant, if its effectiveness fully depends on (sometimes cumbersome) cooperation among national authorities.

     

    Second, independence requirements should be part of the debate. Supervisory authorities under data protection law are subject to high independence standards, resulting from the CJEU-case law[19] and subsequently laid down in the GDPR (and other data protection instruments). In other digital laws, the standard is lower and that may pose difficulties. A first example: the Commission has a key role in the enforcement of the DSA, DMA and AI Act, whereas such a role seems to be excluded under the GDPR. A second example: according to Article 74.8 of the AI Act, only authorities that fulfil the high requirements under EU data protection law can be designated as market surveillance authorities for certain high-risk AI systems, whereas in most other situations the market surveillance authorities can operate with a lower level of independence.    

    Third, addressing the cooperation between the authorities is a priority. This cooperation should not only provide for (compulsory) information sharing, as rightly suggested by the EDPB. This is important, but only a first step.

    A lack of effective regulatory cooperation creates a serious risk for both the effectiveness and the credibility of supervisory interventions. If two authorities investigate and adjudicate the same matter independently, the dangers are obvious: divergent or even contradictory outcomes undermine legal certainty. Yet even when both authorities reach the same conclusion, parallel proceedings can still trigger substantial procedural objections — for example, ne bis in idem concerns or challenges to the concurrent exercise of competences.

    Good regulatory cooperation is not only relevant to avoid risks. Where authorities join forces, the regulatory outcomes may improve, as does their legitimacy. I refer in this context to the judgement of the CJEU in Meta Platforms and Others v Bundeskartellamt[20], which underlines the duty of sincere cooperation between competition authorities and data protection authorities.

     

    Fourth, since the various instruments regulating the digital domain are increasingly interconnected, integration of (some of the) supervisory authorities could be considered. Obviously, this is extremely complex, with all the asymmetries and (vested) interests at stake. However, this merits debate, in the longer term.

    To conclude

    I end this editorial as I started it, with a reference to Commission/Hungary,[21] a case on a national law resulting “in the stigmatisation and marginalisation of non-cisgender or non-heterosexual persons, solely on the ground of their gender identity or sexual orientation.” The CJEU held that such “stigmatisation and marginalisation runs counter to the values of respect for human dignity, equality, and respect for human rights, including the rights of persons belonging to minorities, as referred to in Article 2 TEU.” Hence, the national law “is contrary to the very identity of the Union as a common legal order in a society in which pluralism prevails.”

    As said, today’s environment is challenging and volatile. The risks to the legal order therefore do not stem solely from any particular national law; they arise above all from the digital sphere, where information about individuals circulates broadly and with little control. This reality makes it imperative to launch a fundamental debate on how the enforcement architecture for digital legislation should be (re-)designed.   

    [1] CJEU, Commission v Hungary (Valeurs de l’Union), C-769/22, ECLI:EU:C:2026:326, para 536.

    [2] E.g. Gerbrandy et al., Utrecht Law Review, DOI: 10.36633/ulr.1222

    [3]  Recital 1 of Proposal for Cloud and AI Development Act: “In order to fully harness the benefits of AI across the key sectors of the economy, the Union should act with ambition and foresight, advancing its innovation capabilities, strengthening its competitiveness, security of supply, while reinforcing its technological sovereignty and strategic autonomy in cutting-edge digital technologies”, COM/2026/502 final.  

    [4] The future of European competitiveness, https://commission.europa.eu/document/download/97e481fd-2dc3-412d-be4c-f152a8232961_en, at various places.

    [5] Explanatory Memorandum of Commission Proposal, COM(2025) 837 final.

    [6] Ibidem, Recital 1.

    [7] An authoritative source is the Commission’s Second Report on the application of the General Data Protection Regulation, COM(2024) 357 final.

    [8] Regulation 2025/2518 laying down additional procedural rules on the enforcement of Regulation (EU) 2016/679, OJ L 12.12.2025. Entry into application: 2 April 2027.

    [9] https://www.edpb.europa.eu/registers/register-of-final-one-stop-shop-decisions_en.

    [10] See on this, https://brusselsprivacyhub.com/developments-on-ai-big-tech-and-data-protection-how-to-avoid-a-legal-battleground/.

    [11] Using the title of the book by Ana Bradford, Digital Empires: The Global Battle to Regulate Technology, OUP 2023.

    [12] See e.g. Proposal for Cloud and AI Development Act (see footnote 4).

    [13] In Digital Empires (see footnote 12).

    [14] ERA Forum 2026, https://doi.org/10.1007/s12027-026-00890-y.

    [15] Ibidem.

    [16] Vienna Statement, https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-on-enforcement-cooperation_en.

    [17] https://www.edpb.europa.eu/news/edpb-calls-for-legal-basis-for-cross-regulatory-information-sharing_en.

    [18] Commission Proposal COM(2023) 348 (Procedural Rules Regulation), Explanatory Memorandum.

    [19] Cases C-518/07 (Commission/Germany), C-614/10 (Commission/Austria) and C-288/12 (Commission/Hungary).

    [20] Case C-252/21.

    [21] See paras 554-556 of the judgment.