Editorial by Prof Dr Hielke Hijmans[1]
- The Challenges
The GDPR applies since 2018 and has developed into a source of vast legal battles between data controllers and authorities, and sometimes even between data protection authorities, each of them acting within national legal systems, with sometimes diverging approaches. However, the GDPR includes incentives for consistent approaches through its Cooperation and One-Stop Shop Mechanisms. The work of the EDPB, under Chapters VI and VIII of the GDPR, has further contributed to unified approaches, but has also been challenged.[2] A range of issues has been settled by the Court of Justice, also on enforcement-related issues.[3] In addition, a growing role of private enforcement of the GDPR emerged, also through the actions of privacy NGOs.
In recent times, it is no longer (all) about the GDPR. Whereas on the one hand, the GDPR no longer seems untouchable,[4] on the other hand, other legal instruments such as the DMA, DSA, DA, and AI Act determine the digital legal landscape in the EU. Moreover, developments outside the European Union aim at limiting the role of legislation more in general.[5]
Hence, the landscape is volatile, in a context of rapid technological developments and innovation, with big tech, AI, and neural networks, and a piecemeal reaction by the legislator (including, sometimes, a choice to abolish or simplify legislative norms[6]).
In my view, we should more than ever emphasize the foundational values of the European Union: respect for human dignity, freedom, democracy, equality, the rule of law, and respect for human rights (Art 2 TEU). Focusing on privacy and data protection, it is essential to safeguard human control and dignity.
The loss of control, as exemplified by the Snowden revelations (2013), was a main trigger for the adoption of the GDPR. The importance of human dignity, as identified by Poullet, requires a Capability to Make Autonomous Decisions and an Equality of Humans.[7]
Last but not least, competitiveness and economic performance are compasses for the EU. I point at the key role of the 2024 Draghi Report[8], but in a more historical context, one can mention Brandeis, who regarded competition as a public good and a necessity for individual liberty.[9]
- The responses
Legislative action is the appropriate response from governments to ensure legal security and individuals’ rights, but also to ensure that democratically chosen governments retain their capacity to act in a field dominated by a few globally operating tech firms. Hence, the EU’s Digital Rule Book with its focus on sincere competition and – mainly in the AI Act – responsible innovation.
In order to be successful, this legislative response should – in my view – fulfil three conditions. First, the goals of legislation must be clear. In this light, I recall the double goal of the GDPR: the protection of individuals’ rights and freedoms and the free flow of data. Second, enforcement capacity. Article 8 of the EU Human Rights Charter and the GDPR require that this capacity be laid down with independent regulatory bodies at a distance from the executive branch. Third, effective judicial remedies. In the EU context, this should also preclude fragmentation. Article 277 TFEU and its preliminary rulings play a big role, but the question arises whether this is sufficient in the current volatile digital landscape.
- Fragmentation is a key risk and has different layers
The first layer is fragmentation between the Member States, with the GDPR as an obvious example: The GDPR is a regulation, aiming at creating a level playing field for citizens and businesses, but with national enforcement bodies and opening clauses leaving much room for national specificities.
As a second layer, I mention fragmentation between the legislative instruments: different instruments – sometimes with similar, sometimes with different objectives – have significant overlaps.
- Whereas the GDPR ensures the protection of personal data, the Data Act encourages data sharing, for an optimal allocation of data (including personal data) for the benefit of society.[10]
- The GDPR and the AI Act substantially overlap, for instance concerning automated decision making, transparency and impact assessments.
- Article 5 DMA and Article 26 DSA contain rules on online advertisement services , similar but not identical to the obligations under the GDPR (e.g. in Article 6), but with different scopes ratione personae.
The third layer concerns fragmentation between regulatory structures in the digital domain, not aligned with the structure of the GDPR:
- The DMA provides for supervision by the Commission, with a limited role for national authorities;
- The DSA divides the roles between the Commission (VLOPs and VLOSEs) and National Authorities (LOPs);
- The AI Act focuses on the Marketing of AI Systems under the supervision of a national Market Surveillance Authority, not on the processing of personal data. But in many domains, in particular in relation to high-risk systems, the main risk lies in the processing of personal data, as for instance recognized in the independence requirements for authorities mentioned in Article 74(8) AI Act; moreover, Article 77 of the AI Act recognizes the roles of fundamental rights regulators.
I give this fragmentation a bit more focus. The choice of the EU legislator in the Digital Rulebook has been to recognize the comprehensive position of the GDPR, because a new instrument does not affect the GDPR (Article 1.7 AI Act), is without prejudice to the GDPR (Article 2.4 DSA), or by claiming that data protection is “governed solely by the rules of Union law on that subject, in particular Regulation (EU) 2016/679 [..]” (Recital 10 DSA).
However, what is the practical meaning of these notions in practice, for instance in relation to “pay or consent” models? On 1 July 2025, the Commission sent preliminary findings to Meta over its “Pay or Consent” model for breach of the Digital Markets Act,[11] not long after an EDPB-opinion on the same models directed at large platforms. However the findings were not based on this opinion.[12]
A fourth layer of fragmentation exists due to an absence on EU level of clarity on regulatory responsibilities. The Member States maintain a large margin of maneuver in organizing the enforcement of the digital acts. The roles of the Data Protection Authorities and of other involved regulators differ per Member State, leading to a patchwork of supervision arrangements of EU regulations.
Finally, the Commission has an asymmetric role. The GDPR limits the role of the Commission, which is not considered to fulfil the high criteria of independence under the Charter and the case law of the Court of the Justice, which require a distance from the executive branch.[13] To the contrary, other instruments, such as the DMA, provide for enforcement by the Commission.
- Legal Battlefield?
The various instruments have as a common objective to (re-)gain. digital domain, control over human dignity, under the rule of law.
To state the obvious, reaching this objective in itself is already not evident, in view of the rapid technological developments, the geopolitical context, and last but not least the high (financial) stakes for parties involved.
It will be even more complex if the ecosystem encourages legal battlefields.
The first risk of a potential legal battlefield results from power struggles between authorities, the well known turf wars, where various bodies do consciously not join their capacities and skills.
Another risk relates to unwanted inefficiencies, due to a lack of legal certainty, where competences are not clear, overlap or are absent.
Addressees of the law could benefit, for instance by denying the competence of a regulator or based on arguments of ne bis in idem. Where one authority acts, another should refrain from acting.
In any event, uncertainty provokes a culture of litigation instead of compliance.
- Towards Solutions
As said above, legislative responses should have clear goals, strong enforcement authorities and effective judicial review, all avoiding fragmentation.
In this respect, the GDPR-practice gives direction for good cooperation between authorities, also in the wider digital domain.
First, a quick and efficient communication structure is provided.
Second, cooperation should take place in an early stage of enforcement. Since the GDPR itself contained insufficient incentives, a mechanism will be added to ensure early cooperation: The GDPR Procedural Regulation to Improve Cross-Border Enforcement,[14] currently in the stage of finalization, also includes solutions for differences in administrative law of the Member States.
Third, the law should preclude solo-actions of authorities aimed at avoiding cooperation. Examples in data protection are enforcement acts relating to cookies on the basis of the ePrivacy-Directive instead of the GDPR (a practice of the French CNIL)[15], the involvement of a competition authority in order to sanction a breach of the GDPR,[16] a law suit under private law[17], or unilateral actions against companies without an establishment in the EU (measures against Chat GPT by the Italian DPA)[18].
Fourth, effective judicial review, where possible at EU level. In a recent opinion in Whatsapp v the EDPB, Advocate-General Capeta gives good arguments for a judicial review by the Court of Justice in a composite administrative procedure.[19]
- To conclude: Plea for a Legislative Framework for Enforcement Cooperation
Obviously, all authorities – on national and EU level – empowered with enforcement tasks under EU law are bound by the principle of sincere cooperation laid down in Article 4.3 TEU.
Given the complexities sketched above, with a large number of involved regulators, all working within different legal frameworks, this general duty is in my view not sufficient in the digital domain.
The experiences with the GDPR demonstrate that additional rules for cooperation were considered necessary, even in a domain with one basic regulation, highly similar supervisory authorities, and frameworks for cooperation and consistency within that regulation.
Additional rules are all the more needed, where cooperation is necessary between fundamentally different supervisory authorities, enforcing different EU Acts, currently without a framework for cooperation and consistency (apart from Article 4.3 TEU).
Hence, my plea for an EU legislative framework for enforcement cooperation in the digital domain.
What should be the main focus of such a framework?
In the first place, some practical needs should be addressed: a compulsory exchange of information, also on individual enforcement cases, mutual assistance and joint enforcement.
Furthermore, the framework should set conditions for transparency of the decision making process.
Moreover, there is a need for clarity when there are overlapping competences, for instance to ensure that there is always one authority in the lead. The general mantra like “without prejudice to” does not seem sufficient, at the actual case level. One final decision after an investigation involving various authorities should be the aim.
In this context, a solution should be found for asymmetries in the law, for instance between the DSA/DMA/AI Act, on the one hand, where the Commission has an enforcement role, and the GDPR, on the other hand, where enforcement by the Commission is precluded.
An important challenge is and remains the role of national procedural law in cross-border enforcement, under EU law.
I suggest to start developing a common framework with a certain modesty, addressing the issues just mentioned.
However, in the digital domain there is a clear need of harmonisation of parts of EU Administrative Law. The once developed ReNEUAL Model Rules on EU Administrative Procedure[20], by Hoffmann a.l., could serve as inspiration.
[1] Director Litigation Chamber Belgian DPA and part time Professor at the Vrije Universiteit Brussels. This Editorial is based on a Key Note Speech for the BPH Summer School of 20 June 2025. Nothing in this editorial reflects a position of the Belgian DPA.
[2] E.g, C-97/23P, Whatsapp v EDPB, admissibility action for annulment of EDPB Decision
[3] E.g., C-807/21, Deutsche Wohnen, on the conditions for imposing fines.
[4] Long Read: “7 Years of Enforcing the GDPR: 7 Lessons for the AI-driven Europe”
by Maria Magierska and Sophia Hassel, EU Law Live 2025.
[5] Winning the Race, AMERICA’S AI ACTION PLAN, July 2025.
[6] Proposal for a Regulation amending certain regulations, including the GDPR,
COM(2025) 501 final.
[7] Yves Poullet, La dignité humaine à l’heure de l’IA et des neurosciences, 2025.
[8] The future of European competitiveness, September 2024.
[9] Louis Brandeis, Other People’s Money and How the Bankers Use It, 1914.
[10] Recital 2 of Regulation 2023/2854.
[11] https://digital-markets-act.ec.europa.eu/commission-sends-preliminary-findings-meta-over-its-pay-or-consent-model-breach-digital-markets-act-2024-07-01_en.
[12] 17 April 2024, https://www.edpb.europa.eu/system/files/2024-04/edpb_opinion_202408_consentorpay_en.pdf.
[13] Cases C-518/07, Commission/Germany, and C-614/10, Commission/Austria.
[14] Based on Proposal for a Regulation of the European Parliament and of the Council laying down additional procedural rules relating to the enforcement of Regulation (EU) 2016/679
COM/2023/348 final.
[15] https://www.cnil.fr/fr/les-sanctions-prononcees-par-la-cnil.
[16] Resulting in C-252/21, Meta Platforms and Others.
[17] Resulting in C-645/19: Facebook v Gegevensbeschermingsautoriteit.
[18] https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9870847.
[19] Case C-97/23P.
[20] https://www.reneual.eu/projects-and-publications/reneual-1-0.
