Editorial by Dr. Gabriela Zanfir-Fortuna

Vice President for Global Privacy, Future of Privacy Forum

A brief history of how the Brussels Privacy Symposium, over the past years, was the bellwether for the need to make the new EU digital laws work better by themselves and with each other

When we set out at the beginning of each year to choose a theme for the Brussels Privacy Symposium (BPS) – in between the teams of the Future of Privacy Forum and the Brussels Privacy Hub, we keep an eye on what we think will define the most important points of discussion in the years ahead. In 2023, as the avalanche of new regulations in the digital space was starting to “flood the zone” in Brussels, we took a step back, looked at the big picture, and saw that many of them will significantly overlap, or otherwise interact, with GDPR provisions and among themselves in ways that are not obvious at first sight, are sometimes contradictory, but that did not seem to have triggered much attention from the policymakers of the time.

 That year, long before anyone was paying attention to how complicated the digital regulatory space will be once the new laws in the digital space will all take effect, the topic we proposed was “Understanding the EU Data Strategy Architecture: Common threads – Points of Junction – Incongruities”.

 Fast forward to 2025, after complications started to materialize once all the new digital laws were adopted and most of them became applicable: “Simplification” of the digital regulatory framework is what keeps the Commission and everyone in the tech policy space in Brussels busy, with a re-emergence of the GDPR on the front stage as, indeed, the cornerstone and foundational baseline of all the digital laws. While policymakers are now catching up with the need to untangle the digital laws’ “knot” of the past years, this year at BPS we asked whether the time has come for a data protection law revolution or evolution. 

Starting point

 Looking back at BPS 2023, when we started to point out specific complications of the interplay and overlap of the laws proposed in the digital strategy package, we invited three panels of experts to specifically discuss:

 A potential paradigm shift for data access: aiming to understand and reconcile the push for enabling access to data – including personal data, in the data strategy package with the GDPR and its complex web of strict rules for access to personal data (which, of course, is one of the many facets of “processing personal data”). We asked our speakers whether the provisions designed to enable access to data in the Data Act, Data Governance Act (DGA), the Digital Markets Act (DMA), and Digital Services Act (DSA) represent a paradigm shift in the EU from the current philosophy built around data minimization, purpose limitation and lawful grounds for any access to personal data.

 As it turns out, the Digital Omnibus proposal for simplification to be published later this month is expected to streamline and simplify the Data Act and the Data Governance Act as one of its key components.

A maze of impact assessments: wondering how to make sense of the tower of risk assessments in the digital space, layering the broad legal mandate for Data Protection Impact Assessments under the GDPR, with the novel obligations of (often) the same organizations to conduct systemic risk assessments in the Digital Services Act and Human Rights Impact Assessments in the AI Act, on top of Conformity Assessments and other narrower “risk assessments” under the same AI Act.

And, finally, the future of data enforcement in the EU, which was already emerging as the most complicated consequence of the knot of digital laws, considering the myriad new digital and data enforcers, both at Member State and at EU level.

All of these conversations are detailed in the Symposium report of that year.

Drilling down

A year later, BPS 2024 drilled down further into key areas that tighten the digital laws’ knot, with a focus on the EU AI Act and its interactions with the broader legislative framework: “Integrating the AI Act in the EU Data Governance Ecosystem: Bridging Regulatory Regimes”. We focused, again, on the notion of risk and how it is dealt with in “risk assessments”, “systemic risk assessments”, and various “impact assessments” of digital technologies, from online platforms to AI systems. We raised the flag, again, on an over-complex and “duplicatory” enforcement regime, with a discussion on regulatory perspectives and AI enforcement, asking ourselves whether we are seeing a case of double jeopardy. 

Importantly, we added on the complexity map a new issue: sensitive data. We noted that key provisions from both the DSA and the AI Act include prohibitions or specific obligations related to processing of sensitive data as defined by the GDPR. How to balance prohibitions to use sensitive data with legal obligations to use sensitive data? How does the definition of sensitive data under the GDPR and their particular processing regime impact this? For the curious, the panels from BPS 2024 are all summarized in the event report.

These incursions in the complexity of the overlap and interplay of the various digital laws, the GDPR and the AI Act, were carefully programmed with sensibility and foresight in the previous two years by the Symposium. There should not be surprises if we see, as part of the Omnibus, interventions to clarify and simplify “impact assessments” obligations, streamline the enforcement architecture of the digital strategy laws, or better align regulatory mandates over sensitive data, among other initiatives.

A data protection (r)evolution?

 This year, the Symposium refocused the conversation on the GDPR. In 2026 we will celebrate 10 years from its adoption, a considerable timeframe particularly for a piece of legislation fundamentally attached to tech, be it in a most neutral way. Specifically, BPS 2025 asked whether we are facing a data protection evolution or revolution, as not only the simplification agenda, but also the different pressure points of AI and of competitiveness have opened conversations about whether the GDPR needs an update.

The consensus among speakers and attendees seemed to be that by no means we are in front of a revolution (and that nor should we be). The principles of data protection law as codified now in the GDPR are nimble and all-encompassing enough to have survived 60 years of technological evolution, while continuously being shaped or enhanced. This should be the case also in the face of AI, as well as the complicated digital ecosystem’s regulation.

The European Commission representatives speaking at the event confirmed, nevertheless, that we might be seeing some shape of “evolution” – be it limited or targeted – as they are currently giving more thought on whether further updates should be brought to the GDPR on top of the narrow amendment of registers for processing activities already on the table since May of this year.

For instance, some aspects of the GDPR that they are currently looking at are:

  • processing of personal data for training AI on the basis of legitimate interests, which seems to have a consensus among Data Protection Authorities. (Of note: South Korea is currently also considering amending its data protection act to specifically account for processing of personal data for AI training).
  • the clarifications brought by the CJEU on pseudonymization in the SRB case that pseudonymized data are not always personal.

What next?

Agentic AI, human agency in the age of AI, human oversight of automated decision-making, LLM risk assessments and how they interact with data protection law – were all key points of discussion and workshops this year at the Symposium. As the privacy and tech policy community in Brussels is waiting with interest for the Digital Omnibus to be published in a couple of weeks, in the spirit of BPS I’m already launching an invitation for the same community to start paying attention to all these topics. The Symposium has a penchant for showing a couple of years ahead what the big issues for data protection and privacy will be in the next few years.