EU data protection reform draft “an empty shell”
Privacy groups warn the European Council is undermining new data protection laws

Europe's new data protection laws face being watered down if the latest draft of the regulations is approved, according to privacy groups who have leaked the documents.
The EU wants to reform data-protection legislation to bring it up to date with current technology by strengthening citizens' rights over their personal information.
However, privacy advocate groups EDRi, Privacy International, Access, and the Panoptykon Foundation leaked the latest draft of the laws yesterday, releasing a 350-page document they claimed shows the original intentions of the reform are being underminded.
"The regulation is becoming an empty shell," said Joe McNamee, executive director of European Digital Rights. "Not content with destroying key elements of the proposal, the EU member states are rigorously, systematically and thoroughly undermining the meaning of every article, every paragraph, almost every single comma and full stop in the original proposal."
The changes
While the original draft of the rules have been approved by the European Parliament, EU governments as part of the European Council are now trying to change the proposals.
Originally, the reform sought to ensure companies could only track citizens' online activity if they gave explicit consent.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The latest draft includes a suggestion that people's browser settings such as if cookies are accepted could be interpreted as consent to being tracked online.
"Some of the council's proposals gut data protection of all meaning," the privacy groups said in a statement.
"Having removed the commission's initial proposal for explicit consent and diluted the entire concept of consent of the individual, the council then removes the final element of an individual's control of their data the uses to which the data can be put, once they are collected," the groups added.
The council also doesn't want to classify information collected by "online identifiers" such as cookies and other tracking tools as personal data, meaning firms would be freer to track individuals' online activity.
It also wants to do away with measures making it harder for third parties to process personal data, including requirements such as telling individuals why their data is being processed, and viewing data processing as a last resort.
Instead, companies with a "legitimate interest" in processing personal data would be able to do so.
Under the council's amendments, governments would also be allowed to profile citizens when the reasons to do so meet "important objectives of general public interest", as well as national security objectives.
"This is basically providing a blank cheque to governments which, under various excuses, may start to profile people based on their online political activities and prepare, for example, blacklists who do not fit with the profile of 'normal' citizens," claimed the privacy groups.
IT Pro has approached the European Council for comment, but none was received at the time of publication.
The latest amendments are by no means the final draft of the document, as the European Parliament must approve any changes before they're passed into law, but it's unclear whether the original purpose of the reform will survive the council intact.
The controversy comes after the EU confidently stated the regulations would be reformed by the end of 2015, following criticism that the reform is moving far too slowly.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
Forcing Apple to allow alternative app stores might cause major security risks
Analysis Apple will be forced to allow third-party marketplaces on its devices, but some experts have raised serious security concerns
By Solomon Klappholz
-
Why bolstering your security capabilities is critical ahead of NIS2
NIS2 regulations will bolster cyber resilience in key industries as well as improving multi-agency responses to data breaches
By ITPro
-
New EU vulnerability disclosure rules deemed an "unnecessary risk"
News The vulnerability disclosure rules in the Cyber Resilience Act could also cause a “chilling effect” on security researchers
By Ross Kelly
-
Are you ready for NIS2?
WEBINAR Find out what you should be doing to prepare for the EU’s latest data protection regulation and UK equivalent with our free webinar
By ITPro
-
EU regulators are digging their heels in despite big tech’s Data Act pushback
Analysis EU regulators are no strangers to big tech regulatory push back, so why do companies still persist?
By Ross Kelly
-
Microsoft's EU Data Boundary will begin staggered rollout in January 2023
News Public sector and commercial customers will be the first to benefit when the rollout begins on 1 January across all of Microsoft's core services
By Ross Kelly
-
EU watchdog fights against rules permitting Europol's ‘unlawful’ data practices
News The pushback follows allegations that Europol was allowed to write its own rules when it came to handling sensitive data
By Connor Jones
-
EU to introduce strict IoT security regulation
News Manufacturers will be required to assess all risks, and notify the EU of issues within 24hrs
By Rory Bathgate