Drooid Logo
Back to story perspectives

Full Breakdown

European Union Proposes Changes to GDPR and AI Regulations

11/20/2025, 8:56:36 AM

Overview of Proposed Changes

The European Commission has proposed significant amendments to its General Data Protection Regulation (GDPR) and the forthcoming AI Act, aiming to alleviate regulatory burdens on technology companies. These changes come in response to mounting pressure from major tech firms and the U.S. government, seeking to stimulate economic growth within the European Union (EU). Key modifications include simplifying cookie consent requirements and extending the grace period for high-risk AI regulations.

Key Elements of the Proposal

The proposed changes to the GDPR would facilitate easier sharing of anonymized and pseudonymized personal data, allowing AI companies to utilize personal data for training AI models, provided they adhere to other GDPR stipulations. Additionally, the amendments would delay the implementation of certain high-risk AI rules, originally set to take effect in 2024, until the necessary standards and support tools for AI companies are confirmed. The new regulations also aim to reduce the frequency of cookie consent pop-ups, allowing some non-risk cookies to operate without user prompts.

Henna Virkkunen, executive vice-president for tech sovereignty at the European Commission, stated, “By cutting red tape, simplifying EU laws, opening access to data and introducing a common European Business Wallet we are giving space for innovation to happen and to be marketed in Europe.”

Political Context and Implications

The proposal is now set to be reviewed by the European Parliament and the 27 EU member states, where it requires a qualified majority for approval. This process is expected to be contentious, with potential for significant amendments. The GDPR has long been regarded as a cornerstone of Europe’s digital strategy, and any alterations are likely to provoke a strong political and lobbying response.

The changes follow extensive lobbying from influential figures, including former Italian Prime Minister Mario Draghi, and pressure from major technology companies. The European Commission has framed these adjustments as a means to simplify tech regulations rather than weaken them, addressing concerns that stringent rules may hinder Europe’s competitiveness in the global tech landscape, particularly against dominant U.S. and Chinese firms like Google and OpenAI.

Criticism and Opposition

Critics of the proposed changes argue that relaxing GDPR protections could undermine user privacy and data security. The GDPR has been viewed as a model for data protection worldwide, and any perceived weakening may lead to backlash from privacy advocates and civil society organizations. The ongoing debate reflects a broader tension between fostering innovation and ensuring robust protections for personal data.

What's Next

As the proposal moves forward, stakeholders from various sectors, including technology, privacy advocacy, and government, will closely monitor developments. The outcome of the legislative process will significantly influence the regulatory landscape for AI and data protection in Europe, with potential implications for global standards as well.

Verbatim Quotes

  • “This is being done in the European way.” — Henna Virkkunen, Executive Vice-President for Tech Sovereignty, European Commission
  • “With very few exceptions, Europe doesn’t have any credible competitors in the global AI race, which is dominated by US and Chinese companies like DeepSeek, Google, and OpenAI.” — Source Unspecified