Analysing the Proposed EU GDPR Reforms

24th June 2025Photo by Marco from Pexels

Since its creation and rollout in May 2018, the EU GDPR has set a global benchmark for data privacy. Even since Brexit, the UK has maintained virtually the same GDPR law. However, the European Commission is proposing targeted reforms of the GDPR aimed at simplifying compliance as part of their broader Omnibus IV Simplification Package. This reform and omnibus package aims to simplify record-keeping obligations and reduce the administrative burden for SMEs. The European Commission claims that these reforms will save EU companies €400 million in annual administrative costs. Source: The European Commission

Key Proposals and Their Implications

Expansion of Record-Keeping Exemptions

Under Article 30(5) of the GDPR, organisations with fewer than 250 employees are exempt from maintaining records of processing activities (RoPA), unless their data processing is high-risk, not occasional, or involves special categories of data. Under the proposed reforms, the threshold would increase to include organisations with fewer than 750 employees, provided their data processing does not pose a high risk. This would reduce admin costs for such businesses, although the size of the organisation does not necessarily correlate to the risk involved in their data processing, and loosening record-keeping requirements could potentially weaken data protection standards.

Harmonisation of Enforcement Procedures

Each EU member state currently applies its own interpretation of the GDPR, resulting in a lack of certainty and difficulties when dealing with cross-border cases. The reforms aim to standardise procedures and rules from cross-border cases and enhance cooperation between different data protection authorities. Having more consistent enforcement of the GDPR is beneficial, although some argue that these proposed changes could dilute the law, making the GDPR less effective overall.

Support for GDPR Reforms

There have been significant technological advances like artificial intelligence, machine learning, biometric tracking, and large-scale behavioural profiling since the GDPR was first created, and further updates to the law should reflect this. The rapid rise of AI, for example, presents unique data processing challenges that the original text of the GDPR does not explicitly address. Systems that make autonomous decisions based on personal data, such as automated hiring tools, facial recognition, or predictive analytics, can pose significant risks to individuals’ rights, yet may fall into regulatory grey areas.

Updating the GDPR is therefore seen by some as essential to ensure it remains fit for purpose in an AI-driven world. The European Commission itself acknowledges this, stating that changes must reflect “technological and societal developments” so the law continues to offer strong, meaningful protections without stifling innovation.

The GDPR, while globally influential, has imposed significant administrative burdens, particularly for small companies with limited resources. Removing red tape for smaller organisations could address the disproportionate impact that compliance can have on such businesses, allowing them to grow. Simplifying legal obligations could also encourage more consistent data protection implementation, especially among companies that previously struggled to meet all requirements. 

The European Commission argues that the GDPR’s core protections will remain intact. High-risk data processing, such as that involving sensitive personal data, large-scale profiling, or surveillance, will still be fully regulated and subject to all existing obligations. The European Commission asserts that the risk-based approach will ensure that high-risk data processing will still be subject to strict requirements. From the EU’s perspective, the proposed reforms are not a rollback of GDPR’s principles, but rather a way of ensuring those principles are applied proportionally and practically across all sectors and organisation sizes. Source: European Commission

Criticisms of GDPR Reforms

Some say the simplification of data protection laws could lead to the dilution of protections and have far-reaching impacts on the rights of the individual and the accountability of organisations. Claims that this deregulation could help boost economic growth have been disputed, with some claiming that it would only benefit the largest companies and leave smaller organisations and individuals more vulnerable to exploitation and weaken human rights protections. Despite efforts to harmonise procedures, critics highlight that enforcement remains inconsistent across member states, potentially leading to a “legislative mess.” Source: Euronews

Privacy activist organisation noyb raises concerns that the proposed Procedural Regulations could significantly delay GDPR enforcement, and that the regulation structurally discriminates against users. The procedural framework appears to favour companies, particularly large tech firms, by making it easier for them to defend against complaints. They also claim that instead of making things easier, the new rules would add more paperwork and extra steps. Rather than using one shared digital system, the proposal would require over 40 different EU data protection authorities to store and send documents by hand. This could waste a huge amount of time and cost Member States millions of euros. Source: noyb

Striking the Right Balance

The GDPR has been a cornerstone of data protection not just in the EU but around the world. However, as technology evolves and businesses adapt, so too must the laws that regulate them. The proposed reforms aim to modernise the GDPR, reduce unnecessary administrative burdens, particularly for SMEs, and bring more consistency to cross-border enforcement. While simplification may alleviate burdens for SMEs, it is crucial to ensure that such changes do not compromise the rights and freedoms of individuals. Stakeholders, including noyb, advocate for a reevaluation of the proposed reforms to ensure that the fundamental rights of individuals remain protected and that enforcement mechanisms are both efficient and equitable.

Author: Mike Martin LLM

Mike is an information rights law specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.

Sources

The Record

Article 19

Euronews

European Commission

TechPolicy.press

Noyb

CEPS

Stephenson Harwood

DLA Piper

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details