Brussels Is Rewriting the GDPR. It Should Scrap It Instead.
I’m on the side of privacy. I think data brokers are a menace, and when Ireland fined Meta €1.2 billion in 2023 I didn’t lose a minute’s sleep. If Europe wants a law that stops companies from selling where people sleep at night, I’ll help write it.
My argument is narrower, and harsher. The General Data Protection Regulation (99 articles, 173 recitals, in force since May 2018) has failed on its own terms. The Commission is busy rewriting it. It should be scrapping it.
Not trimmed. Not simplified. Scrapped.
The Banner Is the Whole Legacy
Try a simple test. Ask any European what the GDPR has done for them and they’ll describe a pop-up. Pedants will point out that the cookie consent rule comes from the older ePrivacy Directive; that’s true, but the GDPR’s strict definition of consent, backed by fines of up to 4% of global turnover, is what put a banner on every page on the continent.
Eight years on, the banner has trained 450 million people to click “Accept all” without reading a word. A pensioner in Porto clicks it to check the bus timetable. A student in Kraków clicks it forty times before lunch. Nobody’s data is safer for it.
The Commission now says so itself. Its Digital Omnibus proposal, published last November, concedes that the consent model filled Europe’s screens with banners and left privacy about where it was. That’s the law’s author reviewing the law’s most visible feature.
One star.
Google Won the GDPR
Second test. Who came out ahead?
A bakery in Lyon with an online order form didn’t. It paid a consultant for a privacy policy nobody reads. A two-person app studio in Tallinn didn’t either. Economists who tracked Google Play after 2018 found a large share of apps disappeared from the store, with new launches falling alongside them, while venture money for young European tech firms slipped behind the American trend in the same years. A fixed compliance bill hurts the smallest firms most. They paid it.
The winners are easy to name. OneTrust, a compliance software firm founded in Atlanta in 2016, was worth more than $5 billion within four years on the back of GDPR work, including the consent tools behind the banners Europeans hate. Google, the company the law was meant to rein in, gained ground. When websites trimmed their tracking vendors to cut legal risk, they dropped the small ones and kept the giant whose lawyers had already done the paperwork. Studies of the ad-tech market after 2018 found it got more concentrated, with Google on top.
Enforcement tells the same story. Because the big platforms put their European headquarters in Dublin, the Irish Data Protection Commission became referee for most of Silicon Valley, and cases crawl. That €1.2 billion Meta fine I cheered grew out of a complaint Max Schrems filed in 2013. It took a decade.
A law that needs a Max Schrems to work doesn’t work.
Brussels Already Agrees With Me
The best case for repeal comes from the people who wrote the GDPR and the people paid to defend it.
Mario Draghi’s competitiveness report, written at the Commission’s request, named the GDPR as one reason data costs European firms more than it costs their American rivals. The Omnibus would narrow the definition of personal data, let AI developers train on it under “legitimate interest”, stretch the breach-reporting deadline and fold cookie rules into the GDPR itself. You don’t propose that much surgery on a healthy patient.
Even the regulators fighting the Omnibus accept its premise. The chair of the European Data Protection Board opened her objection by agreeing that simplification is essential to cut red tape. Her complaint is that the Commission goes too far. Mine is that it doesn’t go nearly far enough, and slowly at that. The AI half of the package cleared the Council in June. The half touching the GDPR was still stuck in negotiation over the summer, with the Council’s working text dropping several of the consent fixes.
So Europe will spend another year or two amending a 99-article regulation, and every firm on the continent will pay its lawyers to read the amendments. New compliance costs, same old machine.
What Repeal Can’t Fix
Scrapping the law has a real problem, and I won’t wave it away. Article 8 of the EU Charter of Fundamental Rights makes data protection a right, so Brussels can’t leave a hole where the GDPR was. Rip it out with nothing ready and firms fall back on 27 national regimes, the mess the GDPR was sold as fixing. Companies that already spent heavily on compliance would be asked to spend again, and the bakery in Lyon would get another consultant’s invoice.
Some of the law earned its keep, too. The 72-hour breach notice works. So does the right to ask a company what it holds on you.
None of that changes my view of the rest. Article 8 asks Europe to protect personal data. It doesn’t mention consent pop-ups or a bottleneck in Dublin. A law that goes after brokers and breaches could fit on a few pages.
The baker in Lyon could read it.