Bastiaan Bruyndonckx
Information Communication Technology
Information Governance & Data Protection
Telecommunications, Media & Technology
Commercial law
Dispute Resolution
Intellectual Property (IP)
bastiaan.bruyndonckx@lydian.be
25 May 2025 marks seven years since the General Data Protection Regulation (GDPR) came into effect on 25 May 2018, a landmark in global data privacy and a symbol of Europe’s commitment to protecting individuals’ personal data in the digital age.
Since its adoption, the GDPR has reshaped how organisations collect, process, and store personal data. It has empowered individuals with greater control over their data, fostered transparency, and strengthened accountability.
This anniversary is an opportunity to take a closer look at the key developments that have shaped the GDPR’s journey so far and to explore what lies ahead.
Over the past seven years, data protection authorities across the EU have issued decisions that continue to clarify the practical application of the GDPR. While some cases have made headlines, enforcement trends show a steady, maturing approach focusing on both major players and sector-specific compliance.
Transatlantic data transfers have long been a legal challenge. After the Court of Justice of the EU invalidated both Safe Harbor and the Privacy Shield, the European Commission adopted the EU–US Data Privacy Framework (DPF) in 2023 to re-establish a lawful basis for transfers to certified US companies.
The DPF aims to address earlier concerns by introducing safeguards such as limiting US government access to EU personal data and creating a new redress mechanism for EU individuals via the Data Protection Review Court.
Despite this, critics remain sceptical – arguing that the reforms do not go far enough to meet the standards set by the Schrems II ruling. Civil society groups and privacy advocates have questioned the independence and effectiveness of the redress mechanism, and a legal challenge is already pending before the CJEU.
In May 2024, the European Data Protection Board (EDPB) adopted its first report on the DPF. The report acknowledges improvements, particularly in redress mechanisms and oversight structures. However, it also highlights areas for continued monitoring, including transparency of US government access requests and the long-term effectiveness of the safeguards in practice.
The GDPR now operates alongside a broader set of EU digital regulations designed to create a coherent framework for the data economy and platform governance. Notable examples include:
Together, these instruments reflect the EU’s ambition to build a comprehensive legal framework for the digital world, reinforcing data protection as a foundational value.
Currently under negotiation, the proposal for a regulation laying down additional procedural rules for GDPR enforcement aims to improve cooperation and consistency among data protection supervisory authorities, especially in cross-border cases and to address long-standing criticism of the GDPR's enforcement delays and fragmentation.
The proposal introduces procedural rules to:
On 21 May 2025, the European Commission published a proposal for a regulation aiming at simplifying the GDPR. The changes include a few articles, including Article 30(5) GDPR.
Under Article 30 GDPR, controllers and processors must maintain a Record of Processing Activities (RoPA), a key accountability tool.
There is an exemption for organisations with fewer than 250 employees. However, this only applies under strict conditions, namely, that the processing is occasional, involves no sensitive data, and poses no risk to individuals. As a result, many SMEs still must comply with the full record-keeping requirements.
The new proposal aims to simplify and clarify this derogation by:
In a joint letter to the European Commission, the EDPB and EDPS have already expressed their support for the initiative.
A more ambitious reform has been floated by MEP Axel Voss, with support from Max Schrems. It proposes a three-layered revision of the GDPR, consisting of:
While still at the concept stage, this proposal could significantly reshape how the GDPR is applied in practice, especially if political momentum builds.
The EDPB recently published its strategic priorities for the next three (3) years, signalling a focus on:
This strategy reinforces the EDPB’s leading role in steering the future of data protection in Europe and beyond.
The GDPR remains a living instrument, rooted in strong principles, but continuously evolving. As the regulatory landscape shifts and new expectations emerge, staying informed and adaptive will be more important than ever.
Information Communication Technology
Information Governance & Data Protection
Telecommunications, Media & Technology
Commercial law
Dispute Resolution
Intellectual Property (IP)
bastiaan.bruyndonckx@lydian.be
Intellectual Property (IP)
Information Governance & Data Protection
Product compliance, product safety and product liability
Dispute Resolution
Life Science
Commercial law
Telecommunications, Media & Technology
olivia.santantonio@lydian.be
Commercial law
Dispute Resolution
Information Communication Technology
Information Governance & Data Protection
Intellectual Property (IP)
Telecommunications, Media & Technology
ines.nibakuze@lydian.be