Changes ahead in the regulator line-up
While we still have no news about the appointment of a new term for the European Data Protection Supervisor, the current EDPS Wojciech Wiewiórowski (seeking reappointment) has commented on the EU’s attempts to streamline the GDPR and the AI Act by means of the Digital Omnibus. At the CPDP conference in May, he said that simplification does not mean – and should not be understood to mean – deregulation. He also highlighted enforcement of the digital rulebook, and the need for a harmonised and coherent application of the EU legislative framework. This relates to the DPA cooperation which he says should be strengthened not only among EU Data Protection Authorities but should also take place at a cross-regulatory level across several legal fields.
The AI Act’s enforcement is shared across various authorities. Read how the EU DPAs are currently enforcing the EU AI Act. The EDPS wears two hats here – it is the AI regulator for EU institutions as well as supervises their data protection compliance under the GDPR. No process exists about this as far as I know. Which law will take precedence in a conflict situation?
The regulator has changed in the Netherlands, and a more business-friendly environment is to be expected. In the UK, the government department responsible for sponsoring the ICO is currently seeking to appoint a new Chair to the Information Commission, a governance structure created by the 2025 Data (Use and Access) Act.
In the US, President Donald Trump managed to remove a Federal Trade Commissioner, and this has been approved by the Court of Appeal regardless of the obvious threat to the EU-US data transfer arrangement. In Canada, the legislator plans to strip the DPA of oversight of the private sector, and to establish one body to regulate online harms, social media, AI chatbots, as well as private sector privacy.
Laura Linkomies
Editor, Privacy Laws & Business
August 2026
Previous |
Contents |
Next |