Proposed EU data laws under fire from both sides

The European data protection supervisor says the proposed laws are too weak, but businesses say they are too harsh

Proposed European laws on data protection have come under fire from both sides this week.

The reform of the 1995 Data Protection Directive is one of biggest shake-ups of data protection laws in the European Union in nearly 20 years, affecting Google, Facebook and Microsoft as well as thousands of midsized companies.

Alongside a revised directive, a new regulation will impose laws directly on E.U. member states. The laws aim to increase protection for personal data and harmonize rules across the E.U. But on Wednesday European Data Protection Supervisor Peter Hustinx said the directive is "unacceptably weak," while the British business community has complained that it is too onerous.

Hustinx warned that the regulation may grant excessive powers to the European Commission, but saved his real ire for the directive. "In many instances there is no justification whatsoever for departing from the rules provided in the proposed regulation," he said. He also complained about a lack of legal certainty about the further use of personal data by law enforcement authorities and the weak conditions for transfers to third countries.

British businesses, meanwhile, objected to the requirement to disclose data security breaches without delay normally "within 24 hours" with penalties of up to 2 percent of global turnover for companies that break the law. This new rule is widely seen as a reaction to the Sony PlayStation breach last April when Sony took more than a week to inform its 77 million customers that their data may have been at risk.

The U.S. Department of Commerce has also been critical, saying that 24 hours is "simply too short" and could lead to "massive fines" for companies and to confusing "false alarms" for consumers.

"Given the cost and complexity of assessing data breaches, 24 hours is just not enough time for many businesses. In some cases it takes many days to work out what data has been put at risk and by whom," said Kathryn Wynn, senior associate at technology law firm Pinsent Masons. "British companies are extremely concerned about this."

However, the laws are still in the early stages of a process that could last up to two years. Proposals must still be approved by European Union member states and the European Parliament. The regulation will be enforceable in all member states two years after it has been adopted. Countries will also have a period of two years to transpose the directive into national law.

Follow Jennifer on Twitter at @BrusselsGeek or email tips and comments to

Join the newsletter!


Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jennifer Baker

IDG News Service
Show Comments


Brother MFC-L3745CDW Colour Laser Multifunction

Learn more >



Sony WH-1000XM4 Wireless Noise Cancelling Headphones

Learn more >


Back To Business Guide

Click for more ›

Brand Post

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Tom Pope

Dynabook Portégé X30L-G

Ultimately this laptop has achieved everything I would hope for in a laptop for work, while fitting that into a form factor and weight that is remarkable.

Tom Sellers


This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang


It really doesn’t get more “gaming laptop” than this.

Jack Jeffries


As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr


The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Featured Content

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?