Universiteit Leiden

nl en

Gerrit-Jan Zwenne: ‘The problem is not the GDPR, but the lack of knowledge about it’

Ahead of this year's National Privacy Conference, Gerrit-Jan Zwenne, a lawyer and professor at Leiden University, discusses data breaches, the European push to simplify the GDPR, and asks if legislation needs a fundamentally different approach to AI and Big Tech.

What do you see as the biggest misconception about the EU’s General Data Protection Regulation (GDPR), or privacy law in general? 

‘People often assume that the GDPR doesn’t allow personal data to be used, but that’s often incorrect. The Regulation sets limits on the use of personal data, and if you take the time to understand those limits, you’ll often find that there’s far more scope than people think. So, the problem’s not the GDPR itself, but the lack of knowledge about it.’

Commenting on the Odido data breach, you previously argued that tighter regulations do not necessarily prevent hacks, but that class actions can be more effective. Why do you think so and will we see this more often? 

‘The question is, what has the greatest impact on those responsible for making investment decisions about security? The GDPR already imposes strict requirements, and compliance is monitored by regulators. Yet, if companies fail to meet those requirements, the chances of them being fined are relatively small. Class actions have a different dynamic and will often have a far greater impact.

That said, a data breach is not necessarily the result of non-compliance with security requirements. That’s another common misconception.’

Simplifying the rules

You recently wrote and spoke about the Digital Omnibus, the EU’s proposal to simplify the GDPR. It aims to reduce the regulatory burden on businesses. Where do you see the greatest tension between easing that burden on companies and preserving fundamental rights?

‘The Digital Omnibus aims not so much to relax the rules, but to simplify them: technical adjustments that will help improve consistency and coherence in the regulatory framework. Of course, this might result in less stringent requirements, but that’s not necessarily to be expected.

The GDPR does contain provisions that, with the benefit of hindsight, appear to do little to advance the protection of fundamental rights and freedoms. The Data Protection Impact Assessment (DPIA), for example, mainly seems to be a lucrative business model that benefits privacy consultants. But have all those DPIAs actually resulted in better protection? I have my doubts. And is it really necessary to report every data breach, no matter how minor, in the supervisory authority’s reporting portal? There’s a strong case for limiting notifications to data breaches that pose a high risk. At the previous edition of the privacy conference, the Omnibus proposals had only just been published. We’ll be discussing them in greater detail at this year’s event.’

Same quality control as a jar of peanut butter

AI is rapidly transforming the legal profession and is increasingly being used by lawyers for research, analysis, as well as drafting and summarising documents. So, Big Tech is gaining more and more influence. Do you see this as a trend?

‘With the GDPR, the EU legislator aims to achieve a high level of protection and therefore imposes numerous obligations on public authorities and private organisations that process personal data. At the same time, the Regulation grants a wide range of rights to the individuals to whom that data relates, such as the right of access to data, the right to have data erased, and the right to be forgotten.

Enforcing those rights has proven far from straightforward, even where substantial fines can be imposed. Simply increasing the regulator’s budget will not solve that problem. I believe it would be more effective to focus on imposing rules on those who design and build the systems themselves: in other words, product regulation.

Take the example of how food safety is regulated. As a consumer, I can trust that a jar of peanut butter complies with the applicable legal requirements. I don’t have to check that myself. Likewise, we should be able to trust that an algorithm or AI system is safe. Perhaps the emphasis therefore needs to shift more towards those who develop and market those systems. The AI Act is already moving in that direction.’

Big Tech oversight falls short

It's clear that stricter legislation does not always imply taking power away from large tech companies. Is regulation through instruments such as the Digital Services Act and the Digital Markets Act effective in curbing their influence, or is there room for improvement?

‘It could be improved. Individual users find it’s almost impossible to exercise their rights against Big Tech on their own, and regulatory oversight often falls short. Class actions, however, do appear to have an effect. The same lesson applies here: it’s likely to be more effective to focus regulatory efforts on the companies that develop the systems in the first place.'

The National Privacy Conference

Would you like to hear more about this area of legislation? On 6 November 2026, Gerrit-Jan Zwenne will be speaking on the topic together with other experts including Laura Poolman, Quinten Kroes and Sander Klous during the national privacy conference (Nationale Privacy Congres, language is Dutch) in Naturalis, Leiden. This year will focus on the Digital Omnibus and the intersection between the GDPR and the AI Act. The conference is aimed at those who already have experience with privacy legislation and who would like to gain more in-depth knowledge. More information and registration.

This website uses cookies.  More information.