Digital Omnibus Package: Discussion
Witnesses divided sharply on the digital omnibus package. Civil society and academic experts said it would weaken GDPR, e-privacy and AI safeguards, shift more power to companies, and risk undermining fundamental rights, with particular concern about AI training, transparency and Ireland’s enforcement record. DigitalEurope argued the Commission’s changes are mostly targeted clarifications, useful for predictability, but said the final package should go further on simplification, especially on data sharing and cyber reporting. The committee also heard strong criticism of the Data Protection Commission, with calls for a report, more scrutiny of enforcement, and better recruitment safeguards for the commissioner role.
The purpose of this part of the meeting is to engage with a number of stakeholders on submissions received in relation to the digital omnibus package. On behalf of the committee I welcome the following witnesses to the meeting. Joining us via MS Teams we have Dr. Itxaso Domínguez de Olazábal, who is a policy expert from European Digital Rights, and Mx. Blue Duangdjai Tiyavorabun, who is also a policy adviser for European Digital Rights. Joining us here is Dr. Eileen Culloty, associate professor from the school of communications at DCU and who is also deputy director at the DCU institute for future media, democracy and society. We also have Dr. Tetyana Lokot, who is associate professor in digital media and society from the school of communications. From DIGITALEUROPE we have Mr. Alberto Di Felice, who is its policy and legal counsel. Finally, we have Dr. Johnny Ryan who is director of enforce at the Irish Council for Civil Liberties.
The format of the meeting is that I will invite each organisation in turn to make an opening statement to a maximum of three minutes. I will then call on members of the committee, in the order they indicate to me, to put their questions.
Before I invite opening statements, I wish to explain there are some limitations to parliamentary privilege and the practice of the Houses with regard to reference witnesses may make to other persons in their evidence.
I invite Dr. Itxaso Domínquez de Olazábal and Mx. Blue Duangdjai Tiyavorabun to make their opening statements.
Comment on this
Thank you. I will take the floor first and then my colleague will join.
I thank the Chair and members of the committee for the invitation to speak. The AI and digital omnibus package is simultaneously amending three laws that, taken together, took more than ten years to negotiate, and with the current timeline, specifically looking at the AI omnibus as precedent, it is taking mere months to significantly change the spirit of the law, the structure of the law, and threaten to leave people without protections from harm.
In both process and substance, this proposal raises very serious concerns for us. Starting with process, to create good laws, it is of the utmost importance that due diligence is exercised and that any reform affecting people's rights follows a transparent, evidence-based, inclusive process which is consistent with the treaties. A criterion, which this omnibus and the prior nine likely do not meet. was confirmed by the European Ombudswoman, who recently found maladministration in the preparation of prior omnibus initiatives. We see these issues also with the AI omnibus, a reform that requires full transparency and rigorous fundamental rights and environmental assessments. None of these elements are present.
Additionally, the gravity of these changes cannot be understated. Both GDPR and e-privacy are foundational laws of the digital rule book. Hence, subsequent laws were created with the GDPR and e-privacy in mind, such as the AI Act, which entire logic of high-risk AI systems rests on the foundation built by laws such as GDPR. Therefore, changing the foundation law in the era of big data needs to be done with the utmost due diligence and care as even mapping the impact of this change, for example, of a definition throughout the whole digital acquis and beyond and the subsequent impact on people's lives, is a monumental task. This underlines that a supposedly simple change such as definition, for example, threatens the rights of people in the EU in a way that cannot easily be undone.
Comment on this
The digital omnibus comes at a very sensitive moment. Across Europe, there is growing concern about whether the digital rule book is being effectively enforced. That concern is not limited to one member state, but Ireland is central to how this system works in practice. Ireland's reputation as a human rights champion is, therefore, at stake. Many of us in the digital rights community across Europe have been deeply concerned by how the Data Protection Commission has handled enforcement and the consequences this has had across Europe for the human rights of individuals and collectives. This is happening just as Ireland prepares to take on the Council Presidency. That mean setting priorities and signalling what kind of digital framework the EU stands for.
In that context, weakening the rules instead of strengthening enforcement risks undermining trust in the whole system.
On substance, the issues with the digital omnibus package when it comes to GDPR and privacy are clear. Changing the definition of personal data risks fragmentation, which means people may have rights in one context but may not have the same rights in another. More data will be used to train and develop AI systems without people knowing about it, and even when they do, it would be very difficult to challenge. Loosening rules on access to devices increases tracking in environments where people are already constantly monitored. Reducing transparency and access rights makes it harder to detect and challenge abuses for individuals and organisations. It will become easier for systems to make decisions about people’s opportunities, such as jobs or services, without meaningful human oversight.
These are not just small technical changes, which is how the digital omnibus has been sold to us. They reshape how the system works and move us towards a model where companies assess their own compliance. Self-regulation has never worked. At the same time, there is a shocking cognitive dissonance. We hear of strong commitments to protect children online, yet this proposal makes it easier to profile and influence people, including children. These directions do not align.
There is a broader risk. A "move fast and break things" logic that is typical to big tech is entering EU digital policy-making, but here what can break are fundamental rights. Once data is processed and reused at scale, the harm is very difficult to undo. This translates into harm of fundamental rights. This is not a simplification. It is a political choice about deregulation, about the level of protection we maintain, and about the credibility of the EU’s digital framework.
I thank members and look forward to the discussion.
Comment on this
I thank Dr. Domínguez de Olazábal. I now call Dr. Tetyana Lokot.
Comment on this
I thank the members of the committee for having us. Dr. Eileen Culloty and I will speak on behalf of DCU’s Institute for Future Media, Democracy and Society, a leading research centre focusing on the digital transformation of media, democracy, and society.
Based on our work on media literacy, digital rights and platform regulation, we find that the substantial changes proposed by the digital omnibus package represent a significant weakening of safeguards designed to protect the public, secure personal data and govern AI systems. The justification for the digital omnibus is to simplify complex rules and increase European competitiveness. However, the omnibus introduces complexity instead of clarity and consistent enforcement for the disproportionately burdened small and medium enterprises that comply with existing EU rules. In fact, the key benefactors of the digital omnibus appear to be the major, mostly American, tech companies, which have lobbied aggressively for deregulation.
We are particularly concerned that the omnibus package and its proposals weaken the definition of personal data under GDPR, moving from an objective assessment to a controller-specific interpretation, which restricts the possibility for data subjects to exercise their right to gain access to their own data. These measures undermine legal certainty and weaken personal data protections for individuals. We find that the package also dilutes existing mechanisms for external scrutiny and oversight of AI development systems. It allows developers to rely on so-called legitimate interest rather than consent when processing personal data for AI training. It also allows for special category data to remain within AI training datasets where companies consider removal to be too difficult, with little detail as to how such an assessment would be carried out. The package also delays certain obligations for high-risk AI systems and removes the requirement for public registration of some of these systems. We believe that these changes reduce transparency and risk further normalising the broad use of personal data without sufficiently robust necessity and proportionality checks.
By broadening the definition of research activities under the GDPR to include a wider range of industrial and commercial activities, the omnibus blurs the boundary between commercial activity and scientific research that serves a clear public interest.
The decision to downgrade AI literacy from a direct legal duty on AI providers and deployers to a matter of encouragement by the Commission and member states risks hollowing out existing expectations around meaningful explanation and accountability. Without clear legal obligations, and given the distinct lack of financial support for bodies capable of promoting AI and digital literacy at national level, commitments to improving public understanding of AI systems risk remaining largely aspirational. While public demand for platform accountability is growing, the EU seems to be pursuing a deregulation agenda with little evidence to support it.
Notably, the Commission did not conduct a dedicated rights impact assessment of the omnibus. This is surprising, as the very point of GDPR and the e-privacy framework is the protection of fundamental rights. Instead, such regulatory streamlining risks further restricting the possibilities of data subjects to exercise their rights.
I thank the members for their attention.
Comment on this
I thank Dr. Lokot. I also thank Deputy Ward for stepping in as Chair. Our next speaker is from DigitalEurope, Mr. Alberto Di Felice.
Comment on this
I thank the Cathaoirleach and members of the committee for the invitation to appear today on behalf of DigitalEurope. DigitalEurope is the broadest coalition of Europe’s digital technology industry. We have national trade associations, including Technology Ireland, which is part of IBEC, as well as global companies across the full digital ecosystem.
Much of the discussion around the digital omnibus to date has focused on the GDPR, and the other testimonies so far have confirmed that. That is understandable. There are questions around rights, trust and legal certainty that concern the GDPR. On the GDPR, we think that the Commission has done more good than bad and that some of the proposed clarifications are genuinely useful. There is a risk that, in the noise around them, we would miss an opportunity to make the GDPR more predictable. In particular, clarifying what counts as anonymous data and confirming that security and research can rely on the legitimate interest legal basis are sensible steps that to a large extent confirm existing case law and the more progressive guidance from the European Data Protection Board, EDPB. For us, the GDPR remains a fit-for-purpose framework. It does not need to be reopened wholesale. We consider most of the changes brought forward by the Commission as being targeted clarifications that can be improved.
On e-privacy, we see that there are a lot of structural problems that remain. The proposal puts in place a separate, consent-centred regime for terminal equipment data. That is not just about cookies and advertising, which are mostly addressed in public discourse around these changes. It affects a much broader range of device and machine data, including in industrial environments. A lot of our members are industrial companies from across a number of manufacturing sectors. The only clean solution that we see is to bring all terminal equipment data fully under the GDPR’s legal bases rather than continuing with a parallel system that creates overlaps and actually discourages responsible data use.
If the debate stops at privacy, we will miss a very interesting and important part of the debate, which is very heavy on business models and compliance for Europe’s industrial and business ecosystem, the other parts of the digital omnibus. The Data Act and cyber rules are also part of the same package. On the Data Act, consolidation of several laws is welcome, and tightening business-to-government access to genuine public emergencies is also positive, but the core problem remains untouched. There are mandatory, horizontal data-sharing obligations and ill-fitting cloud-switching rules that cut directly into how European companies build data-driven products and services. For sectors such as manufacturing, health, energy and mobility, this goes directly to investment, product design, trade secrets and Europe’s ability to compete in AI-enabled markets.
On cyber, a single entry point for reporting is useful but a new portal is not simplification if companies still face multiple thresholds, multiple templates and multiple timelines for reporting. The real need is one portal, one core template and convergence around a workable reporting standard rather than a cascade of early warnings and follow-up reports that pull resources away from actually fixing incidents. The Cyber Resilience Act, which is a key piece of compliance for devices and software, still needs substantive adjustment now and not in later omnibus proposals.
Our message today is largely positive but very firm. The Commission has started the right conversation. It is not perfect but the final omnibus must go much further. If known problems are deferred to future fitness checks and future packages, the momentum for real simplification will be lost at exactly the wrong time for European competitiveness.
Comment on this
I thank Mr. Di Felice. Our final speaker is Dr. Johnny Ryan from the Irish Council for Civil Liberties, ICCL.
Comment on this
I thank the Cathaoirleach, Deputies and Senators. The committee is right to scrutinise what has been misrepresented by the Commission as a mere simplification. That is not what is before the committee. If we believe, and there are many who do, that AI will displace large numbers of workers and that it will up-end our understanding of society, then diligent monitoring of data and diligent scrutiny of the laws of data are all the more important.
The ICCL therefore commends the committee. It is good that it is having this hearing. I hope it will produce a report.
I have spoken to senior European Commission officials and people in the chancelleries in several of the capitals pushing this omnibus agenda. I sympathise with their objective, which is to boost European competitiveness. Before I joined this NGO, I worked in industry for many years. I understand the need. There is a problem, however. Europe has many competitiveness problems, but as I wrote in The Guardian in November and again in February, the GDPR, if only it were applied by Ireland, is not among those problems. In fact, it is the solution; we are the problem.
There is a problem with how we regulate data and with our relationship to it. I will present a diagnosis to the committee and suggest three things that it could perhaps factor into its deliberations. Here is the diagnosis, and this committee already produced it in 2021. I will quote from the committee's 2021 report, which states:
Of serious concern to the committee were reports of the particularly slow progress of some cases being handled by the DPC.
[...]
It is now more than five years since the GDPR went into effect, and more than three years since it was applied. The Committee fears that citizens' fundamental rights are in peril.
Half a decade later, those concerns, which the committee's predecessors had, remain live. They are simply more urgent. For all of Europe, it is Ireland that has the responsibility of supervising TikTok, Google, Snapchat, Microsoft and so on. At a meeting of the Committee on Artificial Intelligence earlier this month, the chair of the DPC admitted that it has never completed an inquiry into a company called Google. When we do not complete inquiries into Google, it stops every other European country acting. That is because we are in the way. This should give the committee a sense of where the problem is, not just in the area of data protection law but also in the areas of competitiveness and AI.
This is not for want of resources. Remember, the DPC has almost 300 staff and a budget of €33 million. It is asking for €10 million more. That should be considered carefully. It is also worth reflecting on comments made by Sarah Wynn-Williams, who wrote Careless People. A former Meta executive, Ms Wynn-Williams stated that the industry looks upon the DPC as its lapdog. We have a problem here. I will not read out the section from the Oireachtas banking inquiry's report, but members will recall what it said, namely was that our financial regulator, in the disastrous years leading up to 2008, relied on moral suasion and protracted correspondence, sometimes for more than a decade, and would not use its enforcement powers. That is exactly what we see with the DPC, and the same level of risk is building up now.
Before I get to the recommendations, which I will talk about briefly, let me say that we have obtained from the Public Appointments Service documentation, which we can share with the committee, relating to the process to recruit the latest Data Protection Commissioner. It states clearly that the criteria for selecting our enforcer were senior management criteria for normal civil servants. They were not about expertise or being an enforcer. We carried out no assessment of whether this person had - and I am not suggesting she had - stock options from her previous employer in tech, nor whether she had any enduring contractual obligations not to disparage. This comes around the same time - it is very recent, in the last short period - as the previous holder of the DPC leadership joined the firm that represents Meta in ongoing cases against the DPC. We clearly have a problem.
Comment on this
Absolutely. I am not going beyond anything that is in the written statement. We have a situation that is not one of the gamekeeper turning poacher, because we do not do gamekeepers. We have a real problem, and the justice committee would be well served, and we would all be well served, by looking at three things. One is that this omnibus tackles the wrong problem. Second, it would be useful to finally have hearings on how it is possible that we have yet to complete a single inquiry into a company like Google and, I suspect, others of its size. We need a report on that. This will be a crisis. Third, I suggest that we have a full set of hearings on the general question of why Ireland can not recruit enforcers. There is something wrong with our process of recruitment. We do not just have a revolving door problem; we have a problem with the people who got into particular jobs in the first place as a result of how we specify roles and who is involved in the process of recruitment.
Comment on this
I thank Dr. Ryan. I invite members to indicate and suggest we have a first round of five minutes each.
Comment on this
I have two questions. Maybe Dr. Culloty and Dr. Lokot could answer the first one. I am sure others may have contributions to make. In the current GDPR legislation, there are special exemptions for things that are in the public interest. I want to understand in a bit more detail what is happening with this omnibus Bill in the context of those exemptions when it comes to the training of AI systems. Will the witnesses speak a little more about what the omnibus does to those types of protections, especially as it places the burden on individuals to prove that their data was used inappropriately rather than having the in-built protections that exist currently?
Comment on this
I will go first and then pass over to Dr. Lokot. Building on what the Senator said, it is important to see that the changes to the GDPR are not a clarification. That is a massive simplification of what they are. They are fundamentally redefining how the GDPR works and how data and personal data are defined. It makes it much more subjective. If data controllers are allowed to decide whether something is personal data, it is no longer an objective decision, which it currently is, and that inherently ends in a bizarre scenario where, with the same piece of data, one organisation might decide it is personal data and afford the rights that go with that, and another organisation might decide it is not. In those circumstances, it will be entirely up to individuals to know it is personal data and that they should fight the decision.
Comment on this
Specifically in respect of the training and development of AI systems, a lot of the changes proposed in the omnibus focus on allowing developers to define, for instance, what constitutes legitimate interest and what constitutes data they require to train their systems or data they say could be difficult to remove or isolate in their training data sets. The onus of defining what constitutes these types of data is entirely on the companies. That really undermines the rights of the data subjects because it takes away a lot of their agency, because these decisions might differ from developer to developer or company to company and because no individual data subject has the right, tools or scope to check how each specific AI system is potentially using their data.
Comment on this
There is obviously no transparency. Individuals would not be informed, for example, that their data is being used in a particular way. They have to be able to know that.
Comment on this
No, because it is not consent based. Under legitimate interest, the users are not asked for their consent. In fact, when users try to exercise the right to gain access to their data used by a particular system, the proposed changes essentially limit their rights because they provide that if they are asking for data protection purposes, they can only ask for this data to figure out how it is used. That might not necessarily be the case and, again, it is on the individual data subjects to-----
Comment on this
It is worth mentioning that it is important to understand how the right of transparency and the right of access have been undermined. It is not just about the data subject not being able to understand whether their data is being used for AI operation and training and subsequent processing. It is also important to understand how the digital omnibus is also weakening the principle of purpose limitation. Even if people go to the company and ask about their data and how it is handled, the company can consider this an abusive request. It can just say "No" or ask for money in exchange for that kind of information. We have a situation where the data subject and even the regulator have to run after the companies, which are just going to self-assess that the GDPR does not apply and they do not have to protect people for that reason.
Comment on this
Dr. Ryan wants to come in on this question too. Will he clarify what was meant when he said that because there has been no completion in any of the Google pieces, this means nowhere else can pursue Google because something active is in play? Is that what he meant?
Comment on this
We are the lead authority because Google has its headquarters in this jurisdiction. It has its main establishment here. This means that if a French person complains to the French authority, the Commission Nationale de l’Informatique et des Libertés, CNIL, and if it is a cross-border matter affecting more Europeans than just French people, CNIL has to send that complaint to the Irish DPC, and there it shall stay interminably. Dr. Domínguez de Olazabal made a very good point. She referred to something called "purpose limitation". This is the great hope for European AI. It means that if a big business is collecting lots of data because it runs a popular email service and a popular video service, it cannot automatically use the data it is getting from those services, great though they are, to win the AI market. The data can only be used for those specific purposes. If the digital omnibus goes through, however, that prohibition will be removed by this other concept, the legal basis called legitimate interest. It is very dangerous. The assumption is that it gives European AI a chance to compete in the market. In reality, it will make the unassailable but unlawful data lead that the-----
Comment on this
Basically, Europe is using and debasing the rights of individuals to be able to compete with the likes of the US, for example, which is leading in AI development.
Comment on this
I thank Senator Ruane. We will let her back in for a second round of questions. I call Deputy Ward.
Comment on this
I thank all the witnesses for their opening statements. I have to say that Dr. Ryan's opening remark was scathing. He linked the current lack of regulation enforcement to the similar situation in the banking industry before the last financial crisis. That is a stark statement because we know what happened then. Why does Dr. Ryan think the Data Protection Commission has not undertaken a single inquiry into Google despite repeated complaints?
Comment on this
I cannot get into what individuals' motives are, but I can tell the Deputy that when I was in industry I blew the whistle to the Data Protection Commission about something in online advertising back in 2017. I then filed a formal complaint, with evidence, in 2018. Some of this material made it to the front page of the Financial Times. The last time the Deputy will have heard about this issue was when "Prime Time" showed the location data scandal, when people were shown moving around the Oireachtas. A lot of that came from something called real-time bidding. The DPC has been sitting on an inquiry into Google's real-time bidding system since I complained about it formally back in 2018. I do not know why it cannot produce things, but I do know that it does make Ireland a very convivial environment to operate in. It means that giant US and Chinese firms can operate with impunity in Europe. They are violating European law and we are the back door. That is how it works.
Comment on this
Senator Ruane asked a question I intended asking on the knock-on effect on Europe. Do the same rules exist in relation to complaints being made and followed up for TikTok, Snapchat and other platforms? Has the DPC undertaken any inquiries into those companies?
Comment on this
The DPC has delivered quite a few decisions on Meta, for example, and several on TikTok. The most famous one involved a very large fine of €1.2 billion against Meta. That sounds impressive but if we read paragraph 38 of the EDPB decision, in which the DPC was overruled, we will see that the DPC was pushing hard for there to be no fine at all. As per usual, it was overruled by its European counterparts.
Comment on this
The DPC was looking for no fine whatsoever.
Comment on this
Would the money from that fine have come back into the public purse? It reminds me of the Apple tax stuff that was going on.
Comment on this
The Deputy may be aware that there is an issue with the courts and their resourcing, so it is still on appeal. I am referring to the earlier session. Speaking of courts, though, we have the bizarre situation where, in January last year, the European Court of Justice delivered a decision in a case called DPC v. European Data Protection Board, that is, our enforcer versus all the other European authorities. The other authorities had voted to force the DPC to investigate what Meta does with people's most intimate data. The DPC had refused to do this for five years. When this was voted on, the DPC, instead of investigating Meta, sued the EDPB, that is, all of its European counterparts. In January, that case was thrown out, of course, by the European court. We are way out on our own. It is the wild west here. It is a situation where there is no sheriff and no shame.
Comment on this
One of the most recent investigations from the DPC, which is the one about Grok and the nudification of women's bodies and how this has been handled throughout Europe, was also allegedly forced by the EDPB. The DPC had no intention of acting, but the EDPB forced it to act. The DPC knew it would get a gold star. It is really egregious how the DPC does not want to intervene in some of the cases where people's rights are clearly being harmed, especially in this case where we are looking at women and children. I think we do not even have to ask the reason for this. The whole GDPR and enforcement depends on the DPC acting in good faith or just delivering on its mandate. It is not doing so. Even when it is imposing fines, it is not collecting those fines. Companies keep using the system to lodge appeals and abuse the system, instead of complying with the law and respecting human rights.
Comment on this
No. I have been gazumped. Deputy Ward asked my question.
Comment on this
Fair enough. I will ask a couple of follow-on questions. What is described by the European authorities as an accelerated procedure might be described by others as a rushed procedure. What risks does doing things in this fast-tracked timeline, to use that term, create? I ask our speakers to address if any specific safeguards are missing that could very quickly, and, arguably, easily from a legislative timeframe perspective, address some of the concerns mentioned?
Comment on this
In terms of the timeline, we actually have two different timelines because two different omnibus proposals are being talking about. There is one on AI, which has been accelerated. We will probably see a final vote in the Council and Parliament in April. We are very concerned, as a business association, because we have not really had time to discuss with policymakers the changes we would have wanted. On the digital omnibus, which includes the GDPR, cyber and data, the timeline is much more dispersed. We expect there will be longer discussions, particularly because the GDPR points are very contentious between policymakers. The timeline in terms of the democratic discussion will be much longer. I understand the concerns in terms of impact assessments, but this is the nature of omnibus proposals. They are largely the result of emergency interventions that the Commission needs to put forward to fix something. In this case, they stem from a need to address competitiveness issues, and they go beyond these areas of laws.
When it comes to the fixes, there are genuine philosophical differences when it comes to interpreting effectively how broad these changes are.
If you read the opinions from the EDPB and the European Data Protection Supervisor, EDPS, you would get a better idea of what sort of problems we are talking about.
Particularly looking at those opinions, there are fixes that could fix some of the concerns that come from civil society, both when it comes to the use of legitimate interest and when it comes to the definition of personal data. I hear direct and absolutistic statements when it comes to these changes. We need to start with the fact that these changes come from a basis in case law. They start from a basis in guidance that we have seen from the EDPB and EDPS. We can discuss the merits and boundaries of what that guidance and case law say, but there is language, both in the current proposal and that we could be putting forward, to address some of the concerns whereas what I see coming from civil society is a pure rejection of addressing these areas of the GDPR.
I have spoken about other things than GDPR and data protection. I have to be very honest with everybody and say that the changes to the GDPR were not the main things that we as an industry were asking the European Commission to do in the digital omnibus. We are looking at other areas, such as rules pertaining to how data from companies needs to be shared with other companies and how companies have to comply with cybersecurity legislation.
We consider that the GDPR overall has worked. It has been cumbersome for companies across the spectrum to comply with but it does not need to be fundamentally changed. To the extent that these clarifications from the European Commission can actually be clarifications, we think they would be useful. If they cannot be done, we need to think about the other areas.
Comment on this
Many industry players and others are presenting all of this debate as if civil society is absolutist and we do not understand anything that has to do with pragmatism whereas the others are more pragmatic, but nobody defines all data as personal data. That is a really bad-faith characterisation.
Of course, we are looking at the case, but how the Commission is interpreting the last ruling, which is the SRB ruling, is a very interesting codification that does not read the whole ruling and does not take into account the other precedents. When we look at case law, we already have enough indication about how GDPR needs to be applied. We do not need the Commission coming in not only changing the definition of personal data, but also self-declaring that the Commission could have the power to determine what is and is not pseudonymised data, giving itself much more power than it could ever have had when the GDPR was being negotiated.
In terms of the safeguards and timeline, what is interesting is that even the Council is acknowledging that this process is not the right process in order to reopen fundamental rights legislation, neither GDPR nor e-privacy. When you look at the draft Presidency compromise text, most of the very harmful provisions, such as the definition of personal data or automated decision-making, which should be prohibited but is now permitted under certain conditions, have been struck down. There is a framework for that. This is a digital fitness check. We need a full-on impact assessment, we need to respect the better regulation guidelines, we need democratic oversight, and we need to go article by article and not force colleges later to adopt a package deal just because that is what some companies - I am going to say "some companies" very clearly - are saying. This is not clarification; it is changing the full essence of the GDPR. We are actually looking at the definition of personal data. How is that just clarification? We need to take that all seriously because we are speaking about human rights, and if we are going to touch fundamental rights, we need to do it the proper way and not take advantage of this omnibus and simplification package, which, like all of the nine other omnibuses we have seen, is actually deregulating people's rights and putting people's lives in danger without knowing whether there are going to be enough safeguards to protect them.
Comment on this
It is easy to position industry on one side and civil society on the other and end up saying that one person's simplification is another person's deregulation, but what do we have regulation for? It is meant to be to protect the public interest, to protect democratic values and human rights. What civil society is saying is those things are being undermined.
It is entirely legitimate for business and industry to say that these things are complex and we need these to be clarified. One of the criticisms of this is which business and which industries is it actually helping. There is a legitimate question about whether this aids European SMEs or whether it primarily aids the major tech companies that lobby at European level quite extensively.
The Cathaoirleach mentioned specific measures. One very specific thing is around AI literacy. This sounds very simply, but Article 4 of the AI Act said that any company deploying AI systems should have a requirement that the employees using those systems be given basic training to understand what they are doing. If you think about the importance of human beings making moral choices and human beings as whistleblowers as well, it means people need to have a basic understanding of the tools that they are using and what the implications of those are. It is not a huge obligation to say your employees should be informed, and now it is being removed.
Comment on this
Dr. Ryan mentioned the conviviality of the environment in Ireland. He also mentioned the example of someone in France making a complaint to their local data protection commission, service or whatever. In circumstances where the European headquarters are based here, is there a lot of frustration throughout Europe in that regard? Is that conviviality simply about encouraging more FDI into this country?
Comment on this
It took a long time before Irish people were willing to accept that maybe the country was a tax haven. It started with one academic in Trinity, who was a lone voice for a while. The reality is we appear to be a tax haven again, which is a testament to our innovative capacity, and we are also a digital haven, and there are more and more people in Brussels who see those two things together.
Dr. Eoin Drea did a very good podcast with Hugh Linehan recently. Dr. Drea is a senior person at the European People's Party, EPP's think-tank in Brussels and he gave a very good Brussels insight into just how bad Ireland's reputation was in Brussels. This place is a haven for some of the most dangerous companies in the world. When I say dangerous, we are talking about children committing suicide. This is not just things like CCTV cameras being hacked. This is stuff that every person in this building feels. Everyone knows there is something wrong. We have not yet internalised that we won the race to the bottom and are the cause of that happening, but we are.
Comment on this
It is extraordinary that I have seen the Data Protection Commission, DPC, haul owners of management companies over the coals over breaches of legislation owing to security cameras that are designed to protect their members when what Dr. Ryan described on an international level is much more insidious.
Comment on this
If you go back through the history of the DPC to the early days, you will see private investigators getting hauled up. It is easy to enforce easy, but if you actually want to change a system and a market, you must enforce proportionately and fairly, which means top-down and highest impact. There is no point going after the local butcher for some filing error when the local butcher is using a system created by Microsoft but you are afraid to go after Microsoft. Trickle-down regulation is the way this needs to happen but the DPC is far from doing that.
When the Deputy is asking questions about this, he should ignore the DPC because the people to ask the question of are in the Department of justice. They specify the roles for European enforcers in such a way that an enforcer will not get through that process. The documents show how the interviews were designed. There was a maximum of ten minutes set for anything involving expertise, but that also involved other things. Then, the person who would question you about expertise, according to the documents, is a corporate lawyer who represents big tech. That is Ireland's approach to enforcement.
It is not serious, and it is going to hurt us all very badly.
Comment on this
This is something we could examine again.
Comment on this
There are not many things in my life that I have been afraid of, but this type of stuff is one. It is insidious in the sense that it is very hard for society or people to grab hold of what it means for AI to have such control and input into our lives and decisions, the shape of what you see and do not see, and what your children see. It is very hard for people to grab onto that, understand it and make sense of it. When it came to colonialism, imperialism and war, people could see the brute force and control of those. This is much more liquid in terms of how it seeps into your everyday life. Deputy Ward asked what we can do. The problem is that the omnibus is on its way. This committee only has GDPR as part of its brief, and other committees have waived the scrutiny of this. Even in terms of what we are doing here, it is more of a commentary on something that we do not seem to really want to address or acknowledge.
At a European level, is there something we should be doing? Should our Government be standing up at the European level? At the same time, I can understand why it might not want to, when we want to be attractive to big tech and its systems. There is not really a question within that. It is just that I am constantly dismayed and even a little scared of what it all means.
Comment on this
There is something that Ireland can do. When we speak about the perception that Europeans have of Ireland, it is funny. We said that GDPR and the privacy parts of the omnibus will mainly be taken into trilogues during the next six months, or potentially afterwards. We were saying that it is going to be the Irish Presidency and asking whether we want Ireland to be in charge of that, even though the Council Presidency should be moderate. Ireland has a great responsibility in terms of enforcement, but also in legislative terms. The Council is setting the boundaries for what the Commission can and cannot do, and the Council is a group of member states. I want Ireland to continue what the Cyprus Presidency is doing. It is sending a message to the Commission that it is going too far, this is not the process, this is not the framework and this is not the time. It is saying that we have to look at enforcement and potential laws to protect children, for example, the digital finance Act, which is a modernisation of consumer law.
I really think there is something that Ireland can do, including the Irish MEPs. The European Parliament is going to have to adopt a position on the data omnibus, and it should be a good position. Anything that has to do with law-making has to do with democratic oversight and respecting fundamental rights. There is something that Ireland can do. Otherwise, we would not be speaking about it. I have high hopes for the Irish Presidency precisely because Ireland has a great record when it comes to the rest of human rights. Why should it not have a great record when it comes to digital rights, which are also human rights?
Comment on this
I am concerned because most Government members constantly use the word "simplification" without ever really explaining what the backdrop of that means.
Comment on this
That is part of the story. It is perhaps about educating Irish policymakers, but also going back to the very roots of what due process is, and how such a far-reaching legislative change or set of legislative changes could be processed and discussed. There is a particular process for how the European Commission decides, and that usually involves things like impact assessments and consultation periods that should not be bypassed or compacted. It involves having certain evidentiary requirements. Even if particular Irish policymakers do not feel they know enough to make specific suggestions or criticisms, it is on them to find somebody who does know and can inform them about processes like this. It is to make sure that on the European level, that process is followed. It is to make sure that everybody who this Bill impacts, but also everybody who can speak to that behind-the-curtain, black box stuff knows what actually happens to people's data when it enters AI systems and the particular dangers and threats that we are talking about, in this case, threats to fundamental rights.
Simplification is a misnomer. We are not really talking about simplification if we look through the omnibus in its entirety. These are genuine changes. These are not simplifications of rules or clarifications. These are not aiding enforcement in some way. In some cases, these are pretty spectacular changes that we are talking about. Calling that out, and also asking for greater evidence and impact assessments for those who these changes might impact, is the least that Ireland can do during its Presidency term or otherwise.
Comment on this
I lived in Brussels, so I know Ireland was seen very positively there, irrespective of what one thinks of the DPC. The DPC has nothing to do with the omnibus, and I want to set the record straight on this. As to what Ireland can do regarding these changes, members will have seen that there is a certain amount of disagreement about how much they change, and how much is simplification or rewriting everything. What Ireland can do under its Presidency is look at these issues. The problem that we have seen so far, in the first months of the current Cyprus Presidency, is that all issues where there is minimal disagreement are not looked at. They are parked, and they are not adopted. Ireland could take a proper look at these issues, which are not new. It is true that the omnibus process does not involve the usual process for legislative proposals in terms of impact assessments, but these are not new issues. People in the room know the court cases, the case law and the guidance. They can look at these issues and try to find fixes, with the right objectives in mind.
Comment on this
This committee's previous report mattered. It still matters, and we are still citing it. That is the first thing the committee can do. The second thing is that there is an Irish Commissioner for justice. It is his job to make sure that member states apply the law. Third, I agree with my colleague that it is actually something useful to do. There are two decisions that have led to this. One is the IAB Europe decision at the European Court, where I was one of the parties, and the other is the more important SRB decision. Parsing them during the Presidency would be useful.
Comment on this
I have a final question. The Data Protection Commissioner is an important post. Without referencing any individuals, or the fact that the new Commissioner is in place for a five-year term, regarding the recruitment process that Dr. Ryan mentioned, what precisely does he feel needs to change in respect of that? Is he advocating a cooling-off period or other safeguards to protect the integrity of the office in the way this would be in place for officeholders of the Government?
Comment on this
Those are sensible questions. Asking the questions and considering them in detail is the first result. We must have a situation where the specification of the role must acknowledge what the role is. It cannot be that you are an assistant secretary in the Department of fisheries, and suddenly, with that same set of criteria, you are able to investigate and supervise the most complicated businesses in human history. Clearly, there is something different. It would be useful to take a look at other areas of complex regulation, perhaps in other jurisdictions, and break away from this generic approach where we just appoint managers.
I should say that I am aware of several eminent enforcers who applied and were not shortlisted. I cannot say who they are, but the fact that they were not shortlisted is astonishing. There is something wrong with the system. One element is who is on the panel. In this situation, we had four operative people on the panel, and there was a fifth person from the Public Appointments Service who just sat in.
Of the four, one was from the State and the other was the expert but they were a corporate lawyer representing big tech. There were two others we would not necessarily take issue with. The balance of the panel was wrong. We need careful scrutiny. We are now in the process of appointing an interim head of our new AI office and the way that has been specified is very similar. It asks whether they are a good soldier who can manage an organisation. That is not what we need. We need someone who can keep an eye on these things that are going to shape our lives.
Comment on this
I thank all our guests. Is it agreed we publish all the opening statements from today's hearing on the committee's website? Agreed. I thank all who have taken part and especially for their patience regarding the uncertainty over when we would start. I have to disappoint the members by suggesting we go into private session to deal with a couple of housekeeping items. Is that agreed? Agreed.