Privacy campaign group None of Your Business has criticized the European Union for altering data protection laws to accommodate artificial intelligence. Led by Austrian lawyer Max Schrems, the organization claims the proposal to modify legislation in the context of AI abandons core data protection principles.
In September, the Commission announced an ambitious program to strengthen EU competitiveness and radically lighten the regulatory load for people, businesses, and administrations. It proposed immediate adjustments to digital legislation. Earlier, the EU proposed changes to the General Data Protection Regulation.
A briefing note stated that where the processing of personal data is necessary for the interests of the controller in the context of developing and operating an AI system or model, such processing may be pursued for legitimate interests. Noyb argues that amendments to Article 88c, or Article 88bis in a leaked EU Council compromise draft, would allow Big Tech to use decades of collected personal data with virtually no restrictions.
Max Schrems stated that under these proposals, the profits of AI companies would trump Europeans fundamental right to privacy. He called it a digital expropriation of Europeans. The campaign group noted that people who were never customers, whose data entered systems decades ago through chats or social media, could find their information handed to an AI company without consent.
Companies are automatically assumed to have an overriding legitimate interest when training or using AI products. Schrems added that a likely majority of EU member states prioritize the profit interests of Elon Musk, Marc Zuckerberg, Google, or OpenAI over data protection. He stated that everything entered into digital systems or obtained by AI corporations becomes fair game.
Noyb stated the European Commission abandoned its data protection priorities to serve the tech industry lobby. The European Parliament holds a mixed view on the matter. However, the Court of Justice could examine whether the proposed changes align with EU fundamental rights.
Noyb noted that the Court of Justice previously struck down EU law in cases involving smaller infringements, such as data retention or data transfers to the United States. Noyb previously dismantled two transatlantic data transfer pacts through the Court of Justice of the European Union, including the Safe Harbor Agreement in 2015 via Schrems I and the EU-US Privacy Shield in 2020 via Schrems II.
Schrems stated that the legal route might remain the only option to prevent the dilution of data protection law for the AI industry. He warned that if legislators lose their sense of proportion, people must turn to courts, and extreme laws create legal uncertainty instead of simplification.



