The EU announces new rules to help privacy regulators work on cross-border cases faster and give companies more rights, after criticism of slow investigations
Foo Yun Chee / Reuters :
Context & Ripple Effects
The EU's privacy enforcement machinery has been visibly creaking: a regulator clash over how much to fine Twitter stalled related probes into Facebook and Google, and the Commission only began requiring six-times-a-year GDPR progress reports from Ireland and other lead regulators after human rights group ICCL forced the change (ICCL-triggered reporting changes). Today's announcement answers that criticism directly — procedural fixes to move cross-border cases faster, paired with new rights for the companies under investigation.
The timing matters because this lands a week after EU countries and lawmakers agreed the Data Act, extending Brussels' data-governance regime beyond GDPR. Enforcement capacity, not rule-writing, is becoming the binding constraint on the EU's digital agenda.
First-order effects
- Companies with long-running cross-border GDPR cases — Facebook and Google among those whose investigations were delayed by the Twitter fine dispute — face shorter timelines, while all investigated firms gain formal procedural rights they previously lacked.
- Lead regulators like Ireland's, already under six-monthly reporting obligations, now have a mandated framework for handing cases across borders instead of letting them sit.
Second-order effects
- Faster GDPR resolution raises the cost of the fragmentation strategy some national regulators used to stall fines, pushing enforcement toward whichever authority can actually close a case — and forcing laggard regulators to staff up or lose cases.
- The same enforcement-capacity logic is surfacing elsewhere in Brussels: officials have floated a new directorate of top antitrust figures amid doubts the competition watchdog could enforce the DMA, suggesting parallel builds across regimes rather than one shared body.
Third-order effects
- If the pattern holds, the EU is consolidating from a patchwork of national privacy authorities into a de facto cross-border enforcement apparatus spanning GDPR, the Data Act, and the DMA — shifting the real bottleneck from drafting rules to operating them.
- Granting companies procedural rights inside investigations cuts both ways structurally: it legitimizes the process against criticism, but also gives Big Tech legal levers to contest findings, making case outcomes more contested even as they arrive faster.
The trend: EU digital regulation is pivoting from writing rules (GDPR, Data Act, DMA) to industrializing their enforcement, with procedural reform of cross-border privacy investigations as the latest step.