The EU General Data Protection Regulation (GDPR) and Its Future: Striking a Balance Between Innovation and Privacy
The GDPR is known as one of the strictest data protection laws in the world. It is an ambitious project that strengthens fundamental rights and gives individuals greater control over their personal data. At the same time, it has introduced a new culture of enforcement. Supervisory authorities have adopted a strict approach to assessing the lawfulness of personal data processing.
The landscape is now changing. The European Commission’s Digital Omnibus package aims to simplify and clarify the EU’s digital regulatory framework, including the GDPR. Reform is needed, as the current framework is widely regarded as overly burdensome and as an obstacle to innovation. This raises an important question. Are we moving from a fundamental-rights-based culture of caution to the opposite extreme, where competitiveness takes precedence over data protection? Or are we finally finding a balance in which innovation and privacy can coexist?
Strict interpretations have limited opportunities for innovation
The interpretation of the definition of personal data is central to determining whether the GDPR applies. In the Court of Justice of the European Union’s judgment in Breyer v Federal Republic of Germany (C-582/14), the Court considered whether dynamic IP addresses stored in a website’s log files constituted personal data. The service provider could not identify the user without additional information held by the telecommunications operator. The Court found that information may constitute personal data even where the additional information required for identification is held by a third party.
The key consideration was whether the controller had means reasonably likely to be used to obtain the additional information. Although the judgment itself leaves room for a case-by-case assessment of whether the controller has reasonable and lawful means of identification, the approach adopted by authorities and businesses has become increasingly cautious. Identification does not need to be likely. It is often considered sufficient that identification cannot be entirely ruled out. As a result, all GDPR obligations may become applicable unnecessarily broadly. This shifts attention away from situations involving a genuine risk to privacy.
This cautious approach has led many organisations to abandon potentially beneficial data projects. They have been reluctant, for example, to interpret the available legal bases for processing flexibly. According to the Research Institute of the Finnish Economy, Etla, strict data protection regulation has significantly reduced research and development investment by pharmaceutical and biotechnology companies. When businesses consider whether patient data, customer data or Internet of Things data can be used to develop new services and products, caution driven by the fear of sanctions often prevails. This is not solely the result of the wording of data protection legislation. It is largely a consequence of how the legislation has been interpreted by the authorities.
European policymakers have become increasingly aware that, while the EU has built the world’s strongest data protection regime, it has fallen behind the United States and China in data-driven business and artificial intelligence development. Mario Draghi’s report on European competitiveness has highlighted this issue. The Commission has therefore faced growing pressure to soften digital regulation.
Can the Omnibus bring us happiness?
The Digital Omnibus package published by the Commission on 19 November 2025 aims to simplify regulation, reduce costs and improve the EU’s competitiveness. In practice, this can be seen, for example, in proposed changes to cookie practices. The objective is to reduce the constant need to click consent banners. Users could set broader consent preferences at browser level or provide consent that remains valid for a longer period.
Another visible proposal is to postpone the application of the strictest obligations under the AI Act. This would give companies more time to bring high-risk AI systems into compliance.
Targeted amendments have also been proposed to the core of the GDPR, including changes that would narrow the definition of personal data. This would create more room for the use of personal data in training AI models, including on the basis of legitimate interests. The desire to clarify the rules and remove regulatory overlap is understandable. The current digital regulatory framework, comprising the GDPR, the Data Act, the Digital Services Act, the Digital Markets Act, the NIS2 Directive and the AI Act, has grown into a complex mosaic. Managing it is difficult even for large organisations, let alone smaller businesses.
The proposals have nevertheless attracted vocal criticism. Civil society organisations and data protection experts have described the proposed amendments as a strategy of “a thousand small cuts”. The reforms may not dismantle the GDPR as a whole, but they could weaken its effectiveness in critical areas, such as the legal bases for processing personal data used to train AI models. The key question is the extent to which the problem lies in the wording of the GDPR itself and the extent to which it lies in the culture surrounding its application.
Even before the Digital Omnibus initiative, the European Data Protection Board, or EDPB, had recognised the need for practical simplification. In the so-called Helsinki Statement, the EDPB stated that it aims to make it easier for small and medium-sized enterprises in particular to comply with the GDPR in practice. The objective is to increase dialogue with stakeholders and improve the consistency of regulation without weakening individuals’ fundamental rights. This indicates that the supervisory authorities also recognise that the application of the GDPR has become unnecessarily burdensome. Companies’ compliance work should be facilitated through measures such as practical tools and templates.
A more pragmatic approach to the definition of personal data had also begun to emerge before the Digital Omnibus proposal. In EDPS v SRB (C-413/23 P), it was confirmed that pseudonymised data generally remains personal data from the perspective of an organisation that can obtain additional information and identify the data subject using means reasonably likely to be used, in accordance with the criteria established in Breyer.
At the same time, the judgment opened the possibility that the same data may constitute personal data for one organisation but be anonymous for another organisation that has no realistic means of re-identifying the data subject. The Omnibus proposal consolidates this approach and expressly rejects the position taken by the European Data Protection Supervisor, or EDPS, in the SRB case referred to above. Pseudonymised data is not always personal data for every organisation.
Conclusion
It is clear that data protection regulation has reached a crossroads. Most of the current problems do not arise because the GDPR’s fundamental principles are inherently too strict. They arise because those principles are translated into absolute prohibitions in day-to-day practice instead of being applied through a risk-based approach. From this perspective, amendments to the GDPR’s fundamental concepts may not have been necessary. A stronger culture of interpretation based on risk would have been the more appropriate response.
It is nevertheless difficult to oppose objectives such as removing overlapping regulation, making cookie practices more sensible and reducing the administrative burden on small and medium-sized enterprises. The coming years will determine whether the EU can modernise its data protection framework in a way that preserves its normative strength while enabling innovation.
The central question is whether reform can be achieved without weakening privacy protection or deepening existing competitive imbalances. Such an imbalance could arise if negotiating power is shifted away from individuals and European small and medium-sized businesses towards global technology companies.
Considering the criticism directed at the Digital Omnibus proposal, the political process required to implement the reforms is likely to be challenging. At Folks, we will continue to monitor the progress of the legislative initiative closely.

Anna Paimela
Partner
+358 40 1648626
To receive our articles directly by email, subscribe to the Folks newsletter here.
- Anna Paimela
- Oct 3, 2025
The work of a lawyer has always been shaped by change. Laws are reformed, society evolves, and new phenomena challenge established ways of thinking. Rarely, however, has change felt as rapid and fundamental as it does today. Artificial intelligence and digital solutions have become part of lawyers’ everyday work and are changing the foundations on which that work is carried out. They are no longer distant visions, but practical tools reshaping the way the entire legal profession operates.
Artificial intelligence can process vast amounts of information, identify relevant provisions in documents, conduct case law searches in seconds, and detect risks that would otherwise require time-consuming legal analysis. This change will inevitably affect the skills expected of lawyers. Increasingly, lawyers will need curiosity, the courage to experiment, and the ability to ask what technology means for the client and for the industry as a whole. A lawyer who remains interested in the surrounding world and its development is best placed to serve clients effectively. Adaptability is therefore one of the most important skills for lawyers today.
Although artificial intelligence can make parts of legal work faster and more accurate, lawyers remain responsible for critical thinking and for having the courage to say when a machine-generated answer is not enough. As routine tasks are increasingly handled with the help of technology, the lawyer’s true strengths become clearer: interaction, judgement, an understanding of context, and the ability to make choices. As technical work becomes faster, clients can also see more clearly why they want to rely on a particular lawyer, someone who listens, asks questions, and understands their situation as a whole.
The legal services business is built on trust, and personal interaction is at the heart of building that trust. Clients do not always come to the table with a clearly defined legal question. Sometimes they come with uncertainty, concern, or pressure. In those situations, the lawyer’s role extends beyond analysing facts. It involves listening, asking the right questions, and reflecting different options back to the client. A good lawyer can identify and articulate the wider context behind the client’s situation and help the client move forward. This kind of sparring and support is often just as important as the final legal solution.
When clients feel that they have been heard and that their situation has been understood from their own perspective, they gain confidence even when the answers are not straightforward. That experience is not created by data generated by an algorithm. It is created by the presence of another person. Adaptability is closely connected to being present. Lawyers must understand that law does not operate in a vacuum. It is always linked to the client’s day-to-day business, strategic objectives, and decision-making. A lawyer must therefore be able to see not only what the law says, but also how it affects the client’s business and what risks and opportunities it creates. This often requires sensitivity to the client’s needs, concerns, and objectives, as well as the ability to tailor legal advice accordingly. That sensitivity cannot exist without genuine human interaction.
Because personal encounters are at the heart of our work and the best way to strengthen trust, we celebrated Folks’ 10th anniversary in September. The evening gave rise to genuine conversations and moments in which clients and colleagues shared experiences and perspectives, paused to listen, and felt heard themselves. The warm messages we received after the celebration reinforced our sense that we had succeeded in celebrating precisely what makes our work meaningful: connection and human encounters. We hope the photographs convey that feeling to you as well.
To receive our articles directly by email, subscribe to the Folks newsletter here.
The Regulation on the transparency and targeting of political advertising will apply for the most part from 10 October 2025. Its purpose is to ensure that political advertising is carried out in a way that enables citizens to understand who is seeking to influence their political views, by what means and with what resources. The European Media Freedom Act, in turn, seeks to increase transparency in advertising by public authorities and other public-sector entities. The European Media Freedom Act became applicable on 8 August 2025.
In this article, we examine the principal obligations under the new legislation, particularly from the perspective of advertising publishers, such as media companies, and advertising service providers, such as advertising agencies.
Main obligations for publishers and advertising service providers
The Regulation on the transparency and targeting of political advertising defines political advertising broadly. It covers not only advertising paid for by political parties and candidates, but also other advertising intended to influence the outcome of an election or referendum, voting behaviour, or a legislative or regulatory process. The media sector has sought to preserve the current position to a large extent by ensuring that editorial content and advertising concerning social and political issues are clearly excluded from the scope of the Regulation and from regulatory supervision.
Two categories of operators have a particularly important role in ensuring transparency in political advertising: publishers of political advertising and political advertising service providers. A publisher of political advertising is an operator that provides the space, platform or channel through which a political advertisement is made available to the public, such as a media company. A political advertising service provider, in turn, is an operator that designs, produces or otherwise facilitates political advertising, such as an advertising agency or a digital advertising technology company.
The obligations of service providers relate particularly to the design, financing and targeting of political advertising. The Regulation requires service providers to document all material information concerning the organisation of a campaign. This includes sources of funding, the objectives of the advertising, the definition of target groups and the technical solutions used for targeting. The service provider must provide this information to the publisher so that the advertisement can be approved in accordance with the Regulation.
Publishers have responsibilities at several levels. They must ensure that every political advertisement includes the transparency label required by the Regulation. The advertisement must clearly and immediately identify its sponsor, the nature and duration of the campaign, and any targeting techniques used. It must also clearly indicate where a more detailed transparency notice is available. The advertisement may direct users to the transparency notice through a link or QR code, for example.
To make publication of the transparency label and transparency notice possible, both publishers and political advertising service providers must use contractual arrangements to ensure that advertisers provide them with accurate information concerning matters such as the sponsors of the political advertisement and their background, as well as the election, referendum, legislative process or regulatory process to which the advertisement relates. In addition, publishers and service providers must maintain records of matters including the amounts received from each party in connection with political advertising.
Publishers and service providers must retain this information for at least seven years after the end of the campaign so that the authorities can subsequently review and assess compliance with the Regulation. Publishers must also report all political advertisements published online, together with the information required in the transparency notice, to the European repository. In addition, they must include in their management reports campaign-specific information on the amounts or other benefits received in full or partial consideration for the services provided, including the use of targeting and advertisement-delivery techniques.
Targeting of political advertising
A significant part of the new Regulation concerns the targeting of advertising. The Regulation prohibits the targeting of political advertising on the basis of sensitive personal data, meaning special categories of personal data under the General Data Protection Regulation, such as political opinions, religious beliefs or ethnic origin. Where other categories of personal data, such as age, gender or geographical location, are used for targeting, the targeting is permitted only if the personal data has been collected directly from the data subject and the data subject has given explicit consent to the processing of their personal data specifically for political advertising.
The targeting of political advertising requires controllers to maintain more extensive documentation than under the GDPR alone. Among other things, the controller must carry out an annual risk assessment and adopt, implement and make publicly available internal policies describing how advertising-targeting techniques are used. The controller must also keep records of the use of those techniques and the mechanisms and parameters involved. Additional information must be provided in connection with the transparency label for each targeted advertisement to enable individuals to understand the logic and principal parameters of the techniques used. The new obligations will require digital advertising operators to develop new processes and technical solutions for managing the logic of targeting and ensuring its traceability.
Advertising by public authorities and public-sector entities
Under the European Media Freedom Act, public authorities and public-sector entities must make information on their annual public expenditure on state advertising publicly available in an electronic and user-friendly format. The definition of a public authority or public-sector entity can be considered to include central government administrative authorities, government agencies and institutions, state enterprises and off-budget state funds. It also covers state-owned companies in which the government exercises decisive control. Based on the wording of the legislation, the definition would also include cities and municipalities, including joint municipal authorities, wellbeing services counties and joint county authorities, as well as their subsidiaries and public enterprises. It would further include entities owned by municipalities or wellbeing services counties in which one or more municipalities or wellbeing services counties exercise decisive control.
These categories encompass dozens of different operators. Media companies therefore face the challenge of identifying all entities falling within the scope of the legislation so that they can inform users of their online services of the total annual amounts of public funds received for state advertising and the total annual advertising revenue received from authorities or public-sector entities in third countries. In addition to publishing this information on their own websites, media companies must report it to Traficom’s media service ownership database.
In Finland, information on state advertising is intended to be collected in the procurement data repository maintained by the State Treasury by using purchase invoice data from public authorities and public-sector entities. Information on state advertising, such as the amount of advertising purchased by each public authority or other public-sector entity from each service provider, would therefore be openly and publicly available through the repository. Once the repository is in place, individual authorities and other public-sector entities would not need to publish information on their advertising and public-notice expenditure themselves. At the same time, media companies would be able to verify more easily whether an advertiser qualifies as a public authority or public-sector entity under the European Media Freedom Act.
Conclusion
Although the objectives of strengthening democracy and increasing transparency in advertising are highly commendable, the media sector, among others, has taken a critical view of the new legislation. One concern is that publishing election advertising or state advertising may no longer be commercially viable for media companies because of the extensive disclosure obligations, heavy administrative burden and risk of sanctions. Should this happen, the legislation could have unforeseen consequences for the visibility of elections, electoral participation and the functioning of democracy, as well as for the operating conditions of advertising-funded media.
Because of the new obligations, global digital platforms such as Google and Meta have already announced that they will not participate in political advertising at all. Xandr and Microsoft had withdrawn from the market earlier. It remains to be seen whether election advertising will move from these platforms to domestic media, or whether voters will increasingly receive election-related information, misinformation, disinformation and advertising through platforms such as TikTok or X, even though those platforms have formally prohibited election advertising. According to a study by Faktabaari and CheckFirst, TikTok recommended misogynistic content and reinforced stereotypes in Finland in the run-up to the 2024 European Parliament elections. X has also been alleged to have used data concerning political opinions or religious beliefs for the microtargeting of political advertising. These platforms have therefore been alleged to exhibit precisely the kinds of problems that the new Regulation is intended to address. The transfer of political display advertising to domestic media is complicated by the fact that many Finnish publishers use advertising management systems provided by Microsoft or Google. In addition, current cookie consent mechanisms based on IAB Europe’s Transparency and Consent Framework, or TCF, do not support the collection of the explicit consent required under the Regulation. What is clear is that the decisions made by global digital platforms, and regulation primarily intended to address problems arising on those platforms, will also have significant consequences for domestic media.
At Folks, we are happy to assist not only in navigating the complexities of the new legislation, but also in identifying the opportunities it may create.

Anna Paimela
Partner
+358 40 1648626
To receive our articles directly by email, subscribe to the Folks newsletter here.


























