If it ain't broke, don't fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

Publication date

2026-04

Authors

Kloza, Dariusz
Drechsler, Laura
Fernandes, Elora
Mustert, LisetteORCID 0000-0002-8713-8664ISNI 000000052424623X
Birth, Arian
Rossi, Julien
Dewitte, Pierre
Greser, Jaroslaw
Malgieri, Gianclaudio
Beate Bentzen, Heidi

Editors

Advisors

Supervisors

Document Type

Article
Open Access logo

License

cc_by_nc_nd

Abstract

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently offered. To this end, ten scholars from across Europe were invited to choose a provision of the GDPR, write about what works well and what does not, and why, as well as to suggest a solution for a concrete amendment of the text. The resulting wish-list discussing ten provisions (i.e., those concerning conditions for consent, children’s consent, automated decision-making, data protection by design, data security, data protection impact assessment and prior consultation, derogations for data transfers, dispute resolution by the European Data Protection Board, representation of data subjects and processing for scientific purposes) is necessarily random and far from exhaustive. However, it lays the groundwork for a constructive debate, and we invite others to build on the list with their own proposals.

Keywords

Automated decision-making, Consent, Data protection by design, Data protection impact assessment, Data security, Data subjects – representation, Data transfers – derogations, European Data Protection Board - dispute resolution, GDPR, Processing for scientific purposes, General Business,Management and Accounting, Computer Networks and Communications, Law

Citation

Kloza, D, Drechsler, L, Fernandes, E, Mustert, L, Birth, A, Rossi, J, Dewitte, P, Greser, J, Malgieri, G & Beate Bentzen, H 2026, 'If it ain't broke, don't fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation', Computer Law and Security Review, vol. 60, 106251. https://doi.org/10.1016/j.clsr.2025.106251