cross-posted from: https://lemmy.sdf.org/post/32709886

Big Tech have mastered the art of delay and deflection. Under the GDPR’s ‘one-stop-shop’ mechanism, cases are often handled by regulators in the country where a company is based, rather than where harm occurs. This means that when someone in France, Poland, or Spain suffers from unlawful data misuse by a company based in Ireland or Luxembourg, their complaint can get stuck in an enforcement black hole.

[…]

Right now, EU policymakers have a chance to fix this. The GDPR Procedural Regulation—currently in negotiations—could finally close these enforcement loopholes. It could ensure faster, more efficient investigations, remove barriers to redress, and empower DPAs to take meaningful action. The regulation is not just about bureaucratic processes; it is about making GDPR enforcement a reality, ensuring that cross-border cases are handled fairly and efficiently, rather than getting lost in the complexity of the one-stop-shop mechanism.

Yet, despite its significance, this file has not received the attention it deserves. Too often, procedural law is dismissed as ‘boring’ or ‘too technical’—just another set of legal rules that seem far removed from everyday life. But this perception is dangerously misguided. In reality, this regulation underpins the very foundation of human rights online. It determines whether people […] can seek justice when their data is misused, whether harmful algorithmic profiling can be stopped, and whether the EU’s much-celebrated digital rights framework has real teeth. Many of the harms EU institutions claim to be concerned about – from misinformation to AI-driven discrimination – are exacerbated by the enforcement failures this regulation seeks to address.

Data protection is not just about privacy—it’s about power, and about many other fundamental rights. If we allow enforcement failures to persist, we allow gigantic corporations and other bad actors to control, distort, and weaponise our identities and deepen vulnerabilities. The EU must act now to ensure that GDPR enforcement becomes a reality, not just a promise.

[…]