< Back to all clusters
[TECHNOLOGY] · Germany, United States, China · 2 sources

EU data‑privacy rules face scrutiny as China’s new data‑transfer law tightens abroad moves

A decade after the GDPR entered into force, German privacy experts warn that the EU Commission is seeking to weaken the regulation under the pretext of simplification. Recent proposals would give large data processors more leeway, skip impact assessments, and extend U.S. security agencies' access to European police data in a pending travel‑agreement negotiation. New procedural rules for cross‑border investigations, adopted late last year, will only take effect in 2027.

China’s Personal Information Protection Law (PIPL), modeled on the GDPR, also tightens control over data leaving the country. The law obliges organisations that process Chinese citizens’ data abroad to undergo a security assessment and meet additional national‑security conditions before transferring information to third‑party jurisdictions. Both sets of rules highlight a growing clash between European privacy standards and Chinese sovereignty‑driven data controls.