How can Europe move from “consent chaos” to predictable enforcement and friction-light data use?
The problem is less the wording of the GDPR than its enforcement and cross-border procedures.
In June 2025, EU legislators reached a deal on the GDPR Procedural Regulation to speed up and harmonize cross-border cases, a critical step toward reducing forum shopping and uneven remedies.
In parallel, the Data Act has applied since 12 September 2025, opening access to connected-product and related-service data and supporting interoperability through Common European Data Spaces.
Can this create an “enforce-and-share” path that avoids rewriting the GDPR?