I am fortunate to deliver this column from Rome, a historical city of unparalleled beauty. The IAPP Italian chapters in Milan and Rome gathered for a full-day KnowledgeNet, with an agenda focused on the EU General Data Protection Regulation 10 years in.
Conversations throughout the day prompted reflection on a broader question: how should we assess regulatory convergence in Europe? If convergence remains a work in progress, could Europe’s predictability and coherence be two contextual elements that, in comparison to other jurisdictions, compensate for the current alignment gap?
A defining characteristic of EU policymaking is its predictability. The seeds of legislative initiatives are usually planted years before they are first talked about publicly. Commissioners’ mission letters usually provide a reliable view of what is coming in the next few years. It doesn’t guarantee the outcome, but it certainly draws a clear direction of travel.
The EU has also been remarkably consistent in defining its digital policy objectives. The focus will be on a human-centric approach to the use of technology, harmonization of rules or digital sovereignty and the underlying ethos to policy proposals in the digital space.
The EU single market is another element to build both predictability and coherence. At least in theory, rules are fairly harmonized across the continent and make it easier for organizations to operate across borders and navigate compliance obligations. The picture is not perfect, but the foundations for consistency are there.
Brussels is increasingly concentrating on implementation, clarification and simplification. The various Digital Omnibus initiatives are emblematic of this trend. Their stated objective is straightforward: reduce unnecessary administrative burdens, streamline overlapping requirements and lower the cost of compliance. The simplification ambitions may be a slight course correction but do not deviate significantly from the approach that has formed the bigger policy picture in the past two decades.
Similarly, privacy regulators are investing significant effort in guidance and templates designed to address the complexity of interplay between laws and to leverage compliance investment across obligations. There is a genuine effort underway to find coherence.
Yet coherence, consistency and convergence are not interchangeable concepts. Predictability suggests a degree of clarity. Coherence suggests that different pieces fit together.
Convergence, however, requires that different stakeholders and systems seek to actively move closer together. This distinction matters.
Within the EU, member states continue to balance collective European ambitions with domestic political and economic priorities. National interests, political priorities, industrial or economic agendas can create friction with broader EU objectives.
Beyond Europe’s borders, building global consensus on digital norms has become more difficult in a fragmented geopolitical environment where digital sovereignty considerations often encourage individualization.
For practitioners, predictability, coherence and convergence should translate into an operational reality. If full alignment remains a pipe dream, predictability and coherence might help to benchmark the pertinence of compliance and governance strategies, and to arbitrate them in light of business imperatives.