WEBVTT

00:00.000 --> 00:15.000
All right. Hello everyone. Thank you to the organization, first of all, for the chance to be with you here today.

00:15.000 --> 00:27.000
I will be discussing the digital omnibus and just proposing some of my thoughts on the possibility of this being an opportunity or a risk for open source,

00:27.000 --> 00:34.000
and spoiler is kind of a bit of both. Just to contextualize, I am not a lawyer. This is not legal analysis, but just my perspective.

00:34.000 --> 00:42.000
As a practitioner, I am the head of policy and compliance element, and also the DPO at the matrix.org foundation.

00:42.000 --> 00:51.000
So I have some experience of trying to implement EU policy in both the non-profit and the commercial perspectives of open source.

00:52.000 --> 01:02.000
So to give a brief introduction, if you are not familiar with the digital omnibus, it is a series of regulatory proposals that spans across various packages,

01:02.000 --> 01:10.000
I am sure you are all familiar with the GDPR, and it also covers the privacy directive and IS2 and the EU data act.

01:10.000 --> 01:21.000
There is a separate omnibus which focuses on AI and the AI act specifically, which I will not cover today, so this is focus on the first one.

01:21.000 --> 01:35.000
This was initially proposed in November 2025, but it is actually the second stage of the development of this proposal, following an initial call for evidence that happened in the spring and summer of last year.

01:35.000 --> 01:43.000
So right now we are in this phase of open consultation that has introduced the regulatory proposal.

01:43.000 --> 01:58.000
So that explicit aim here is to harmonize and simplify the requirements of these various regulations, which hopefully will reduce our administrative vote and incentivize innovation.

01:58.000 --> 02:14.000
This is really the aim here. So my goal for today and for the time we have together is to discuss my perspective on these potential risks and opportunities, but also encourage you all to engage with the consultation process for this proposal.

02:14.000 --> 02:23.000
As it touches on many of the core pieces of legislation that we all have to work with, so I think it is quite key that as an open source community we contribute.

02:23.000 --> 02:34.000
And it is still open until 11th of March and like the open source digital ecosystems, which ends on Tuesday, so you have some time if you haven't started looking at it yet.

02:34.000 --> 02:41.000
So what are the key changes that we are expecting to see from this proposal?

02:41.000 --> 02:55.000
First one is a simplified approach to cookies. I think we have been waiting for a long time for an update on the privacy directive, which has promised the simplification for a while, and it helps to address consent fatigue.

02:55.000 --> 03:07.000
There's a big focus on improving access to data and including access to for AI, but again I won't focus as much on that side of things.

03:07.000 --> 03:14.000
There's the hope for an alignment and standardization of key definitions and concepts across regulations.

03:14.000 --> 03:26.000
And if you've ever had to look at all of these separately, it can be tricky to have a glossary in your mind of all of these definitions and what they, they mean and how they can apply to you.

03:26.000 --> 03:42.000
There's also the proposal for an integrated reporting system, which will cover incident reporting and personal reach reporting, which should hopefully harmonize all of the requirements from the GDPR to the future CRA requirements.

03:42.000 --> 03:48.000
There's also a proposal to relax some of the timeline requirements around the GDPR.

03:48.000 --> 04:08.000
And there's some other changes, which are really, really associated with the GDPR, such as reducing some of the transparency requirements on controllers, expanding legitimate interests to include scientific research and again AI development, and to standardize the DPA approach.

04:08.000 --> 04:21.000
This is not an extensive list, the proposal is nearly 200 pages long, so this is some of the key points from my perspective that could impact our community.

04:21.000 --> 04:32.000
So now going to opportunities, as someone that says it depends for a living, having less legal complicit complexity will be really, really useful.

04:32.000 --> 04:41.000
Having more clarity would definitely give us more bandwidth and give us more capacity to innovate, to be creative on how we approach these things.

04:41.000 --> 04:52.000
There's definitely a big opportunity here for us to have clarity and for us to be able to focus on what's really important as opposed to spending our time figuring out how all of these things work together.

04:52.000 --> 05:01.000
And of course, as an open source community and open source projects in general, we could really benefit from these streamlined requirements.

05:01.000 --> 05:08.000
This source thing is not something that we have in abundance, and it can be really tricky to make sense of all of this at times.

05:08.000 --> 05:21.000
So if we can reduce our admin load, I'm trying to make sense of all of these things, hopefully we will reduce costs and be able to focus our efforts in our funding into development and creativity and innovation.

05:21.000 --> 05:34.000
Then we have the single point of entry for incidents and reporting of breaches, which from my perspective could be the most impactful operational change from this proposal.

05:34.000 --> 05:46.000
I believe that in the latest data stock of this, there are about 350 breaches reported every single week to the various supervisory authorities.

05:46.000 --> 05:51.000
The supervisory authorities have to also grapple with all of these different requirements in timelines.

05:51.000 --> 06:06.000
So if we do have a single point of entry that we can focus on, report on, we can spend our time actually trying to prevent incidents, getting to the bottom line and the root cause of these incidents and make them stop.

06:06.000 --> 06:16.000
Essentially, or prevent them as much as possible instead of having to navigate different reporting requirements, different timelines, and then contractual requirements on top of that.

06:16.000 --> 06:25.000
Another opportunity that not managed to fit in here is this approach to standard DPA, data protection, impact assessments.

06:25.000 --> 06:39.000
There's many times this idea that we have to reinvent the wheel and be working in isolation in these cases, but actually a lot of us are facing the same problems and we're facing the same issues, especially when we're trying to innovate.

06:39.000 --> 06:44.000
So a lot of the risks that we're considering and a lot of the things that we are assessing are the same.

06:44.000 --> 06:55.000
That we can publish DPAs and that supervisory authorities will have standard approaches and standard risks to DPAs would be a very welcome opportunity.

06:55.000 --> 07:08.000
But now we move on to risks, which really, from my perspective, is one big risk and it is touching the key definition of personal data in the GDPR.

07:08.000 --> 07:19.000
So the current definition of personal data in very, very basic terms is personal data is something that could be used to identify an individual directly or indirectly.

07:19.000 --> 07:31.000
The current proposal adds about two paragraphs to this definition, uses the word entity about seven times and it can introduce a lot of nuance.

07:31.000 --> 07:40.000
And again, nuance is not always the best thing when we're trying to be transparent and when we're trying to make sure that people's rights are protected.

07:40.000 --> 07:55.000
So from my perspective, when we start touching the key definition and when we start introducing nuance, we will have more complexity, we will have more confusion, not clarity and simplification.

07:55.000 --> 08:00.000
There is really the risk of diluting some of our very hard earned protections.

08:00.000 --> 08:04.000
And also we've been talking this whole week about digital sovereignty.

08:04.000 --> 08:13.000
And one of the biggest strengths and advantages we've had in Europe is our strong protection and our really core focus on personal data protections.

08:13.000 --> 08:27.000
So if we need open sources to deliver a digital sovereignty and if we need to focus on our European stance on these things, we really should not be touching a core principle of a lot of these regulations.

08:28.000 --> 08:38.000
Again, when we start adding nuance and we start adding the perspective that as a controller, I can decide that something is personal data, it won't be for someone else.

08:38.000 --> 08:44.000
It will just have a lot of complexity and need for discussion that not all of us will have the time for.

08:44.000 --> 08:49.000
And it just opens the possibility for abuses of this definition.

08:49.000 --> 09:02.000
So that would be a main part of my response to this consultation would be really encouraging the lawmakers to reconsider touching the definitions of the GDPR.

09:02.000 --> 09:09.000
And instead bringing up the other definitions in the other legislations to this core principle.

09:09.000 --> 09:14.000
And really when we talk about open source, we talk about trust and this trust is earned through transparency.

09:14.000 --> 09:24.000
And if we start bringing in complexity and nuance, I believe that it will make people a lot less willing to share this perspective and to be transparent.

09:24.000 --> 09:30.000
So that is really a risk that I'm really not willing to take.

09:30.000 --> 09:32.000
Also, this, thank you.

09:33.000 --> 09:48.000
This seems to be really really focused on a very specific case, but actually when you look through the past evidence for this digital omnibus, it is actually not been something that has been asked for by most of the participants.

09:48.000 --> 09:55.000
What we really need is to simplify the work that when it comes to paperwork, not to discuss what is was personal data or not.

09:55.000 --> 10:00.000
I think we're all in agreement on what needs to be protected at this point.

10:00.000 --> 10:05.000
So to conclude, yes, everything is getting more complicated.

10:05.000 --> 10:10.000
We have more and more pieces of regulations coming out every single day.

10:10.000 --> 10:13.000
And our digital ecosystems are getting more and more complex.

10:13.000 --> 10:20.000
We've been talking a lot about the need to address this, the need to bring sovereignty back.

10:20.000 --> 10:27.000
But we also need to consider the strain that this puts and the big pressure that it puts on open source projects.

10:27.000 --> 10:31.000
There's a way to simplify our lives and making sure that we can focus on the real problems.

10:31.000 --> 10:33.000
That is very welcome.

10:33.000 --> 10:42.000
But this simplification should not come at the cost of personal data and those protections that took a long time to be embedded into law.

10:42.000 --> 10:51.000
So I would really encourage you to make the effort to take the time to engage with this process, to highlight any of the risks that I might have not considered.

10:51.000 --> 11:01.000
And to just support each other and discuss with your colleagues what other risks the law make is might not considered when what we need to do to prevent this from happening.

11:01.000 --> 11:04.000
Thank you very much for your time.

11:04.000 --> 11:23.000
We've got some time for a few questions.

11:23.000 --> 11:29.000
There will be a big lobby coming up on the GDPR simplification.

11:30.000 --> 11:36.000
So how can we support that lobby? How can we support every and others financially or with hands on?

11:36.000 --> 11:41.000
It's very difficult to find anything online. I've tried to search very little.

11:41.000 --> 11:49.000
So maybe you can give them more a few guidelines or directions where to find out to help every and others in this lobby.

11:49.000 --> 11:57.000
I hope so. How to participate now in terms of the GDPR simplification.

11:57.000 --> 12:05.000
So if you search digital fitness check consultation that is the current consultation period that is open and how you can provide.

12:05.000 --> 12:11.000
But yes, I do think that as a community we do need to communicate better.

12:11.000 --> 12:17.000
And we do all have some of the open source calls that we tend to have every week.

12:17.000 --> 12:20.000
But there is so much going on that this has not been at the top of the agenda.

12:20.000 --> 12:26.000
So that was really the goal for my talk today was to bring it up and so that we can find a solution.

12:26.000 --> 12:36.000
So I don't think I don't have the answer today, but I would be very happy to work with others and to start that group that we can focus on this.

12:36.000 --> 12:48.000
Take one more question and then we're also going to have a five minute transition moment.

12:48.000 --> 12:58.000
Thank you. Are you used to about simplification a lot when it's vibing this and this is how this is used about simplification a lot in this vibing this is how the European Commission describes it, right?

12:58.000 --> 13:08.000
But the other institutions like European Parliament discusses a Monday, even in council member set representatives are pointing out how this is much more than simplification but deregulation.

13:08.000 --> 13:18.000
Then you think would be important for the user right terminology and that because as you have worked out it's pretty much making things more complicated for some people as well, right?

13:18.000 --> 13:21.000
Sorry, I could not.

13:21.000 --> 13:27.000
There's a lot of noise vocabulary that words simplification, you know, is that does that not complicate?

13:27.000 --> 13:36.000
Yes, so there is the words simplification that use harmonization but it is in fact complicating in somewhere areas, but that is of course my interpretation.

13:36.000 --> 13:47.000
I have to use the terminology that it is in the current proposals, but yes, my perspective is that the new ones will add further complication instead of simplification,

13:47.000 --> 13:53.000
but that is something that we have to engage in the process in the way that it is put out to us.

13:53.000 --> 13:57.000
Thank you so much.

