Small firms got the lighter rule they wanted, but the margin left no room for triumphalism. The floor’s highest-respected Yes voice framed the issue as sovereignty by way of a joke about “some Brussels Eurocrat” whose exposed details had left the country suffering.
The substantive Yes case was that compliance has become an innovation tax: one developer said, “Half a dozen promising app ideas are dead in the water”, while others described GDPR as overcomplex, costly and hostile to smaller firms and AI. The appeal ran from simpler domestic rules to a broader complaint that “The UK should have its own, simpler data protection rules”, with even the lighter voices conceding that firms serving Europe would still face the EU regime.
No voters answered with two anxieties the Yes side never quite resolved. One warned of “two completely separate regulatory nightmares instead of one”, while another argued that, with AI scraping the internet, “we need more control of our data, not less”; alongside them came the quieter case that the current system is established, supported by guidance, and not obviously broken.
That left the debate talking past itself: Yes treated privacy law chiefly as a burden on enterprise, sovereignty and new technology, while No treated it as infrastructure for trust, trade and personal confidentiality. The question also exposed the practical limit of regulatory divergence — adequacy, parity and European market access mattered even to a Yes voter who urged, “Do not pretend the export lane comes free.”
The verdict was permission to lighten the domestic rulebook, not a blank cheque to abandon the protections or the trading relationships around it.
20 Opinions
What we have now does not appear to be broken, therefore does not need fixing.
With the rise of AI and what it drives privacy is important. In terms of trade it is important that we keep parity with other nations (like it or not the EU is important for trade. Sometimes having different laws make them more difficult to train, understand and enforce in a trading nation
Trade is vital to this country especially outside the EU, so unless we return to the EU it must be kept as it is until we find another way to also maintain trade and keep privacy protections.
Reform the current system. Protection of people's information data & confidentiality in a digital age is paramount
What has GDPR ever done for us? Certainly no viaducts
If anything in an age where AI is scraping every corner of the internet we need more control of our data, not less
I returned to software development a year ago. Before that, I was a freelancer in internal systems, with a department handling GDPR. Half a dozen promising app ideas are dead in the water because AI can do them with a single prompt and the right connectors. Another half-dozen, because the obscene risks, eye-watering fines and nit-picking compliance associated with GDPR can only be tolerated by massive corporate concerns with deep pockets.
It’s an EU top down imposition & hinders rather than helps businesses. Like many things some say “better the devil” but why is it always like this. Bad law, badly thought out & implemented & then those who are to blame’s just want to forget & move on. I think all laws should be forensically reviewed - not by Civil Servants - after say 3 years of operation and if found wanting are repealed. Maybe more effort can then be employed at outset. Improve this & improve our economy.
No. GDPR is well established and companies already know what they’re doing in relation to it. Other OECD nations have broadly similar regulation, even the US, and the simplification isn’t really that big a prize. In this AI age data protection is actually even more important.
The UK should have its own, simpler data protection rules that reduce costs for British businesses. Other countries have their own systems and still trade successfully with the EU.