Last week the Privacy Supervisors of the G7 had their meetings in Paris. We just checked the communique to see what they considered relevant topics and issues of the time: AI-generated abuse, agentic AI, smart glasses, children’s privacy, enforcement cooperation and cross-border data flows.
The good news: they identify the right topics.
The bad news: with these privacy supervisors at the helm, the world may be sleepwalking into a dystopian surveillance nightmare. The document shows 95% awareness, coordination and policy vocabulary. But it does not show urgency. And it hardly shows a will to act (5%).
That is what concerns us.
Our perspective comes from financial supervision. After the financial crisis, the IMF captured one brutal truth: supervisors may have information, mandates, frameworks and authority, but none of that matters if they lack the willingness to intervene. Effective supervision requires more than ability. It requires the will to act.
So we rewrote the Paris communique into the version that should have been issued by supervisors who understand urgency, systemic risk and have the will to act before harm becomes infrastructure.
THE HRIF.EU PARIS G7 COMMUNIQUE – WRITTEN WITH A SENSE OF URGENCY AND WILL TO ACT-MINDSET
We, the G7 Data Protection and Privacy Authorities, recognize that current technological developments—particularly in artificial intelligence, biometric sensing, and pervasive data collection—create immediate and systemic risks to fundamental rights. These risks are no longer hypothetical. They require supervisory action that is intrusive, skeptical, and, where necessary, restrictive.
Children’s Protection and Age Assurance
We recognize the necessity of protecting children in digital environments and will require effective safeguards where risks are identified. However, we will not endorse or permit age assurance models that result in disproportionate identification, tracking, or profiling of users. Child protection cannot serve as a justification for expanding systemic surveillance of the general population. We will require that age assurance solutions are demonstrably privacy-preserving, data-minimizing, and purpose-limited, and we will intervene where implementations create new structural risks to anonymity, freedom of expression, or lawful access to information.
AI-Generated Harms and Deepfakes
The generation and dissemination of non-consensual intimate imagery, including involving children, constitutes a priority enforcement area. We will identify and act against developers and deployers of AI systems that enable such harms without effective safeguards. This includes the use of our corrective powers to prohibit processing, impose fines, and require design changes. We will not rely on ex post remedies alone.
Connected Devices and Smart Glasses
Devices capable of continuous or covert data capture present structural risks of unlawful surveillance. We will require data protection by design and by default, including visible indicators, limitations on data collection, and strict purpose limitation. Where such safeguards are absent, we will intervene to restrict or prohibit deployment. Market entry does not precede compliance.
Agentic AI Systems
Given the autonomy and opacity of agentic AI systems, we will subject these systems to heightened scrutiny. Providers must demonstrate effective human oversight, auditability, and accountability across the supply chain. Where these conditions cannot be met, deployment will be limited or suspended. Complexity does not reduce responsibility.
Enforcement Cooperation
We will move beyond information sharing toward coordinated enforcement. This includes joint investigations, allocation of lead authorities in cross-border cases, shared evidence frameworks, and aligned corrective measures. Where systemic risks are identified, we will act collectively and without delay. Documentation of past enforcement is not a substitute for present intervention.
Cross-Border Data Transfers and Government Access
Cross-border data flows will be permitted only where equivalent protection of fundamental rights is ensured in practice. We will actively assess third-country legal frameworks governing government access to personal data, including necessity, proportionality, and effective redress. Where deficiencies are identified, we will impose restrictions or suspensions on transfers. We will not defer such action pending judicial review.
“Data Free Flow with Trust” requires enforceable guarantees. Trust is not presumed; it must be verified and, where necessary, enforced.
We recognize that effective supervision requires not only the capacity to act, but the willingness to take timely, potentially disruptive decisions. We are committed to exercising that mandate.
So how did we get to rewriting the G-7 communique?
In essence we applied the lessons of the lack of supervision that preceded the financial crisis.
IMF REPORT 2010: LEARNING TO SAY NO !
In 2010 the IMF published a staff position note given what happened in the Financial Crisis, to have a look at the role of supervisors. Because after the crisis we were drawing up all kind of repair-plans, but the main theme was: all those repair plans won’t work if the supervisors don’t dare to act. So the staff note identifies a very important pillar of supervision: the will to act.
The summary of the report is pretty solid, so I let the authors (Jose Viñals and Jonathan Fiechter, with Aditya Narain, Jennifer Elliott, Ian Tower, Pierluigi Bologna, and Michael Hsuwords) do the talking here themselves:
“Based on an examination of lessons from the crisis and the findings of these assessments of countries’ compliance with financial standards, the paper identifies the following key elements of good supervision—that it is intrusive, skeptical, proactive, comprehensive, adaptive, and conclusive. To achieve these elements, the “ability” to supervise, which requires appropriate resources, authority, organization and constructive working relationships with other agencies must be complemented by the “will” to act.
Supervisors must be willing and empowered to take timely and effective action, to intrude on decision-making, to question common wisdom, and to take unpopular decisions. Developing this “will to act” is a more difficult task and requires that supervisors have a clear and unambiguous mandate, operational independence coupled with accountability, skilled staff, and a relationship with industry that avoids “regulatory capture.”
PARIS G7 PRIVACY COMMUNIQUE AND THE WILL TO ACT
Now, if you read with the IMF Framework in mind, to us this signals a 95% Ability to Act and a 5% will to act. And the enforcement section says it all. Top priority: let’s stay in touch set up a database of enforcement actions all over the world. Seriously. Is that all?
AI, ROBOTS, SMART GLASSES AND NO URGENCY
We are currently entering a dark age where big tech money runs away with technological progress to perform mass surveillance and skill extraction on the public. We can see that in a number of countries in essence the government does not enforce the rule of law, but acts as a part of a corrupted regime. There is a stone-cold polarization and high rate of geopolitical tensions going on in the world, that requires limiting the use we make of new technologies, before it is too late.
It’s simple: when interest rates were too low, incentive structure in the financial sector went astray. Everyone ran away with the money, seeking revenue. And we ended up messing up the financial system pretty heavily. With supervisors halfway believing that a new industrialized era of long-term low interest rates was at hand, due to the new technology shifts. Well, that turned out not to be true. There was a big misconception on risks as everyone was wearing pink glasses to look at the world.
The Paris communique is those pink glasses all over again. It softens all the relevant today’s surveillance and privacy matters into dialogue, welcome, explore, and so on. The softening nature of the language is actually even more worrying/dystopian than if the communique were to have an explicit nightmare scenario of the future and huge letters saying WARNING-WE MUST ACT NOW.
EU-US DATA TRANSFER AS THE ELEPHANT IN THE ROOM
In the Netherlands HRIF.EU just had to raise awareness and nudge our government to block the Solvinity take-over by Kyndryl, due to data governance concerns and concerns on sovereign data protection. So with that in mind we figured: is there anything here in the communique that demonstrates the big shift we now see in Europe: a turning away from the US, a revisit of alliances.
Well, read for yourself. Does this look like the EU will ever – by itself – withdraw from the EU-US privacy framework agreement, when geopolitically necessary?
We welcome the G7 Digital & Technology Ministers’ reiteration of “the importance of maintaining trust-based data frameworks based on [their] commitment to Data Free Flow with Trust (DFFT), respecting applicable legislation on privacy, data protection, intellectual property rights, including trade secrets, and security, while preserving governments’ ability to address legitimate public policy objectives”.
This paragraph is revealing. It places “government access to personal data” inside the vocabulary of trust, interoperability and cross-border data flows. That is obedience in policy form. It is not the language of supervisors preparing to test whether fundamental rights are actually protected. It is the language of authorities adapting themselves to the political need to keep data flowing.
The paragraph turns out to be already outdated as well. As the Supreme Court slaughtered the FTC-independency, it also undermined the EU-US Data Transfer Adequay arrangements, as outlined by Noyb. So in essence the next time around the US Data Protection Authority delegation will be looked upon with different eyes.
HRIF.EU acts whenever privacy supervisors look away
In the Netherlands HRIF.EU is now running 4 lawsuits against the local Data Protection Authority. Reason being: they fail to act. They have no will to act.
We presented a 3,5 year long running illegal banking monitoring/surveillance dragnet to them (see article here), with all proof included and they don’t want to enforce. They would rather drink tea with the banks to discuss future surveillance mechanisms under even stricter Know-Your-Customer frameworks
This autumn, the court cases will be heard. And we need your support.
In a country where privacy supervisors routinely look away — and where the next DPA chair is going to be the lawyer who represented Big Tech and TikTok, mind you — public-interest enforcement cannot be left to the institutions alone.
That is why HRIF.EU acts. And that is why we ask for your support.
Support HRIF.EU
Our request is simple. Particularly if you are residing outside the Netherlands and have some funds to spare to support us in our cause. Open your bank-app and direct some funds to Human Rights in Finance (EU), IBAN: NL94 TRIO 0320 7857 85 BIC-Code: TRIONL2U
Don’t overdo it. Small is beautiful. But many small donations do make the difference.