A letter shows the Irish DPC held ten meetings with Facebook and agreed on a GDPR bypass by moving consent into terms and conditions. The DPC then drafted EDPB guideline language to allow this approach, but other DPAs criticised it, calling it a circumvention of GDPR. The final EDPB Guidelines 2/2019 were published without any reference to the bypass.
Why it matters: The episode highlights regulator influence attempts on EU data‑protection guidance and the pushback from other authorities to protect GDPR integrity.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.