A view from Brussels: The suspension of disbelief
Conceptualized during Greco-Roman times, the “suspension of disbelief” is a theory used in theatrical arts. It postulates that the audience tricks its mind to believe what is presented on stage, against logic or rational thinking, just because leaning into believing is the whole point.
Some suspension of disbelief would be helpful as the EU simplification journey runs its course. Brussels has been debating digital reform for months, alongside reform of defense, agriculture, taxation, etc. And so, the first signal of simplification for the IAPP community came from the European Commission’s Internal Market, Industry, Entrepreneurship and SMEs Directorate-General.
Proposed by the European Commission in May 2025, the Omnibus IV package will enter into force over the summer. Its primary objective is not privacy or digital reform, but rather to reduce regulatory burden by extending certain small and medium enterprise relief measures to a newly created category of companies, “small mid-cap” enterprises.
SMCs are companies with fewer than 1,000 employees and either annual turnover of up to 200 million euros or an annual balance-sheet total of up to 172 million euros — thresholds the European Parliament and Council increased from the Commission’s original proposal.
For privacy professionals, Omnibus IV addresses one thing: Records of processing activities obligations under the EU General Data Protection Regulation.
The new law extends the GDPR’s Article 30 derogation beyond SMEs to SMCs. In practice, organizations with fewer than 1,000 employees may no longer need to maintain a ROPA, provided their processing activities are not likely to result in a high risk to individuals’ rights and freedoms.
One can genuinely debate whether, all things considered, addressing ROPAs was in fact the most impactful area to, quoting the Commission, “boost the competitiveness of EU companies.” There is no point in relitigating the past, but we can certainly question what it does for the future.
The answer is underwhelming: Barely anything.
The first catch is that high-risk remains a limiting factor, rightfully so one would argue. Where a data protection impact assessment identifies processing that is likely to result in a high risk under Article 35 GDPR, the documentation obligation remains.
The second catch concerns controllers and processors subject to data protection officer obligations. In this case, ROPAs remain necessary unless the relevant processing is merely ancillary to their core business and unlikely to present high risk. Public authorities, meanwhile, remain fully subject to the record-keeping requirement.
The result is a halfway attempt at simplification. Organizations must still determine whether processing is high risk. They must still conduct DPIAs where required. Many must still appoint DPOs. And many will still decide to maintain records for at least part of their processing activities because it is an essential documentation tool for visibility, traceability and accountability.
Will SMCs that can benefit from this new exemption stop doing ROPAs? Some would be legally entitled to do so but the operational tradeoffs may not be worth it.