
Restoring Legal Certainty in EU Data Protection Law
The final DigiData report on contextual identifiability, anonymisation assurance, scientific research, AI development and supervisory governance in the Digital Omnibus.
Selected engagements and public studies show the substance, range and institutional settings of DigiData’s work. Forthcoming work is labelled clearly; private Council of Europe AI-in-education materials are not published here.
Recent reports and expert contributions on data protection, digital fairness and regulatory policy.

The final DigiData report on contextual identifiability, anonymisation assurance, scientific research, AI development and supervisory governance in the Digital Omnibus.

Slides, prepared remarks and a companion lecture from the European Economic and Social Committee hearing on the Digital Fairness Act, commercial practices and the evidence needed for enforcement.
The examples distinguish commissioned studies, ongoing advisory work, public submissions, personal-capacity contributions and research partnerships. The wording avoids implying that every organisation shown is a conventional fee-paying client or endorses DigiData.

A final study report combining legal interpretation, stakeholder input, practical use cases, enforcement analysis and cross-regulatory mapping for Article 5(1)(a) and (b) of the AI Act.
Contribution: A public Commission study designed to improve legal clarity, support harmonised application and strengthen practical enforcement.

A comparative legal and policy study of interface tactics, system-level manipulation, personalisation, gamification and commercial exploitation affecting minors.
Contribution: Child-centred proposals on design standards, algorithmic scrutiny, enforcement and the development of a coherent digital-fairness framework.

Use-case mapping, legal gap analysis and regulatory design addressing AI systems operating within education as a protected public function.
Contribution: The working materials remain private. The engagement demonstrates DigiData’s ability to connect rights, educational quality, lifecycle duties and institutional implementation.
Research on collective redress, Article 82 damages, national procedural divergence, litigation funding, automation and the relationship between public and private enforcement.
Contribution: A public report examining how industrial-scale litigation can strengthen access to justice while creating new questions of calibration, finality and institutional legitimacy.

A detailed intervention on Google Search data sharing, anonymisation, utility, recipient context, tiered access architecture and institutional coherence.
Contribution: The submission introduced the Anonymisation and Utility Impact Assessment as an evidence framework for preserving both privacy and meaningful contestability.
Two linked submissions: Phase 1 examines consumer attitudes, risk tolerance and expectations; Phase 2 develops an operational accountability framework for adaptive, consequential and agentic consumer AI.
Contribution: A proportionate architecture that distinguishes beneficial AI from exploitative optimisation and translates consumer protection into functional risk tiers, mandates, evidence, redress and earned safe harbours.

Co-authorship of the first outcome report following a multidisciplinary workshop convened by Leiden eLaw and ECPAT International with Council of Europe support. The analysis addressed general monitoring, proportionality, private communications, children’s participation and competing rights.
Contribution: The report was presented to the Lanzarote Committee during its exchange with the European Commission and set out both contested questions and areas of workable common ground.
Co-authorship of the second expert-workshop report, assessing hashing, image and text classifiers, on-device scanning, secure enclaves and the consequences of deploying detection technologies in open and encrypted communications.
Contribution: The report converted technical and legal disagreement into concrete safeguards concerning audit, repurposing, accuracy, human review, data sets, children’s rights and survivor participation.
Co-authorship of a successful Erasmus consortium proposal addressing disinformation across technological, legal, political, economic and educational dimensions. The programme joined European universities around media education and fact-checking.
Contribution: The €450,000, three-year programme supported a joint cross-disciplinary postgraduate curriculum and the development of eight online learning modules for current and future media professionals and educators.
Research within a Volkswagen Foundation-funded consortium examining political microtargeting, information asymmetry, manipulation and the relationship between human decision-makers and platform algorithms.
Contribution: The €1.5 million programme connected Leiden eLaw with the Max Planck Institute for Human Development, the University of Bristol and Northeastern University to develop evidence-based interventions, transparent information architectures and regulatory responses.
Download the public files directly or follow the official publication record where one exists.

Slides, prepared remarks and a companion lecture from the European Economic and Social Committee hearing on the Digital Fairness Act, commercial practices and the evidence needed for enforcement.
The Digital Omnibus, contextual identifiability and a reliable assurance route for privacy enhancing technologies.
PublishedA comprehensive analysis of subliminal, purposefully manipulative, deceptive and vulnerability-exploitative AI practices, including constitutive elements, enforcement challenges, use cases and interaction with the wider EU digital acquis.
PublishedA 155-page analysis of manipulative interfaces and system architecture, personalised influence, gamification, children’s vulnerabilities and the adequacy of the GDPR, DSA, UCPD and AI Act.
PublishedA submission on Article 6(11) DMA that preserves anonymisation as the legal condition for sharing personal search data, proposes tiered access modalities and introduces the AUIA.
PublishedA proposal for a binding duty of evidence and public reason-giving when digital regulators choose among materially different lawful routes affecting rights, legal certainty, investment and scale.
PublishedAn analysis of collective redress, Article 82 GDPR, procedural fragmentation, forum selection, automation and the need to keep harm, procedure and remedy tightly coupled.
PublishedA proportionate, architecture-aware account of consumer AI risk. It argues against placing the primary burden on consumers, treats vulnerability as relational and distinguishes beneficial assistance from exploitative optimisation.
PublishedAn operational framework for adaptive and agentic consumer services, combining a five-tier functional risk ladder with mandates, action receipts, prohibited optimisation objectives, vulnerability-event controls, rights-friction parity, evidence packs, redress by design and earned safe harbours.
PublishedA cross-acquis taxonomy that separates legal status from route, scope, artefact form, circulation and assurance instead of treating non-personal data as one coherent object.
PublishedA documentation stack in which the legal baseline, complete assessment dossier and portable data-status claim remain separate, reviewable and time-bounded.
PublishedAn institutional case for cooperative digital administration, clearer responsibility, procedural discipline, auditable separation and an enforceable duty of inter-regulatory cooperation.
PublishedA reconstruction of proportionality as a discipline of justified interference and rights-sensitive technological architecture across EU law, the GDPR and the AI Act.
PublishedA rights-based critique of addiction-centred policy narratives and a case for evidence-led, function-specific regulation of manipulation, exploitation and genuine harm.
PublishedA multidisciplinary analysis of the EU proposal on online child sexual abuse, addressing general monitoring, proportionality, private communications, adolescent sexual exploration, voluntary detection and institutional safeguards.
PublishedA technology-focused assessment of detection tools and end-to-end encryption under the EU proposal, covering hashing, image and text classifiers, on-device techniques, secure enclaves, repurposing risks and legal safeguards.
PublishedAn earlier policy report on consumer and regulatory harms associated with virtual currencies and the need for legal certainty in technically complex markets.

The final DigiData report on contextual identifiability, anonymisation assurance, scientific research, AI development and supervisory governance in the Digital Omnibus.
“The strongest argument is rarely the loudest position. It is the one that makes its assumptions visible, survives the hard objection and still leaves a workable route forward.”DigiData working principle
DigiData publishes work when commissioning terms, timing and subject matter permit it. Some work remains confidential, and some institutional materials cannot be released before the relevant process concludes.
Tell DigiData what decision, dispute or policy problem you need to resolve. The initial enquiry form is designed to establish scope, urgency and the expertise the work may require.