Home

Donate
Perspective

Europe’s Digital Rules Need an Independent Enforcer

Kai Zenner, Maria Koomen / Sep 15, 2026

Kai Zenner is Head of Office and Digital Policy Adviser to MEP Axel Voss (European People's Party Group) in the European Parliament and a Fellow of Practice at the TUM Think Tank. Maria Koomen is a democracy and tech analyst. All views expressed in this article are personal.

Republish

Fifteen years of digital law-making have given the European Union the densest rulebook in the world. But the EU has built rules faster than it has built the capacity to enforce them. By our count, 171 EU digital laws are enforced by 315 different bodies holding 597 overlapping mandates. A single service such as TikTok’s recommender system must satisfy the Digital Services Act, the General Data Protection Regulation, the Audiovisual Services Directive, and the AI Act at once, each under different regulators and with conflicting deadlines.

Underneath that complexity sit public authorities that enforce unevenly, resources that fall short almost everywhere, and a European Commission caught between policing the rulebook and courting the governments whose companies it is meant to hold to account.

What follows from that complexity is visible in the caseload. In 2024, the German, Spanish and Italian data protection authorities issued 416, 281 and 140 fines; a dozen member states issued fewer than ten. Ireland’s Data Protection Commission, lead regulator for most of the large American platforms, dismisses 99.93 percent of complaints without a substantive decision and has never completed an inquiry into Google. Where enforcement does arrive, it rarely changes conduct. Google reportedly earned back its €2.4bn antitrust fine within two weeks of trading. The result is a widening gap between what the EU law promises and what citizens experience.

The underlying problem is political. The Commission sets the policy agenda, writes the digital laws, enforces them, evaluates them and negotiates trade and security with the same governments whose companies it is meant to police. In 2025, the Commission hesitated in its Digital Markets Act decisions against Apple and Meta amid US tariff threats.

In early 2026, President von der Leyen personally directed the delay of a Google Search fine that the Commission’s DG Competition had already prepared. More than thirty civil society organizations described the event as a capitulation. Companies read those signals accurately. Digital industry lobbying in Brussels rose from € 97 million in 2021 to a record € 151 million in 2025, with the five largest US platforms averaging more than one Commission meeting a day.

Brussels is not short of proposals on how to address those problems. They range from internal coordination to fully independent enforcement. At the lighter end sits coordination: an internal task force of senior officials, a digital coordination unit in the Secretariat-General or a permanent multi-stakeholder clearing house. Although these concepts are legally strong, they are institutionally weak. They add process to an institution whose problem is not a shortage of information but an inability to act on it. At the heavier end sit independent authorities, most ambitiously a European digital agency potentially absorbing the Commission’s DSA, DMA and AI Act powers. While those proposals might be strong enough to overcome some existing enforcement problems, they collide with the Court of Justice’s Meroni doctrine and with capitals defending their own regulators.

The way to close this enforcement gap is to sequence these proposals.

The first step should be taken in 2027. The EU should establish a Digital Regulation Cooperation Forum, modeled on the UK’s Digital Regulation Cooperation Forum (DRCF), which brings together four regulators overseeing financial services, data protection, communications and competition. The European version would seat existing EU-level bodies responsible for data protection, online platforms, digital markets, artificial intelligence, cybersecurity, telecommunications and competition: the European Data Protection Board for data, the European Board for Digital Services for platforms, the DMA High-Level Group for gatekeepers, the AI Board, ENISA, BEREC, the European Competition Network and the Joint Committee of the European Supervisory Authorities.

The European Data Protection Supervisor offered to supply the secretariat, so there would be no new body, no new establishment plan and no new leadership post to fight over. The Commission would chair without a vote, an arrangement that signals from the outset that the Commission’s enforcement role is meant to transition. The legal base for the EU DRCF would be a targeted digital governance Omnibus amending the relevant laws, tabled alongside the Digital Fitness Check planned for the first quarter of 2027.

Such a coordination forum will, however, not close the enforcement gap. It has no binding authority and it cannot neutralize geopolitical pressure. Its strengths are that it is cheap and fast and that it is difficult to oppose, since Member States such as the Netherlands and Ireland already run national versions of it. Its function is to build the shared evidence and methods, as well as the institutional trust that the second step requires.

The second reform step belongs in the EU’s next seven-year budget cycle, running from 2028 to 2034: the transformation of the existing European Health and Digital Executive Agency (HaDEA) into a Digital Enforcement Agency with the power to investigate and fine very large services and GPAI model providers that break the bloc’s tech rules. An executive agency, in EU terms, isn’t a regulator. It’s a body created by the European Commission, the EU’s executive arm, to run specific funding programs and administrative tasks on its behalf. HaDEA is the right structure precisely because nobody is invested in defending it as it currently stands. Executive agencies get reshuffled every time the EU renegotiates its multi-year budget, and HaDEA itself has already been restructured twice.

It has no entrenched mandate, no specialist constituency, and no coalition of member states with a stake in keeping it as it is. What it does have is a solid foundation to build on: offices in Brussels, functioning HR and audit systems, and staff already used to collaborating with the Commission and national counterparts.

The timing of our sequenced reform proposal is not incidental. The Multiannual Financial Framework (MFF) window opens once every seven years. Proposing a new EU body outside of this window would attract the full force of the "another agency" objection; inside it, the proposal reads as a reallocation of existing commitments.

The AI Act introduces an additional timeline: Article 112 obliges the Commission to evaluate by August 2028 whether the AI Office has adequate powers and resources, and by August 2029 whether a dedicated Union agency is needed. When those reviews come due, either a worked institutional answer is already on the table, or one gets improvised under deadline.

How the Digital Enforcement Agency is designed will eventually decide whether other EU institutions see the added value and do not feel threatened. In this regard, it seems preferable that the Commission keep policy and designation, deciding who is a gatekeeper, which services are very large, and which GPAI models carry systemic risk. The agency would take over only downstream technical enforcement duties: investigations, audits, inspections, fines and remedies. It would be organized around four supervisory domains (i.e., gatekeeper conduct, systemic risk and online safety, GPAI models and data processing, and democratic integrity) rather than around individual laws, because organizing by legislation would import the very fragmentation it exists to cure. National authorities would keep domestic cases.

This is in line with the short-selling judgment and the EU Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) precedent, as the powers are technically defined, objectively triggered, and fully reviewable to satisfy the Meroni doctrine.

Independence then has to be structural rather than declared. The chair should be proposed by the Commission, scrutinized by Parliament, and appointed by the Council, with serving politicians and senior Commission officials excluded from the outset, because contested appointments have been the most reliable weapon ever used against new EU bodies. The agency needs budget lines the Commission cannot unilaterally cut, supplemented by the existing DSA supervisory fee, redirected with surgical legal changes from the Commission to the agency that does the supervising. Companies could challenge decisions first through an internal appeals board, then before a dedicated digital chamber within the EU’s General Court, a specialized panel built to move faster than ordinary chambers — all with deadlines that trigger automatic escalation.

A standing register requiring outside advisers to disclose ties to the companies under investigation would keep conflicted experts out of the process. Applying AMLA’s supervisory ratio, this is a body of 450 to 500 people, the majority of them transferred from Commission enforcement units rather than newly recruited.

The third successive and final step is treaty reform. Major changes will need unanimity and ratification across twenty-seven constitutional orders, a threshold that has made treaty revision a thing of the past. To overcome the enforcement gap, it, however, must remain the destination, as it would authorize explicitly what secondary law has been doing implicitly for decades: fully independent enforcement across the Digital Single Market, covering not only AI, data and platforms but also cybersecurity, connectivity and competition, with accountability chains designed for supervisory institutions rather than borrowed from internal market harmonization. Within those larger reform ideas, steps one and two are not mere placeholders. They are the political and institutional preparation without which step three would never become realistic.

The strongest case for delegating enforcement is not administrative coherence. It is leverage in a geopolitical world and a Europe with strong national interests. When enforcement rests with a politically led institution, it can be traded, and every capital and every general counsel knows it, which is exactly why pressure is worth applying. More staff or stiffer internal rules wouldn’t change that, because the final decisions still sit with politically appointed leadership who also negotiate the trade deals the pressure is tied to. Move enforcement to a body that is technically bounded and judicially reviewable, and structurally incapable of capitulating, and retaliation stops paying. European digital law then ceases to be a bargaining chip and finally has the chance to work in practice.

The window for making that change is the budget negotiation that takes place now. Miss it, and the next one does not open until 2035.

Support Tech Policy Press
If you've found our work helpful, consider supporting us.

Authors

Kai Zenner
Kai Zenner is Head of Office and Digital Policy Adviser for MEP Axel Voss (European People's Party Group) in the European Parliament and was involved in the AI Act negotiations on a technical level. He focuses on AI, privacy, the EU’s digital transition and Better Regulation. Zenner is a member of t...
Maria Koomen
Maria Koomen is a democracy and tech analyst.

Topics

Related

Perspective
The Enforcement Dilemmas in Europe’s Digital RulebookMay 19, 2025
Analysis
How US Officials Are Pressuring Europe Over Its Platform RegulationsAugust 19, 2025