According to NSA deputy and privacy whistleblower Edward Snowden , Europe's General Data Protection Regulation (GDPR) has lost its meaning and will remain ineffective until Internet regulators are hit with large fines.
The General Data Protection (GDPR) came into force across the European Union on May 25, 2018, and aims to give EU citizens greater control over their personal data. Specifically, it introduces potentially huge fines for organizations found to have failed to protect their customers’ data. And while the GDPR was seen by many as a major boost to data protection, Snowden appears to be underestimating it.

“The problem is not data protection, the problem is data collection,” he said.
Snowden was speaking via video link from Russia, where he now lives after leaking details about secret US government surveillance programs to journalists in 2013.
“Data protection regulation assumes that data collection is primarily correct, appropriate and does not pose a threat or risk as long as it will never be leaked,” he added.
Snowden said that while GDPR was a “good first attempt,” he now says it is “not the solution because it is not the good internet we want.”
One of the most important features of the GDPR is that organizations can face a maximum fine of €20 million or 4% of global turnover – whichever is greater. While some large GDPR fines have already been imposed, Snowden said: “Until we see these fines being applied every year to internet leaders, until they reform their behavior and start complying, we can’t be sure of anything,” he said.

However, for Snowden, the bigger issue is that the collection of personal data through websites, apps, and more has become a dominant business model for the Internet.
