The Innovation Mandate
Europe’s Digital Regulators Must Account for the Economy They Now Govern
Europe’s debate about digital regulation has become trapped in a set of impoverished binaries. Rights or innovation. Privacy or growth. Safety or scale. Brussels or Silicon Valley. The framing is analytically lazy and politically convenient, but it obscures the real institutional problem now facing the European digital economy. The difficulty is not that Europe has chosen rights. Nor is it that the GDPR, the AI Act, the DSA, the DMA and the wider data acquis are inherently hostile to technological development. The more precise problem is that Europe has constructed a dense digital supervisory state whose discretionary choices increasingly determine the conditions of investment, deployment and scale, while the law does not yet require those supervisors to account, in a disciplined and public way, for the economic consequences of that discretion.
That is the argument of my new paper, The Innovation Mandate: Making Europe’s Digital Supervisory State Accountable for Rights, Growth and Scale. The claim is deliberately narrower than much of the current rhetoric on competitiveness.
Europe does not need a weaker digital rulebook. It needs a more accountable supervisory architecture. It needs regulators who, when Union law leaves them room to choose, must explain how their choices protect rights, preserve legal certainty, and avoid unnecessary damage to lawful innovation, investment, and scale.
The distinction matters. A deregulatory argument would ask Europe to relax its commitments to data protection, fundamental rights, safety and consumer protection in order to compete with jurisdictions that have made different constitutional choices. That is neither legally plausible nor normatively attractive. The European model cannot survive by abandoning the premise that made it distinctive. But nor can it survive if every invocation of innovation is treated as an attack on rights, or if supervisory authorities are permitted to exercise market-shaping discretion without a structured duty to explain why the burdens they impose are necessary, proportionate and no greater than the law requires.
The modern digital regulator is not merely an enforcement body. That description belongs to a simpler administrative world. Digital regulators now translate open-textured statutes into operational market conditions. A data protection authority’s view of legitimate interests, anonymisation, joint controllership, automated decision-making, special-category data, children’s data, international transfers or DPIA expectations may decide whether a product can be financed or deployed. The EDPB’s guidance can convert contestable interpretations into practical obligations across the internal market. Under the AI Act, supervisory choices about high-risk classification, conformity assessment, serious-incident reporting, post-market monitoring, general-purpose AI obligations, sandbox design, and the evidential content of compliance will determine how quickly and by whom AI systems can be brought to market. The same is true, in different forms, under the DSA and DMA, where risk assessments, audits, researcher access, recommender transparency, gatekeeper remedies and data-use restrictions do not merely police markets but help constitute them.
The accountability gap is not in the statute alone; it is in the supervisory discretion that turns law into market condition.
This is the discretionary layer where enacted law becomes economic reality. It is also the layer least adequately disciplined by existing accountability mechanisms. Supervisory authorities are often required to report how many complaints they received, how many investigations they opened, how many fines they imposed and how many documents they published. They are not usually required to explain whether a guidance document increased legal certainty, whether divergent national interpretations undermined scale, whether a remedy protected rights through unnecessarily costly means, whether a sandbox criterion excluded smaller firms, or whether a less burdensome lawful alternative was available. That is the governance gap.
The legal point is not revolutionary. It is orthodox. Proportionality is not an optional mood in EU public law. It is the constitutional grammar of justified public power. From the German administrative tradition of suitability, necessity and proportionality stricto sensu, through the Convention language of fair balance, to the Court of Justice’s own case law under the Treaties and the Charter, the function of proportionality has always been to discipline the relationship between legitimate objectives and the means chosen to pursue them. A measure may pursue an important public interest and still be unlawful if it is overbroad, insufficiently justified or more restrictive than necessary.
That matters for digital supervision because the GDPR itself is not a monastic instrument concerned only with restriction. Article 1 protects fundamental rights and freedoms with respect to personal data and the free movement of such data. Recital 4 is unusually explicit: the right to the protection of personal data is not absolute; it must be considered in relation to its function in society; and it must be balanced against other fundamental rights in accordance with proportionality. That sentence has been under-operationalised. It is routinely cited, but rarely institutionalised. The innovation mandate would make it administratively real.
The mandate does not sit above rights. It makes proportionality inside the EU legal architecture operational.
Nor does the Court of Justice’s case law support the caricature that data protection demands maximum restriction in every context. Promusicae requires fair balance between competing rights. Schecke rejects undifferentiated publication where more tailored approaches are available. ASNEF prevents Member States from turning a balancing provision into an absolute prohibition. Google Spain is rights-protective but still methodologically structured. Digital Rights Ireland, Tele2, La Quadrature, Schrems I and Schrems II show the other side of the same discipline: where the interference is serious, and safeguards are inadequate, broad appeals to administrative convenience, security or economic interest will not suffice. The lesson is not that innovation wins. It is that unreasoned power loses.
Recent data cases make the point unavoidable. Meta Platforms v Bundeskartellamt, SCHUFA, IAB Europe, Schrems v Meta and KNLTB are not marginal privacy disputes. They structure platform economics, credit scoring, adtech, personalised advertising, data combination and ordinary commercial interests. These cases are rights-centred, but they are also market-shaping. Once that is acknowledged, the supervisory institutions that translate those judgments into practical expectations should be required to explain their choices. They may take a demanding view. Often they should. But they should be able to say what risk they are addressing, which lawful alternatives they considered, why less burdensome safeguards were insufficient, and why the final position is proportionate.
The innovation mandate I propose is therefore a secondary duty of regard, not a trump card. DPAs, the EDPB, the AI Office and national AI authorities should, when exercising general functions and discretionary powers, have regard to responsible innovation, legal certainty, proportionate compliance burdens, investment, competitiveness and sustainable economic development. But that duty must operate without prejudice to fundamental rights, health and safety, consumer protection, children’s rights, DPA independence and the level of protection required by Union law. The phrase “without prejudice” is doing serious legal work. It is the difference between a constitutional settlement and a lobbying slogan.
The mandate would not create a defence to unlawful processing. It would not authorise unsafe AI. It would not allow ministers to direct supervisory decisions. It would not give industry a veto over enforcement. It would not require courts to maximise innovation. Its legal bite would be familiar: did the authority consider the mandatory factors, did it give intelligible reasons, did it remain within the bounds of proportionality, and did it preserve the rights floor?
The practical machinery is equally important. A mandate written as aspiration would be useless. The core mechanism should be the supervisory impact statement: a concise public document that accompanies major guidance, strategic enforcement positions, sandbox criteria, consistency opinions, and other supervisory choices of general market significance. The statement should identify the legal uncertainty being addressed, the rights or safety risks at stake, the likely effects on legal certainty, innovation, investment and scale, the less burdensome lawful alternatives considered, the implications for SMEs and scale-ups, and the reasons for the chosen approach. This should not become a legislative impact assessment in miniature. The point is not bureaucratic theatre. The point is reasoned public administration.
Annual accountability should reinforce that discipline. Regulators should report on metrics that matter: speed of guidance, duration of cross-border cases, consistency of national approaches, sandbox throughput, SME support, cross-regulatory conflicts, adoption or rejection of less burdensome, rights-preserving alternatives, and evidence of how supervisory practice has affected lawful deployment. These are not growth-department KPIs. They are rule-of-law KPIs for a supervisory state whose decisions now allocate economic opportunity.
The regulator keeps the legal decision; the mandate makes the evidence, alternatives and reasons visible.
The mandate must also discipline industry. Firms should not be rewarded for vague complaints that Europe is “falling behind” or that compliance is expensive. Some compliance costs are the price of lawful and trustworthy technology. A credible industry submission should identify the exact legal barrier, the lawful activity affected, the rights or safety risks, the mitigation stack, the evidence base, the investment or deployment consequence, and the narrower supervisory alternative sought. Investors and trade associations should be expected to provide aggregated evidence about delayed financing, abandoned deployments, relocation decisions, inconsistent Member State interpretations and duplicative compliance burdens. The mandate should force everyone to become more precise.
Germany is central to this argument. A legal culture that treats Datenschutz as the sole supervisory mission will struggle to build an AI and data economy, even where the law provides lawful avenues for responsible data use. Germany can move first by amending the BDSG to give the BfDI and, where appropriate, the Datenschutzkonferenz, a secondary mandate for responsible data use, legal certainty, proportionate compliance, innovation and competitiveness. That mandate should preserve the primary duty to protect personal data and fundamental rights, exclude individual-case direction, require published reasons for major positions and establish annual parliamentary accountability. A Growth and Innovation Advisory Panel could provide evidence on technological development, investment effects and implementation barriers, but with strict anti-capture safeguards: balanced membership, public minutes, conflict declarations, no role in individual cases and no access to confidential enforcement files.
The independence objection is serious but not fatal. EU law rightly requires data protection authorities to act free from external influence. Commission v Germany, Commission v Austria and Commission v Hungary remain fundamental guardrails. But independence is not unaccountability. A legislature may define statutory objectives, require reasons, impose reporting duties and create consultation structures, provided it does not allow government, industry or advisory bodies to direct the outcome of individual complaints, investigations, fines or corrective measures. The innovation mandate belongs to the former category, not the latter. It structures discretion; it does not capture it.
The AI Act makes the case even stronger. Its purpose is expressly dual or plural: to promote the uptake of human-centric and trustworthy AI, to protect health, safety, and fundamental rights, to support innovation, and to improve the internal market. The route to market under the Act will depend heavily on supervisory interpretation. If classification, standards, technical documentation, conformity assessment, sandbox learning, and post-market expectations are slow, fragmented, or excessively precautionary without adequate justification, the result will not be neutrality. It will be a redistribution of advantage to incumbents, foreign jurisdictions and firms large enough to absorb uncertainty. The mandate would not lower AI Act obligations. It would require the AI Office and national authorities to ensure implementation is coherent, timely, proportionate, and innovation-aware.
The economic evidence should be handled carefully. It does not prove that the GDPR alone caused Europe’s scale-up problem. That claim is too crude. Europe’s innovation difficulties are overdetermined: capital markets, procurement, fragmentation, talent, risk appetite, industrial policy and regulatory design all matter. But the defensible proposition is enough. Digital supervisory choices affect the expected cost, timing and certainty of lawful deployment. Those factors matter for financing, product strategy and scale. Once that is accepted, supervisory indifference to the impact of innovation is no longer credible.
The settlement is therefore simple, but not simplistic: protect the rights floor absolutely; where Union law leaves discretion, require the supervisory authority, the lead supervisory authority, or the EDPB to explain why its chosen approach is proportionate, coherent, innovation-aware, and no more burdensome than the law requires.
Europe should resist the demand to become a low-rights jurisdiction. That would be a category error. But it should also resist the complacent view that rights-based digital regulation can be administered through opaque, fragmented and economically under-accountable discretion. The next phase of European digital governance will not be judged only by the elegance of its statutes. It will be judged by the quality of the institutions that interpret, apply and operationalise them.
A high-rights legal order can support innovation, but only if the supervisory state is capable of reasoned, proportionate and predictable administration. The innovation mandate is an attempt to make that proposition legally real.
The full paper will be available on SSRN and SoCArxic shortly.




