The EU Is Keeping Data Centres in the Dark
The Quiet Machinery of Secrecy: How the EU Buried Data Centre Transparency
by Stefanie Khoury
The European Commission and Big Tech are keeping secrets. That’s what was revealed in Investigate Europe’s explosive investigation last Spring that shined a light on the 2024 European regulation on data centre environmental disclosures. That legislation is shaping how millions of Europeans understand (or fail to understand) the environmental cost of the digital economy.
The regulation was adopted without European Parliamentary debate because the Commission Delegated Regulation (EU) 2024/1364 was adopted under delegated powers. In theory, these powers are to update laws in fast-moving sectors or to ensure their proper implementation. In this case, they were used to adopt Article 5, which at clause 5 basically says: whatever data centres tell the state about their environmental footprint will be kept confidential. To be clear, it isn’t a confidentiality clause targeting competitors; it is a clause specifically aimed at keeping information from the public.
The regulation justifies its secrecy clause by invoking two legal instruments: Regulation 1049/2001 (the EU’s general transparency law) and Directive 2003/4/EC (which governs public access to environmental information). Under the Aarhus Convention, the regulation should presume disclosure and treat secrecy as the exception requiring justification since it defends the principle that information about the environment is a public right, not a corporate asset. Directive 2003/4/EC flows from the notion that there is a democratic right to government accountability for environmental protection, which intersects with human rights. In EU law, a river’s pollution levels, a factory’s emissions, a facility’s water use are meant to be considered as belonging to the public sphere, because the public bears the consequences. But Regulation 2024/1364 takes a category of information (i.e. the environmental footprint of data centre infrastructure) and reclassifies it as commercially sensitive, default blanketing confidentiality.
This is alarming regarding issues of transparency, but even more arresting is that the Commission allegedly copied almost verbatim the text suggested by Microsoft and DigitalEurope. Big Tech isn’t fighting transparency requirements in public because they don’t have to; they’re circumventing transparency altogether by ensuring the requirements are drafted with confidentiality already embedded.
Data centres now consume electricity at a scale comparable to mid-sized countries, and their water use for cooling is a documented and growing source of opposition. Ireland alone now channels roughly a fifth of its electricity through data centres. Aggregate EU figures put data centre electricity demand on a trajectory to nearly double by 2030, reviving interest in nuclear power as governments search for ways to meet rising energy demand. Our drinking water is also at risk, with research linking USA data centres to water pollution. Meanwhile, the EU seems set on data centre growth at all costs, with investments topping €176 billion across the next 5 years.
Amidst this hyper-expansion, the specifics of the environmental impact of data centres are being shielded by Article 5(5). Last May, following Investigate Europe’s report, 35 MEPs demanded the Commission remove what they argue is unlawful regulation, citing its conflict with the Aarhus Convention. Those demands are still pending.
There is a second, quieter violence connected to Article 5. Delegated acts are a genuine feature of EU governance, meant for technical implementation. In practice, this pushes decisions with substantial public consequences, including access to information about the environmental footprint of data centres, beyond public scrutiny into venues not easily subject to public challenge. The Commission’s spokesperson stated that it fulfilled its obligation “to respect business secrets and confidentiality of the reported information and data” – arguably over the obligations to public information and protection.
This is how depoliticised governance works under a system organised around the free movement of capital. Environmental and social questions are reframed as technical questions; those are delegated to expert committees who then produce texts that protect commercial interests; and, commercial interests are treated as naturally deserving protection, while public interests in land, water, and environmental accountability are not. The Aarhus Convention was meant to check that, but Article 5 shows how easily it can be worked around by simply asserting, in the text of the law itself, that the information in question is commercial not environmental. With that, public information open to scrutiny is recast as protected from competitors.
The confidentiality clause was buried in plain sight in the complexity of EU law-making. If there is a lesson in the stealth of Regulation 2024/1364, it’s this: there is no transparency. Big Tech knows there will be opposition to the raw data on data centre energy consumption, so with the complicity of governing bodies, it’s managing visibility by disclosing aggregated information, not details.
The EU is betting big on data centres, claiming they will safeguard sovereignty and competitivity. But by kowtowing to Big Tech, the Commission is showing that sovereignty is already being surrendered.

