Digital technology should serve human beings, not the other way around - Meet COMPASS
Q&A with Robert Steiner, the Vice President of COMPASS, an NGO that focuses on how EU digital regulation is written versus implemented and how it plays out in practice, and affects the end user - you. He shares why the NGO started, its focus, and why it chose Tuta Mail to secure its communications.
Robert Steiner has over two decades experience in building regulatory-compliant products and partnerships across banking, pharmaceuticals, manufacturing and enterprise tech - navigating PCI DSS, GDPR, GxP, SOX, PSD2, eIDAS and WCAG across multi-jurisdictional environments, with teams across five continents. Today he serves as the Vice President of COMPASS.
Question: What is COMPASS’ mission?
Mr. Steiner: Europe writes good laws and implements them badly. Between the law as published in the Official Journal and the law as experienced by a person clicking “Accept All Cookies” at 7am, there is a vast gap. COMPASS exists to close it.
The mission underneath all of it is simple - digital technology should serve human beings, not the other way around.Regulation is the mechanism and human experience, dignity and participation are the point.”
Question: What kinds of work do you do? And how does the organisation go about it?
Mr. Steiner: Four kinds of work: We monitor implementation - tracking how regulations like the AI Act, GDPR and the DSA behave once they leave Brussels and meet reality. We publish independent analyses - our recent pieces cover the EU AI Act Omnibus vote, a practical AI Act field guide, and the cookie consent mechanism as privacy theatre. We translate - the same evidence has to work for a compliance officer and for a fifteen-year-old, without being diluted for either. And we channel what we find back to the people writing and enforcing the rules. If they are willing to listen, of course.
How we go about it matters as much to us as what we do. Claims we publish trace to verifiable sources, findings are separated from inference, and corrections are published when facts require it. We built the governance infrastructure - conflict-of-interest policy, funding ethics, data protection by design - on day one rather than retrofitting it later, and we practise what we advocate, down to a website with no dark patterns, no cookies - not even functional ones - and no advertising or profiling scripts of any kind. The only analytics we run are cookie-free and aggregate.
Question: What prompted the start of COMPASS? Was there a specific event?
COMPASS Logo. Image: COMPASS
Mr. Steiner: Less a single event than a pattern that refused to stop repeating. The defining example is one every European knows intimately - cookie consent. A law designed to protect privacy that, through poor implementation, trained hundreds of millions of people to click “Accept All” - achieving the exact opposite of its intent. Nobody was monitoring that gap as their actual job. Universities were too large to be fast enough, regulators lacked the operational depth, commercial compliance firms serve paying clients, and activists are often too easily dismissed as adversarial by the institutions that need to change. It might not be a pretty truth, but unfortunately it is the reality.
When we looked at the AI Act arriving into that same vacuum, at a scale that makes GDPR look manageable, the conclusion was unavoidable.
We founded COMPASS out of personal conviction - out of love for both technology and Europe - because the alternative was watching the cookie banner story repeat itself with much higher stakes. And this was all ahead of the Digital Omnibus - we most certainly did not see that coming.”
Question: What EU laws or regulations are you currently monitoring most closely? And is there an emerging trend or issue you’d like to highlight?
Mr. Steiner: Most closely the EU AI Act and what the Digital Omnibus is doing to it, the GDPR as it is lived rather than as it is written, the DSA, and Chat Control as the live legislative threat to encryption. Something you have been very direct about - and it really made us proud of picking you.
The overarching issue I would highlight is that the implementation gap we were founded to monitor is now widening by design. The Digital Omnibus agreement of this May delays the AI Act’s high-risk obligations - the rules covering AI in hiring, education, essential services - from 2 August 2026 to 2 December 2027. The EU has already decided these systems are high-risk; it has now also decided they can wait sixteen months. Well… “decided”… after a preparatory process in which, of the 138 invitees to the Commission’s five key “Reality Check” meetings, 114 represented business and nine represented civil society - Corporate Europe Observatory documented this in November 2025.
Lobbying is and remains a huge challenge for the EU. We analysed the Parliament’s Omnibus vote in detail, and the abstention numbers tell their own story. You can find the source for the Reality Check figures here.
The Structural Deficit Map shows what EU digital regulations COMPASS is watching. Screenshot: COMPASS
Three trends inside that frame worry us most. First, Chat Control - the normalisation of the idea that encryption is negotiable, which your readers know better than anyone.
Second, what researchers call algorithmic monocultures in hiring - a topic we have been slightly obsessed with, and one that has barely been mentioned even on LinkedIn, where you would most expect it. When many employers run the same AI screening models, the same candidate gets rejected everywhere by the same statistical judgement, a failure mode the AI Act’s high-risk obligations were built to address - two weeks from now, originally. Until December 2027 the only guardrails are rules that were never designed for that problem, and the Omnibus package offers no interim answer for how Europeans are meant to be protected in the meantime.
And third, a cultural, if not pop-cultural one - the prolific, almost spam-like social sharing of vibe-coding tools and workflows with zero critical assessment of privacy or security risks. You have influencers recommending tools with absolutely no feeling of responsibility should anyone have adverse effects from listening to their advice. The tools are not the problem; lack of critical thought and blind adoption without assessment are - credentials pasted into prompts, generated code shipped unreviewed, a security posture inherited from a tutorial. It truly is not difficult to copy-paste a privacy policy into any LLM and see if there are risks - the problem is that there is no awareness of the need to do it.
Question: What is important for you when it comes to email communication?
Mr. Steiner: There are many critical aspects one can take into consideration when selecting an email provider, especially for their organisation. We can only share what we found most crucial for email communication - that it is secure and private, that trackers, suspicious email addresses or links are either removed or highlighted as a risk, that the UI is easy to use, and that it is European.
We couldn’t be happier with Tuta as our choice. And that is coming with product management experience and an intense twenty-year reliance on email every single day. The main challenge we wanted to resolve was to use one simple, user-friendly and secure solution for all our email addresses - a European solution with an untarnished security and data-protection reputation.”
Question: Why did you choose Tuta Mail instead of another email provider?
Mr. Steiner: When selecting vendors - and it is the same with hosting and other services - we choose the ones that truly align with us in values. We founded COMPASS out of personal conviction, out of love for both technology and Europe, and we value vendors who truly believe in what they do.
Question: What do you like best about Tuta Mail and why is it important?
Mr. Steiner: As a product person, making me select a single favourite feature is like making me pick a favourite flavour of ice cream - they go so well together that I will allow myself three. :) My favourite would be the option of restricting the sharing of sensitive communication with a password. It’s so simple, so elegantly done and such a useful feature when you are sharing something and want to make sure you have that extra layer of security and privacy. A really close second is the heads-up notice when a message comes from an email address that could not be verified. A small drop in focus at the end of a particularly email-intensive day, or one sneaky and intelligent fraud attempt, and in a split second you can make a mistake regardless of how many cybersecurity trainings you’ve had - that simple feature is so beneficial. And, lastly, the peace of mind that our communication is ours - that no marketing is getting tailored based on it, that no model is getting trained on it. It is sad that this is so unique and important in 2026, but it is, and we are grateful for it every day.
Question: Why is it important for you that Tuta Mail end-to-end encrypts all data possible?
Mr. Steiner: With Meta removing end-to-end encryption from Instagram direct messages this May, and Chat Control threatening to jeopardise a feature that not so long ago was simply considered the standard of a high- quality service, it is essential for providers like Tuta to uphold the practices and values we never thought we would see put in question by the very institutions we trusted to guard our privacy. Meta’s stated reason, by the way, was that very few people were opting in - which to me is an argument for better defaults, not for removal.
Now more than ever, end-to-end encryption is essential for democracy, freedom of speech, civic participation and the ability to communicate freely.”
Like many, Andrea and I used to look at what was happening in some other parts of the world and feel fortunate to be Europeans. Watching EU institutions now step back from that standard - and come close to creating a legal market for scanning the private communications of Europeans - is disheartening.
Question: Tuta Mail is often considered to give customers a reputation benefit due to the encryption. Is it the same in your country? How does this benefit COMPASS?
Mr. Steiner: Since Tuta sits behind our own domain, the volunteers, organisations and politicians we communicate with don’t really know what vendors we use - in fact, this interview is us disclosing it publicly, on purpose. Apart, of course, from that one comment where I gushed with pride on LinkedIn, watching you fight to preserve E2EE. I would say it works the other way around - it is an expectation the other party has towards us, because of our public policies and stance on privacy and data protection - and with Tuta, our infrastructure lives up to it. One thing we are careful about as an NGO - we remain fully independent of every vendor and partner, regardless of any relationship we might have. That both ensures we continuously hold you up to your own standards, and that our judgement stays free should we ever notice anything suspicious about any vendor or partner.
Question: What would you say to another organisation considering switching to Tuta?
Mr. Steiner: It is incredibly simple and a pleasure to use. I think most organisations dread the idea of changing vendors, expecting it to be complex, lengthy or incredibly boring - I can testify it is none of those things. We moved our twelve email addresses without drama, and the learning curve is minimal as the UI is fairly straightforward. Of course, as with any new service it takes a day or two to shape muscle memory, but the UI really does make it simple.
Get involved!
Below Robert has shared three ways you can get involved with COMPASS, in ascending order of commitment.
-
Read and share the work - it is public, free, and written to be understood.
-
Volunteer with us - we run a growing EU-wide volunteer programme with real roles (policy research, writing, data, design, grants) and a proper portal, not an inbox where CVs go to die.
-
Support us - COMPASS is in its founding period, independent by design and bootstrapped by necessity, and every contribution goes into the monitoring and education work itself.