On 6 September of this year, the General Court declared the European Data Protection Supervisor’s (EDPS) action to annul two provisions laid down in the new Europol Regulation inadmissible (T-578/22). These two provisions retroactively legalise unlawful data processing activities by the EU Agency for Law Enforcement Cooperation (Europol). While this action for annulment could help in bringing an end to the lengthy saga between the EDPS and Europol, the lack of legal standing seems to imply that the EDPS will have to continue to make ‘the best of it’ by resorting to its (limited) administrative enforcement powers. This blogpost argues that the new Europol Regulation forms a threat to the protection of the fundamental right to data protection, while the EDPS’ possibilities for monitoring and supervising compliance with the EU’s data protection rules remain limited. Furthermore, the separation of powers seems to reduce the EDPS’ possibilities to intervene in the law-making process, which makes it particularly relevant that the EDPS is able to seek legal protection where new legislative initiatives violate the fundamental right to data protection, something that is currently being denied by the General Court.