The Digital Omnibus on data: what would change in the GDPR and why it is still stuck

The Digital Omnibus on data is the proposal through which the European Commission aims to simplify the EU’s data, privacy and cybersecurity rules. Its reference is COM(2025) 837 and it was presented on 19 November 2025. It would amend the GDPR, the Data Act, the ePrivacy Directive and the NIS2 Directive, and would repeal four laws outright. As things stand it is not law and creates no obligations. The file has been stuck in the Council since the Cypriot Presidency withdrew its compromise text on 30 June 2026 for lack of a qualified majority. It is worth knowing what it contains, because it will shape the next decade of European digital law, and it is worth knowing that there is no need to act yet.

If you need data protection advice for your business, request a free initial assessment.

Table of contents

What the Digital Omnibus on data is and how it differs from the AI one

There are two digital omnibuses and they are constantly confused. The Commission presented both on the same day, with consecutive numbers, and only one has become law. Telling them apart comes first, because their legal status is opposite.

AspectAI OmnibusOmnibus on data
ProposalCOM(2025) 836COM(2025) 837
Laws affectedAI ActGDPR, Data Act, ePrivacy and NIS2
StatusAdopted. Regulation (EU) 2026/1744, in force since 27 July 2026Under negotiation, no Council common position
Effect on your businessAlready mandatoryNone yet

The AI omnibus went through separately and was adopted in eight months. It reorganised the AI Act timeline and left the transparency obligations untouched, as we explain in our analysis of AI transparency obligations for businesses. The data omnibus has gone the opposite way.

Where the legislative process stands

The Digital Omnibus on data has no Council common position. The Cypriot Presidency withdrew its compromise text on 30 June 2026 when it became clear that it did not have a qualified majority among the Member States. The Irish Presidency reopened consultations in July, tabled revised compromise texts in September and put the file to Member States’ ambassadors (Coreper) on 7 October 2026 with a view to adopting a negotiating mandate with the European Parliament.

DateMilestone
19 November 2025The Commission presents proposal COM(2025) 837
11 February 2026The European Data Protection Board and the European Data Protection Supervisor adopt Joint Opinion 2/2026
20 February 2026The Cypriot Presidency’s compromise text emerges, deleting the new definition of personal data
30 June 2026Cyprus withdraws its text for lack of a qualified majority
1 July 2026Ireland takes over the Council Presidency
16 July 2026The Simplification working party examines the file and Member States are consulted on pseudonymised data, processing for AI and consent exemptions for cookies
7 October 2026The Irish Presidency’s updated compromise goes to Coreper with a view to a negotiating mandate

Joint Opinion 2/2026 supported the aim of simplification, but warned that the new definition of personal data should say what personal data is, not what it stops being. That objection proved decisive. The Cypriot compromise ended up removing the definition from the text.

The practical consequence is that none of the changes below is settled. Any of them could disappear or change shape before the final vote.

The changes it proposes to the GDPR

The proposal touches the core of the regulation, not its edges. It redefines what personal data is, creates a new legal basis for artificial intelligence and moves the rules on cookies, which currently sit in the ePrivacy Directive, into the GDPR. They are the most far-reaching amendments since 2016.

The definition of personal data would depend on who processes the data

Article 4(1) would no longer apply in absolute terms. Information would not be personal data for a given entity if that entity cannot identify the data subject using means reasonably likely to be used by it. The analysis shifts to the real capabilities of each controller, not those of any conceivable third party.

For a company working with pseudonymised data the effect would be enormous. The same dataset could fall outside the GDPR in its hands and inside it in its provider’s. It is also the point that has met the most resistance and the first one the Council removed from its text.

Legitimate interest as a basis for training and operating AI systems

A new Article 88c would recognise legitimate interest as a legal basis for developing and operating artificial intelligence systems. It would not be automatic. It would require a real, lawful and specific interest, processing necessary to achieve it and a balancing test in which the data subject’s rights do not override it.

It would come with reinforced safeguards, specific impact assessments and an unconditional right to object. The proposal also adds an exception for sensitive data that appears residually in training datasets, provided the controller takes measures to avoid collecting it and deletes what it detects.

Cookies would move from ePrivacy into the GDPR

Storing and accessing information on the user’s device would be regulated within the GDPR. Refusal would have to be possible with a single click or an equivalent means. In the Commission’s proposal, a refusal would open a six-month cooling-off period during which the user could not be asked again.

The change with the greatest technical reach is another one. Controllers would have to respect automated, machine-readable signals, so that users can express their preference once in the browser instead of banner by banner.

Breach notification would go from 72 to 96 hours

The deadline for notifying a personal data breach would be extended to 96 hours where there is a likely high risk. Notification would also be made through a single entry point created under the NIS2 Directive, with a common template proposed by the European Data Protection Board.

The aim is to end multiple notifications. Today the same incident may have to be reported separately to the data protection authority, the cybersecurity authority and, in the financial sector, the supervisor under DORA. The single entry point would bring those three channels together. If you operate under the NIS2 Directive, this is the change that would affect you most.

The four laws the Data Act would absorb

The proposal brings data regulation together in a single text. It folds the useful content of four laws into the Data Act and repeals them, on the basis that they duplicate obligations or have become obsolete.

Law repealedReason
Regulation (EU) 2022/868, the Data Governance ActIts content is integrated into the Data Act
Directive (EU) 2019/1024, on open dataIts content is integrated into the Data Act
Regulation (EU) 2019/1150, on platform-to-business relationsConsidered absorbed by the Digital Services Act
Regulation (EU) 2018/1807, on the free flow of non-personal dataConsidered obsolete

For a company that reuses public sector data or acts as an intermediary for third-party data, this means its obligations would move to a different reference law without disappearing. The full picture of which digital rules affect you today is in our guide to the digital regulatory framework in Spain and the European Union.

What a Spanish company should do in the meantime

Nothing that involves redoing processes. The current GDPR applies in full and without qualification until the Omnibus is adopted and published, which will not happen before 2027 even in the best-case scenario. Getting ahead of a text that the Council has already changed twice is a waste of budget.

It does make sense to prepare the ground with decisions that are useful under the current rules and will remain so under the future ones.

  1. Document which datasets you hold in pseudonymised form and by what means you could re-identify them
  2. Check whether your AI-related processing has a solid legal basis today, without counting on the future Article 88c
  3. Check that your cookie banner makes refusing as easy as accepting, which is already required
  4. Time your internal breach procedure against the current 72-hour deadline, not the proposed 96 hours
  5. Keep an eye on the file over the coming months, because the Irish Presidency wants to make progress before the end of the year

Example: a company that was about to rebuild its cookie banner

An e-commerce platform based in Valencia, which we will call Vertia, budgeted in the spring for a complete overhaul of its consent system. The idea was to get ahead of the six-month cooling-off period and the automated browser signals announced in the proposal.

It would have spent the budget on a regime that still does not exist and that the Council has been negotiating again since July. The sensible decision is the opposite. Bring the banner into line with what current law and the Spanish Data Protection Agency (AEPD) already require, and leave the architecture ready to accept automated signals on the day they are adopted.

In data protection, this mistake is common when a European proposal receives a lot of coverage. A Commission proposal is not law, and more falls by the wayside between presentation and publication in the Official Journal than people think. The prudent approach is always to distinguish between what is already binding and what is only written in a working document.

Has the Digital Omnibus already been adopted?

The AI one has: it is Regulation (EU) 2026/1744 and has been in force since 27 July 2026. The data one, which amends the GDPR, has not. It is still under negotiation and the Council has not yet reached a common position.

Not because of the Omnibus. None of its changes is enforceable yet. It is worth checking that you comply with the current rules, above all that refusing cookies is as easy as accepting them, because that is already required and is a frequent ground for complaints.

Under the current proposal, yes, through the new Article 88c, but that article does not exist yet. Today you need a legal basis under Article 6 GDPR and a documented balancing test. Building a project around a law that has not been adopted means taking on an unnecessary risk.

There is no date. The Irish Presidency aims to secure a Council negotiating mandate and to make progress with the European Parliament before the end of 2026, but the file has already been derailed once. Even if an agreement were reached this year, publication and entry into application would take several more months.

If your company processes personal data at scale, develops artificial intelligence systems or is designing its consent architecture now, it pays to decide carefully what to do today and what is better left to wait. At Innovatech we follow the file closely and help separate the real obligation from what is still only a proposal. Tell us about your case and we will review it.

Managing Partner at Innovatech Legal | Website | + posts

Marta Suárez-Mansilla is Managing Partner of Innovatech Legal and a Spanish lawyer (abogada), Madrid Bar (ICAM), working in technology law. She completed Harvard Law School's Copyright course and BerkeleyX's Blockchain programme, and has advised technology companies for more than eight years.