In short: On 19 November 2025, the European Commission published the Digital Omnibus package. 6 GDPR changes to watch and what businesses should do now.
Introduction
On 19 November 2025, the European Commission published the "Digital Omnibus" legislative package, the first serious review of the EU's digital legal framework since the GDPR and the AI Act came into force.
The official aim: simplification, reducing the administrative burden, and supporting innovation and AI.
Digital Omnibus (Data Omnibus) – amends:
- the GDPR,
- the Data Act,
- the Data Governance Act,
- the Regulation on the free flow of non-personal data,
- the Open Data Directive.
Digital Omnibus on AI (AI Omnibus) – amends the AI Act, in particular:
- the deadlines for high-risk AI obligations,
- some documentation obligations,
- the role of the AI Office and its interaction with other EU laws.
These are part of a broader "digital package", which includes:
- the Data Union Strategy,
- a proposal for a Regulation on European Business Wallets,
- model clauses and standard contractual clauses for cloud and data sharing,
- a Digital Fitness Check that will assess the entire "digital rulebook" and may pave the way for further changes after 2026.
Important: this is not yet law – negotiations follow (Parliament, Council, trilogues), which may take many months or even years.
3. GDPR & privacy: 6 changes to watch
3.1. "Legitimate interest" for AI training becomes explicit
The proposal introduces into the GDPR a recital clarifying that legitimate interest can be a legal basis for:
- training AI models,
- subsequent AI uses,
- including large-scale data analysis, provided that the existing safeguards are respected (proportionality, minimisation, data subject rights, etc.).
In addition, a new exception is proposed under Article 9, which would allow the processing of special categories of data (e.g. health, biometric data) for detecting and correcting bias in AI systems, under strict conditions and adequate safeguards.
Practical implications:
- mapping the AI uses in your organisation (where you train models, what data you use, where it comes from, what rights apply);
- updating LIAs (Legitimate Interest Assessments) for the relevant AI scenarios;
- defining clear opt-out and transparency mechanisms towards data subjects.
3.2. Redefining "personal data" (and more room for non-personal data)
Digital Omnibus proposes a clarification of the definition of personal data, inspired by CJEU case law (the SRB case):
- data is personal for a controller only if it could reasonably identify the person, using the means it is likely to have access to;
- the fact that someone else (a future recipient, another authority) could identify the person does not automatically turn the data into "personal" for you.
For businesses, this could mean more room for:
- aggregated or pseudonymised datasets,
- B2B data sharing / sharing with authorities,
- certain analytics scenarios where you don't realistically hold the re-identification key.
But beware:
- the risk of "indirect re-identification" remains;
- DPAs will likely have their own guidelines – and excessive optimism here can lead to investigations.
3.3. Cookies and privacy signals – fewer banners, new rules
On cookies and ePrivacy, Digital Omnibus proposes:
- new exceptions to consent, including for:
- first-party cookies/statistics,
- certain security-related uses;
- an obligation for operators to respect preferences expressed through an automated signal (e.g. from the browser or operating system) – a kind of European "privacy signal";
- moving part of the rules on access to devices from ePrivacy into the GDPR, with broader exceptions.
The Commission's promise: fewer pop-ups and one-click decisions, preferences valid for 6 months, and more control at the browser level.
Critics (EDRi, NOYB) argue, however, that:
- the exceptions are too broad and allow tracking without consent in more scenarios;
- shifting the focus to browser signals may reinforce the power of the large platforms that control these interfaces;
- the risk is that ePrivacy protections will be "diluted".
What this means for you:
- a serious discussion with the marketing/legal/IT teams about a post-Omnibus cookie strategy;
- choosing a CMP/CMS (Consent Management Platform) capable of handling automated signals (similar to GPC);
- reviewing your analytics settings (especially first-party ones) to take advantage of the permitted exceptions, but without losing users' trust.
3.4. Breach reporting: from 72 to 96 hours and clearer thresholds
In the GDPR, the current deadline for notifying the supervisory authority is "without undue delay and, where feasible, not later than 72 hours".
Digital Omnibus proposes:
- extending this to 96 hours,
- setting a clearer and higher threshold for defining when an incident must be notified;
- For security and data protection teams: extending the deadline provides additional time for analysis and triage, but the responsibility to maintain a robust incident response process and rigorous documentation remains unchanged.
3.5. A single portal for incidents and an extended "one-stop-shop"
On cybersecurity, the Omnibus proposes a "single entry point" at EU level for incident notifications, managed by ENISA. The idea is that a single set of information could cover the requirements from: the GDPR, NIS2, DORA, CER, eIDAS, etc.
Potential benefits:
- less duplicated work,
- more consistency in what you report to whom.
Challenges:
- integration into internal processes (who notifies, how you aggregate the information),
- the risk that a "trivial" incident reported generically reaches more authorities than you'd want.
3.6. DSARs and "abuse of rights"
Digital Omnibus introduces a provision allowing controllers to refuse certain access requests (DSARs) when they are assessed as constituting an "abuse of rights" within the meaning of the GDPR.
For example, the following may be considered abusive:
- situations in employment disputes where access requests are used solely as a tool for evidentiary "fishing", with no real connection to the exercise of the data subject's rights;
- the repeated submission of identical requests, without a legitimate purpose or without any new elements that would justify the request.
However, the notion of "abuse of rights" is not exhaustively defined, and the supervisory authorities will still have the final say in assessing whether a request is abusive.
Implications:
- it is a useful tool, but it must be used with care – decisions to refuse should be: well documented, legally reviewed, and supported by a clear internal policy on abusive DSARs.
See where you stand, in a few minutes: on the
askGDPR.ro platform you can run a
free self-assessment of your GDPR compliance and
chat with an AI assistant about data protection. The platform generates and keeps your records up to date (ROPA, LIA, DPIA) and covers document review, website security analysis, privacy and cookie policies, training management, compliance questionnaires, DPO details and the relationship with the supervisory authority (ANSPDCP), an incident register, security measures and international transfers.
4. AI Act: more time, but not less responsibility
On the AI side, Digital Omnibus:
- postpones the application of obligations for high-risk AI systems:
- for many of the systems in Annex III, the deadline moves from August 2026 to December 2027,
- for other systems, until August 2028;
- extends the simplified compliance regime to "small mid-cap" companies as well (not only SMEs);
- removes the AI literacy obligation directly from the text of the AI Act (although Member States and the Commission are encouraged to continue promoting it);
- strengthens the role of the AI Office for GPAI models and for AI used in very large platforms;
- clarifies that certain processing of sensitive data is permitted for detecting and correcting bias in AI, under strict safeguards.
In practice: this is not the time to halt AI compliance projects, but rather to use the time gained for:
- documenting processes,
- assessing AI risks,
- coordinating between the DPO, the CISO and the technical teams.
5. Why the package is so controversial
The European Commission's narrative
The Commission presents the "Digital Omnibus" package as a targeted intervention, not as a reopening of the GDPR. Its stated objective is to adjust the existing framework in line with CJEU case law and EDPB recommendations, maintaining high data protection standards while reducing regulatory complexity and facilitating innovation, especially in the AI space.
The critics' narrative (EDRi, NOYB, a segment of MEPs)
Critical voices argue that the proposal marks a significant regression in digital protections and that it reopens the pillars of the GDPR, ePrivacy and the AI Act without a solid impact assessment. In their view, the package primarily benefits big tech companies, to the detriment of SMEs, and shifts the focus from fundamental rights towards considerations of competitiveness and geopolitical influence.
The industry perspective
Technology-sector associations and the business community welcome the package as a step towards simplification, but consider it insufficiently ambitious, calling for deeper reforms, including on the uneven application of the GDPR across Member States.
In reality, the final positioning will take shape over the coming period, in the negotiations between Parliament, the Council and the Commission.
6. What should already be done (even if the text is not final)
This is not the time to completely rewrite internal policies, but there are strategic measures that can be prepared in advance:
Monitor developments
- follow the updated versions of the proposals and the reactions of the EDPB and national authorities;
- if you operate in several Member States, monitor the positions of each supervisory authority.
Take stock of your AI uses
- identify the areas where you use personal data for AI training or scoring;
- review the existing legal bases and the scenarios where a strengthened legitimate interest could apply;
- ensure transparency and genuine opt-out options for data subjects.
Build a "post-banner" strategy for cookies
- discuss with the marketing and product teams about the user experience in a scenario where the browser sends a privacy signal;
- check whether your analytics, adtech and CMP providers can handle such signals;
- plan a gradual shift towards more first-party data and less intrusive tracking.
Optimise your incident response procedures
- align your reporting workflows across the GDPR, NIS2, DORA and other applicable regulations;
- design a process that can adapt to a single notification portal;
- define the responsibilities and internal criteria for the reporting threshold.
Update your DSAR governance
- define clear criteria for identifying potentially abusive requests, without affecting the legitimate exercise of rights;
- implement a dual-review mechanism (DPO + legal) before refusing a request.
Review your data classification
- carry out a clear mapping of personal, non-personal and "borderline" data (pseudonymised, aggregated);
- document the reasoning for the data considered non-personal, following the logic of "the means reasonably likely to be used for identification".
7. Conclusion
Digital Omnibus is not just a marginal adjustment, but an important recalibration of the European digital architecture. Although still at the proposal stage, the direction of travel is visible:
- greater flexibility for the use of data and AI;
- procedural simplification through consolidated rules and single reporting mechanisms;
- an essential debate about the limits of relaxing the rules without compromising fundamental rights.
From a data protection and security perspective, the mature approach is to treat Digital Omnibus as an early signal: you don't change everything now, but you calibrate your processes, data architectures and governance so that you can quickly integrate the new requirements, regardless of the final form of the text.
Frequently asked questions
What is the Digital Omnibus package?
It is a legislative package published by the European Commission on 19 November 2025, the first serious review of the EU's digital legal framework since the GDPR and the AI Act. Its stated aim is simplification, reducing the administrative burden, and supporting innovation and AI. The package has a "Data Omnibus" component (amending the GDPR, the Data Act, the Data Governance Act and other acts) and an "Omnibus on AI" component (amending the AI Act).
What would change in the GDPR?
The article outlines 6 changes to watch: legitimate interest becomes an explicit basis for AI training; a redefinition of "personal data" with more room for non-personal data; new rules for cookies and a European "privacy signal"; extending the breach notification deadline from 72 to 96 hours with clearer thresholds; a single EU portal for incidents, managed by ENISA; and the option to refuse access requests (DSARs) assessed as an "abuse of rights".
When does it enter into force and is it final?
No. For now it is only a proposal from the European Commission, not law. Negotiations between the Parliament, the Council and the Commission (trilogues) follow, which may take many months or even years, and the final text may change. For the AI Act, the proposal postpones some deadlines (for example, many high-risk systems in Annex III would move from August 2026 to December 2027).
What should businesses do now?
This is not the time to fully rewrite policies, but to prepare strategically: monitor developments and the EDPB's reactions; take stock of your AI uses and update your LIAs; build a "post-banner" cookie strategy; align your incident response procedures across the GDPR, NIS2 and DORA; update your DSAR governance; and review the classification of personal, non-personal and "borderline" data.
Want to prepare your organisation for the GDPR changes?
We help you calibrate your processes, LIAs and data governance before the text becomes law.