Skip to main content
Praxikon

Digital Omnibus and the GDPR

What the Digital Omnibus proposal would change in the GDPR

On 19 November 2025 the European Commission proposed a package that, among other things, amends the GDPR and the ePrivacy rules. This is a different file from the Digital Omnibus on AI, adopted as Regulation (EU) 2026/1744. This page follows the GDPR part: what was proposed, what the institutions think of it, and what is and is not settled on the reference date.

Reference date of this layer: 15 September 2026. Every item was checked against its source; the date per item is shown. Anything after the reference date is not yet here.

On the reference date no adopted text was established for this file. Everything below is a proposal or a position in the procedure. Your obligations under the current GDPR do not change because of it yet.

  1. under negotiationRaad van de Europese Unie, Iers voorzitterschapCM 3890/26 (voorlopige agenda Antici-groep vereenvoudiging, 11 september 2026); ST 12535/26 en WK 13065/26 (herziene compromistekst en toelichting, aangekondigd); ST 12955/26 (AOB-nota stand van zaken omnibuspakketten voor Raad Algemene Zaken 22 september 2026); 2025/0360(COD)

    Council: Irish Presidency continues with a revised compromise, Antici Group 11 September 2026

    The provisional agenda of 3 September 2026 (CM 3890/26) schedules an exchange of views on the Presidency revised compromise text for the Digital Omnibus at the Antici Group (Simplification) meeting of 11 September 2026. The Digital Omnibus amends, among other acts, the GDPR (Regulation (EU) 2016/1679). The compromise text ST 12535/26 and the explanatory note WK 13065/26 were still to be issued at that time. In an AOB note of 10 September 2026 (ST 12955/26) the Presidency announces it will brief the General Affairs Council of 22 September 2026 on the state of play of the omnibus packages. File 2025/0360(COD) is listed in that note. These documents do not show a Council mandate.

    What this means: The Council is still negotiating. Expect new compromise texts and possibly a mandate in autumn 2026, but that is not certain. Follow the Antici Group and Coreper agendas for the moment a mandate is confirmed.

  2. under negotiationEuropees Parlement, commissies ITRE en LIBE (gezamenlijke commissie)Procedure 2025/0360(COD); COM(2025)0837; ontwerpverslag PE786.818; amendementen PE786.820, PE790.967, PE790.968, PE791.071, PE791.072, PE791.073, PE791.873, PE791.874, PE791.883

    European Parliament: joint ITRE-LIBE draft report, amendments tabled, no committee vote yet

    The Commission proposal COM(2025)0837 (Digital Omnibus) was published on 19 November 2025; committee referral was announced in Parliament on 19 January 2026. ITRE and LIBE handle the file jointly, with rapporteurs Aura Salla (ITRE, EPP) and Marina Kaljurand (LIBE, S&D), both appointed 25 February 2026. IMCO (rapporteur Alex Agius Saliba) and JURI (rapporteur Brando Benifei) give opinions. The joint draft report PE786.818 is dated 22 June 2026; nine amendment documents were tabled on 27 July 2026. On 15 September 2026 OEIL lists the procedure as Awaiting committee decision: there is no committee vote, no plenary vote and no Parliament position yet.

    What this means: Parliament has no position yet and trilogues with the Council and Commission have not started. The proposed GDPR changes, such as those to the definition of personal data and Article 22, are therefore not law and may still change substantially. Keep working under the current GDPR for now. Because the committee vote, the plenary position and the trilogues are still to come, a final text is not to be expected in the short term.

  3. under negotiationRaad van de Europese Unie, Antici-groep (vereenvoudiging) en CoreperST 10729/26 (nota aan Coreper, 22 juni 2026); ST 10677/26 (compromis 18 juni 2026); procedure 2025/0360(COD)

    Council: Cyprus Presidency tables negotiating mandate, Coreper vote of 26 June 2026 cancelled

    The Antici Group (Simplification) examined the proposal on 16 January, 13 February, 27 February, 24 April, 8 May, 27 May and 15 June 2026; the Presidency tabled five compromise texts. Coreper discussed the file on 8 June 2026 and gave guidance on trade secret protection under the Data Act, the mandatory automated and centralised cookie consent signal and the absence of an impact assessment for it, and flexibility for a national entry point for incidents. On 22 June 2026 the Presidency asked Coreper to confirm the negotiating mandate. The compromise amends fourteen GDPR articles, deletes Article 88a and regulates cookies via Article 5(3) ePrivacy, adds a paragraph 2a to the proposed Article 29a on pseudonymisation, leaves Article 37 GDPR unchanged and amends Article 49 (with recital 40a) for transfers in tax cooperation. According to the EP legislative train, the Coreper vote scheduled for 26 June 2026 was cancelled. As of 15 September 2026 there is no Council general approach or mandate.

    What this means: The Council has no position yet, and Member States differ mainly on pseudonymisation, AI training and cookies. The Council compromises show the final text will likely differ from the Commission proposal, so do not build compliance on the proposal text.

  4. finalEuropees Comité van de Regio'sCOR-2025-04240 (CELEX 52025AR4240)

    Committee of the Regions adopts opinion on the Digital Omnibus

    At its 171st plenary session on 6 and 7 May 2026, the European Committee of the Regions adopted one opinion covering the Data Union Strategy (COM(2025) 835), the Digital Omnibus on AI (COM(2025) 836) and the Digital Omnibus (COM(2025) 837), which amends the GDPR among other acts. The rapporteur is Pehr Granfalk. The Committee supports simplification but asks for proportionality for smaller authorities, and says simplification must remain aligned with privacy and data protection.

    What this means: No direct consequence for you. The opinion is non-binding and is a procedural step in the legislative procedure, which is still ongoing on 15 September 2026.

    EUR-Lex, procedurepagina 2025/0360(COD)checked on 15 September 2026
  5. finalEuropees Economisch en Sociaal ComitéEESC-2025-03929 (CELEX 52025AE3929, PB C, C/2026/3225)

    European Economic and Social Committee adopts opinion on the Digital Omnibus

    On 18 March 2026, at plenary session 604, the EESC unanimously (194 for, 0 against, 0 abstentions) adopted a single opinion on both Digital Omnibus proposals: COM(2025) 837 (including amendments to the GDPR) and COM(2025) 836 (Digital Omnibus on AI). Rapporteur was Heiko Willems, co-rapporteur Angelo Pagliara. The opinion was published in the Official Journal on 2 July 2026 (C/2026/3225). It is an advisory step in ordinary legislative procedure 2025/0360(COD), which is still ongoing.

    What this means: No direct consequence for you. The opinion is not binding and the GDPR remains unchanged until the proposal is adopted.

  6. finalEuropese Centrale BankCON/2026/9 (CELEX 52026AB0009)

    European Central Bank issues opinion on the Digital Omnibus

    On 10 March 2026, at the request of the European Parliament (9 December 2025), the ECB issued an opinion on the Digital Omnibus proposal COM(2025)837. The ECB broadly supports the proposal. It asks for a clearer definition of 'public emergency' for access to private data. It also wants joint controllers to be able to submit a single breach notification through the new single entry point. Finally, it opposes bringing DORA incident reporting into that single entry point.

    What this means: This opinion has no direct legal consequence for controllers or processors. It is a non-binding step in the legislative procedure. The ECB proposal for a single joint breach notification by joint controllers may still shape the final text.

  7. finalEuropean Data Protection Board en European Data Protection SupervisorEDPB-EDPS Joint Opinion 2/2026 (over COM(2025) 837)

    EDPB and EDPS adopt Joint Opinion 2/2026 on the Digital Omnibus

    The Joint Opinion was adopted on 10 February 2026 and published on 11 February 2026. The EDPB and EDPS support simplification but strongly urge the co-legislators not to adopt the change to the definition of personal data. They also consider that an implementing act should not determine when pseudonymised data is no longer personal data. They welcome the research definition, the exception for biometric authentication under the individual's sole control, the higher breach notification threshold and longer deadline, and common templates and DPIA lists, provided the EDPB prepares and approves them itself. They consider a specific provision on legitimate interest for AI (Article 88c) unnecessary. They want to keep the Article 22 prohibition in principle and want abuse of the right of access tied to abusive intent. On cookies they strongly support the aim and suggest an exception for contextual advertising.

    What this means: The opinion is not binding, but it carries significant weight in the legislative negotiations. Expect the definition change and the Article 22 relaxation to be uncertain, while the breach and DPIA simplifications have the supervisors' support. Your current obligations are unchanged.

  8. finalAutoriteit PersoonsgegevensPosition paper AP: Omnibus Digitaal en Omnibus AI (januari 2026)

    Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus

    The AP supports simplification but finds that the omnibus proposals do not strike the right balance with protection, and calls on the legislator to look at them critically. It wants the definition of personal data kept as it is, since uncertainty weakens both protection and supervision. Less transparency and accountability means less effective supervision: the AP wants to keep the current threshold for notifying data breaches. The AI literacy obligation should stay with organisations. Many proposals, such as limiting the right of access for excessive requests and explicitly naming legitimate interest for AI, are in the AP's view so vaguely worded that they do not solve the problems. Positive elements include EU level templates for DPIAs and breach notifications and harmonised cookie rules. The AP announces a joint analysis with the other European data protection authorities.

    What this means: This is the position of your Dutch supervisory authority, not a new rule. The proposals have not been adopted, so the current GDPR still applies: notify data breaches under the current threshold, handle access requests under the current rules and still carry out your own balancing test when relying on legitimate interest for AI. Expect a strict stance from the AP if the definition of personal data or the notification duty is relaxed after all.

  9. proposalEuropese CommissieCOM(2025) 837 final, artikel 3, punt 1, onder a (wijziging artikel 4, punt 1 AVG); 2025/0360(COD); ST 15698/25

    Proposal: relative definition of personal data (Article 4(1) GDPR)

    The proposal adds sentences to the definition of personal data. Information relating to a person is not necessarily personal data for every entity merely because another entity can identify that person. Information is not personal for an entity that cannot identify the person using means reasonably likely to be used by that entity, even if a later recipient has such means. In Joint Opinion 2/2026 of 10 February 2026 the EDPB and EDPS strongly urge the co-legislators not to adopt this change.

    What this means: If adopted, whether pseudonymised data counts as personal data for you would depend on your own means of identification. This may reduce the burden for recipients of pseudonymised datasets, but you would need to document which means you could reasonably use. This is still a proposal; nothing changes today.

  10. proposalEuropese CommissieCOM(2025) 837 final, artikel 3, punt 10 (nieuw artikel 41a AVG); 2025/0360 (COD); ST 15698/25

    Proposal: implementing acts on when pseudonymised data ceases to be personal data (new Article 41a GDPR)

    The Commission may adopt implementing acts specifying means and criteria to determine whether data resulting from pseudonymisation no longer constitutes personal data for certain entities. To do so, it must assess the state of the art and develop criteria or categories that controllers and recipients can use to assess the re-identification risk for typical recipients. Applying those means and criteria may be used as an element to demonstrate that the data cannot lead to re-identification. The EDPB is closely involved and has eight weeks to give an opinion on the draft. Adoption follows the examination procedure of Article 93(3). In Joint Opinion 2/2026 the EDPB and EDPS suggest deleting the article, because such an implementing act would de facto set the material scope of data protection law.

    What this means: If adopted, following the criteria of a Commission implementing act could serve as one element to demonstrate that your pseudonymised data cannot lead to re-identification. It is not conclusive proof, so you still need to document how you applied them. No such criteria exist today, and the Council Presidency compromise of June 2026 removes this power.

  11. proposalEuropese CommissieCOM(2025) 837 final, artikel 3, punt 15 (nieuw artikel 88c AVG); 2025/0360 (COD); ST 15698/25

    Proposal: legitimate interest for development and operation of AI (new Article 88c GDPR)

    Processing of personal data necessary for the interests of the controller in the context of the development and operation of an AI system or AI model may, where appropriate, be pursued for legitimate interests (Article 6(1)(f)). This does not apply where other Union or national laws explicitly require consent, or where the data subject's interests or fundamental rights override, in particular where the data subject is a child. Appropriate organisational and technical measures and safeguards are required, such as data minimisation in source selection, training and testing, protection against disclosure of residually retained data, enhanced transparency and an unconditional right to object. The EDPB and EDPS consider the provision unnecessary (Joint Opinion 2/2026, para. 39) and ask for clarification if it is kept (paras. 40 to 45).

    What this means: If adopted, you would have explicit statutory confirmation that AI development and operation can rely on legitimate interest. You would still need to carry out and document the three-step test case by case, offer an unconditional right to object and be able to honour it technically. The basis would not apply where law requires consent. For children, their interests weigh more heavily in the balancing test, but the basis is not automatically excluded.

  12. proposalEuropese CommissieCOM(2025) 837 final, artikel 3, punt 3 (wijziging artikel 9 AVG); 2025/0360(COD); ST 15698/25

    Proposal: exception for incidental special category data in AI development (Article 9(2)(k) and 9(5) GDPR)

    A new exception to the ban on processing special categories of personal data would cover the development and operation of an AI system or model, provided appropriate technical and organisational measures are taken to avoid collecting or otherwise processing such data. Where such data are nevertheless identified in training, testing or validation datasets or in the AI system or model, the controller must remove them; if removal requires disproportionate effort, the controller must in any event effectively protect them without undue delay from being used to produce outputs and from disclosure to third parties. Recital 33 states the derogation does not apply where special category data are necessary for the processing; Article 9(2)(a) to (j) then applies. The EDPB and EDPS recommend adding the words incidental and residual to the enacting terms (Joint Opinion 2/2026, para 48).

    What this means: If adopted, you would no longer need to fit incidental special category data in AI training into one of the existing Article 9 exceptions. You would need demonstrable filtering measures, a removal process, and documentation of when removal is disproportionate and what protection you apply instead. As of 15 September 2026 this is still a proposal: the Council has no general approach and Parliament no position, so do not rely on it yet.

  13. proposalEuropese CommissieCOM(2025) 837 final, artikel 3, punt 3, onder a (nieuw artikel 9, lid 2, onder l AVG), overweging 34; 2025/0360(COD); ST 15698/25

    Proposal: exception for biometric verification under the data subject's sole control (Article 9(2)(l) GDPR)

    The proposal adds an exception to the ban on processing biometric data. Processing is allowed where it is necessary to confirm a data subject's identity (verification, a one-to-one comparison) and the biometric data or the means needed for verification are under the sole control of the data subject. According to recital 34 this is the case, for example, where the data are stored only on the data subject's side, or stored by the controller in state-of-the-art encrypted form with the key held solely by the data subject. Identification (a one-to-many search in a database) is not covered. In Joint Opinion 2/2026 the EDPB and EDPS welcome the exception, but ask to add necessity and proportionality to the recital, to delete the statement that such processing is not likely to create significant risks, and to include examples of appropriate safeguards.

    What this means: If adopted, you could offer biometric verification (such as fingerprint or face login) without relying on explicit consent as the Article 9 exception, provided the data subject has sole control: storage on the person's own device, badge or smart card, or encrypted storage where only the data subject holds the key. Storing biometric data centrally in the clear or with a key you control would not be covered. You would still need a legal basis under Article 6, must check whether a less intrusive method suffices, and must carry out a risk assessment.

  14. under negotiationEuropese CommissieCOM(2025) 837 final, artikel 3, punten 1(b), 2 en 6; 2025/0360 (COD); ST 15698/25

    Proposal: definition of scientific research, purpose limitation and information duty for research (Article 4(38), 5(1)(b) and 13(5) GDPR)

    The proposal adds a definition of scientific research. It includes research that supports innovation and research that also furthers a commercial interest. Further processing for archiving in the public interest, scientific or historical research or statistics would, in accordance with Article 89(1), be considered compatible with the initial purposes, independent of the conditions of Article 6(4). For research, controllers need not inform data subjects where that is impossible, would involve disproportionate effort, or would render impossible or seriously impair the research. They must then take appropriate measures, including making the information publicly available. The EDPB and EDPS welcome these parts and suggest improvements. As of 15 September 2026 the proposal is still under negotiation; neither Parliament nor the Council has adopted a position.

    What this means: If adopted, reuse of data for research would no longer require a separate compatibility assessment, although the Article 89(1) safeguards would still apply. You could then replace individual information with appropriate measures such as public information. The broad definition would bring commercial research and development more readily within research under the GDPR. For now the current GDPR applies unchanged.

  15. proposalEuropese CommissieCOM(2025) 837 final, 2025/0360(COD), artikel 3, punt 4 (vervanging artikel 12, lid 5 AVG) en overweging 35; Raadsdocument ST 15698/25 van 20 november 2025; EDPB-EDPS Joint Opinion 2/2026, par. 53 t/m 59

    Proposal: refusing requests that abuse the right of access (Article 12(5) GDPR)

    The proposal adds to the existing rule on manifestly unfounded or excessive requests. A controller could refuse, or charge a reasonable fee for, an access request under Article 15 where the data subject abuses the rights conferred by the GDPR for purposes other than protecting their data. The burden of proof stays with the controller. For a manifestly unfounded request the controller must demonstrate it. For an excessive request, reasonable grounds to believe it is excessive would suffice. Recital 35 gives examples of abuse. A data subject provokes a refusal in order to claim compensation. A data subject makes requests only to harm the controller. Or a data subject offers to withdraw the request in return for a benefit. According to that recital, overly broad and undifferentiated requests are also excessive. In Joint Opinion 2/2026 the EDPB and EDPS want abuse tied to an abusive intention, such as an evident intention to cause harm, rather than to the purpose of the request, since the Court of Justice has confirmed that access may be sought for other purposes. They also recommend removing the lower burden of proof threshold and the statement on overly broad requests.

    What this means: If adopted, you would gain an express ground to refuse access requests that do not serve to protect personal data, such as requests designed to provoke a damages claim. Your evidence of excessiveness would face a lower threshold. You would still need to substantiate and document the abuse case by case. The wording may still change before adoption, particularly if the EDPB and EDPS criticism is taken on board. Until then the current GDPR applies as interpreted by the Court. The purpose of a request does not in principle make it invalid (C-307/22). Since Brillen Rottler (C-526/24, 19 March 2026), however, you may refuse a request as excessive, even a first one, if you show it was made solely to artificially create a compensation claim. As of 15 September 2026 the European Parliament has not voted in committee. The ITRE and LIBE draft report dates from 22 June 2026.

  16. proposalEuropese CommissieCOM(2025) 837 final, artikel 3, punt 5 (wijziging artikel 13, lid 4 AVG); ST 15698/25; 2025/0360 (COD)

    Proposal: no information duty in clear, non data-intensive relationships (Article 13(4) GDPR)

    Controllers would not need to provide Article 13 information where data are collected in a clear and circumscribed relationship, the activity is not data-intensive and there are reasonable grounds to assume the data subject already has the controller's identity and contact details and the purposes. The exemption would not apply where data are transmitted to other recipients or a third country, automated decision-making including profiling is carried out or the processing is likely to result in a high risk within the meaning of Article 35. Recital 36 gives a craftsman and their clients, and associations and sports clubs, as examples. In Joint Opinion 2/2026 of 10 February 2026 the EDPB and EDPS support the direction but ask for sharper definitions of not data-intensive activity and clear and circumscribed relationship, removal of reasonable grounds to assume, and a right to receive the full information on request. As of 15 September 2026 this is still a proposal: the European Parliament committee vote has not taken place and the Council has no mandate yet.

    What this means: If adopted, small service providers such as a craftsman or a plumber could omit a privacy notice for simple customer contacts. As soon as you share data with other recipients, transfer it outside the EU, profile or carry out high risk processing, you would still have to inform. The Article 15 right of access remains. The threshold of not data-intensive is still unclear, and according to Recital 36 employment relationships do not qualify.

  17. proposalEuropese CommissieCOM(2025) 837 final, artikel 3, punt 7 (vervanging artikel 22, leden 1 en 2 AVG); 2025/0360(COD); ST 15698/25

    Proposal: reformulation of automated individual decision-making (Article 22 GDPR)

    Article 22 would no longer be framed as a right not to be subject to an automated decision. It becomes an exhaustive list of cases where such a decision is allowed: where necessary for entering into or performing a contract (regardless of whether the decision could be taken otherwise than by solely automated means), where authorised by Union or Member State law with suitable safeguards, or where based on explicit consent. Recital 38 says the fact that a human could take the decision does not prevent solely automated processing, but where several equally effective solutions exist the least intrusive must be used. The EDPB and EDPS (Joint Opinion 2/2026, paras 65 to 72) want to keep the wording of a prohibition in principle, as the CJEU held in SCHUFA (C-634/21). They support the clarification on contracts but want the phrase 'regardless of whether the decision could be taken otherwise' kept only in the recital, not in the enacting terms. The European Parliament is building its position through a joint ITRE and LIBE draft report of 22 June 2026; no committee vote has taken place.

    What this means: If the Commission text survives, you could more easily justify fully automated decisions in a contractual context, even where a human could have taken the decision. The Article 22(3) safeguards (human intervention, expressing a view, contesting) remain. The supervisory authorities also accept that the mere possibility of a human decision is no obstacle. They do insist that you choose the least intrusive equally effective means and that the prohibition stays the starting point. The proposal is still under negotiation, so do not adjust your decision-making to it yet.

  18. proposalEuropese CommissieCOM(2025) 837 final, 2025/0360 (COD), artikel 3, punt 8 (wijziging artikel 33 AVG), artikel 3, punt 14 (nieuw punt (hc) in artikel 70, lid 1 AVG) en artikel 6, punt 1 (nieuw artikel 23a NIS2); Raadsdocument ST 15698/25

    Proposal: breach notification only for high risk, within 96 hours, via a single entry point (Article 33 GDPR)

    Notification to the supervisory authority would be required only for breaches likely to result in a high risk (currently: unless unlikely to result in a risk). The deadline moves from 72 to 96 hours. Notification would go through an EU single entry point run by ENISA under NIS2; until it exists, controllers notify the authority directly. The EDPB would propose a common template and a list of high-risk circumstances, adopted by the Commission by implementing act and reviewed at least every three years. The EDPB and EDPS (Joint Opinion 2/2026 of 10 February 2026) welcome the higher threshold, the longer deadline and the entry point, but want the EDPB itself to prepare and approve the template and list.

    What this means: If adopted, you would notify fewer breaches and have an extra day. You would need to justify why a breach is not high risk; the internal register duty of Article 33(5) remains. The duty to inform data subjects in high-risk cases (Article 34) is unchanged. Today the 72-hour deadline and the low threshold still apply: as of 15 September 2026 this is still a proposal, with no Council or Parliament position and no trilogue.

  19. proposalEuropese CommissieCOM(2025) 837 final, artikel 3, punten 9 en 11 tot 14 (wijziging artikel 35, 57, 64 en 70 AVG); ST 15698/25; 2025/0360 (COD)

    Proposal: EU-wide DPIA lists, template and methodology (Articles 35, 57, 64 and 70 GDPR)

    National lists of processing operations requiring or not requiring a DPIA would be replaced by EU-wide lists. Within nine months of the amending regulation becoming applicable, the EDPB would propose the lists, a common template and a methodology. The Commission would adopt them by implementing act and review them at least every three years. Existing national lists, such as the Dutch AP list, remain valid until the implementing act is adopted. The power of national authorities to set lists (Article 57(1)(k)) and the related consistency procedure (Article 64(1)(a)) are removed.

    What this means: If adopted, you would work with the same DPIA list and template in every Member State, simplifying work for cross-border organisations. Until the implementing act exists, the Dutch AP list remains authoritative. You may later need to align your own DPIA methodology with the EU template.

  20. under negotiationEuropese CommissieCOM(2025) 837 final, artikel 3, punt 15 (nieuw artikel 88a AVG) en artikel 5 (wijziging artikel 5, lid 3 en schrapping artikel 4 richtlijn 2002/58/EG); ST 15698/25; 2025/0360(COD)

    Proposal: cookie rules move from ePrivacy to the GDPR, with new exceptions and a six-month rule (new Article 88a GDPR and Article 5(3) ePrivacy)

    Storing or accessing personal data in a natural person's terminal equipment would be governed by the GDPR and require consent, unless necessary for transmitting a communication, a service explicitly requested by the data subject, aggregated audience measurement by the controller solely for its own use, or security. Refusal must be possible with a single-click button or equivalent means; after a refusal no new consent request for the same purpose may be made for at least six months. Article 5(3) ePrivacy would no longer apply where the user is a natural person and personal data are involved; Article 4 ePrivacy (security) is deleted. Article 88a would apply six months after entry into force. In Joint Opinion 2/2026 of 10 February 2026 the EDPB and EDPS support the aim, warn that splitting the rules over different instruments creates legal uncertainty and suggest an extra exception for contextual advertising. The Council Presidency compromise of 22 June 2026 deletes Article 88a; no text has been adopted.

    What this means: If adopted, you could set first-party audience measurement and security cookies without consent and would need to redesign your banner: single-click refusal and a pause of at least six months after refusal. Supervision would sit with the GDPR authority. For personal data of natural persons the Dutch legal basis would move from the Telecommunications Act (Article 11.7a) to the GDPR; for other data and legal persons Article 11.7a would remain. The Council is considering keeping the rules in the ePrivacy Directive instead, so the outcome is uncertain. Today the current cookie rules apply in full.

  21. under negotiationEuropese CommissieCOM(2025) 837 final, 2025/0360 (COD), artikel 3, punt 15 (nieuw artikel 88b AVG); ST 15698/25

    Proposal: consent and objection via machine-readable browser signals (new Article 88b GDPR)

    Controllers would have to ensure their online interfaces accept consent, refusal and objection (Article 21(2)) through automated, machine-readable means, and must respect those choices. Media service providers are exempt when providing a media service. The Commission would request European standardisation organisations to draft standards; conformity with a harmonised standard gives a presumption of compliance. The obligation for controllers would apply 24 months after entry into force; web browser providers that are not SMEs would have to offer the technical means after 48 months. On 8 June 2026 Coreper gave guidance for further work specifically on this centralised consent signal for cookies and on the absence of an impact assessment for it.

    What this means: If adopted, your website or app would have to read and honour browser signals within two years of entry into force, and could not ignore a browser-level refusal. Your consent management tool would need updating. Media service providers are exempt. This element is still under discussion in the Council, so the final text may differ.

  22. proposalEuropese CommissieCOM(2025) 837 final; SWD(2025) 836 final; procedure 2025/0360(COD)

    Commission publishes Digital Omnibus proposal COM(2025) 837

    On 19 November 2025 the Commission adopted the Digital Omnibus proposal. It amends among others the GDPR (Regulation (EU) 2016/679), the EUDPR (2018/1725), the Single Digital Gateway Regulation (2018/1724), the Data Act (2023/2854), the ePrivacy Directive (2002/58/EC), NIS2 and CER. It repeals the Data Governance Act, the P2B Regulation, the Free Flow of Non-Personal Data Regulation and the Open Data Directive. It is a separate file from the Digital Omnibus on AI (2025/0359(COD)), which was adopted as Regulation (EU) 2026/1744 and does not amend the GDPR. The referral to the ITRE and LIBE committees was announced in Parliament on 19 January 2026, and the file is still at committee stage there.

    What this means: The proposal itself changes nothing for you. It marks the start of the legislative procedure in which the GDPR amendments above are negotiated. Expect the final text to differ materially from this proposal.

Looking for the Digital Omnibus on AI? To the AI omnibus (Regulation (EU) 2026/1744)