Legislation in motion
Council: Cyprus Presidency tables negotiating mandate, Coreper vote of 26 June 2026 cancelled
- Date
- Status
- under negotiation
- Body
- Raad van de Europese Unie, Antici-groep (vereenvoudiging) en Coreper
- Reference
- ST 10729/26 (nota aan Coreper, 22 juni 2026); ST 10677/26 (compromis 18 juni 2026); procedure 2025/0360(COD)
What it is about
The Antici Group (Simplification) examined the proposal on 16 January, 13 February, 27 February, 24 April, 8 May, 27 May and 15 June 2026; the Presidency tabled five compromise texts. Coreper discussed the file on 8 June 2026 and gave guidance on trade secret protection under the Data Act, the mandatory automated and centralised cookie consent signal and the absence of an impact assessment for it, and flexibility for a national entry point for incidents. On 22 June 2026 the Presidency asked Coreper to confirm the negotiating mandate. The compromise amends fourteen GDPR articles, deletes Article 88a and regulates cookies via Article 5(3) ePrivacy, adds a paragraph 2a to the proposed Article 29a on pseudonymisation, leaves Article 37 GDPR unchanged and amends Article 49 (with recital 40a) for transfers in tax cooperation. According to the EP legislative train, the Coreper vote scheduled for 26 June 2026 was cancelled. As of 15 September 2026 there is no Council general approach or mandate.
What this means in practice
The Council has no position yet, and Member States differ mainly on pseudonymisation, AI training and cookies. The Council compromises show the final text will likely differ from the Commission proposal, so do not build compliance on the proposal text.
The GDPR articles concerned
- Article 4: Definitions
- Article 5: Principles relating to processing of personal data
- Article 9: Processing of special categories of personal data
- Article 12: Transparent information, communication and modalities for the exercise of the rights of the data subject
- Article 13: Information to be provided where personal data are collected from the data subject
- Article 22: Automated individual decision-making, including profiling
- Article 25: Data protection by design and by default
- Article 29: Processing under the authority of the controller or processor
- Article 33: Notification of a personal data breach to the supervisory authority
- Article 35: Data protection impact assessment
- Article 37: Designation of the data protection officer
- Article 49: Derogations for specific situations
- Article 57: Tasks
- Article 64: Opinion of the Board
- Article 70: Tasks of the Board
- Article 88: Processing in the context of employment
Source: Raad van de EU, register (ST 10729/26)checked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Part of the file
Themes where this returns
- Assessing risks in advance: DPIA and FRIA
- Automated decisions and human oversight
- Biometrics and emotion recognition
- Data quality, minimisation and data governance
- Keeping records: record of processing, technical documentation and logs
- Knowledge in the organisation: data protection officer and AI literacy
- Privacy by design and risk management by design
- Reporting: data breaches and serious incidents
- Rights of people: access and explanation of decisions
- Transparency: informing people
- Using special categories of personal data to detect bias
- Who is responsible: roles in both laws
The counterpart in the other law
- Article 2 AI Act: Scope
via Using special categories of personal data to detect bias
- Article 3 AI Act: Definitions
- Article 4 AI Act: AI literacy
via Knowledge in the organisation: data protection officer and AI literacy
- Article 5 AI Act: Prohibited AI practices
- Article 6 AI Act: Classification rules for high-risk AI systems
- Article 9 AI Act: Risk management system
- Article 10 AI Act: Data and data governance
- Article 11 AI Act: Technical documentation
via Keeping records: record of processing, technical documentation and logs
- Article 12 AI Act: Record-keeping
via Keeping records: record of processing, technical documentation and logs
- Article 14 AI Act: Human oversight
- Article 16 AI Act: Obligations of providers of high-risk AI systems
- Article 18 AI Act: Documentation keeping
via Keeping records: record of processing, technical documentation and logs
- Article 19 AI Act: Automatically generated logs
via Keeping records: record of processing, technical documentation and logs
- Article 25 AI Act: Responsibilities along the AI value chain
- Article 26 AI Act: Obligations of deployers of high-risk AI systems
- Article 27 AI Act: Fundamental rights impact assessment for high-risk AI systems
- Article 50 AI Act: Transparency obligations for providers and deployers of certain AI systems
- Article 73 AI Act: Reporting of serious incidents
- Article 86 AI Act: Right to explanation of individual decision-making
Case law8 of 21
- Schrems v Meta: no unlimited retention and aggregation of data for targeted advertising
2024-10-04 · final, Hof van Justitie van de EU (Vierde kamer), Maximilian Schrems tegen Meta Platforms Ireland Limited
- Council of State: 600,000 euro fine for wifi tracking in Enschede stays annulled
2026-07-29 · final, Raad van State, Afdeling bestuursrechtspraak
- EDPS v SRB: pseudonymised data are not always personal data for everyone, but the information duty applies from collection
2025-09-04 · final, Hof van Justitie van de EU (Eerste kamer), Europese Toezichthouder voor gegevensbescherming (EDPS) tegen Gemeenschappelijke Afwikkelingsraad (SRB)
- Gelderland District Court: bankruptcy trustee is controller, DPA fine for unsecured hard drive cut to 58,125 euros
2025-08-07 · status not established, Rechtbank Gelderland
- Dun & Bradstreet: right to an intelligible explanation of an automated decision, trade secrets are no absolute ground for refusal
2025-02-27 · final, Hof van Justitie van de EU (Eerste kamer), CK tegen Magistrat der Stadt Wien, met Dun & Bradstreet Austria GmbH als andere partij
- Overijssel District Court revokes DPA fine for wifi tracking in Enschede
2024-02-02 · final, Rechtbank Overijssel
- SCHUFA: a credit score on which third parties draw strongly is automated decision-making
2023-12-07 · final, Hof van Justitie van de EU (Eerste kamer), OQ tegen Land Hessen, met SCHUFA Holding AG als interveniënt
- Interim relief judge: DPA must redact fine amount when giving an enforcement decision to complainants
2024-05-31 · status not established, Rechtbank Den Haag, voorzieningenrechter (kort geding, team handel)
Guidelines8 of 24
- Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
- Guidelines 03/2026 on web scraping in the context of generative AI
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Guidelines 02/2026 on Anonymisation
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
2024-12-17 · final, European Data Protection Board (EDPB)
- Decision on the list of processing operations for which a DPIA is mandatory (Dutch DPA)
2019-11-27 · in force, Autoriteit Persoonsgegevens (AP)
- Guidelines on transparency under Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
- Guidelines 02/2025 on processing of personal data through blockchain technologies
2026-07-07 · final, European Data Protection Board (EDPB)
Enforcement and fines8 of 15
- Netflix fined 4.75 million euros for failing to properly inform customers
2024-11-26 · under appeal, Autoriteit Persoonsgegevens
- 10 million euro fine for Uber over unclear retention and transfer information, objection rejected
2023-12-11 · under appeal, Autoriteit Persoonsgegevens
- Dutch DPA fines Uber 824.99 million euros for automated driver deactivation
2026-08-21 · under appeal, Autoriteit Persoonsgegevens
- Ten municipalities fined a total of 250,000 euros for unlawful files on Muslim residents
2026-02-03 · final, Autoriteit Persoonsgegevens
- Experian Netherlands fined 2.7 million euros for credit scoring without legal basis or information
2025-10-16 · final, Autoriteit Persoonsgegevens
- Coolblue fined 40,000 euros on objection for cookies without consent
2024-12-23 · status not established, Autoriteit Persoonsgegevens
- Clearview AI: 30.5 million euro fine and penalty orders for illegal facial database
2024-05-16 · final, Autoriteit Persoonsgegevens
- 150,000 euro fine for ICS for missing DPIA on digital identity checks
2023-12-18 · final, Autoriteit Persoonsgegevens
Legislation in motion6 of 17
- Proposal: EU-wide DPIA lists, template and methodology (Articles 35, 57, 64 and 70 GDPR)
2025-11-19 · proposal, Europese Commissie
- Council: Irish Presidency continues with a revised compromise, Antici Group 11 September 2026
2026-09-11 · under negotiation, Raad van de Europese Unie, Iers voorzitterschap
- European Parliament: joint ITRE-LIBE draft report, amendments tabled, no committee vote yet
2026-06-22 · under negotiation, Europees Parlement, commissies ITRE en LIBE (gezamenlijke commissie)
- Proposal: definition of scientific research, purpose limitation and information duty for research (Article 4(38), 5(1)(b) and 13(5) GDPR)
2025-11-19 · under negotiation, Europese Commissie
- Proposal: breach notification only for high risk, within 96 hours, via a single entry point (Article 33 GDPR)
2025-11-19 · proposal, Europese Commissie
- Commission publishes Digital Omnibus proposal COM(2025) 837
2025-11-19 · proposal, Europese Commissie
Analysis6 of 13
- Agentic AI under the EU AI Act: how to govern autonomous agents
2026-07-07
- AI DPIA: when it's required + free template (2026)
2026-03-23
- Agentic AI governance: obligations, controls and how to get started under the EU AI Act
2026-07-07
- Does an AI agent fall under the EU AI Act?
2026-07-07
- Who is responsible when an AI agent makes mistakes?
2026-07-07
- EU AI Act Article 26: deployer obligations explained
2026-03-21