Guideline
Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
- Date
- Status
- final
- Body
- Autoriteit Persoonsgegevens
- Reference
- Position paper AP: Omnibus Digitaal en Omnibus AI (januari 2026)
What it is about
The AP supports simplification but finds that the omnibus proposals do not strike the right balance with protection, and calls on the legislator to look at them critically. It wants the definition of personal data kept as it is, since uncertainty weakens both protection and supervision. Less transparency and accountability means less effective supervision: the AP wants to keep the current threshold for notifying data breaches. The AI literacy obligation should stay with organisations. Many proposals, such as limiting the right of access for excessive requests and explicitly naming legitimate interest for AI, are in the AP's view so vaguely worded that they do not solve the problems. Positive elements include EU level templates for DPIAs and breach notifications and harmonised cookie rules. The AP announces a joint analysis with the other European data protection authorities.
What this means in practice
This is the position of your Dutch supervisory authority, not a new rule. The proposals have not been adopted, so the current GDPR still applies: notify data breaches under the current threshold, handle access requests under the current rules and still carry out your own balancing test when relying on legitimate interest for AI. Expect a strict stance from the AP if the definition of personal data or the notification duty is relaxed after all.
The GDPR articles concerned
Source: Autoriteit Persoonsgegevenschecked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Part of the file
Themes where this returns
The counterpart in the other law
- Article 3 AI Act: Definitions
- Article 5 AI Act: Prohibited AI practices
- Article 6 AI Act: Classification rules for high-risk AI systems
- Article 9 AI Act: Risk management system
- Article 10 AI Act: Data and data governance
- Article 14 AI Act: Human oversight
- Article 16 AI Act: Obligations of providers of high-risk AI systems
- Article 25 AI Act: Responsibilities along the AI value chain
- Article 26 AI Act: Obligations of deployers of high-risk AI systems
- Article 27 AI Act: Fundamental rights impact assessment for high-risk AI systems
- Article 50 AI Act: Transparency obligations for providers and deployers of certain AI systems
- Article 73 AI Act: Reporting of serious incidents
- Article 86 AI Act: Right to explanation of individual decision-making
Case law8 of 19
- Council of State: 600,000 euro fine for wifi tracking in Enschede stays annulled
2026-07-29 · final, Raad van State, Afdeling bestuursrechtspraak
- Overijssel District Court revokes DPA fine for wifi tracking in Enschede
2024-02-02 · final, Rechtbank Overijssel
- The Hague District Court cuts DPA fine on police for mobile camera cars without completed DPIA to 30,000 euros
2024-10-08 · status not established, Rechtbank Den Haag
- EU Court of Justice in KNLTB: a purely commercial interest can be a legitimate interest
2024-10-04 · final, Hof van Justitie van de Europese Unie
- Noord-Nederland District Court upholds DPA fine for village livestream, reduces it to 375 euros
2025-01-09 · status not established, Rechtbank Noord-Nederland
- IAB Europe: the TC String is personal data and the industry body is a joint controller
2024-03-07 · final, Hof van Justitie van de EU (Vierde kamer), IAB Europe tegen Gegevensbeschermingsautoriteit (België)
- Brillen Rottler: even a first access request can be abusive if made solely to claim compensation
2026-03-19 · final, Hof van Justitie van de EU (Vierde kamer), Brillen Rottler GmbH & Co. KG tegen TC
- EDPS v SRB: pseudonymised data are not always personal data for everyone, but the information duty applies from collection
2025-09-04 · final, Hof van Justitie van de EU (Eerste kamer), Europese Toezichthouder voor gegevensbescherming (EDPS) tegen Gemeenschappelijke Afwikkelingsraad (SRB)
Guidelines8 of 20
- EDPB Template for personal data breach notification
2026-06-10 · adopted, European Data Protection Board (EDPB)
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
2024-12-17 · final, European Data Protection Board (EDPB)
- Guidelines 01/2021 on Examples regarding Personal Data Breach Notification
2021-12-14 · final, European Data Protection Board (EDPB)
- Guidelines 9/2022 on personal data breach notification under GDPR
2023-03-28 · final, European Data Protection Board (EDPB)
- Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
- Guidelines 03/2026 on web scraping in the context of generative AI
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Guidelines 05/2020 on consent under Regulation 2016/679
2020-05-04 · final, European Data Protection Board (EDPB)
- Consultation on the draft list of processing operations for which no DPIA is required (Dutch DPA)
2026-06-24 · under consultation, Autoriteit Persoonsgegevens (AP)
Enforcement and fines8 of 11
- Coolblue fined 40,000 euros on objection for cookies without consent
2024-12-23 · status not established, Autoriteit Persoonsgegevens
- 150,000 euro fine for ICS for missing DPIA on digital identity checks
2023-12-18 · final, Autoriteit Persoonsgegevens
- Dutch DPA and tennis federation KNLTB end litigation: fine cut from 525,000 to at most 250,000 euros
2025-10-18 · status not established, Autoriteit Persoonsgegevens
- 600,000 euro fine for AS Watson (Kruidvat) over tracking cookies without consent
2024-05-02 · annulled, Autoriteit Persoonsgegevens
- 500 euro fine and penalty order for Stichting Oud Lemmer over webcam livestream
2021-07-09 · status not established, Autoriteit Persoonsgegevens
- DPA cuts Kruidvat fine to 50,000 euros on objection
2025-05-27 · status not established, Autoriteit Persoonsgegevens
- Ten municipalities fined a total of 250,000 euros for unlawful files on Muslim residents
2026-02-03 · final, Autoriteit Persoonsgegevens
- Experian Netherlands fined 2.7 million euros for credit scoring without legal basis or information
2025-10-16 · final, Autoriteit Persoonsgegevens
Legislation in motion6 of 18
- Proposal: breach notification only for high risk, within 96 hours, via a single entry point (Article 33 GDPR)
2025-11-19 · proposal, Europese Commissie
- Council: Irish Presidency continues with a revised compromise, Antici Group 11 September 2026
2026-09-11 · under negotiation, Raad van de Europese Unie, Iers voorzitterschap
- Proposal: cookie rules move from ePrivacy to the GDPR, with new exceptions and a six-month rule (new Article 88a GDPR and Article 5(3) ePrivacy)
2025-11-19 · under negotiation, Europese Commissie
- Proposal: definition of scientific research, purpose limitation and information duty for research (Article 4(38), 5(1)(b) and 13(5) GDPR)
2025-11-19 · under negotiation, Europese Commissie
- Proposal: relative definition of personal data (Article 4(1) GDPR)
2025-11-19 · proposal, Europese Commissie
- European Parliament: joint ITRE-LIBE draft report, amendments tabled, no committee vote yet
2026-06-22 · under negotiation, Europees Parlement, commissies ITRE en LIBE (gezamenlijke commissie)
Analysis6 of 9
- AI DPIA: when it's required + free template (2026)
2026-03-23
- EU AI Act Article 26: deployer obligations explained
2026-03-21
- DPIA vs FRIA: 5 key differences, when you need both, plus a free FRIA template (2026)
2025-08-05
- AI Act regulator inspection: which documents must your organisation be able to show?
2026-07-07
- The draft high-risk classification guidelines: the two routes under Article 6 explained
2026-06-13
- Commission Guidelines on High-Risk AI: How the Article 6(3) Filter Works
2026-05-20