Guideline
EDPB and EDPS adopt Joint Opinion 2/2026 on the Digital Omnibus
- Date
- Status
- final
- Body
- European Data Protection Board en European Data Protection Supervisor
- Reference
- EDPB-EDPS Joint Opinion 2/2026 (over COM(2025) 837)
What it is about
The Joint Opinion was adopted on 10 February 2026 and published on 11 February 2026. The EDPB and EDPS support simplification but strongly urge the co-legislators not to adopt the change to the definition of personal data. They also consider that an implementing act should not determine when pseudonymised data is no longer personal data. They welcome the research definition, the exception for biometric authentication under the individual's sole control, the higher breach notification threshold and longer deadline, and common templates and DPIA lists, provided the EDPB prepares and approves them itself. They consider a specific provision on legitimate interest for AI (Article 88c) unnecessary. They want to keep the Article 22 prohibition in principle and want abuse of the right of access tied to abusive intent. On cookies they strongly support the aim and suggest an exception for contextual advertising.
What this means in practice
The opinion is not binding, but it carries significant weight in the legislative negotiations. Expect the definition change and the Article 22 relaxation to be uncertain, while the breach and DPIA simplifications have the supervisors' support. Your current obligations are unchanged.
The GDPR articles concerned
- Article 4: Definitions
- Article 5: Principles relating to processing of personal data
- Article 6: Lawfulness of processing
- Article 9: Processing of special categories of personal data
- Article 12: Transparent information, communication and modalities for the exercise of the rights of the data subject
- Article 13: Information to be provided where personal data are collected from the data subject
- Article 22: Automated individual decision-making, including profiling
- Article 33: Notification of a personal data breach to the supervisory authority
- Article 35: Data protection impact assessment
- Article 41: Monitoring of approved codes of conduct
- Article 88: Processing in the context of employment
Source: European Data Protection Boardchecked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Part of the file
Themes where this returns
- Assessing risks in advance: DPIA and FRIA
- Automated decisions and human oversight
- Biometrics and emotion recognition
- Data quality, minimisation and data governance
- Keeping records: record of processing, technical documentation and logs
- Reporting: data breaches and serious incidents
- Rights of people: access and explanation of decisions
- Transparency: informing people
- Using special categories of personal data to detect bias
- Who is responsible: roles in both laws
The counterpart in the other law
- Article 2 AI Act: Scope
via Using special categories of personal data to detect bias
- Article 3 AI Act: Definitions
- Article 5 AI Act: Prohibited AI practices
- Article 6 AI Act: Classification rules for high-risk AI systems
- Article 9 AI Act: Risk management system
- Article 10 AI Act: Data and data governance
- Article 11 AI Act: Technical documentation
via Keeping records: record of processing, technical documentation and logs
- Article 12 AI Act: Record-keeping
via Keeping records: record of processing, technical documentation and logs
- Article 14 AI Act: Human oversight
- Article 16 AI Act: Obligations of providers of high-risk AI systems
- Article 18 AI Act: Documentation keeping
via Keeping records: record of processing, technical documentation and logs
- Article 19 AI Act: Automatically generated logs
via Keeping records: record of processing, technical documentation and logs
- Article 25 AI Act: Responsibilities along the AI value chain
- Article 26 AI Act: Obligations of deployers of high-risk AI systems
- Article 27 AI Act: Fundamental rights impact assessment for high-risk AI systems
- Article 50 AI Act: Transparency obligations for providers and deployers of certain AI systems
- Article 73 AI Act: Reporting of serious incidents
- Article 86 AI Act: Right to explanation of individual decision-making
Case law8 of 21
- Council of State: 600,000 euro fine for wifi tracking in Enschede stays annulled
2026-07-29 · final, Raad van State, Afdeling bestuursrechtspraak
- Overijssel District Court revokes DPA fine for wifi tracking in Enschede
2024-02-02 · final, Rechtbank Overijssel
- Noord-Nederland District Court upholds DPA fine for village livestream, reduces it to 375 euros
2025-01-09 · status not established, Rechtbank Noord-Nederland
- Schrems v Meta: no unlimited retention and aggregation of data for targeted advertising
2024-10-04 · final, Hof van Justitie van de EU (Vierde kamer), Maximilian Schrems tegen Meta Platforms Ireland Limited
- Interim relief judge: DPA must redact fine amount when giving an enforcement decision to complainants
2024-05-31 · status not established, Rechtbank Den Haag, voorzieningenrechter (kort geding, team handel)
- EDPS v SRB: pseudonymised data are not always personal data for everyone, but the information duty applies from collection
2025-09-04 · final, Hof van Justitie van de EU (Eerste kamer), Europese Toezichthouder voor gegevensbescherming (EDPS) tegen Gemeenschappelijke Afwikkelingsraad (SRB)
- Gelderland District Court: bankruptcy trustee is controller, DPA fine for unsecured hard drive cut to 58,125 euros
2025-08-07 · status not established, Rechtbank Gelderland
- Dun & Bradstreet: right to an intelligible explanation of an automated decision, trade secrets are no absolute ground for refusal
2025-02-27 · final, Hof van Justitie van de EU (Eerste kamer), CK tegen Magistrat der Stadt Wien, met Dun & Bradstreet Austria GmbH als andere partij
Guidelines8 of 22
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
2024-12-17 · final, European Data Protection Board (EDPB)
- Guidelines 03/2026 on web scraping in the context of generative AI
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
- Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
- Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR (legitimate interest)
2024-10-08 · adopted, European Data Protection Board (EDPB)
- Guidelines 05/2020 on consent under Regulation 2016/679
2020-05-04 · final, European Data Protection Board (EDPB)
- Guidelines 02/2026 on Anonymisation
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Guidelines on transparency under Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
Enforcement and fines8 of 15
- Ten municipalities fined a total of 250,000 euros for unlawful files on Muslim residents
2026-02-03 · final, Autoriteit Persoonsgegevens
- Experian Netherlands fined 2.7 million euros for credit scoring without legal basis or information
2025-10-16 · final, Autoriteit Persoonsgegevens
- Coolblue fined 40,000 euros on objection for cookies without consent
2024-12-23 · status not established, Autoriteit Persoonsgegevens
- Netflix fined 4.75 million euros for failing to properly inform customers
2024-11-26 · under appeal, Autoriteit Persoonsgegevens
- Dutch DPA and tennis federation KNLTB end litigation: fine cut from 525,000 to at most 250,000 euros
2025-10-18 · status not established, Autoriteit Persoonsgegevens
- 600,000 euro fine for AS Watson (Kruidvat) over tracking cookies without consent
2024-05-02 · annulled, Autoriteit Persoonsgegevens
- 10 million euro fine for Uber over unclear retention and transfer information, objection rejected
2023-12-11 · under appeal, Autoriteit Persoonsgegevens
- 500 euro fine and penalty order for Stichting Oud Lemmer over webcam livestream
2021-07-09 · status not established, Autoriteit Persoonsgegevens
Legislation in motion6 of 18
- Council: Irish Presidency continues with a revised compromise, Antici Group 11 September 2026
2026-09-11 · under negotiation, Raad van de Europese Unie, Iers voorzitterschap
- Proposal: definition of scientific research, purpose limitation and information duty for research (Article 4(38), 5(1)(b) and 13(5) GDPR)
2025-11-19 · under negotiation, Europese Commissie
- Proposal: cookie rules move from ePrivacy to the GDPR, with new exceptions and a six-month rule (new Article 88a GDPR and Article 5(3) ePrivacy)
2025-11-19 · under negotiation, Europese Commissie
- European Parliament: joint ITRE-LIBE draft report, amendments tabled, no committee vote yet
2026-06-22 · under negotiation, Europees Parlement, commissies ITRE en LIBE (gezamenlijke commissie)
- Proposal: exception for biometric verification under the data subject's sole control (Article 9(2)(l) GDPR)
2025-11-19 · proposal, Europese Commissie
- Proposal: implementing acts on when pseudonymised data ceases to be personal data (new Article 41a GDPR)
2025-11-19 · proposal, Europese Commissie
Analysis6 of 13
- Agentic AI under the EU AI Act: how to govern autonomous agents
2026-07-07
- AI DPIA: when it's required + free template (2026)
2026-03-23
- Agentic AI governance: obligations, controls and how to get started under the EU AI Act
2026-07-07
- Does an AI agent fall under the EU AI Act?
2026-07-07
- Who is responsible when an AI agent makes mistakes?
2026-07-07
- EU AI Act Article 26: deployer obligations explained
2026-03-21