Monthly Update – November 2025
Have you been feeling overwhelmed by the wave of EU digital regulations over the past few years? You are not alone. Between the AI Act, the Data Act, NIS2, and more, each one has added fresh layers of compliance and complexity.
Even regulators have started to acknowledge it. Their ambitious digital rulebook has made life harder for businesses trying to do the right thing, and has reduced the EU's competitiveness compared to companies operating outside of Europe.
Enter the Digital Omnibus: the European Commission's proposal to bring some order to the chaos.
What is it?
On 19 November 2025, the European Commission published the Digital Omnibus proposal: a package of targeted amendments to the GDPR, the AI Act, the ePrivacy Directive, NIS2, and several other regulations. The aim is to align digital laws, reduce overlap, and make compliance more practical for organisations of all sizes.
It is a proposal, not a law. Formal negotiations between the Commission, the European Parliament, and the Council of the EU are underway. As of mid-2026, the AI-related changes have reached a provisional agreement, while the GDPR and ePrivacy amendments are still being negotiated. Adoption of the GDPR-related changes is realistically expected around mid-2027.
What are the key proposals?
1. Breach reporting
Only high-risk breaches would need to be reported to data protection authorities.
The deadline for breach reporting would be extended from 72 to 96 hours.
A single reporting portal would cover incident reporting under GDPR, NIS2, DORA, eIDAS, and the CER Directive.
2. Access and transparency simplified
In two specific situations, organisations may be able to refuse an access request: when the request serves any purpose other than protecting personal data (for example, "just to make a point"), or when the request is clearly broad or repetitive.
In certain close and limited relationships where the data subject likely already has the most relevant information and the processing is not data-intensive, a transparency notice may not be required.
3. Personal data clarified
Data would not be considered personal if an organisation has no "means reasonably likely" to identify someone.
Note: this proposed change to the definition of "personal data" is contested. The Council has indicated it may remove it from the final text. This is one of the more closely watched elements of the negotiations.
4. Specific rules for AI development
Legitimate interest could be used as a legal basis for developing and operating an AI system or model.
Sensitive personal data could be processed for the purpose of developing and operating AI systems, subject to conditions. This would create an exception to the general ban on processing such data.
5. Biometric data
A second exception to the general ban on processing sensitive data would apply specifically to biometric data.
Organisations could use biometric data (for example, facial recognition) to verify a data subject's identity, provided that the biometric data and the tools required for verification remain under the sole control of the data subject.
6. Cookie consent and the ePrivacy Directive
The GDPR and ePrivacy Directive currently overlap in confusing ways when it comes to cookies. The Digital Omnibus aims to resolve this.
The proposal would bring all processing of personal data on or from terminal equipment under the GDPR only, through two new articles.
Article 88a would provide exemptions from the consent requirement for storing personal data on terminal equipment, covering certain analytics and audience measurement.
Article 88b would clarify how users should be able to give or refuse consent, with the goal of reducing the current wave of consent fatigue.
7. Scientific research
Scientific research would be formally recognised as a legitimate interest for organisations.
A definition of "scientific research" would be added to the GDPR, clarifying that this does not include research that also aims to further a commercial interest.
The transparency obligation could be reduced when providing full information would be disproportionate.
8. DPIA requirements
A single mandatory list would spell out when a DPIA is required and when it is not.
The EDPB would also create templates and a methodology to help organisations carry out DPIAs more consistently.
Why these changes matter
The proposal signals a shift toward risk-based and interoperable compliance in the EU. The goal is to streamline how businesses handle overlapping rules, without lowering the bar for data protection. For businesses, the message is to stay informed. This is only a proposal, and many provisions may change significantly before adoption. The EDPB and EDPS have already published a Joint Opinion raising both support for certain simplifications and clear concerns about others, particularly around the proposed narrowing of the definition of personal data and the interaction with the AI Act. You can read our breakdown of that Joint Opinion in our February 2026 Monthly Update.
What happens next?
AI Act changes: A provisional agreement was reached in May 2026. Formal adoption is still pending. GDPR and ePrivacy changes: Still in active negotiations as of mid-2026. Adoption realistically expected around mid-2027. Your action now: No compliance changes are required today. But the direction of travel is clear. If you want to contribute to the consultation or understand how these proposals might affect your business specifically, book a call and we will help you think it through.
That's a wrap!
The Digital Omnibus is one of the most significant overhauls of EU digital law in years. It will not take effect overnight, but the signals are clear: the Commission wants simpler, more interoperable rules. Whether that ambition survives the legislative process intact is a different question.
Stay close to these developments. We will keep tracking them and breaking them down as the negotiations progress.
We take great care in providing information to you, but please be aware of the fact that these blogposts can not be considered a substitute for professional legal advice, nor do they create an attorney-client relationship.