INSIGHT // 63 Strategic Risk

The EU Digital Omnibus at Two Speeds: An Adopted AI Act Deferral and a Contested GDPR Reset

Abstract: On 19 November 2025 the European Commission proposed the Digital Omnibus, a two-part package to simplify the EU's rules on artificial intelligence, data protection, and cybersecurity. For US companies the temptation is to read it as across-the-board relief and pause compliance work accordingly. That reading is unsafe, because the package moves at two speeds. The AI Act track was adopted and its legislative process concluded on 29 June 2026, pushing the high-risk deadlines out to 2 December 2027 and 2 August 2028. The larger track, which would rewrite the definition of personal data, the legal basis for AI training, and the cookie rules, is still a contested proposal that the EU's own data-protection bodies have warned goes too far. One half of the package now fixes dates that are law. The other is a text that does not yet exist.
Plain Language Summary

This article examines the EU Digital Omnibus, a package the European Commission proposed on 19 November 2025 to make the EU's digital rules simpler. It comes in two parts. One part changes the AI Act and has already been adopted: it delays the obligations for high-risk AI systems to December 2027 and August 2028, and takes effect three days after it is published in the EU Official Journal. The other part would change the General Data Protection Regulation (GDPR), the cookie rules, and the Data Act, but it is still only a proposal and remains disputed. The article describes what each part would change, which of the two is now law and which is still only proposed, and where that split leaves US technology and life-sciences companies. It does not give advice on any specific product or company.

Table of Contents
  1. Two Omnibuses, Two Speeds
  2. The AI Act Deferral: A Moved Calendar and a Changed File
  3. The GDPR and ePrivacy Reset That Has Not Landed
  4. One Incident Portal and a Trimmed Data Act
  5. Strategic Considerations

US companies have spent two years treating EU digital compliance as a set of fixed dates to race toward. The AI Act's high-risk obligations were coming in August 2026, the GDPR was a settled constraint, the Data Act had just begun to apply, and the cybersecurity regimes were stacking new reporting duties on top of one another. The European Commission's Digital Omnibus, proposed on 19 November 2025, resets that board.1Proposal for a Regulation as regards simplification of the digital legislative framework, COM(2025) 837 final (19 Nov 2025), and the accompanying Digital Omnibus on AI, COM(2025) 836 final. It is presented as simplification, with the Commission estimating at least EUR 5 billion in combined recurring and one-off savings by 2029 and, among the individual measures, more than EUR 800 million a year from modernizing the cookie rules.2Digital Omnibus (n 1), explanatory memorandum, for the EUR 5 billion and EUR 1 billion figures; European Commission "Digital Package" FAQ and press release IP/25/2718 (19 Nov 2025) for the cookie figure and the "up to EUR 5 billion" framing; all are the Commission's own estimates, non-binding. For a US planning team, the reset is real, but it is not uniform, and the shape of the risk is that the two halves of the package are at very different stages of becoming law.

The instinct to bank the whole package as relief, and to slow compliance spending across the board, is where the exposure sits. One half of the Omnibus is now adopted and its dates are fixed. The other half is a proposal that the co-legislators have not agreed and that the EU's data-protection bodies have asked to be reined in. A company that redesigns its AI-training legal basis or its consent banners around the proposed text is building to a draft that may narrow before it lands, if it lands at all.

1. Two Omnibuses, Two Speeds

The Digital Omnibus is not one instrument but two proposals published together. The first, the Digital Omnibus on AI, keeps to the AI rulebook, amending the AI Act together with the aviation Basic Regulation and, in the text as adopted, the Machinery Regulation as well.3Regulation (EU) 2024/1689 (AI Act) [2024] OJ L 2024/1689, Art. 6, Annex I, Annex III, Art. 50, Art. 113 (staggered application dates). The second, the broader Digital Omnibus Regulation, reaches across the GDPR, the ePrivacy Directive, the Data Act, and the cybersecurity and data-governance instruments in a single amending act. Reading them as one package is the first mistake, because their legislative fortunes diverged almost immediately.

The AI track moved with unusual speed. The Parliament and the Council fixed their negotiating mandates, a provisional agreement was reached on 7 May 2026, the Parliament approved the text on 16 June 2026, and the Council adopted it on 29 June 2026, concluding the legislative procedure. The amending regulation enters into force on the third day after its publication in the Official Journal, an urgency clause carried from the Commission's original proposal so that the rewritten timetable is in place before the AI Act's general application date. At that point the AI Act's own timetable is formally displaced. That track is, for practical purposes, settled law, and its dates are fixed.

The AI half of the Omnibus is adopted; its dates are fixed. The data-protection and cybersecurity half is still a Commission proposal in committee, unagreed by the co-legislators. Planning that treats the two as equally certain inverts the actual risk.

The broader Regulation is on a different clock. As of 30 June 2026 it remains in the parliamentary committee stage, with no committee report adopted and no Council general approach or plenary vote recorded. Its most consequential elements, the ones that would change what counts as personal data and how AI models may be trained, are precisely those that the European Data Protection Board and the European Data Protection Supervisor flagged in a joint opinion as going beyond a technical amendment.4EDPB-EDPS Joint Opinion 2/2026 on the Digital Omnibus (10 Feb 2026). A proposal carrying that kind of institutional resistance is not a safe foundation for a compliance redesign, and its timeline to adoption, if it is adopted in recognizable form, is open. The two speeds are the analytical key to the whole package: one part tells a company what the law now is, the other tells it only what the Commission would like the law to become.

2. The AI Act Deferral: A Moved Calendar and a Changed File

The headline of the adopted AI track is time. The AI Act's obligations for high-risk systems, which were to apply from August 2026 and August 2027, are pushed back. Standalone high-risk systems listed in Annex III, the category that captures uses such as employment, biometrics, and critical infrastructure, now apply from 2 December 2027. High-risk systems that are safety components of products regulated under the Union harmonization legislation listed in Annex I, which is where medical devices and in vitro diagnostics sit, apply from 2 August 2028. The stated rationale is that the harmonized standards and support tools on which conformity depends are not yet in place, an echo of the pattern that has dogged other new-approach regimes.

For life-sciences companies the classification detail is the part that matters. An AI-enabled medical device or diagnostic does not sit in the Annex III bucket that most general commentary focuses on. Where the AI system is itself, or is a safety component of, a device regulated under the Medical Device Regulation or the In Vitro Diagnostic Regulation, and that device must undergo notified-body conformity assessment, the AI system is high-risk under Art. 6(1) AI Act and takes the later 2 August 2028 date; a self-certified lower-class device with an AI feature is not high-risk on this route at all.5Under Art. 6(1) AI Act, an AI system that is itself, or is a safety component of, an MDR (EU) 2017/745 or IVDR (EU) 2017/746 device is high-risk only where the device needs third-party (notified-body) assessment; such systems take the Annex I date of 2 Aug 2028. The adopted Digital Omnibus on AI narrows that gateway (Art. 3(14), Art. 6(1a) to (1c) AI Act) and adds a power to limit Art. 9 to Art. 15 and Art. 17 to Art. 25 AI Act where the Section A Annex I legislation already protects equivalently and the limitation would not reduce the AI Act's overall level of protection (Art. 2(13) AI Act). The adopted text also narrows the gateway itself, providing that an AI system used solely for non-safety-related aspects such as performance optimization or quality control does not qualify as a safety component unless its failure or malfunction would endanger health and safety, and tying the definition of a safety component to the component's intended purpose. Where a given diagnostic feature falls on that line is a question the new wording poses rather than answers. The later date is genuine additional runway for the dual MDR-and-AI Act conformity problem that a connected diagnostic already faces, a problem examined in the compliance cliffs confronting AI in pharmaceutical research and development. The runway is real, and the file that must land on it is not quite the file that was there before. The risk-management system, the training-data governance, the technical documentation, and the conformity assessment all survive, but the adopted text also empowers the Commission, by delegated act due in August 2027, to limit the AI Act's own requirements for products covered by the Section A Annex I legislation where that legislation already provides equivalent or higher protection and the limitation would not reduce the overall level of protection the AI Act provides, and it extends to small mid-cap companies the simplified Annex IV technical-documentation form that notified bodies must accept, a route small and medium enterprises already had, while naming both categories in the requirement that the quality-management system be scaled to the size of the provider's organization, which the Act already imposed on every provider and which the notified body still assesses. Whether a given device is reached by either turns on delegated acts that do not yet exist and on a size classification the AI Act has only just acquired.

Reading the deferral as a reprieve is the trap. A US firm that stood down its AI Act readiness program when the calendar slipped will find, at the new date, that the same body of work is due, now compressed against standards that arrive late and notified-body capacity that is still forming. For a provider outside the new small-enterprise and small mid-cap brackets, the amendment defers when the demonstration is required rather than reducing what must be demonstrated, and it fixes that timing to a date rather than to the actual availability of the standards, so a late standard does not buy a later deadline. The deferral also touches only the high-risk timetable: the prohibited-practice bans in force since February 2025 and the general-purpose-AI model obligations in force since August 2025 are unchanged by it.

Several changes on the AI track are not deferrals at all, and a planner who watches only the dates will miss them. The transparency duties for AI-generated and manipulated content under Art. 50 AI Act proceed on their original footing, applying from 2 August 2026 with only a four-month window, to 2 December 2026, for providers whose generative systems were already on the market to bring the machine-readable marking into line, so the duty to disclose synthetic media still arrives on its original schedule. A new prohibition targeting AI-generated non-consensual intimate imagery and child sexual abuse material was added to the Act's list of prohibited practices, with its own near-term transition. Registration obligations for certain non-high-risk systems are eased, small and medium enterprises gain quality-management-system flexibilities that were previously confined to micro-enterprises, and the AI Office is given a more central supervisory role over general-purpose-AI-based systems. A new provision allows the processing of special-category data to detect and correct bias outside the high-risk provider case, reaching providers and deployers of other AI systems and models as well as deployers of high-risk systems, on the conditions that already governed the provider derogation, a change that lowers a threshold rather than raising one. The net effect is a genuine re-shaping of the AI compliance calendar, not a wholesale retreat, and the items that did not move are as important to a plan as the ones that did.6Digital Omnibus on AI (n 1), as adopted: Art. 50 AI Act transparency retained, a new prohibited practice added to Art. 5 AI Act, plus the registration, SME quality-management, AI Office supervision, and bias-detection amendments.

3. The GDPR and ePrivacy Reset That Has Not Landed

The changes a US data or AI business would most want are on the slower track, and that is exactly why they should not yet be planned around. The Digital Omnibus Regulation proposes to write a contextual, relative test of identifiability into the GDPR's definition of personal data, so that information is not personal in the hands of an entity that lacks the means reasonably likely to be used to identify the individual.7Regulation (EU) 2016/679 (GDPR) [2016] OJ L119/1, Art. 4(1) (personal data), Art. 6(1)(f) (legitimate interests), Art. 9 (special categories), Art. 12(5) (manifestly unfounded or excessive requests), Art. 15 (access), Art. 33 (breach notification). The Commission presents this as a codification of the Court of Justice's ruling in the Single Resolution Board case, but the ruling is narrower than that framing suggests. The Court accepted that pseudonymized data are not personal data in all cases and for every person, and that the perspective from which identifiability is assessed turns on the circumstances of each processing operation. It then held that, for a controller's own duty to inform the data subject, identifiability falls to be assessed at the moment of collection and from the controller's position rather than the recipient's, and it set aside the General Court judgment that had reasoned the other way.8Case C-413/23 P European Data Protection Supervisor v Single Resolution Board, judgment of 4 September 2025, ECLI:EU:C:2025:645, decided under Regulation (EU) 2018/1725; the Court of Justice set aside the General Court judgment in Case T-557/20 and referred that case back. For a US company that processes large volumes of pseudonymized or telemetry data, a codified relative test would be valuable, and the same proposal adds a legitimate-interest footing for AI model training and a conditional derogation permitting some special-category data to be processed in AI development.

The difficulty is that these are the provisions least likely to survive intact. In their joint opinion, the EDPB and EDPS warned that the personal-data changes go beyond the Court's own reasoning and would significantly narrow the concept of personal data, and they objected to letting the Commission decide by implementing act what ceases to be personal data after pseudonymization. The Board's chair framed the point as a limit rather than a detail, cautioning that simplification cannot come at the expense of fundamental rights and that the changes risk significantly weakening individual protection.9EDPB-EDPS Joint Opinion 2/2026 (n 4); see also the accompanying EDPB statement by its Chair, Anu Talus (11 February 2026). When the Union's two data-protection bodies describe a proposal as lowering the level of protection, the co-legislators have both the political cover and the legal argument to narrow it, and the text that emerges from trilogue may look materially different from the one on the table now.

The cookie and ePrivacy elements sit in the same posture. The proposal would move the rule governing access to information on a user's device out of the ePrivacy Directive and into the GDPR so far as personal data are processed, leaving Art. 5(3) of the Directive to govern the residue, and would create consent exceptions for low-risk purposes such as aggregate statistics and security, alongside a duty to respect machine-readable preferences expressed through browser settings.10Directive 2002/58/EC (ePrivacy Directive) [2002] OJ L201/37, Art. 5(3) (storing or accessing information on terminal equipment); the Digital Omnibus would relocate and recast this rule within the GDPR framework so far as personal data are concerned. A US business drowning in consent-banner engineering has every reason to want this. But the reform is unadopted, and consent under the ePrivacy Directive as transposed by each Member State remains the law that binds as of 30 June 2026. Rebuilding a consent architecture around the proposed exceptions now would commit engineering to a rule the co-legislators have not enacted. The proposal also raises the personal-data breach notification window from 72 to 96 hours and raises the reporting threshold, and it would let a controller refuse a data-subject access request that amounts to an abuse of the right, but each of these, too, is a proposed change to be watched, not a rule to be relied on.

4. One Incident Portal and a Trimmed Data Act

The part of the slower track with the clearest operational appeal for a US in-house team is the consolidation of cybersecurity reporting. A single security incident can trigger overlapping notification duties: a personal-data breach notification under the GDPR, an incident report under the NIS2 Directive, an ICT-incident report under the Digital Operational Resilience Act for financial-sector entities, and, for critical entities, a further track under the Critical Entities Resilience Directive.11Directive (EU) 2022/2555 (NIS2) [2022] OJ L333/80; Regulation (EU) 2022/2554 (DORA) [2022] OJ L333/1; Directive (EU) 2022/2557 (CER) [2022] OJ L333/164. The Digital Omnibus proposes a single reporting entry point, operated by the European Union Agency for Cybersecurity, so that one submission can feed the several regimes rather than obliging separate, differently timed filings. For a company that has watched a single event propagate across incompatible reporting calendars the appeal is obvious.

The appeal, again, is not the same thing as the law. The single entry point is part of the broader Regulation and shares its uncertain timeline, so the several reporting playbooks a company maintains cannot yet be retired. Building an incident-response process around a consolidated portal that does not yet exist would leave a gap on the day an actual incident triggers the duties that are in force now.

The Data Act elements are more incremental but point the same way. The proposal would remove the much-criticized essential requirements imposed on smart contracts that execute data-sharing agreements, exempt certain bespoke data-processing services under contracts concluded on or before 12 September 2025 from the switching obligations, and extend the simplified regime beyond small and medium enterprises to small mid-cap companies below a raised size threshold. It would also fold the Data Governance Act, the Free Flow of Non-Personal Data Regulation, and the Open Data Directive into a consolidated Data Act, and repeal the Platform-to-Business Regulation outright as largely superseded.12Regulation (EU) 2023/2854 (Data Act) [2023] OJ L 2023/2854, applicable from 12 Sep 2025; the Digital Omnibus would amend it and consolidate several adjacent data instruments into it. For US cloud and connected-device businesses this trims the edges of a regime whose core obligations remain in force in the meantime. The consolidation is architecture, and it may simplify the map considerably, but the map it would replace is the one that governs until the Regulation is adopted.

5. Strategic Considerations

The questions the Omnibus forces are not the ones its simplification framing invites. The first is which half of the package a given decision depends on. A plan that turns on the AI Act deadlines can be re-sequenced now against the 2 December 2027 and 2 August 2028 dates, with the life-sciences classification detail that puts AI-enabled devices on the later date rather than the earlier one. A plan that turns on the definition of personal data, the legal basis for training a model, the treatment of special-category data in AI development, or the shape of consent management depends on a proposal that is unagreed and actively contested, and the law that binds in the meantime is the one that proposal would replace.

The second is the cost of building to a draft. Redesigning a data architecture, a consent flow, or an incident-response process around the proposed text carries a rework risk if the co-legislators narrow it, and the EDPB and EDPS opinion signals that narrowing is a live possibility for the provisions US businesses value most.

The third is the interaction with sectoral law that the Omnibus does not touch. The AI Act deferral does not move the Medical Device Regulation, so a connected diagnostic still answers to its device timeline even as its AI obligations shift, and the adopted AI text's mechanisms for running the AI Act and sectoral conformity assessments as a single exercise change how they interlock rather than removing either. The fourth is the feedback into US governance. A deferred European deadline can quietly drop off a board-level risk register, and a proposed European relief can be over-weighted in planning; the first misreading resurfaces as a scramble against a deadline that only moved rather than vanished; the second, as a redesign built on a text that never passed. Underlying all of these is the timing caveat that a fast-moving file demands: the AI track is settled, but the broader Regulation's content and calendar can still change, and a plan made against it should be revisited as it advances. These questions require analysis tied to a company's specific systems, products, and exposure.

REFERENCES

01
European Commission, Proposal for a Regulation of the European Parliament and of the Council amending Regulations (EU) 2016/679, (EU) 2018/1724, (EU) 2018/1725, (EU) 2023/2854 and Directives 2002/58/EC, (EU) 2022/2555 and (EU) 2022/2557 as regards the simplification of the digital legislative framework, and repealing Regulations (EU) 2018/1807, (EU) 2019/1150, (EU) 2022/868, and Directive (EU) 2019/1024 (Digital Omnibus), COM(2025) 837 final (19 November 2025); and Proposal for a Regulation of the European Parliament and of the Council amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI), COM(2025) 836 final (19 November 2025). Together, the "Digital Omnibus" package. As of publication, COM(2025) 836 (the AI track) had completed the ordinary legislative procedure, while COM(2025) 837 (the broader track) remained in the parliamentary committee stage, with no Council general approach or plenary vote recorded.
02
Digital Omnibus (n 1), explanatory memorandum, which states that "[i]nitial estimates foresee possible savings of at least EUR 1 billion annually, from moment of entry into force, with an additional EUR 1 billion savings in one-off costs, amounting to a total of at least EUR 5 billion over 3 years by 2029." The cookie figure is from the accompanying "Digital Package" FAQ ("more than EUR 800 million in savings for businesses annually"). The Commission's public communication frames the headline more cautiously, as savings of "up to EUR 5 billion" in administrative costs by 2029: European Commission, "Simpler EU digital rules and new digital wallets to save billions for businesses and boost innovation," press release IP/25/2718 (19 November 2025). All are the Commission's own projections and are not binding. The Union-wide EUR 37.5 billion simplification figure sometimes cited relates to the whole simplification agenda through 2029, not to the Digital Omnibus alone.
03
Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (AI Act) [2024] OJ L 2024/1689, in particular Art. 6 and Annexes I and III (high-risk classification), Art. 50 (transparency obligations), and Art. 113 (staggered application). The application dates for high-risk systems were revised by the Digital Omnibus on AI (n 1), on which a provisional interinstitutional agreement was reached on 7 May 2026, which the European Parliament approved on 16 June 2026 and the Council adopted on 29 June 2026, concluding the legislative procedure; the amending regulation enters into force on the third day following its publication in the Official Journal, an urgency clause present in the Commission's proposal and retained in the text as adopted. The revised application dates are fixed at 2 December 2027 for standalone high-risk systems (Annex III) and 2 August 2028 for AI systems that are safety components of products covered by the Annex I harmonisation legislation.
04
European Data Protection Board and European Data Protection Supervisor, Joint Opinion 2/2026 on the Proposal for a Regulation as regards the simplification of the digital legislative framework (Digital Omnibus) (10 February 2026), warning in particular that the proposed changes to the concept of personal data go beyond the case law and risk significantly narrowing the notion and weakening the level of protection.
05
Regulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on medical devices [2017] OJ L117/1 (MDR); Regulation (EU) 2017/746 of 5 April 2017 on in vitro diagnostic medical devices [2017] OJ L117/176 (IVDR). Both are Union harmonisation instruments listed in Annex I to the AI Act (n 3). Under Art. 6(1) AI Act an AI system that is itself, or is a safety component of, such a device is high-risk only where the device must undergo third-party (notified-body) conformity assessment; where it does, the AI system takes the Annex I application date (2 August 2028) rather than the Annex III date (2 December 2027). The Digital Omnibus on AI (n 1), as adopted, narrows that gateway: it refines the definition of ‘safety component’ in Art. 3(14) AI Act so that a component fulfils a safety function where its intended purpose is to prevent or mitigate risks to health and safety, and inserts Art. 6(1a) to (1c) AI Act, under which systems used solely for non-safety-related aspects such as performance optimisation or quality control do not qualify as safety components save where failure or malfunctioning would endanger health and safety. The same instrument adds Art. 2(13) AI Act, under which the requirements in Art. 9 to Art. 15 and Art. 17 to Art. 25 AI Act may be limited for Art. 6(1) high-risk systems where, cumulatively, the Section A Annex I legislation already provides an equivalent or higher level of protection and the limitation does not reduce the overall level of protection provided for by the AI Act, the specifying delegated acts to be adopted by 2 August 2027; and it extends to small mid-cap companies the option in Art. 11(1) AI Act of supplying the Annex IV technical documentation in simplified form, an option SMEs, including start-ups, already had, on a form notified bodies were already obliged to accept, re-targeting the Commission's simplified form from small and microenterprises to SMEs and SMCs; the amendment to Art. 17(2) AI Act likewise adds SMEs and SMCs to a requirement that implementation of the quality management system be proportionate to the size of the provider's organisation, a requirement that bound every provider of a high-risk system before the amendment and binds every provider after it.
06
Digital Omnibus on AI (n 1), as adopted. Beyond the revised high-risk application dates (n 3), the amending regulation retains the transparency obligations for AI-generated and manipulated content in Art. 50 AI Act (with a four-month transitional period, to 2 December 2026, for providers of AI systems generating synthetic audio, image, video or text content placed on the market before 2 August 2026 to comply with the marking duty in Art. 50(2) AI Act), adds a new prohibited practice to Art. 5 AI Act addressing AI-generated non-consensual intimate imagery and child sexual abuse material, eases registration for certain non-high-risk systems, extends quality-management-system flexibilities from micro-enterprises to small and medium enterprises, centralizes AI Office supervision over general-purpose-AI-based systems, and permits providers and deployers of other AI systems and models, and deployers of high-risk AI systems, to process special-category data to detect and correct bias, subject to the same limitations, conditions and safeguards that applied to the existing provider derogation.
07
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) [2016] OJ L119/1, in particular Art. 4(1) (definition of personal data), Art. 6(1)(f) (legitimate interests), Art. 9 (special categories of personal data), Art. 12(5) (manifestly unfounded or excessive requests), Art. 15 (right of access), and Art. 33 (notification of a personal data breach). The Digital Omnibus (n 1) proposes amendments including extending the breach-notification window under Art. 33 from 72 to 96 hours (with a raised reporting threshold) and widening Art. 12(5), so that a controller may refuse a request where the data subject exercises the right for purposes unrelated to the protection of their personal data, with the burden of demonstrating that resting on the controller; the right of access in Art. 15 is not itself rewritten. As of publication they remain unadopted.
08
Case C-413/23 P European Data Protection Supervisor v Single Resolution Board, judgment of 4 September 2025, ECLI:EU:C:2025:645 (Court of Justice, First Chamber). The case was decided under Regulation (EU) 2018/1725, whose recital 5 requires provisions following the same principles as the GDPR (n 7) to be interpreted homogeneously with it. The Court accepted, at paras 82 and 86, that pseudonymised data are not personal data in all cases and for every person, and observed, at para 100, that the relevant perspective depends on the circumstances of the processing in each individual case; but it held, at para 111, that for the purposes of the information obligation in Art. 15(1)(d) of that Regulation the identifiable nature of the data subject must be assessed at the time of collection and from the point of view of the controller, and found, at para 120, that the pseudonymised comments were personal data because the controller held the information needed to identify their authors. The General Court was accordingly held to have erred in law (para 115), its judgment in Case T-557/20 was set aside (para 118), and that case was referred back to it.
09
EDPB-EDPS Joint Opinion 2/2026 (n 4); and the European Data Protection Board's accompanying public statement by its Chair, Anu Talus, cautioning that simplification must not come at the expense of fundamental rights and that the proposed changes risk significantly weakening the level of protection (11 February 2026).
10
Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (ePrivacy Directive) [2002] OJ L201/37, Art. 5(3) (storing information in, or gaining access to information stored in, a user's terminal equipment). The Digital Omnibus (n 1) proposes to relocate and recast this rule within the GDPR framework, with consent exceptions for aggregate statistics and security and a duty to honour machine-readable browser preferences.
11
Directive (EU) 2022/2555 (NIS2 Directive) [2022] OJ L333/80; Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA) [2022] OJ L333/1; Directive (EU) 2022/2557 (Critical Entities Resilience Directive, CER) [2022] OJ L333/164. The Digital Omnibus (n 1) proposes a single reporting entry point, operated by the European Union Agency for Cybersecurity (ENISA), to consolidate the overlapping incident-notification duties across these instruments and the GDPR.
12
Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data (Data Act) [2023] OJ L 2023/2854, applicable from 12 September 2025. The Digital Omnibus (n 1) proposes to amend it (including removal of the smart-contract essential requirements, switching-obligation exemptions for contracts concluded on or before 12 September 2025, and extension of the simplified regime to small mid-cap enterprises) and to consolidate the Data Governance Act (Regulation (EU) 2022/868), the Free Flow of Non-Personal Data Regulation (Regulation (EU) 2018/1807), and the Open Data Directive (Directive (EU) 2019/1024) into it; the Platform-to-Business Regulation (Regulation (EU) 2019/1150) would be repealed outright, with a small set of its provisions continuing to apply until 31 December 2032.

Which half of the Digital Omnibus a given decision rests on, and whether a plan should be re-sequenced now or held against the current law, are questions worth resolving before the file advances rather than after.

Get in Touch