Digital Omnibus (data/GDPR)
Proposed European Union ยท no upcoming deadlines
Deadlines
No dated deadlines yet.
Summaries for reference, not legal advice. Check the official text.
What it does
Commission proposal to simplify EU digital rules. It would amend the GDPR (personal data definition, processing for AI, a new cookie/terminal-equipment consent regime in Art 88a/88b, breach notification only for high-risk breaches within 96 hours) and the ePrivacy Directive, NIS2, CER Directive and Data Act. A single-entry point would handle incident reporting, and the Data Governance Act, Free Flow Regulation, Platform-to-Business Regulation and Open Data Directive would be repealed and merged into the Data Act. The AI Act part was split out and adopted separately as Regulation (EU) 2026/1744.
- Who it applies to
- Would affect all GDPR controllers/processors, website and app operators using cookies, NIS2/CER entities (incident reporting), and Data Act/DGA actors.
- Penalties
- No new penalties; existing regimes (GDPR, Data Act, NIS2) would continue to apply.
- Enforced by
- N/A (legislative proposal); European Parliament (ITRE/LIBE) and Council
- Official name
- Proposal for a Regulation amending Regulations (EU) 2016/679, 2018/1724, 2018/1725, 2023/2854 and Directives 2002/58/EC, 2022/2555 and 2022/2557 as regards the simplification of the digital legislative framework (Digital Omnibus)
- Citation
- COM(2025) 837 final, 2025/0360(COD)
- Topics
- privacy, data-access, cybersecurity, breach-notification, ai
Research notes
Tabled 19 Nov 2025. Per the European Parliament Legislative Train (updated 1 Aug 2026): ITRE/LIBE joint draft report published 22 June 2026, amendment deadline 15 July 2026 with 1,750+ amendments, and no plenary vote date. A Council negotiating-mandate vote planned for 26 June 2026 was cancelled, and work continues under the Irish Presidency. No trilogues had started, and adoption is not expected before late 2026 at the earliest. No dates apply until it is adopted.
Related
Questions about Digital Omnibus (data/GDPR)
- Who does Digital Omnibus (data/GDPR) apply to?
- Would affect all GDPR controllers/processors, website and app operators using cookies, NIS2/CER entities (incident reporting), and Data Act/DGA actors.
- What are the penalties under Digital Omnibus (data/GDPR)?
- No new penalties; existing regimes (GDPR, Data Act, NIS2) would continue to apply.