Skip to content

Digital Omnibus (data/GDPR)

Proposed European Union ยท no upcoming deadlines

Deadlines

No dated deadlines yet.

Summaries for reference, not legal advice. Check the official text.

What it does

Commission proposal to simplify EU digital rules. It would amend the GDPR (personal data definition, processing for AI, a new cookie/terminal-equipment consent regime in Art 88a/88b, breach notification only for high-risk breaches within 96 hours) and the ePrivacy Directive, NIS2, CER Directive and Data Act. A single-entry point would handle incident reporting, and the Data Governance Act, Free Flow Regulation, Platform-to-Business Regulation and Open Data Directive would be repealed and merged into the Data Act. The AI Act part was split out and adopted separately as Regulation (EU) 2026/1744.

Who it applies to
Would affect all GDPR controllers/processors, website and app operators using cookies, NIS2/CER entities (incident reporting), and Data Act/DGA actors.
Penalties
No new penalties; existing regimes (GDPR, Data Act, NIS2) would continue to apply.
Enforced by
N/A (legislative proposal); European Parliament (ITRE/LIBE) and Council
Official name
Proposal for a Regulation amending Regulations (EU) 2016/679, 2018/1724, 2018/1725, 2023/2854 and Directives 2002/58/EC, 2022/2555 and 2022/2557 as regards the simplification of the digital legislative framework (Digital Omnibus)
Citation
COM(2025) 837 final, 2025/0360(COD)
Topics
privacy, data-access, cybersecurity, breach-notification, ai
Verified 2026-09-22 europarl.europa.eu digital-strategy.ec.europa.eu
Research notes

Tabled 19 Nov 2025. Per the European Parliament Legislative Train (updated 1 Aug 2026): ITRE/LIBE joint draft report published 22 June 2026, amendment deadline 15 July 2026 with 1,750+ amendments, and no plenary vote date. A Council negotiating-mandate vote planned for 26 June 2026 was cancelled, and work continues under the Irish Presidency. No trilogues had started, and adoption is not expected before late 2026 at the earliest. No dates apply until it is adopted.

Related

Questions about Digital Omnibus (data/GDPR)
Who does Digital Omnibus (data/GDPR) apply to?
Would affect all GDPR controllers/processors, website and app operators using cookies, NIS2/CER entities (incident reporting), and Data Act/DGA actors.
What are the penalties under Digital Omnibus (data/GDPR)?
No new penalties; existing regimes (GDPR, Data Act, NIS2) would continue to apply.

When the rules change: new data, privacy and AI laws and deadlines, the next morning.