GDPR, AI, and Cookies: What the EU’s Data Omnibus Could Change for Companies
Update Data Protection No. 266
The Council of the European Union is currently negotiating the so-called Data Omnibus, through which the Commission aims to simplify the Union’s data law and reduce the compliance burden on companies. At the center of these efforts are amendments to the General Data Protection Regulation (GDPR), particularly regarding the processing of personal data for the training of Artificial Intelligence and the scope of personal data status of pseudonymized data, as well as adjustments to the Data Act, the ePrivacy Directive, and notification obligations in connection with security incidents. For companies, this entails both potential facilitations in data use and shifts in established compliance obligations, the concrete scope of which is likely to become clearer only as the negotiations progress. The legislative procedure is still in its first reading, during which the Council is working on its negotiating position, while a position of the European Parliament and the subsequent trilogue are still pending. The following article assesses the procedural status, presents the key regulatory content, and identifies what preparatory steps companies can already take.
I. Legislative Status and Timeline
The Data Omnibus proposal stems from the Commission’s efforts to simplify the Union’s digital legal framework and to reduce the compliance burden on companies. It was published on 19 November 2025 together with a second initiative, the Digital Omnibus on Artificial Intelligence (AI Omnibus). Both drafts pursue the same overarching objective but address different subject matter: the AI Omnibus is limited to amendments of the AI Act and has already entered into force as Regulation (EU) 2026/1744 of 8 July 2026, whereas the Data Omnibus addresses data law and touches on the core of the GDPR (we reported in Data Protection Update No. 250).
Unlike the AI Omnibus, the Data Omnibus has not yet been adopted. The procedure remains in its first reading, during which the Council first establishes its negotiating position. Following several compromise proposals discussed under the Cypriot Council Presidency, the file is now with the Irish Council Presidency, which presented a revised proposal in early September 2026. This proposal continues to be assessed differently across Member States on several points, so that a common Council position is not yet foreseeable.
Several procedural steps are therefore still required before a final regulation is reached. Only after the Council agrees on a general approach can the European Parliament determine its position, before negotiations between the institutions commence in the trilogue. Against this background, a conclusion of the procedure is not expected before 2027, although the precise timeline cannot be reliably predicted given the current state of negotiations.
II. Key Regulatory Content
The draft addresses four areas that are closely interlinked in practice: the GDPR, the Data Act together with adjacent data legislation, the cookie rules of the ePrivacy Directive, and the notification framework for cyber and data protection incidents. Central among these are the amendments to the GDPR, as they intervene directly in the regulatory substance of the Regulation for the first time and affect its core concepts.
1. Personal Data Status of Pseudonymized Data
For the first time, the draft directly clarifies the definition of personal data in Article 4(1) GDPR. It clarifies that pseudonymized data are not automatically personal data for a recipient merely because they constitute personal data in the hands of the controller. Instead, the decisive factor is whether the specific entity has means that are reasonably likely to lead to identification. This incorporates into the text of the Regulation the concept of a relative, recipient-focused approach to identifiability known from the case law of the Court of Justice of the European Union. In practical terms, the same dataset may in the future be personal data for one company, while for another company that lacks realistic means of identification, it falls outside the scope of the GDPR.
For companies, this represents a noticeable expansion of their room for maneuver, but also an increased documentation requirement, since the absence of identifiability must be demonstrated on a case-by-case basis. In the Council negotiations, this point is among the comparatively consensus-capable ones. Currently under discussion are primarily safeguard mechanisms intended to prevent circumvention through disclosure to entities that possess means of identification.
2. AI Training Based on Legitimate Interest
The draft clarifies that the training, testing, and validation of AI systems using personal data can in principle be based on a legitimate interest under Article 6(1)(f) GDPR. The established assessment framework for legitimate interest remains unaffected, meaning that a balancing of interests must still be carried out on a case-by-case basis and the principles of the Regulation continue to apply. However, the draft specifies which considerations are to be taken into account in this balancing exercise, in particular the benefit of the processing, the reasonable expectations of data subjects, and the envisaged safeguards, which include a right to object and compliance with technical signals indicating opposition to use for training purposes.
In addition, the draft provides for a narrowly circumscribed exception for special categories of personal data. Under the new Article 9(2)(k) GDPR, the processing of such data in the AI context is to be permissible insofar as it does not occur in a targeted manner, but rather sensitive data are merely unavoidably contained in the training data, and the controller implements technical and organizational measures to avoid and remove such data to the greatest extent possible. This aspect is one of the most contentious elements of the proposal. While certain Member States consider the approach viable, it is rejected elsewhere – partly because AI-specific special rules are considered misplaced in the fundamentally technology-neutral GDPR, and partly because a more far-reaching waiver of the case-by-case burden of proof is demanded. A viable majority has not yet emerged on this point.
3. Adjustments to Data Law (Data Act and Adjacent Legislation)
A substantial portion of the draft concerns the consolidation of data law, in which the Data Act is to be developed into the central legal act, while the Data Governance Act, the Regulation on the free flow of non-personal data, and the Open Data Directive are to be merged into it. In addition to numerous supplementary definitions, two areas of practical relevance are being recalibrated. First, the protection of trade and business secrets is strengthened: data holders are to be able to refuse the sharing of data more easily, particularly where sensitive information could reach third countries with lower levels of protection. Second, public authority access to corporate data is more narrowly defined, with disclosure being required only in the case of a public emergency and no longer in the case of a general exceptional necessity.
For data-holding companies, this tends toward a reduction in burden, as both the protection of trade secrets and the limits on governmental access rights are tightened. In the Council negotiations, discussions continue regarding the precise scope of the trade secret exception and accompanying interpretive guidance; the general direction of a more restrictive design of access rights is largely undisputed.
4. Integration of Cookie Rules into the GDPR
The draft transfers the consent requirement for storing and reading information on end-user devices – previously regulated in the ePrivacy Directive – into the GDPR, and seeks to reduce the burden described as “consent fatigue” caused by the multitude of cookie banners. The proposal envisages transmitting users’ individual decisions in the future via automated, machine-readable signals – such as those from the browser or operating system – directly to websites. In addition, a catalog of consent-free grounds is to be established, specifying in which cases storage is permissible without separate consent.
5. Simplification of Notification Obligations
Finally, the draft aims to consolidate the notification and reporting obligations currently scattered across multiple legal acts. In the area of the GDPR, the notification to the supervisory authority is to be waived where a data breach is unlikely to result in a high risk, although the documentation obligation remains in place. Beyond this, the Commission pursues the objective of replacing multiple notifications under the GDPR, NIS 2, and other legal acts with a common notification procedure through a single reporting point, so that an incident would only need to be reported once and would be forwarded in the background to the competent authorities.
For companies operating in multiple Member States, this would represent a noticeable reduction in burden. However, the concrete design of this single reporting point is particularly contentious in the Council and has already moved significantly away from the original model of a uniform European reporting office in the course of the negotiations, so that the practical benefit for those subject to notification obligations cannot yet be reliably assessed.
III. Recommendations for Companies
The Data Omnibus has not yet been adopted, so there is no immediate need for implementation at present. Nevertheless, preparatory steps can already be taken that will reduce the subsequent adjustment effort and make potential room for maneuver usable.
First, it is advisable to review one’s own data inventories with regard to the proposed recipient-focused approach to personal data status. Companies should document what means of identification they actually possess and in what constellations re-identification can realistically be excluded. Such an inventory creates the basis for quickly assessing, in the event of the draft’s adoption, which processing operations could in the future fall outside the scope of the GDPR, and it is also beneficial regardless of how the legislative process proceeds.
Second, companies that use personal data for the development or operation of AI systems should review their legal bases for processing and their safeguards at an early stage. Since the draft bases training on legitimate interest but leaves the required balancing of interests unaffected, a careful and comprehensibly documented balancing assessment is of particular importance. It is advisable to incorporate the envisaged safeguard mechanisms – in particular a practicable right to object and compliance with technical signals indicating opposition to use for training purposes – into one’s own processes already now.
Third, existing notification and consent processes should be examined to determine whether they can be adapted to the foreseeable changes. This concerns both the internal handling of data breaches, where the notification threshold is to be aligned with the high-risk standard in the future, and the design of cookie consent, which could be restructured through machine-readable signals and a catalog of consent-free grounds. Since the concrete design of these areas is still open in the Council, companies should monitor further developments and refrain from premature restructuring, while at the same time preparing their own processes so that they can be adapted with reasonable effort.
IV. Conclusion and Outlook
The Data Omnibus addresses central points of data law through the redefinition of personal data status, the legal basis for AI training, and the consolidation of notification obligations, combining relief for companies with shifts in established obligations. Its practical significance will only become apparent with the final text, which is currently not foreseeable, as neither a common position within the Council nor the stance of the European Parliament has yet emerged. Given the early stage of the legislative process, there is no immediate need for companies to act, but there is reason to follow further developments and to prepare their own processes for the foreseeable changes.
This article was created in collaboration with our student employee Emily Bernklau.