1. Digital Policy
  2. Instruments
  3. Data Omnibus

Proposal · not law · creates no obligations · CELEX 52025PC0837

Data Omnibus

COM(2025) 837 final — Digital Omnibus Regulation (proposal)

Known as the Digital Omnibus. Official text: COM(2025) 837 final — Digital Omnibus RegulationTier 1 · primary law

Status
Stalled as of 26 September 2026
Key dates
1 dated event
Competent authority
not established in this dataset
Sanction ceiling
none recorded

NOT LAW. A Commission proposal before the Council without an agreed position. The Cypriot Presidency withdrew its compromise text from COREPER in late June 2026 for lack of a qualified majority; the file passed to the Irish Presidency, whose revised compromise (ST 12535/26, 3 September 2026, not an official publication) restores an AI legitimate-interest clause and reworks the pseudonymised-data provision. Must never be rendered as an Act. The Commission's own label is 'Digital Omnibus'; 'Data Omnibus' is the informal shorthand used in this brief.

What it does

Simplification of the data acquis: an entity-relative test for personal data in Art. 4(1); a new Art. 41a on pseudonymised data; relocation of cookie consent into a new Art. 88a; a new Art. 88c legitimate-interest basis for AI model training.

How it allocates obligations

Inherits the GDPR's.

Regulated actor
Controller · Processor
Protected party
Data subject
Territorial reach
Established in the EU · Outside the EU, serving EU users
Implementation model
Not applicable — proposal
Enforcement mechanism
Would inherit the GDPR's.

Key dates

Entry into force, application and transposition are different events and are kept apart. A date at month precision is shown as a month rather than invented as a day.

  1. 19 November 2025Legislative proposalCOM(2025) 837 final published. A proposal, not law.

The whole compliance calendar, filterable →

Who it applies to

No rules recorded

The applicability engine holds no rule for this instrument yet. Absence of a rule is absence of knowledge, not evidence that the instrument does not reach you.

Answer three questions instead →

Key provisions

No provisions recorded

No article of this instrument has been entered into the dataset. The obligations it imposes are therefore described here only in general terms, and the applicability rules for it cannot point at articles.

Enforcement

No enforcement recorded

This dataset holds no enforcement action under this instrument. That is what the record says; it is not a finding that none has been taken.

The whole enforcement observatory →

Evidence and sources

Every statement this site makes about Data Omnibus, graded by what actually carries it. The grade is derived from the claim type and its sources, never stored, so it cannot drift from what it describes.

The instrument record itself was last verified on 27 August 2026; every claim below carries its own date.

1 Primary law1 Secondary only3 Attributed view1 Interpretation
Primary lawlaw

The Commission's four principal proposed GDPR reforms were: an entity-relative test for personal data in Art. 4(1); a new Art. 41a empowering the Commission to set, by implementing acts, the means and criteria for determining when pseudonymised data ceases to be personal; relocation of cookie consent into a new Art. 88a; and a new Art. 88c providing an explicit legitimate-interest basis for AI model training. None is law.

Tier 1 · primary lawstates this

COM(2025) 837 final — Digital Omnibus Regulation — European Commission 19 November 2025 Art. 3 (amendments to Regulation (EU) 2016/679): point 1(a) (Art. 4(1), added sentences), point 10 (new Art. 41a), point 15 (new Arts 88a and 88c)

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part VIII

Read it in the brief →Last verified 27 September 2026
Secondary onlyfact

The Data Omnibus has moved in both directions before the Council: by May 2026 successive Cypriot Presidency texts had deleted three of the Commission's four principal GDPR reforms, the Cypriot Presidency withdrew its text from COREPER in late June 2026 for lack of a qualified majority, and the Irish Presidency's revised compromise of 3 September 2026 then restored an AI legitimate-interest clause (as a new Article 88 bis, without the Commission's safeguards) and moved pseudonymised data into a new Article 25a. As of 25 September 2026 the Council has no agreed mandate and trilogues have not begun.

Tier 4 · press / advocacystates this

Digital Omnibus negotiations — GDPR July 2026 update — Privacy Next 8 July 2026

Tier 4 · press / advocacystates this

EU Digital Omnibus Hands the Wheel to the Referee — International Center for Law & Economics 11 June 2026 Paragraph citing 'Council document 9547/26' of 21 May: the compromise 'deletes three of the Commission's four principal GDPR reforms'

Tier 4 · press / advocacystates this

EU Council draft drops unconditional opt-out from GDPR AI clause — PPC Land 26 September 2026 Sections 'The clause, line by line' (ST 12535/26, 3 September 2026; the AI clause renumbered Article 88 bis) and 'Personal data after the SRB judgment' (new Article 25a)

Read it in the brief →Last verified 26 September 2026
Attributed viewattributed

The EDPB and EDPS adopted Joint Opinion 1/2026 on the AI Omnibus and Joint Opinion 2/2026 on the Data Omnibus, holding in the second that the personal-data definition change goes far beyond a targeted modification and would significantly narrow the concept, that the Art. 41a implementing-act power should not be entrusted to the Commission, and that Art. 88c is unnecessary.

Tier 2 · regulatorstates this

EDPB–EDPS Joint Opinion 2/2026 on the Digital Omnibus proposal — European Data Protection Board February 2026 Paras 17 ('significantly narrowing the concept of personal data') and 21 ('goes far beyond a targeted modification of the GDPR'); paras 23 and 25 (applying the definitions is for supervisory authorities; 'suggest deleting proposed Article 41a GDPR'); para 39 ('it is not necessary to add a specific provision to the GDPR on this point')

Tier 2 · regulatorsupports in part

EDPB–EDPS Joint Opinion 1/2026 on the AI Omnibus proposal — European Data Protection Board 20 January 2026 Title page: Joint Opinion 1/2026 on the Digital Omnibus on AI, adopted on 20 January 2026

Read it in the brief →Last verified 27 September 2026
Attributed viewattributed

noyb concluded that the Digital Omnibus's GDPR and ePrivacy amendments would produce multiple conflicts with the Charter and a clear departure from the GDPR's logic and CJEU case law.

Tier 4 · press / advocacystates this

Digital Omnibus Report V3: Analysis of Select GDPR and ePrivacy Proposals by the Commission — noyb 24 February 2026 "Our analysis reveals that the parts amending the GDPR and the ePrivacy Directive would lead to multiple conflicts with the EU's Charter of Fundamental Rights … and a clear departure from the current logic of the GDPR or CJEU case law"

Read it in the brief →Last verified 27 September 2026
Attributed viewattributed

ICLE argues that the Digital Omnibus's greatest weakness is its silence on enforcement architecture: without institutional reform, the authorities that read the GDPR expansively will read the new exemptions narrowly.

Tier 4 · press / advocacystates this

EU Digital Omnibus Hands the Wheel to the Referee — International Center for Law & Economics 11 June 2026 Opening section: 'Finally, the package’s greatest weakness was its silence on enforcement architecture. Without institutional reform, we argued, the same authorities that had interpreted the GDPR into a “law of everything” would read the new exemptions just as narrowly.'

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part VIII

Read it in the brief →Last verified 27 September 2026
Interpretationinterpretation

The November 2025 Digital Omnibus is an official concession that the rulebook the Union spent six years building requires structural repair before it has finished arriving.

Tier 2 · regulatorsupports in part

Legislative Train — Digital Package — European Parliament 2026

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part VIII

Read it in the brief →Last verified 27 August 2026

The full bibliography and the evidence method →

How it interacts

1 recorded interaction with other instruments — each with a direction, the provisions that carry it and its own sources. Direction is preserved as recorded: an instrument that amends another is not the same as one amended by it.

Data Omnibus Amends GDPR

PROPOSED amendment only. The Digital Omnibus proposes changes to the personal-data definition, a new Art. 41a, relocation of cookie consent to Art. 88a and a new Art. 88c. None is law; the proposal is stalled in Council.

What the brief argues
  • Primary lawThe Commission's four principal proposed GDPR reforms were: an entity-relative test for personal data in Art. 4(1); a new Art. 41a empowering the Commission to set, by implementing acts, the means and criteria for determining when pseudonymised data ceases to be personal; relocation of cookie consent into a new Art. 88a; and a new Art. 88c providing an explicit legitimate-interest basis for AI model training. None is law.
  • Secondary onlyThe Data Omnibus has moved in both directions before the Council: by May 2026 successive Cypriot Presidency texts had deleted three of the Commission's four principal GDPR reforms, the Cypriot Presidency withdrew its text from COREPER in late June 2026 for lack of a qualified majority, and the Irish Presidency's revised compromise of 3 September 2026 then restored an AI legitimate-interest clause (as a new Article 88 bis, without the Commission's safeguards) and moved pseudonymised data into a new Article 25a. As of 25 September 2026 the Council has no agreed mandate and trilogues have not begun.

Recorded as at August 27, 2026