DIGITAL OMNIBUS BLOG

The European Commission has unveiled the Digital Omnibus, a proposal for a far-reaching legislative package designed to modernise the EU’s digital rulebook in one sweep. The Digital Omnibus proposes amendments to the GDPR, creating new GDPR bases for AI training and operation, expanding research permissions, and tying directly into the Data Act and NIS2 reforms. Alongside this, the Commission has proposed a separate amendment to the AI Act that would delay and reorganise the rollout of high risk AI obligations. Both proposals signal a significant shift in how the EU intends to regulate data and AI over the next decade.

The proposal is politically explosive: civil-society groups denounce it as the biggest weakening of GDPR since its its entry into force, while big tech and AI companies welcome it as overdue. The proposals now move into the ordinary legislative procedure where Parliament and Council will spend months rewriting and negotiating the final text.

Below, we outline the most important points and amendments that clients should be aware of.

GDPR CORE CHANGES

Definition of personal data becomes controller-relative

The proposal rewrites one of the pillars of EU privacy law: what counts as personal data. Under the new approach, identifiability becomes controller-specific. In other words, if a company cannot reasonably identify an individual from the data it holds, that data is not personal data for that company. This creates a split in obligations along the value chain. Upstream players who collect data may still be fully bound by the GDPR, while downstream companies, such as (sub)processors, who only receive pseudonyms could step outside GDPR scope. The real battleground will be the interpretation of “reasonably likely”: the vaguer the standard, the more room companies will have to argue that they simply cannot identify anyone. Regulators, unsurprisingly, will not take that at face value.

For clients, this introduces both opportunity and risk. If the proposal would enter into force, businesses that use pseudonymised datasets could consider part of their processing would be “non-personal” if they do not have access to the “key” to make the data personal once again. We expect data protection authorities to implement the rule strictly until courts settle the boundaries.

Transparency and research carve-outs

The proposal introduces limited situations where organisations do not need to provide the full privacy notice normally required: (a) simple relationships where very little personal data is processed and the organisation already has direct contact details for the individual, and (b) genuine scientific research where giving the usual notice would make the research impossible or would seriously undermine the objectives of the project. Even in these cases, organisations must still consider alternative ways to inform people, for example through public notices.

This will genuinely help research intensive clients, universities, health innovators and deep tech companies that run long-term studies or work with complex datasets. It does not create a shortcut for commercial actors who try to dress up profiling or marketing as “research”. Supervisory authorities will expect strong transparency safeguards, especially where the individuals involved are vulnerable or where the use of data is particularly sensitive.

Breach notifications

The breach notification deadline moves from 72 to 96 hours after becoming aware of the breach. The extra 24 hours is helpful but not transformative.

DATA ACT & DATA GOVERNANCE CORE CHANGES

The Omnibus brings together rules that were previously scattered across different instruments in the Data Act. On top of this structural change, the proposal contains a benefit for smaller organisations: SMEs and small mid cap companies receive targeted exemptions from several cloud switching obligations that would otherwise require costly technical work to ensure portability and interoperability. These exemptions are designed to ease the financial pressure on smaller companies that want to migrate away from a provider but lack the resources for a full technical overhaul.

SMEs that rely heavily on cloud infrastructure will welcome the possibility of lower switching costs and more manageable migration paths. Larger enterprises will not benefit from these exemptions. This part of the Omnibus will require careful reading once the final implementing rules are published.

AI ACT CORE CHANGES

High risk obligations delayed and made conditional

The Commission wants to slow down the rollout of the AI Act’s high risk rules. Under the current law, most high risk systems would need to comply from August 2026, with some product linked systems following in 2027. The Commission now accepts that the EU is not ready. There are too few assessment bodies, there are no harmonised standards for the core requirements, and several national authorities are still setting up basic structures.

The proposal replaces the fixed start date with a conditional one. The high risk obligations will only start once the essential standards and compliance tools are in place. When the Commission considers the system ready, Annex III obligations will start six months later and Annex I obligations will start after one year. This gives companies more time, but it also means the exact start date becomes uncertain. For clients, the message is simple: compliance planning should continue, but with the understanding that the Commission can activate the obligations sooner or later depending on how quickly the ecosystem matures.

Expanded real world testing

The proposal makes it much easier to test high risk AI systems in real life situations before they meet the full set of compliance requirements. Providers of high-risk AI systems can run controlled trials outside the strict confines of regulatory sandboxes. This matters most for sectors where simulations only go so far, for example automotive, robotics, medical technology and complex industrial settings.

Permission to use sensitive data for bias detection

The proposal adds a new legal basis allowing high risk AI providers to process special categories of personal data solely to detect and correct bias. This is subject to strict safeguards such as limited access, strong security, clear deletion rules and detailed documentation. The Commission considers this essential for building fair and reliable high risk AI systems. Clients working with datasets that are likely to generate bias questions should expect this mechanism to become part of standard practice. It will also require coordination with data protection teams to implement the safeguards correctly.

SME and mid cap relief

The simplifications for SMEs in the original AI Act are extended to small mid cap companies. These include lighter technical documentation, more flexible quality management requirements and a more forgiving approach to administrative penalties. This is meant to reduce the cost of compliance for companies that are beyond SME size but still lack the resources of large enterprises.

LOOKING AHEAD

Both proposals mark a clear shift in the EU’s digital strategy. The Commission wants faster innovation, lighter compliance for smaller players and a more coherent rulebook, but it also opens the door to major reinterpretations of long standing privacy and AI rules. The coming legislative process will decide how far these changes go. Parliament and Council will rewrite large parts of the text and several elements may be redrafted from scratch. On behalf of our clients, we will keep a close eye on the negotiations and treat this as the start of a multi-year transition rather than a final outcome. We will continue to monitor the developments and provide updates as the proposals evolve.

If you have questions about any of these changes or want to understand how the shifting regulatory landscape affects your business, feel free to contact Cresco’s Innovation Team at [email protected]. We are following the legislative process closely and can help you navigate both the current rules and what is coming next.

Team

Axel Desmet
Associate
Ward Verwaeren
Counsel
Aida Kaloci
Associate
Olivier Van Raemdonck
Managing Partner

Expertises

data & privacy