On November 19, 2025, the European Commission published its proposal for the so-called “Digital Omnibus.” But what exactly does this comprehensive and ambitious proposal entail?
The “Digital Omnibus” proposal brings together various elements of digital technology that differ in substance and aims to revise and harmonize several key pillars of EU digital regulation, in particular the Data Act, the GDPR, and the AI Act. The main drivers behind this initiative are simplifying overlapping regulations, reducing administrative burdens for businesses, and increasing legal certainty
within the European Union.
One notable feature is that the European Commission is attempting to codify certain principles from the case law of the Court of Justice. For example, the definition of “personal data” from case law (including the SRB, GAR, and Nowak judgments) is explicitly included in the proposal. This attempt at clarification is, in itself, to be welcomed: after all, it provides greater legal certainty for both data subjects and data controllers.
In addition, the European Commission is proposing a more ambitious—and more controversial—reform: broader opportunities to train AI systems using personal data. This step fits into the broader strategy to keep the European Union competitive in the field of artificial intelligence, yet it touches on one of the most sensitive GDPR issues: the large-scale processing of personal data and its lawfulness. The question therefore arises as to whether this expansion will be adopted in its current form.
The proposal also includes an extension of the reporting deadline for data breaches posing a potentially high risk from 72 to 96 hours. In our view, this extension better reflects the practical feasibility of meeting this deadline.
One notable change is the proposed centralization of notifications and complaints under a single umbrella contact point, regardless of whether they concern, for example, a GDPR, eIDAS, or NIS2 notification. Furthermore, complaints and reports would no longer be directed to the Belgian Data Protection Authority, but to an EU-wide body that coordinates complaints and reports among member states. Should this change be implemented, we are certainly very curious about the practical implementation of this streamlining and whether this shift will actually lead to more efficient enforcement.
Finally, it is important to emphasize that for now, everything will remain as it was. The proposal still needs to be approved by the European Parliament and the Council, after which negotiations will follow. Even if the Digital Omnibus is adopted in its current or amended form, it is likely that many of the changes will have little impact on day-to-day operations. After all, the core obligations under the GDPR remain in place.
Therefore, it remains crucial to strive for GDPR compliance within your organization. We guide companies through this process using a clear step-by-step plan, practical advice, and a realistic timeline.
Would you like to learn more about GDPR obligations or new European regulatory initiatives?
Feel free to contact our technology and design experts.
