On November 19, 2025, the European Commission (the “Commission”) unveiled the much-anticipated digital omnibus legislative package (the “Digital Omnibus”), setting the stage for a new era of digital governance and regulatory simplification across the European Union. According to the Commission, this initiative is designed to enable European businesses to devote more energy to innovation and growth, rather than navigating complex compliance landscapes.
The Digital Omnibus is complemented by the Data Union Strategy and the European Business Wallet proposal, each aiming to simplify organizations’ ability to conduct business across EU Member States.
Single Cybersecurity Incident Reporting Point
One of the key proposals within the Digital Omnibus is the introduction of a single-entry point for cybersecurity incident reporting. Presently, companies operating in the EU are subject to overlapping obligations under multiple frameworks, including the Directive of the European Parliament and of the Council on measures for a high common level of cybersecurity across the EU (the “NIS2 Directive”), the EU General Data Protection Regulation (“GDPR”) and the Digital Operational Resilience Act, each requiring separate notifications in the event of a cyber incident.
With the Digital Omnibus, the Commission proposes a unified reporting interface enabling businesses to satisfy all their incident notification requirements through one secure portal. The Commission stated that the interface will be engineered with robust security safeguards and undergo comprehensive reliability and effectiveness testing prior to its launch.
Amendments to the AI Act
The Digital Omnibus package also addresses the implementation of the Artificial Intelligence Act (“AI Act”), aiming to foster responsible innovation while protecting society, safety and fundamental rights.
Targeted amendments to the AI Act include:
- Implementation Timeline Linked to Support Tools: The application of high-risk AI rules will be tied to the availability of necessary standards and support tools, ensuring that companies have the resources required for compliance. The timeline for enforcement of these rules is set at a maximum of 16 months, only beginning once the Commission confirms that the needed tools are in place.
- Simplified Compliance for SMEs and SMCs: Simplifications currently available to small and medium-sized enterprises (“SMEs”) will be extended to small mid-cap companies (“SMCs”), including streamlined technical documentation requirements and special consideration in the application of penalties.
- Processing of Special Category Data: Providers and deployers of all AI systems and models will be permitted to process special categories of personal data for the purpose of bias detection and correction, provided appropriate safeguards are implemented, thereby facilitating compliance with data protection laws.
- Promoting AI Literacy: Rather than imposing vague obligations on providers and deployers of AI systems, the Commission and Member States will take responsibility for fostering AI literacy while retaining targeted training obligations for deployers of high-risk AI systems.
- Flexible Post-Market Monitoring: Providers will be offered greater flexibility in post-market monitoring by removing the requirement for a harmonized post-market monitoring plan.
- Reduced Registration Burdens for Providers in High-Risk Areas: Providers of AI systems used in high-risk areas, but which are only deployed for narrow or procedural tasks, will benefit from reduced registration requirements.
- Centralized Oversight of General-Purpose AI Models: The AI Office will reinforce its powers and centralize oversight over a broad range of AI systems, particularly those built on general-purpose AI models or embedded in very large online platforms and search engines, reducing governance fragmentation.
- Expanded Regulatory Sandboxes: The amendments introduce expanded opportunities for regulatory sandboxes and real-world testing. The AI Office will set up an EU-level AI regulatory sandbox, which will be available from 2028.
- Clarifying Legislative Interplay and Procedures: Targeted changes will clarify the relationship between the AI Act and other EU legislation and adjust procedures under the Act to enhance its implementation and overall operation.
Enhanced Data Access
The Commission announced that the Digital Omnibus shall improve access to data, in particular simplifying data rules by:
- Consolidating EU Data Rules via the Data Act: The Digital Omnibus consolidates EU data rules via the Data Act, merging four pieces of legislation for greater legal clarity.
- Exemptions for SMEs and SMCs: Targeted exemptions from some cloud-switching rules are expected to yield 1.5 billion euro in one-off savings.
- Model Contractual Terms and Standard Clauses: New guidance for compliance with the Data Act will be provided through model contractual terms for data access, and use, and standard contractual clauses for cloud computing contracts.
- Boosting AI Innovation: Enhanced access to high-quality, up-to-date datasets will support the growth of European AI companies and strengthen EU-wide innovation potential.
GDPR Amendments and Modernized Cookie Rules
Other key proposals encompassed within the Digital Omnibus include:
- Targeted Amendments to the GDPR: The Commission proposes specific amendments to the GDPR aimed at, among others:
- Extending the data breach reporting deadline from 72 hours to 96 hours;
- Codifying the recent case law of the Court of Justice of the European Union with respect to the definition of personal data;
- Clarifying the rules on the use of personal data for AI training purposes; and
- Simplifying certain administrative obligations for businesses, such as the requirement to conduct data protection impact assessments.
- Cookie Consent Rules: The Commission proposes modernizing cookie consent rules by reducing the frequency of cookie banners and enabling users to provide and manage consent through one-click mechanisms and centralized browser or operating system preferences.
The Digital Omnibus, together with the Data Union Strategy and European Business Wallet, will be presented to the European Parliament and the European Council for further consideration and adoption.
Read the press release. Read the Digital Omnibus.
Search
Recent Posts
Categories
- Behavioral Advertising
- Centre for Information Policy Leadership
- Children’s Privacy
- Cyber Insurance
- Cybersecurity
- Enforcement
- European Union
- Events
- FCRA
- Financial Privacy
- General
- Health Privacy
- Identity Theft
- Information Security
- International
- Marketing
- Multimedia Resources
- Online Privacy
- Security Breach
- U.S. Federal Law
- U.S. State Law
- Workplace Privacy
Tags
- Aaron Simpson
- Accountability
- Adequacy
- Advertisement
- Advertising
- Age Appropriate Design Code
- Age Verification
- American Privacy Rights Act
- Anna Pateraki
- Anonymization
- Anti-terrorism
- APEC
- Apple Inc.
- Argentina
- Arkansas
- Article 29 Working Party
- Artificial Intelligence
- Audit
- Australia
- Austria
- Automated Decisionmaking
- Baltimore
- Bankruptcy
- Belgium
- Biden Administration
- Big Data
- Binding Corporate Rules
- Biometric Data
- Blockchain
- Bojana Bellamy
- Brazil
- Brexit
- British Columbia
- Brittany Bacon
- Brussels
- Business Associate Agreement
- BYOD
- California
- CAN-SPAM
- Canada
- Cayman Islands
- CCPA
- CCTV
- Chile
- China
- Chinese Taipei
- Christopher Graham
- CIPA
- Class Action
- Clinical Trial
- Cloud
- Cloud Computing
- CNIL
- Colombia
- Colorado
- Committee on Foreign Investment in the United States
- Commodity Futures Trading Commission
- Compliance
- Computer Fraud and Abuse Act
- Congress
- Connecticut
- Consent
- Consent Order
- Consumer Protection
- Consumer Rights
- Cookies
- COPPA
- Coronavirus/COVID-19
- Council of Europe
- Council of the European Union
- Court of Justice of the European Union
- CPPA
- CPRA
- Credit Monitoring
- Credit Report
- Criminal Law
- Critical Infrastructure
- Croatia
- Cross-Border Data Flow
- Cross-Border Data Transfer
- Cyber Attack
- Cybersecurity
- Cybersecurity and Infrastructure Security Agency
- Data Breach
- Data Brokers
- Data Controller
- Data Localization
- Data Privacy Framework
- Data Processor
- Data Protection Act
- Data Protection Authority
- Data Protection Impact Assessment
- Data Protection Officer
- Data Security
- Data Transfer
- David Dumont
- David Vladeck
- Deceptive Trade Practices
- Delaware
- Denmark
- Department of Commerce
- Department of Defense
- Department of Health and Human Services
- Department of Homeland Security
- Department of Justice
- Department of the Treasury
- Design
- Digital Markets Act
- District of Columbia
- Do Not Call
- Do Not Track
- Dobbs
- Dodd-Frank Act
- DORA
- DPIA
- E-Privacy
- E-Privacy Directive
- Ecuador
- Ed Tech
- Edith Ramirez
- Electronic Communications Privacy Act
- Electronic Privacy Information Center
- Electronic Protected Health Information
- Elizabeth Denham
- Employee Monitoring
- Encryption
- ENISA
- EU Data Protection Directive
- EU Member States
- European Commission
- European Data Protection Board
- European Data Protection Supervisor
- European Parliament
- Facial Recognition Technology
- FACTA
- Fair Credit Reporting Act
- Fair Information Practice Principles
- Federal Aviation Administration
- Federal Bureau of Investigation
- Federal Communications Commission
- Federal Data Protection Act
- Federal Trade Commission
- FERC
- Financial Data
- FinTech
- Florida
- Food and Drug Administration
- Foreign Intelligence Surveillance Act
- France
- Franchise
- Fred Cate
- Freedom of Information Act
- Freedom of Speech
- Fundamental Rights
- GDPR
- Geofencing
- Geolocation
- Geolocation Data
- Georgia
- Germany
- Global Privacy Assembly
- Global Privacy Enforcement Network
- Gramm Leach Bliley Act
- Hacker
- Hawaii
- Health Data
- HIPAA
- HITECH Act
- Hong Kong
- House of Representatives
- Hungary
- Illinois
- India
- Indiana
- Indonesia
- Information Commissioners Office
- Information Sharing
- Insurance Provider
- Internal Revenue Service
- International Association of Privacy Professionals
- International Commissioners Office
- Internet
- Internet of Things
- Iowa
- IP Address
- Ireland
- Israel
- Italy
- Jacob Kohnstamm
- Japan
- Jason Beach
- Jay Rockefeller
- Jenna Rode
- Jennifer Stoddart
- Jersey
- Jessica Rich
- John Delionado
- John Edwards
- Kentucky
- Korea
- Large Language Model
- Latin America
- Laura Leonard
- Law Enforcement
- Lawrence Strickling
- Legislation
- Liability
- Lisa Sotto
- Litigation
- Location-Based Services
- London
- Louisiana
- Madrid Resolution
- Maine
- Malaysia
- Maryland
- Massachusetts
- Meta
- Mexico
- Michigan
- Microsoft
- Minnesota
- Missouri
- Mobile
- Mobile App
- Mobile Device
- Montana
- Morocco
- MySpace
- Natascha Gerlach
- National Institute of Standards and Technology
- National Labor Relations Board
- National Science and Technology Council
- National Security
- National Security Agency
- National Telecommunications and Information Administration
- Nebraska
- NEDPA
- Netherlands
- Nevada
- New Hampshire
- New Jersey
- New Mexico
- New York
- New Zealand
- Nigeria
- Ninth Circuit
- North Carolina
- North Dakota
- North Korea
- Norway
- Obama Administration
- OCPA
- OECD
- Office for Civil Rights
- Office of Foreign Assets Control
- Ohio
- Oklahoma
- Online Behavioral Advertising
- Online Privacy
- Opt-In Consent
- Oregon
- Outsourcing
- Pakistan
- Parental Consent
- Payment Card
- PCI DSS
- Penalty
- Pennsylvania
- Personal Data
- Personal Health Information
- Personal Information
- Personally Identifiable Information
- Peru
- Philippines
- Poland
- PRISM
- Privacy
- Privacy By Design
- Privacy Notice
- Privacy Policy
- Privacy Rights
- Privacy Rule
- Privacy Shield
- Profiling
- Protected Health Information
- Ransomware
- Record Retention
- Red Flags Rule
- Rhode Island
- Richard Thomas
- Right to Be Forgotten
- Right to Privacy
- Risk Assessment
- Risk-Based Approach
- Rosemary Jay
- Russia
- Safe Harbor
- Salesforce
- Sanctions
- Schrems
- Scott Kimpel
- Securities and Exchange Commission
- Security Rule
- Senate
- Sensitive Data
- Serbia
- Service Provider
- Singapore
- Smart Grid
- Smart Metering
- Social Media
- Social Security Number
- South Africa
- South Carolina
- South Dakota
- South Korea
- Spain
- Spyware
- Standard Contractual Clauses
- State Attorneys General
- States Attorney General
- Steven Haas
- Stick With Security Series
- Stored Communications Act
- Student Data
- Supreme Court
- Surveillance
- Sweden
- Switzerland
- Taiwan
- Targeted Advertising
- Telecommunications
- Telemarketing
- Telephone Consumer Protection Act
- Tennessee
- Terry McAuliffe
- Texas
- Text Message
- Thailand
- Transparency
- Transportation Security Administration
- Trump Administration
- United Arab Emirates
- United Kingdom
- United States
- Unmanned Aircraft Systems
- Uruguay
- Utah
- Vermont
- Video Privacy Protection Act
- Video Surveillance
- Virginia
- Viviane Reding
- Washington
- Whistleblowing
- Wireless Network
- Wiretap
- ZIP Code