The EU wants to spare users from endless consent clicks. The compromise could reshape how companies collect and use personal data.

Eight months after the Commission presented the Digital Omnibus rulebook, Parliament is facing 1,840 amendments and months of political bargaining. Negotiations will begin after the summer, with lawmakers aiming for a committee vote before February 2027.

The European Commission presented the Data Omnibus in November 2025 as part of a wider simplification package, which included the AI Act. While the AI Omnibus was approved this June, the rest of the proposal remains at the committee stage. 

It looks to amend the General Data Protection Regulation (GDPR), the ePrivacy Directive, the Data Act and EU cybersecurity-reporting rules. It would also repeal the Data Governance Act, the Open Data Directive, the Free Flow of Non-Personal Data Regulation and the Platform-to-Business Regulation, transferring some of their provisions into an expanded Data Act.

You might be interested

After presenting a draft report in June, Parliament’s co-rapporteurs, Finnish centre-right MEP Aura Salla and Estonian socialist MEP Marina Kaljurand, received up to 1,840 amendments

Ms Salla’s appointment as the Industry Committee’s lead negotiator has attracted controversy because before entering Parliament, she worked at Meta as Public Policy Director and Head of EU Affairs. In February, seven organisations called for her to be withdrawn, arguing risk of conflicts of interest. But Salla denied any conflict. She claimed to have complied with Parliament’s transparency requirements and held no financial or personal interest that could compromise her work.

Parliament pushes back narrower definition of personal data

Brussels wishes to clarify when pseudonymised information falls outside the GDPR is one of the most contested parts of the Data Omnibus. Pseudonymised data does not directly identify someone. But can still be used to link a person using additional information. Therefore, the same information could be personal data for one organisation but not another. A company receiving pseudonymised data might fall outside the GDPR if it does not have means to identify the people concerned.

Ms Marina Kaljurand told the joint Industry and Civil Liberties committee that her first amendments would be “keeping the definition of personal data intact”. “This is a fundamental principle of the GDPR. The changes proposed by the Commission would not only add legal uncertainty, but they would not have an effect on the implementation,” she added.

MEP Markéta Gregorová (Greens/CZE) pointed to the benefits for companies trading in pseudonymous profiles. “Changing the scope of a regulation cannot happen in an omnibus,” Gregorová said. “We cannot let a whole part of the industry claim they are out of scope just because they want to.”

Also, two European data-protection regulators urged lawmakers to reject the wording. The European Data Protection Board and European Data Protection Supervisor warned that it would narrow the concept of personal data and adversely affect the fundamental right to data protection.

The Commission has signalled that it is prepared to revise its approach. Responding to MEPs in July, it said they could “move on the definition of personal data”. At the same time, insisted that the legislation should provide a solution for pseudonymised information.

More data to train AI

A second dispute concerns whether AI companies should be able to rely more on “legitimate interest” to process personal data. The omnibus wants developing and operating AI models to qualify as a legitimate interest under the GDPR. Nevertheless, the Commission exception applies to sensitive information, such as health data, ethnicity, political views or sexual orientation.

For the right-wing co-rapporteur, access to data is part of Europe’s struggle to develop alternatives to US providers. “Many of you have been engaging together with me on the Mythos access scandal, and this just underlines how much we need right now European alternatives when it comes to AI, and what that requires is more data for our companies to be able to train their models. However, we need to keep our high standards when it comes to privacy, and of course, owning our own data,” she told the committee.

But MEP Kaljurand rejected the idea. “We should never think that compromising on fundamental rights will increase our competitiveness. Technical solutions that support privacy and trust are, and will continue to be, European industry’s advantage,” she said.

Also, the European Consumer Organisation (BEUC) wants the legitimate-interest provision removed. The organisation warns that it could become a general route for AI developers to reuse personal data without consent. “The use of ‘legitimate interest’ for AI systems to process data should not be allowed,” it recommends.

Fighting the cookie fatigue

The Commission also plans to reduce cookie banners. Instead of answering a banner on every website, a user could set a preference once, and participating services would be required to read it. The proposal would also prevent a website from asking again for the same consent for six months after a refusal.

Lawmakers are particularly concerned about the effect on publishers and online services funded by ads. In Parliament, MEP Gregorová called automated signals “a great opportunity to end cookie banners as we know them”.

But she said the Commission had not explained how the mechanism would operate or prevent dominant browser companies from gaining further power. “The Commission does not seem to have an idea of how the system of automated signals would work. It is up to us legislators to give it some flesh then, and this is what I will focus on. People deserve a genuine choice, and there is a need to finally get rid of the cookie banners while ensuring fair competition on the market,” she concluded.

The right also supports reducing cookies, with ECR shadow calling for proportionate rules. He added that “the new framework needs to reduce the requirement for consent without undermining protection, preventing fraud, technical diagnosis, frequency controls, protecting trademarks”.

Manufacturers and users fight over connected-product data

The Data Act, which became applicable in September 2025, gives users rights over data produced by products they own or operate. In some cases, they can ask manufacturers to provide that information to another company, such as an independent repair service. The Omnibus would reopen parts of that compromise. Manufacturers argue that horizontal sharing obligations do not reflect how data is used in industrial sectors and could expose trade secrets, benefit competitors or weaken investment in connected products.

DIGITALEUROPE, a trade association representing the technology sector, wants voluntary data sharing to become the default, “built on sectoral codes of conduct recognised by the Commission and used where access genuinely supports innovation and safety”. But digital-rights organisations say that the EU is reopening recently adopted data laws before testing their effects. EDRi argues that the proposed changes could concentrate greater control in dominant data holders, restrict access for public-interest research and weaken smaller data intermediaries.

That concern was echoed in Parliament. MEP Michael McNamara (Renew/IRL) called on Brussels to maintain the balance of control between manufacturers and users. He sought additional safeguards when governments request privately held data during public emergencies and warned against changes that could allow public authorities to overreach.

Tax data sent to the United States

Member states have opened another front in the Data Omnibus negotiations: the legal basis used to send Europeans’ financial information to countries outside the EU. At the request of several national delegations, the Cyprus Council presidency added wording covering international tax cooperation. The proposed recital says personal-data transfers may be necessary for “important reasons of public interest”.

The Council proposal could make it easier for member states to justify existing automatic exchanges under Article 49 of the GDPR, which provides exceptions allowing personal data to leave the European Economic Area.

MEP Aura Salla said lawmakers are aiming for a committee vote before February 2027, although no formal date has been set. Before then, Parliament expects a targeted assessment of the proposal to be published during autumn.