Search
Contact
Symbolbild zum Digital Omnibus
19.12.2025 | KPMG Law Insights

Digital Omnibus: More efficiency instead of deregulation

The European Commission aims to streamline digital legislation. On November 19, 2025, it presented its proposals for the “Digital Omnibus” (including a separate AI Omnibus). The AI Omnibus was published in the Official Journal of the European Union on July 24, 2026, and entered into force on July 27, 2026. It primarily postpones the applicability of certain provisions of the AI Act.

The core of the reform package: the various pieces of digital legislation are to be simplified and more closely interlinked. The package also includes accompanying initiatives, including a data strategy and new tools for companies to facilitate practical implementation.

In response to the ongoing digital transformation, many new legal regulations have emerged in recent years, including the AI Act, the Data Act, the GDPR, the ePrivacy Directive, and the Cyber Resilience Act. However, these various pieces of legislation have so far shown little coordination with one another. This not only creates confusion for companies but also leads to overlapping obligations. The result is a significant administrative burden.

Data protection level to be maintained

For the European Commission, the reform proposals are primarily about efficiency and practicality. The changes are intended primarily to simplify the rules and should not lead to a fundamental reduction in the level of protection. Only redundant provisions are to be removed, and overlapping requirements are to be consolidated. The European Commission aims to maintain the EU’s high standard of data protection. At the same time, it is foreseeable that certain proposals—particularly those regarding cookies, access to end devices, and AI training scenarios—will be the subject of politically and legally contentious debate.

Planned changes to the GDPR and the ePrivacy Directive

The content of the GDPR is to be partially adapted. At the same time, certain rules on access to end devices (cookies and similar identifiers) are to be modernized and – insofar as personal data is processed in the process – transferred more strongly into the GDPR enforcement framework.

Among other things, the EU Commission wants information and documentation obligations for companies to be simplified in certain cases. There are also plans to simplify the reporting of data breaches, including through more harmonized and standardized reporting processes as well as thresholds and deadlines in order to reduce multiple reports and over-reporting.

Some ePrivacy rules are to be integrated into the GDPR, in particular requirements for storing and accessing information on end devices. Insofar as personal data is processed in the process, these end device access rules are to be transferred from the ePrivacy Directive to the GDPR. To counteract “consent fatigue”, consent pop-ups are to be significantly reduced: Banners should no longer be required for low-risk and harmless purposes (for example, pure reach measurement). In addition, uniform preferences via browser and system settings or one-click decisions should be possible, which websites must respect for at least six months. However, consent will still be required for accessing data on end devices.

Pseudonymized data should be easier to use for AI training

A proposed amendment to the GDPR is already the subject of heated debate: The European Commission aims to clarify the rules on pseudonymization (i.e., the replacement of directly identifying information with identifiers or codes) so that, subject to appropriate safeguards and under certain conditions, datasets can be more easily shared and used (including in the context of AI training), without them automatically being considered personal data for every recipient. According to the Commission, this amounts to the codification of a recent CJEU ruling on relative personal reference. The decisive factor is whether the specific third party or recipient has means that can reasonably be used for re-identification. The controller who pseudonymizes the dataset, however, should remain fully bound by the GDPR.

In addition, clarifications on data processing for AI purposes (for example through training and development) should be more operationalized, in particular on the basis of “legitimate interests” under certain safeguards and on effective objection options.

The protection of personal data is enshrined in fundamental rights under EU law, in particular in Art. 8 CFR and Art. 16 TFEU. Clarifications under secondary law must be measured against this. The extent to which the proposed clarification of the term will be effective will therefore depend largely on how it is specifically formulated in the legislative process and how the ECJ and supervisory practice apply the definition of “reasonably foreseeable means”.

Planned changes to the Data Act and Data Governance Act

The use of data is to be brought together in a bundled data legal framework in future. The approach is to consolidate several building blocks of the “data acquis” in the Data Act. In particular, the content of the Data Governance Act (DGA), the open data rules and the free flow of non-personal data rules are to be integrated into a restructured Data Act.

The EU would also like to address some of the industry’s concerns. For example, the strict requirements for data brokerage services under the DGA are to be significantly relaxed. Instead of highly formalized obligations, the focus should be on more risk-based requirements and voluntary evidence and trust approaches, depending on how they are structured.

Companies have also frequently criticized the obligation to disclose data under the Data Act and the resulting weakening of trade secret protection. The EU Commission now wants to strengthen the protection of trade secrets. Companies should be able to refuse to disclose data if they can prove that there is a high risk that the data could otherwise be used unlawfully.

Improvements are also to be made in other areas: The EU Commission wants to make it easier to reuse public data in order to strengthen data-driven business models. The switching obligations for cloud providers are to be clarified. In addition, government access to company data (B2G) is to be focused more on genuine emergencies in order to reduce legal uncertainty and burdens.

SMEs and the new category of small mid-caps are to be exempted from many obligations.

Easier reporting of cyber incidents

The EU Commission wants to make it much easier for companies to report security incidents by creating a central European reporting portal. All reports under the GDPR, EU Digital Identity Regulation, CER, NIS-2 and DORA are to be bundled there and then automatically forwarded to national authorities. It is important to note that the material reporting obligations are not to be eliminated as a result, but the submission is to become more centralized and consistent. Parallel reports to different authorities are to be reduced. Until now, companies may have had to report a single incident to several authorities.

Artificial intelligence

Adjustments are also planned for the AI Act. It has already been decided:

  • The AI Act is being amended to include a ban on AI practices that generate non-consensual sexual and intimate content or depictions of child sexual abuse. This specifically covers so-called “nudification” applications and certain intimate deepfakes.
  • The regulations for high-risk AI systems have been postponed and will now only apply from December 2, 2027 for stand-alone high-risk AI systems and from August 2, 2028 for high-risk AI systems embedded in products.
  • The requirements for AI literacy have been updated. Providers and operators of AI systems must take measures to promote AI literacy among their employees and other individuals who use or operate AI systems on their behalf. At the same time, the European Commission and the member states are to provide appropriate support services.
  • Article 49(2) of the AI Act already required providers to register even non-high-risk AI systems. The Commission had sought to remove this requirement in the Digital Omnibus proposal—but the Council and Parliament have now agreed to retain it after all.
  • The standard of absolute necessity for the processing of special categories of personal data for the purpose of detecting and correcting distortions has been reinstated.
  • The deadline for the establishment of AI laboratories by the competent authorities at national level is extended until August 2, 2027.
  • The transitional period granted to providers for the implementation of transparency solutions for artificially created content will be reduced from six months to three months; the new deadline has been set for December 2, 2026.

The obligations for SMEs and small mid-caps will be simplified in certain areas. In this way, the EU Commission aims to promote innovation.

The Council and Parliament have also agreed on clearer responsibilities and procedures at EU level, particularly for systems based on general-purpose AI models. The AI Office is to take on a stronger coordinating role and contribute to a more uniform application of the regulations. The aim is to improve cooperation between national supervisory authorities and reduce fragmentation without fundamentally changing the existing decentralized enforcement structure.

What the Digital Omnibus would mean for companies

The EU Commission’s proposals would bring more clarity and predictability for companies. The strict obligations and high level of protection would essentially remain in place. However, the improved structure and interlinking of the individual legal acts as well as the simplified documentation requirements would make it easier for companies to handle them in practice.

While the AI Omnibus is already in effect, the further timeline for the remaining proposals in the Digital Omnibus depends on the progress of the legislative process.

The Commission has also launched a consultation on the Digital Fitness Check. This is also intended to simplify the EU’s digital regulation and ensure that overlaps and inconsistencies in existing digital legislation are reduced. New initiatives are also mentioned in the package, such as the “Data Union Strategy”, as well as an instrument such as the “European Business Wallets”, which are intended to facilitate administrative processes in the single market.

 

Explore #more

11.08.2026 | In the media

Guest article in *Versicherungsmonitor* on the topic of cyber claims regulation

Cyberattacks—particularly ransomware campaigns—pose challenges for insurers when it comes to claims settlement. When entire IT infrastructures at insured companies come to a standstill and the…

11.08.2026 | KPMG Law Insights

Transparency Requirements Under Article 50 of the AI Act: Companies Should Address These Questions Now

The transparency requirements of the EU AI Act have been in effect since August 2, 2026. These obligations apply to chatbots, AI assistants, avatars, synthetic…

10.08.2026 | In the media

Op-Ed on the Procurement Acceleration Act and Sustainable Public Procurement

On April 23, 2026, the Bundestag passed the Act on Accelerating the Award of Public Contracts. After the Act was published in the Federal Law…

05.08.2026 | Deal Notifications

KPMG Law and KPMG Advise NMP Germany on the Acquisition of Klöckner Desma Elastomertechnik GmbH

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) and KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG) advised NMP Germany GmbH on the legal, tax, and financial aspects of the transaction…

04.08.2026 | In the media

Portrait of Mathias Oberndörfer in the *Börsen-Zeitung*

Mathias Oberndörfer has been with KPMG for more than 20 years—reason enough for an in-depth profile in the *Börsen-Zeitung*. The Börsen-Zeitung traces his career path…

03.08.2026 | Unkategorisiert

KPMG Law und KPMG beraten NMP Germany beim Erwerb der Klöckner Desma Elastomertechnik GmbH

Die KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) und die KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG) haben die NMP Germany GmbH beim Erwerb der Klöckner Desma Elastomertechnik Gruppe…

03.08.2026 | In the media

Statement by KPMG Law experts on the EU Packaging Regulation in the business magazine *impulse*

Starting January 1, 2030, packaging must consist of at least 70 percent recyclable materials. Starting August 1, 2030, so-called “deceptive packaging” will also be banned.…

30.07.2026 | KPMG Law Insights

CRD VI and Third-Country Banks: Preserving Cross-Border Access to the EU Market

From 11 January 2027, third-country banks will need to reassess whether they may continue to provide banking services into the EU on a cross-border basis.…

28.07.2026 | In the media

Op-ed in the FAZ on the topic “Who is liable when algorithms make decisions?”

Artificial intelligence has made its way into the boardroom. Whether it’s investment decisions, risk analysis, or workforce planning—the results of artificial intelligence are increasingly being…

23.07.2026 | In the media

Statement by KPMG Law experts on Südwestrundfunk (SWR) regarding the GKV Savings Act

On the TV program ” SWR Aktuell Rheinland-Pfalz,” KPMG Law hospital expert Harald Maas discusses the GKV Savings Act and the growing financial pressure…

Contact

Francois Heynike, LL.M. (Stellenbosch)

Partner
Head of Technology Law

THE SQUAIRE Am Flughafen
60549 Frankfurt am Main

Tel.: +49-69-951195770
fheynike@kpmg-law.com

Dr. Daniel Taraz

Senior Manager

Fuhlentwiete 5
20355 Hamburg

Tel.: +49 40 360994-5483
danieltaraz@kpmg-law.com

© 2026 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll