
The European Commission aims to streamline digital legislation. On November 19, 2025, it presented its proposals for the “Digital Omnibus” (including a separate AI Omnibus). The AI Omnibus was published in the Official Journal of the European Union on July 24, 2026, and entered into force on July 27, 2026. It primarily postpones the applicability of certain provisions of the AI Act.
The core of the reform package: the various pieces of digital legislation are to be simplified and more closely interlinked. The package also includes accompanying initiatives, including a data strategy and new tools for companies to facilitate practical implementation.
In response to the ongoing digital transformation, many new legal regulations have emerged in recent years, including the AI Act, the Data Act, the GDPR, the ePrivacy Directive, and the Cyber Resilience Act. However, these various pieces of legislation have so far shown little coordination with one another. This not only creates confusion for companies but also leads to overlapping obligations. The result is a significant administrative burden.
For the European Commission, the reform proposals are primarily about efficiency and practicality. The changes are intended primarily to simplify the rules and should not lead to a fundamental reduction in the level of protection. Only redundant provisions are to be removed, and overlapping requirements are to be consolidated. The European Commission aims to maintain the EU’s high standard of data protection. At the same time, it is foreseeable that certain proposals—particularly those regarding cookies, access to end devices, and AI training scenarios—will be the subject of politically and legally contentious debate.
The content of the GDPR is to be partially adapted. At the same time, certain rules on access to end devices (cookies and similar identifiers) are to be modernized and – insofar as personal data is processed in the process – transferred more strongly into the GDPR enforcement framework.
Among other things, the EU Commission wants information and documentation obligations for companies to be simplified in certain cases. There are also plans to simplify the reporting of data breaches, including through more harmonized and standardized reporting processes as well as thresholds and deadlines in order to reduce multiple reports and over-reporting.
Some ePrivacy rules are to be integrated into the GDPR, in particular requirements for storing and accessing information on end devices. Insofar as personal data is processed in the process, these end device access rules are to be transferred from the ePrivacy Directive to the GDPR. To counteract “consent fatigue”, consent pop-ups are to be significantly reduced: Banners should no longer be required for low-risk and harmless purposes (for example, pure reach measurement). In addition, uniform preferences via browser and system settings or one-click decisions should be possible, which websites must respect for at least six months. However, consent will still be required for accessing data on end devices.
A proposed amendment to the GDPR is already the subject of heated debate: The European Commission aims to clarify the rules on pseudonymization (i.e., the replacement of directly identifying information with identifiers or codes) so that, subject to appropriate safeguards and under certain conditions, datasets can be more easily shared and used (including in the context of AI training), without them automatically being considered personal data for every recipient. According to the Commission, this amounts to the codification of a recent CJEU ruling on relative personal reference. The decisive factor is whether the specific third party or recipient has means that can reasonably be used for re-identification. The controller who pseudonymizes the dataset, however, should remain fully bound by the GDPR.
In addition, clarifications on data processing for AI purposes (for example through training and development) should be more operationalized, in particular on the basis of “legitimate interests” under certain safeguards and on effective objection options.
The protection of personal data is enshrined in fundamental rights under EU law, in particular in Art. 8 CFR and Art. 16 TFEU. Clarifications under secondary law must be measured against this. The extent to which the proposed clarification of the term will be effective will therefore depend largely on how it is specifically formulated in the legislative process and how the ECJ and supervisory practice apply the definition of “reasonably foreseeable means”.
The use of data is to be brought together in a bundled data legal framework in future. The approach is to consolidate several building blocks of the “data acquis” in the Data Act. In particular, the content of the Data Governance Act (DGA), the open data rules and the free flow of non-personal data rules are to be integrated into a restructured Data Act.
The EU would also like to address some of the industry’s concerns. For example, the strict requirements for data brokerage services under the DGA are to be significantly relaxed. Instead of highly formalized obligations, the focus should be on more risk-based requirements and voluntary evidence and trust approaches, depending on how they are structured.
Companies have also frequently criticized the obligation to disclose data under the Data Act and the resulting weakening of trade secret protection. The EU Commission now wants to strengthen the protection of trade secrets. Companies should be able to refuse to disclose data if they can prove that there is a high risk that the data could otherwise be used unlawfully.
Improvements are also to be made in other areas: The EU Commission wants to make it easier to reuse public data in order to strengthen data-driven business models. The switching obligations for cloud providers are to be clarified. In addition, government access to company data (B2G) is to be focused more on genuine emergencies in order to reduce legal uncertainty and burdens.
SMEs and the new category of small mid-caps are to be exempted from many obligations.
The EU Commission wants to make it much easier for companies to report security incidents by creating a central European reporting portal. All reports under the GDPR, EU Digital Identity Regulation, CER, NIS-2 and DORA are to be bundled there and then automatically forwarded to national authorities. It is important to note that the material reporting obligations are not to be eliminated as a result, but the submission is to become more centralized and consistent. Parallel reports to different authorities are to be reduced. Until now, companies may have had to report a single incident to several authorities.
Adjustments are also planned for the AI Act. It has already been decided:
The obligations for SMEs and small mid-caps will be simplified in certain areas. In this way, the EU Commission aims to promote innovation.
The Council and Parliament have also agreed on clearer responsibilities and procedures at EU level, particularly for systems based on general-purpose AI models. The AI Office is to take on a stronger coordinating role and contribute to a more uniform application of the regulations. The aim is to improve cooperation between national supervisory authorities and reduce fragmentation without fundamentally changing the existing decentralized enforcement structure.
The EU Commission’s proposals would bring more clarity and predictability for companies. The strict obligations and high level of protection would essentially remain in place. However, the improved structure and interlinking of the individual legal acts as well as the simplified documentation requirements would make it easier for companies to handle them in practice.
While the AI Omnibus is already in effect, the further timeline for the remaining proposals in the Digital Omnibus depends on the progress of the legislative process.
The Commission has also launched a consultation on the Digital Fitness Check. This is also intended to simplify the EU’s digital regulation and ensure that overlaps and inconsistencies in existing digital legislation are reduced. New initiatives are also mentioned in the package, such as the “Data Union Strategy”, as well as an instrument such as the “European Business Wallets”, which are intended to facilitate administrative processes in the single market.
Partner
Head of Technology Law
THE SQUAIRE Am Flughafen
60549 Frankfurt am Main
Tel.: +49-69-951195770
fheynike@kpmg-law.com
Senior Manager
Fuhlentwiete 5
20355 Hamburg
Tel.: +49 40 360994-5483
danieltaraz@kpmg-law.com
© 2026 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.
KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.