Brussels, 7 May 2026 — GDPR is no longer untouchable
Late in the evening of 7 May 2026, after more than a dozen hours of trilogue talks, negotiators from the Council of the European Union and the European Parliament announced a provisional agreement on simplifying part of the rules on artificial intelligence. The statement was technical and dry, written in the kind of language that sends you to sleep by the third paragraph. And yet that was the moment when — almost imperceptibly — a dogma that had been with us for eight years finally cracked: the belief that the General Data Protection Regulation is sacred, untouchable, an act no one in Brussels would dare lay a finger on.
Because the 7 May agreement is only the second half of a much larger operation. The first half began six months earlier. On 19 November 2025 the European Commission presented the Digital Omnibus package — a set of legislative proposals that, for the first time since 2016, open GDPR up to a thorough revision while simultaneously merging, simplifying and in places dismantling almost the entire body of EU digital law: the ePrivacy Directive, the Data Act, the Data Governance Act, the cybersecurity rules (NIS-2, DORA, CER), as well as eIDAS and the P2B Regulation. The Commission promises businesses savings of at least five billion euros over three years. The Austrian activist Max Schrems and his organisation noyb reply that this "simplification" is far removed from what business actually needs and very close to what the large platforms need — and that, under the banner of cutting red tape, fundamental rights are being quietly weakened.
Who is right? As usual, a little of both. Below we take the Digital Omnibus apart piece by piece: exactly what it changes in GDPR, what it changes in the AI rules, what it changes for cookies and what it changes for incident reporting. And — most importantly for a Polish controller — what is already law and what is merely a political signal on which no decision to dismantle your own compliance should ever rest.
What the Digital Omnibus is and where it came from
In Brussels jargon, an "omnibus" is an act that amends many other acts in a single move — a legislative bus that picks up a dozen passengers along the way. The Digital Omnibus is in fact two parallel proposals: one devoted to data and privacy, the other to artificial intelligence. The Commission presents it as the first stage of a broader programme to "slim down" the digital acquis, meaning the entire body of rules adopted during the feverish years of 2016–2024, when the Union was trying to tame technology faster than technology allowed itself to be tamed.
The diagnosis underpinning the package is hard to dispute. The rules were layered on independently of one another, without a shared vocabulary. A business processing data and running a digital service had to juggle GDPR, ePrivacy, the Data Act, NIS-2 and — in the financial sector — DORA all at once, with each of those acts defining the same phenomena differently, setting different deadlines and requiring contact with a different authority. Everyone bore the cost of that fragmentation: companies, civil society organisations and public administration, where a single municipality can simultaneously be subject to GDPR as a controller, to the KSC Act as a public body and to the re-use rules as a holder of public sector information.
The Digital Omnibus responds with four moves. First, it consolidates data law into a single One Data Act, absorbing the Data Governance Act, the Open Data Directive and the Regulation on the free flow of non-personal data into an amended Data Act. Second, it modernises GDPR and ePrivacy. Third, it creates a single entry point for reporting cybersecurity incidents. Fourth, it repeals rules that have outlived their purpose — such as the P2B Regulation, whose functions have been taken over by the Digital Services Act and the Digital Markets Act. It sounds sensible. The devil, as ever, lives in the definitions.
The new definition of personal data — the change nobody is talking about
If you had to point to a single provision in the whole package that will change controllers' daily reality the most, it would be the amendment to Article 4(1) GDPR — the definition of personal data. The interpretation in force today is absolute: information is personal data if there is any possibility, however theoretical, of linking it to a natural person by anyone anywhere in the world. That approach, entrenched in the case law of the Court of Justice of the EU, means that in practice almost any encrypted or hashed identifier ends up being treated as personal data, because somewhere, someone holding the right key could theoretically re-identify the individual.
The Digital Omnibus proposes a shift to a relative, contextual approach. Information is to be personal data if and only if the specific entity processing it is genuinely able to identify the person concerned, using means it could reasonably be expected to deploy in the circumstances. In other words: the same dataset may be personal data for one company that holds the re-identification key and non-personal data for another that does not hold it and cannot obtain it with reasonable effort. The Commission completes the picture by clarifying the rules on pseudonymisation, indicating when it is effective enough for the data to be regarded as non-personal in the hands of an entity with no access to the additional information.
For scientific research, analytics projects and the development of artificial intelligence, this is a fundamental change — vast volumes of data suddenly fall outside the GDPR regime. For privacy advocates it is exactly the same mechanism seen from its dark side: a definition that for eight years set the regulation's broad, protective scope is being narrowed, and with it the range of situations in which a citizen can exercise their rights. The dispute is not academic. Whether a given record is "personal" determines whether the information obligation applies, whether the individual can demand access, rectification and erasure, and whether the supervisory authority can intervene at all.
Training AI on personal data — legitimate interest enters the game
The second heavyweight element of the package concerns artificial intelligence. Ever since machine learning models began consuming data on an internet-wide scale, European controllers have been asking one apparently simple question: on what legal basis may personal data be used to train a model? Consent is unworkable in practice with datasets running into billions of records. Contract is rarely adequate. That left the controller's legitimate interest under Article 6(1)(f) GDPR — but without express confirmation from the legislature, few were willing to build a risky project on it.
The Digital Omnibus provides that confirmation outright. Processing personal data for the purposes of developing and operating artificial intelligence systems may be based on legitimate interest — provided a proper balancing test is carried out, with separate consideration given to the rights and freedoms of individuals, including children. The AI-related part goes further: for special categories of data — those under Article 9, including data on health, origin or opinions — the standard of "strict necessity" has been retained for processing them in order to detect and correct model bias. That is a nod to reality: sensitive data appears incidentally in large training sets, and paradoxically its controlled use is sometimes necessary to stop a model from discriminating.
For Polish firms deploying AI — from a law firm building an assistant to analyse contracts to a municipal utility testing predictive maintenance for its networks — this is a genuine unlocking. But note: confirming the legal basis does not release you from the balancing test, from the information obligations or from a data protection impact assessment where the risk is high. We wrote in more detail about how the AI Act and information security intertwine into a single regime in our article on the AI Act and information security — the Digital Omnibus does not so much simplify that puzzle as rearrange it.
96 hours instead of 72 — and only where the risk is high
Anyone who has ever reported a personal data breach to the President of UODO knows the stress of those seventy-two hours. The clock starts the moment the breach is identified, and over a weekend or during a ransomware attack, when half the team is fighting to restore systems, those three days can evaporate in an hour. The Digital Omnibus proposes two corrections that will bring real relief, especially for smaller organisations.
First, extending the deadline for notifying the supervisory authority from 72 to 96 hours. Four days instead of three is not a luxury — it is the difference between a considered notification and a panicked one in which the controller states things that cannot later be taken back. Second — and this is the more significant change — narrowing the notification obligation to breaches likely to result in a high risk to the rights and freedoms of individuals. Today the threshold is lower: every breach that "may result in a risk" must be notified, and the only exemption is where the risk is unlikely. After the change, there will be no obligation to report minor incidents with negligible consequences, which supervisory authorities cannot process anyway.
The Commission adds to this a simplification of the information obligations for low-risk processing. For a company with modest resources, or for a local government budgetary unit with no legal department of its own, that is a breath of air. For a privacy advocate it is another place where the bar of protection drops slightly. "High risk" is an evaluative concept, and every evaluative concept means a future dispute with the supervisory authority and a future ruling from an administrative court.
The end of cookie banners — but not tomorrow and not for free
If there is one element of the Digital Omnibus that every internet user will feel, it is the reform of consent for operations on terminal equipment — in plain terms, the end of the era of clicking "Accept all" on every site. The Commission openly acknowledges what users have known for years: cookie banners do not serve their informational purpose, do not give real control over privacy, and merely tire people out and train them to click without thinking. Classic "cookie fatigue".
The solution rests on two pillars. The first: moving the rules on cookies and similar technologies out of the ePrivacy Directive and into GDPR, ending the long-standing duality in which the same data was subject to two different regimes. The second: creating machine-readable, EU-wide preference signals — consent settings generated once, at browser or system level, which websites will have to respect automatically. The user states their wishes once, and banners become unnecessary. The list of situations in which consent is not required at all has also been extended — for example, for low-intrusion statistical measurement.
Except — and here the idyll ends — those signals do not yet exist. They still have to be developed by standardisation bodies at the Commission's request. Only once a standard has been adopted and a six-month transition period has run will website operators be obliged to honour them. Until then, the banners stay with us. An exception has also been provided for media service providers, who will retain the ability to contact users directly about advertising and content funding — which is already raising questions as to whether the reform is creating a loophole for the largest publishers.
One incident reporting point instead of five forms
For entities caught by several regimes at once — and in Poland their number is growing rapidly following the amendment of the act on the national cybersecurity system — the Digital Omnibus brings a purely procedural but extremely practical change. Today a serious security incident can trigger parallel reporting obligations under NIS-2, DORA, GDPR, CER and eIDAS — to different authorities, on different deadlines, on different forms whose content overlaps by 80%. Instead of putting out the fire, the controller fills in the same boxes five times over.
The package creates a single European reporting channel built by ENISA. The principle is simple: you report an incident once, and the system automatically forwards the information to the competent authorities according to their remit. Importantly, the substantive triggers do not change. What must be reported and when stays the same; only the way you do it changes. This is a rare example of a simplification that takes nothing away from the citizen while genuinely lightening the load on the obliged entity. For an organisation still working out its obligations following the entry into force of the amended KSC Act — which we covered in our analysis of the amendment to the act on the national cybersecurity system — it is a signal to design your incident reporting procedure with that future single entry point in mind, rather than replicating five separate routes.
The AI Act track — what exactly was agreed on 7 May 2026
Let us return to the evening we began with. The provisional agreement of 7 May 2026 concerns not GDPR but the AI Act — and it is part of the same simplification operation. Its most widely reported element is the postponement of the rules on high-risk AI systems by no more than sixteen months. The industry, which had been warning for months that it would not be ready in time for the original deadlines, has been given breathing space. Critics reply that postponing protection is also a way of weakening it.
The agreement does, however, contain several elements that pull in the opposite direction — towards tightening. A ban on so-called "nudifier apps" has been introduced — applications that generate nude images of a person without their consent — with particular regard to material depicting child sexual abuse. The obligation to register high-risk AI systems in the EU database has been reinstated even where the provider itself considers its system to fall outside the classification — closing a gap through which it was possible to slip out from under supervision. The deadline for establishing national AI regulatory sandboxes has been extended to 2 August 2027, while the grace period for implementing transparency obligations for artificially generated content has been shortened to three months — with a new deadline of 2 December 2026. Finally, the powers of the AI Office over systems based on general-purpose models have been clarified.
And here comes the cardinal caveat: a provisional agreement is not law. It is political in nature — it sets the direction, but it produces no legal effects until the proposal has been formally approved by the Council and Parliament and then published in the Official Journal of the EU. The same applies to the entire GDPR strand of the Digital Omnibus, which is still a Commission proposal at the very start of the legislative path. Anyone who dismantles their compliance today, counting on what has "already been agreed", will be making a costly mistake — and, worse, an entirely self-inflicted one.
"Simplification" or a quiet weakening of protection?
Two camps have formed around the Digital Omnibus, and it is worth knowing both sets of arguments, because they will shape the final text. Its supporters — led by the Commission and a substantial part of the business community — point out that the 2016 version of GDPR was written in a world before the explosion of generative AI, that its absolute definition of personal data leads to absurdities, and that the fragmentation of reporting obligations genuinely holds back European competitiveness. In their narrative, five billion euros of savings over three years is money companies will invest in development instead of in filling in forms.
The opposing camp — led by noyb and Max Schrems, but also including some European data protection authorities — warns that systemic changes are being smuggled in under the banner of "simplification". A relative definition of personal data narrows the scope of protection. Legitimate interest as a basis for training AI opens the way to processing the data of millions of people without their knowledge. Narrowing the breach notification obligation reduces transparency. The EDPB and the EDPS issued a joint opinion in which — and this is an important nuance — they support the objective of simplification and strengthening competitiveness while raising specific concerns about some of the solutions, particularly those relating to the definition of data and to the legal bases for processing for AI purposes. It is a balanced position, far from outright condemnation but also far from enthusiasm.
Our assessment as practitioners is prosaic: the Digital Omnibus contains both good and risky elements, and the final balance depends on details that have yet to emerge from negotiations in Parliament and the Council. A single reporting point is an unqualified good. Extending the breach notification deadline is a sensible correction. The relative definition of personal data is a double-edged tool that brings order in the hands of an honest controller and gives a dishonest one a pretext to shed its obligations. That is why what matters for a controller today is not a moral verdict on the package but the cool question: which parts affect me, and when.
What the Digital Omnibus means for a Polish controller
Let us start with the most important point: as of today, nothing has changed and you need to change nothing. GDPR applies in its 2016 version, ePrivacy applies, the 72-hour deadline applies, and cookie banners must be maintained. The Digital Omnibus is a proposal — in its AI part with a provisional agreement, in its GDPR part only at the start of the legislative path. So the first and most important recommendation is this: do not dismantle compliance on the strength of announcements. A controller who scraps its record of processing activities today, or stops reporting breaches "because Brussels is relaxing it anyway", is exposing itself to a fine under the current state of the law — and the President of UODO decides cases according to the law in force today, not according to proposals.
What is worth doing now is mapping your exposure. A local government unit running dozens of processing activities and also subject to the KSC Act should know which of its processes will benefit from a single reporting point and from the extended breach deadline. A municipal company piloting predictive analytics on residents' data should be putting its legal bases in order now, because once legitimate interest for AI becomes law, the winner will be the organisation that already has a balancing test ready, not the one that starts writing it after publication in the Official Journal. An SME running a website with ten tracking scripts should be watching the work on the preference signal standard, because a six-month transition period passes faster than you think.
And one more thing that is easy to forget in the euphoria of "simplification": fewer formalities does not mean less accountability. UODO fines are rising regardless of Brussels reforms — recall the fine of over eleven million zloty imposed on one courier operator for the absence of data processing agreements with its subcontractors, or the series of sector inspections we described in connection with the UODO fine imposed on the municipality of Myślenice for shortcomings in its public information bulletin. The Digital Omnibus will change the rules of the game, but it will not abolish the game itself. An organisation that treats data protection as a living process rather than a stack of papers to tick off will come through this change calmly. One that hopes the reform will solve its neglect for it will be painfully disappointed.
We summarise the direction previously set by CJEU case law in our article on GDPR in the case law of the CJEU.
Why work with Fib.Code on GDPR change
The Digital Omnibus is not a single regulation that can be handled with a single training session. It is a weave of data protection law, technology law, cybersecurity and — increasingly — algorithmic ethics. To advise on it sensibly you have to read the draft regulation in the original, understand the CJEU case law around the definition of personal data, know the realities of training machine learning models and understand how the President of UODO actually conducts proceedings. No single lawyer can cover all of that, and neither can a single engineer.
The Fib.Code team combines these competencies day in, day out. As part of our legal advisory on EU regulatory change we act as data protection officer and information security officer for clients in the local government, municipal utility and private sectors, we run GDPR audits and implement information security management systems to ISO/IEC 27001, and we follow EU digital regulation at proposal stage rather than after publication. Our approach rests on three principles. First, we watch the proposal but advise according to the law in force — we do not let a client dismantle compliance on the basis of announcements. Second, we prepare the organisation for change in advance — when legitimate interest for AI or a single reporting point become law, our clients have procedures ready rather than a blank page. Third, we integrate regimes instead of multiplying them — GDPR, the KSC Act, the AI Act and the future Digital Omnibus must form one risk register and one set of policies, not four competing systems.
The result is an organisation that fears neither a supervisory inspection today nor the entry into force of new rules tomorrow — because it has thought through, documented and rehearsed both.
What to do in the coming week
One thing, achievable in an hour. Convene a short meeting with your data protection officer, the person responsible for IT and — if you have one — the information security officer, and ask four questions. First: which of our processing operations currently rest on legal bases that the Digital Omnibus may change, particularly where we use or plan to use AI? Second: is our breach notification procedure ready to work in a real crisis within 72 hours — because until the law changes, it is 72, not 96? Third: how many tracking scripts and cookie banners do we maintain, and who here is following the work on the European preference signal standard? Fourth: does our risk register tie GDPR, the KSC Act and the AI Act into a single whole, or are we keeping three separate notebooks?
If the answer to any of these is "I don't know", that is precisely the gap worth closing now, calmly, rather than under the pressure of an inspection or of an implementation deadline once the proposal becomes a regulation.
Get in touch: l.grabowski@fibcode.com | fibcode.com/en/contact. Directly related material: The AI Act and information security — what the new rules have in common, The 2026 amendment to the KSC Act — what you need to know after 3 April and The UODO fine for Myślenice — public information bulletins, sector inspections and local government in 2026 — the Digital Omnibus is directly interwoven with each of these threads.


