Why the Hurry? Getting the Digital Omnibus Right – And What’s Needed For That
Main takeaways
- While the EU’s digital rulebook requires structural modernisation, EU policymakers cannot afford to sacrifice technical precision for quick wins
- The Digital Omnibus remains a great opportunity to bolster Europe’s edge, but true simplification takes time and real effort; rushing risks tangling the regulatory knots even further
- To foster innovation, the EU must focus on providing regulatory predictability and consistency to avoid disjointed implementation across 27 Member States later
Recent discussions on simplifying EU tech rules have revealed a rare point of consensus: Europe’s rulebook is overdue for a serious overhaul. However, as co-legislators are now unpicking the details of the European Commission’s Digital Omnibus proposal, covering everything from cybersecurity to data and privacy, warning lights are starting to flash.
Together with the AI Omnibus, the Digital Omnibus is one of the Commission’s first attempts at simplification. But while the AI process required urgency given looming deadlines, the Digital Omnibus is a far more technical exercise – reaching into the core of data protection principles that have been in place for a decade.
Yet, co-legislators are moving at very different speeds. With the Council already rushing towards the finish line, but the European Parliament still trailing behind, there is a real risk of creating a legislative tangle that makes implementation and enforcement harder than before.
This exercise must be about more than just slashing red tape – it is about ensuring that revised rules do not create new problems downstream. If those negotiating on behalf of Member States, or Parliament, move too quickly, we risk replacing old complexity with new, unpredictable interpretations that ultimately stifle Europe’s digital dynamism.
1. Defining personal data: Clarity, not guesswork
The Commission’s move to codify a relative, entity-specific approach to personal data is a good start. This means that if the data is just a string of numbers that the controller cannot link to a name or face, it shouldn’t be treated with the same weight as sensitive personal details. For too long, companies have been forced to treat vast quantities of data as ‘personal,’ even when they have no realistic way of identifying the individual behind it.
However, the current proposal relies on the murky concept of ‘reasonable means’ to identify a natural person, without providing sufficient detail on what this actually entails. This is like giving a driver a map with no street names. If we leave interpretation to 27 different national authorities, the EU will not have simplified anything. Europe will simply have moved the confusion into a different room, leaving others to deal with it.
To fix this, we need a clear objective list defining what ‘reasonable’ entails in this specific context. This should include factors such as the cost of identification, the time required to identify a natural person, as well as the state of available technological safeguards.
2. Cookie consent: More than a ‘set and forget’ toggle
Integrating the cookie rule – which, under the ePrivacy Directive, requires websites to obtain consent before placing non-essential cookies on a user’s device – into the General Data Protection Regulation (GDPR) is a bold move proposed by the Commission with the aim of reducing the current avalanche of cookie pop-ups.
But as the proposal currently stands, there is a major risk of creating a split regime that makes compliance even more difficult. If personal data on a given cookie is governed by the GDPR, and non-personal data on the same cookie falls under the e-Privacy Directive, businesses remain trapped in a regulatory loop rather than seeing any real simplification.
The most concerning part, however, is the push to replace website-specific consent with browser-level consent, creating sort of a master switch. Privacy should not be a ‘set and forget’ toggle. Expecting European users to give their internet browser universal consent for cookies on every possible website, is like signing a blank contract for the next six months.
Instead of a master switch, a practical way to address consent fatigue among Europeans would be to expand exemptions for low-risk activities that use cookies – such as first-party analytics, contextual advertising, and frequency capping. This would allow Europeans to focus their attention on data-processing choices that actually matter, rather than clicking through endless consent banners just to unlock the most basic website features.
3. AI training: Moving from guidance to legal certainty
If we are serious about European competitiveness, the legal basis for AI training must be engraved directly into the Omnibus legislation. While the recognition of ‘legitimate interest’ as a legal basis for AI training in the Commission’s proposal certainly is encouraging, it must remain unambiguous. Today’s existing, non-binding guidance from the European Data Protection Board (EDPB) is not enough. It simply fails to provide the certainty investors and developers need to commit to Europe.
Moreover, legitimate interest should also be extended to cover AI training by third parties, not just data controllers. Restricting this ignores the reality of downstream innovation, where developers need datasets to fine-tune models before they ever can become ‘controllers’ themselves.
Forcing AI developers to avoid collecting sensitive data from the open web is technically impossible. It would perversely require companies to process more data just to pre-filter the entire internet, before deciding what to collect – a blatant contradiction.
Conclusion
Simplification does not mean lowering standards, it should be about clearing the legal hurdles that currently prevent innovators from meeting those standards efficiently. With the Digital Omnibus, the European Union finally has a chance to prove it actually can be both a global privacy leader and a thriving tech hub. But to get there, the EU co-legislators must take the appropriate amount of time to get the technical details right.
The Council is currently rushing to reach a general approach, yet the European Parliament has barely started to discuss the proposal. This means there is a very real risk that instead of simplifying things, a rushed Omnibus will end up complicating implementation and enforcement even more. True simplification isn’t a race, it is about building a foundation that holds up in the real world.