AA

Over the past few years, organisations operating in the EU have had to contend with a rapidly expanding body of digital regulation. The General Data Protection Regulation (GDPR) marked only the starting point. Since its adoption, a wide range of additional legislative instruments has entered into force, addressing areas such as data protection, online platforms, data access and sharing, cybersecurity, and Artificial Intelligence.

Although these initiatives respond to real and pressing challenges, their cumulative effect has been to create a regulatory environment that many organisations experience as fragmented, overlapping, and difficult to navigate. These difficulties are particularly acute for small and medium-sized entities, which often lack the resources needed to manage complex and sometimes inconsistent compliance requirements.

These concerns have been explicitly acknowledged by the European Commission. In November 2025[1], it published the so-called Digital Omnibus package, a set of proposals aimed at adjusting the existing EU digital regulatory framework as part of a broader strategy focused on simplification and competitiveness. Rather than introducing additional layers of regulation, the package seeks to rationalise and fine-tune the current framework. Its stated objectives include reducing unnecessary administrative burdens, improving the practical operability of compliance obligations, and ensuring that EU digital regulation functions more effectively in practice. This contribution examines the nature of the Digital Omnibus package and explains why it is particularly relevant in the context of higher-education research projects.

The proposed Digital Omnibus package

At present, the Digital Omnibus package does not have binding legal force. It consists of a series of proposals published by the European Commission in November 2025, which must still proceed through the ordinary EU legislative process before any amendments can take effect. The package represents an initial step by the Commission towards improving the day-to-day functioning of existing EU digital legislation. Instead of creating new regulatory obligations, it brings together a number of targeted and largely technical adjustments to current instruments. These are intended to generate practical benefits for businesses, public authorities, and individuals alike.

According to the Commission, the overarching aim is to make compliance with EU digital rules less costly, more efficient, and easier to manage, while maintaining the same level of regulatory protection. In this sense, compliance is framed not as a purely administrative burden, but as a potential source of competitive advantage for organisations that operate responsibly. The proposals build on stakeholder consultations and on early experience with the implementation of recent digital legislation. A recurring theme throughout the package is the central role of data as a strategic economic resource, particularly in relation to innovation and the development and deployment of trustworthy Artificial Intelligence.

It is important to note that the proposed amendments are explicitly technical in character. They are not designed to alter the core policy objectives of EU digital regulation, nor to dilute existing safeguards. Instead, the emphasis is on streamlining, harmonisation, and clarification, with the aim of improving the practical effectiveness of the regulatory framework.

Key areas affected

The Digital Omnibus package proposes amendments across several established domains of EU digital regulation, including:

  • the EU AI Act
  • the GDPR
  • the Data Act
  • EU cybersecurity legislation

Proposed changes relating to the GDPR and privacy

A number of the proposed amendments are intended to clarify how the GDPR applies in practice, particularly in scenarios involving the use of Artificial Intelligence.

Organisations involved in the development or deployment of AI systems frequently encounter uncertainty when identifying an appropriate legal basis for processing personal data. In particular, there has been ongoing debate as to whether reliance on legitimate interests is compatible with heightened regulatory attention to consent and purpose limitation. The proposal seeks to provide explicit confirmation that legitimate interests may serve as a valid legal basis where personal data processing is necessary for the development, testing, or operation of AI systems, provided that the standard safeguards are observed. These include the completion of a balancing test and the implementation of suitable technical and organisational measures. While this clarification would not remove the obligation to assess risks to individuals, it would offer greater legal certainty around an approach already adopted by many organisations in practice.

Processing of special category data

The package also proposes two narrowly defined exceptions to the general prohibition on processing special category personal data. First, it would permit the use of biometric data for identity verification purposes where such processing is necessary and where both the biometric data and the verification mechanism remain under the exclusive control of the individual, for example through on-device facial recognition. Second, it would allow limited residual processing of special category data in the development and operation of AI systems or models where such data appears unintentionally or cannot reasonably be avoided. This would be subject to strict conditions, including measures to minimise collection, prevent misuse, and remove the data where feasible. The stated objective is to address practical challenges in AI development without undermining the GDPR’s fundamental protective framework.

Personal data breach notification

Further amendments concern personal data breach reporting obligations. Under the current regime, most personal data breaches must be notified to supervisory authorities within 72 hours, unless the breach is unlikely to result in a risk to individuals. The proposal would narrow this obligation, requiring notification only where a breach is likely to result in a high risk to the rights and freedoms of affected individuals. In addition, the notification deadline would be modestly extended from 72 to 96 hours, allowing organisations additional time to assess incidents and submit more meaningful information.

Proposed changes to the AI Act

One of the most consequential proposals relates to the timing of the application of obligations for high-risk AI systems under the EU AI Act. Rather than applying from a fixed date, the proposal would link their commencement to the availability of key guidance documents and technical standards. Once these materials are in place, organisations would be granted a short preparatory period before the obligations become applicable. While this approach may provide additional flexibility, it also introduces a degree of uncertainty for long-term compliance planning.

The package also envisages postponing certain labelling requirements for AI-generated content, allowing providers more time to adapt their systems while detailed guidance is developed.

From a governance perspective, the role of the EU AI Office would be expanded, resulting in more centralised supervision in specific areas. At the same time, the existing obligation on organisations to ensure a sufficient level of AI literacy among staff would be softened. Rather than constituting a strict legal requirement, the emphasis would shift towards guidance, training initiatives, and best-practice measures supported by the Commission and Member States. Documentation and registration obligations for AI systems would also be simplified, particularly for small and medium-sized enterprises.

The amendments proposed in relation to the Data Act aim to reduce complexity and improve the accessibility of data access and sharing obligations.

Currently, EU data-sharing obligations are distributed across multiple legislative instruments, each employing distinct terminology and procedures. This fragmentation can make it difficult for organisations to determine when data must be shared and under what conditions. The proposal would consolidate elements of this framework within the Data Act itself, positioning it as a clearer reference point for data access and reuse obligations. In practical terms, this is intended to facilitate quicker and more consistent compliance assessments.

Under the existing framework, mandatory data sharing may expose businesses to risks relating to commercially sensitive information. The proposed amendments would strengthen safeguards for trade secrets, allowing data holders to refuse access where there is a substantial risk of unlawful acquisition, use, or disclosure in third countries, particularly where legal protections fall below EU standards. This change is intended to reassure businesses that compliance with data-sharing obligations will not compromise their competitive position.

The Data Act currently permits public authorities to request data from businesses in situations of “exceptional need”, a concept that has been criticised as overly broad. The proposal would narrow this provision by limiting mandatory data sharing to clearly defined public emergency scenarios, while introducing additional procedural safeguards, including rules on compensation and the protection of trade secrets and personal data.

Cybersecurity and incident reporting

Finally, the Digital Omnibus package proposes measures aimed at simplifying cybersecurity and incident reporting obligations, particularly where multiple regulatory regimes apply simultaneously.

A central element of this approach is the introduction of a single reporting channel for cyber and data incidents. At present, the same incident may trigger parallel notification obligations under instruments such as the GDPR, the NIS2 Directive, and sector-specific cybersecurity rules, often requiring separate submissions to different authorities. Under the proposal, organisations would submit a single report via a central reporting point, which could then be used to satisfy multiple legal obligations, with information shared among the relevant supervisory bodies. This is intended to reduce duplication and administrative pressure, especially in time-critical situations.

At this moment, the Digital Omnibus package remains at the proposal stage, and no immediate action is required. Its content may still evolve as it progresses through the EU legislative process. Nevertheless, it provides a clear indication of the Commission’s regulatory direction. Organisations operating in, or targeting, the EU — including those involved in EU-funded research projects — should anticipate greater legal certainty over time, a sustained emphasis on proportionality and simplification, and an increased focus on practical, workable compliance solutions.

For CyberEthics Lab. and CyberSocial Lab., actively involved in Horizon Europe projects as an Ethics and Legal Consultant, closely monitoring the evolution of the Digital Omnibus is of sum importance. The initiative is expected to reshape and streamline the EU digital regulatory framework, with direct implications for ethical governance, legal compliance, risk management, and accountability in the development and deployment of digital technologies, including AI-driven systems.

References

Service involved