EU Digital Omnibus proposal reopens GDPR to simplify multi-regulation compliance
The European Commission's proposed Digital Omnibus would amend foundational data regulations like the GDPR, potentially narrowing the definition of personal data and creating new derogations for processing sensitive data during AI development. These legislative changes could significantly affect the legal burden and compliance requirements for streaming platforms and AI-driven video technology vendors operating in the EU.
Key Takeaways
- Proposed Article 41a empowers the Commission to define technical criteria for when pseudonymized data stops being personal data
- A new derogation allows incidental processing of sensitive personal data categories specifically for training and validating AI models
- Consolidation of the Data Governance Act and Open Data Directive into an amended Data Act increases reliance on GDPR definitions
- Proposals include a single-click cookie consent mechanism and browser-level privacy preference settings to reduce consent fatigue
Why It Matters
This move signals a pivot from establishing new digital protections to streamlining existing ones to boost European competitiveness. For streaming and AI video vendors, it could lower the barrier for model training by easing restrictions on sensitive data use. However, the selective codification of identifiability rules creates a bifurcated compliance landscape where data may be personal for one entity but not another. This fragmentation risks legal uncertainty if member states or the EDPB push back on the Commission's attempts to centralize technical threshold authority. Watch for the final trilogue consensus on whether the 'means reasonably likely to be used' test exclude subsequent recipients, a key point of friction for data brokers and advertisers.
Additional Context
The Digital Omnibus arrives as the EU grapples with the implementation of its sprawling digital rulebook. Per DLA Piper in June 2026, the Council of the EU gave the final green light to the 'AI Omnibus' portion of the package, which officially defers the compliance deadline for certain high-risk AI systems from August 2026 to December 2027. This delay reflects the practical challenges in designating national competent authorities and finalising harmonized technical standards for AI safety and bias detection.
While the AI-specific amendments have found a path forward, the 'Data Omnibus' affecting the GDPR remains under intense negotiation. According to Usercentrics in February 2026, a major point of contention is the 'single-click' consent rule for cookies, which the Council's internal drafts have fluctuated on. The European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) issued Joint Opinion 2/2026 in early 2026, specifically warning that the proposed changes to the definition of personal data could create a gap between EU law and the Council of Europe’s Convention 108+, which many third-country adequacy agreements rely upon.
The inclusion of Article 41a is particularly controversial as it moves the power to set technical thresholds for data anonymity from independent supervisory authorities to the European Commission. Law firms like White & Case noted in late 2025 that these amendments are a direct attempt to codify the CJEU’s ruling in EDPS v SRB, aiming to provide more certainty for data science and research teams. For the streaming industry, these changes could simplify the legal status of audience measurement data that has been pseudonymized before being shared with third-party advertisers.
Read full article at google.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source