EU Digital Omnibus on Data (GDPR, ePrivacy, NIS2, DORA simplification)

Commission proposal moving cookie and terminal-equipment consent into new GDPR Articles 88a and 88b (browser-level signals binding on controllers), narrowing personal-data definitions and simplifying overlapping reporting under NIS2, DORA and GDPR. In trilogue; adoption not expected before late 2026.

JurisdictionEuropean Union
CategoryPrivacy & Data Protection
StatusProposed
Latest development

Analysis

The “EU Digital Omnibus” you describe is a proposed package, not yet adopted, that would amend the GDPR to add Articles 88a and (originally) 88b, move terminal‑equipment / cookie consent rules from ePrivacy into the GDPR, and streamline incident reporting across GDPR, NIS2 and DORA; it is still in trilogue and no final text or binding deadlines exist yet, and some elements (notably Article 88b browser signals) have already been removed in Council negotiations.European Commission proposal – COM(2025) 837 (referenced in commentary) EDPB–EDPS Joint Opinion 2/2026 on the Proposal for a Regulation – Digital Omnibus TwoBirds analysis of Digital Omnibus single harmonised incident reporting

Below is a forward‑looking, proposal‑based analysis. All requirements and timelines are conditional on the final outcome of trilogue and may change.


Key Requirements (Proposal‑Based)

Note: These are proposed requirements from the Commission text and subsequent negotiations, not yet binding law.


Compliance Challenges

Because the Omnibus is not yet final, most challenges are inferred from existing analyses and stakeholder commentary.


Implementation Best Practices (Preparing for Potential Adoption)

Because the Omnibus is not yet final, these are pre‑implementation best practices aligned with the current direction of travel.

  • Build an internal “single reporting playbook” aligned with Omnibus concepts
  • Develop a central incident reporting procedure that aligns thresholds and definitions across **GDPR, NIS2 and D

Recent developments

  • — Analysis of the 1,840 amendments tabled on the Digital Omnibus package, detailing how it simultaneously modifies GDPR, ePrivacy, NIS2, DORA, the Data Act, eIDAS and the Critical Entities Resilience Directive, with a focus on simplifying and harmonizing digital obligations and breach reporting.[9] (source)
  • — European Parliament “Legislative Train” update on the Digital Omnibus proposal, situating it within the broader digital rulebook reform and describing the consolidation of single market data rules into the Data Act and the streamlining of overlapping privacy, cybersecurity and resilience requirements.[7] (source)
  • — European Commission digital strategy update outlining the Digital Omnibus as part of an agile EU digital rulebook, including the creation of a single-entry point for all cybersecurity incidents and data breach reports and the merging of several data and open‑data instruments into a restructured Data Act.[12] (source)
  • — News article describing how the Digital Omnibus consolidates reforms to GDPR, the AI Act, NIS2, ePrivacy and the Data Act into one package, including a new unified reporting interface allowing businesses to satisfy notification duties under GDPR, NIS2, DORA, eIDAS and CER through a single secure portal.[11] (source)
  • — Policy blog commentary on the February 2026 developments of the Digital Omnibus, explaining how incident reporting will be centralised via a common EU portal that routes reports under GDPR, NIS2, DORA and related regimes to the competent authorities, reducing duplicate notifications and administrative burden.[6] (source)
  • — Summary of the EDPB–EDPS Joint Opinion 2/2026 on the Digital Omnibus, welcoming simplification such as a single European notification portal and common DPIA methodology while warning that raising breach notification thresholds and extending deadlines must not weaken data‑subject protection under GDPR and related regimes.[1] (source)
  • — Industry-focused explainer on the Digital Omnibus package describing how it amends GDPR, the Data Act, AI Act, NIS2, ePrivacy and DORA to eliminate overlapping requirements, streamline incident reporting into a single ENISA‑managed portal, and recalibrate consent and cookie mechanisms to reduce friction while maintaining compliance.[4] (source)
  • — Law firm overview of the Digital Omnibus proposal detailing the central operational reform of a single EU entry point for incident notifications across GDPR, NIS2, CRA, DORA, eIDAS and CER, and explaining implications for privacy, cybersecurity and operational resilience governance in regulated sectors.[5] (source)

Related regulations

Put it into practice

Browse all regulations · Compliance deadlines · Latest updates