EU Digital Omnibus on Data (GDPR, ePrivacy, NIS2, DORA simplification)
Commission proposal moving cookie and terminal-equipment consent into new GDPR Articles 88a and 88b (browser-level signals binding on controllers), narrowing personal-data definitions and simplifying overlapping reporting under NIS2, DORA and GDPR. In trilogue; adoption not expected before late 2026.
| Jurisdiction | European Union |
|---|---|
| Category | Privacy & Data Protection |
| Status | Proposed |
| Latest development |
Analysis
The “EU Digital Omnibus” you describe is a proposed package, not yet adopted, that would amend the GDPR to add Articles 88a and (originally) 88b, move terminal‑equipment / cookie consent rules from ePrivacy into the GDPR, and streamline incident reporting across GDPR, NIS2 and DORA; it is still in trilogue and no final text or binding deadlines exist yet, and some elements (notably Article 88b browser signals) have already been removed in Council negotiations.European Commission proposal – COM(2025) 837 (referenced in commentary) EDPB–EDPS Joint Opinion 2/2026 on the Proposal for a Regulation – Digital Omnibus TwoBirds analysis of Digital Omnibus single harmonised incident reporting
Below is a forward‑looking, proposal‑based analysis. All requirements and timelines are conditional on the final outcome of trilogue and may change.
Key Requirements (Proposal‑Based)
Note: These are proposed requirements from the Commission text and subsequent negotiations, not yet binding law.
- Move terminal‑equipment (cookie) rules from ePrivacy into the GDPR (new Article 88a)
- The proposal would shift rules on “storing or accessing information on a user’s device” (currently in the ePrivacy Directive) directly into the GDPR, in Article 88a, whenever such storage/access involves personal data.Kennedys: 2025 EU Digital Omnibus – insertion of GDPR Articles 88a and 88b EDPB–EDPS Joint Opinion 2/2026 – discussion of Article 88a(3) GDPR
- Proposed Article 88a(1) conditions the storage or access of personal data in terminal equipment on the data subject’s consent, extending GDPR consent standards directly to device‑level tracking.EDPB–EDPS Joint Opinion 2/2026 – text excerpts of Article 88a
- Define and limit permitted no‑consent uses on terminal equipment (four purposes)
- Commentaries and the draft text describe four purposes for which terminal‑equipment processing of personal data would be lawful without consent:
- Transmission of a communication.
- Provision of a service explicitly requested by the user.
- The controller’s own aggregated audience measurement.
- Maintaining or restoring security of the service or device.EDPB–EDPS Joint Opinion 2/2026 – lawful processing without consent AesirX explanation of Article 88a purposes
- This narrows the broad consent requirement by codifying specific exemptions for necessary functionality and security.Arnold & Porter advisory on Omnibus impacts – consent exceptions
- Introduce (and partially remove) obligations for machine‑readable browser/OS consent signals (Article 88b)
- The Commission’s original proposal COM(2025) 837 would have added Article 88b, requiring controllers to recognise automated, machine‑readable consent or refusal signals, set in browsers, OS or other tools, instead of repeatedly prompting banners.Lukasz Olejnik blog on Commission proposal to “kill” cookie consent nightmare PPC.land analysis quoting COM(2025) 837 and 88b obligations
- According to Council‑stage reporting, the Council position of 18 June 2026 removed the core signal provision from Article 88b, meaning browser‑level signals may not be adopted as originally proposed.PPC.land – Council drops cookie signal after Google lobbying ConsentModeHQ status update on Article 88a/88b
- Standardised recognition of consent/refusal and direct‑marketing objections (original Article 88b concept)
- The draft would allow data subjects to give consent, refuse consent, or object to direct marketing through automated machine‑readable means (browser, OS, EU Digital Identity Wallet, or comparable tools), and controllers would have to honour those signals.Lukasz Olejnik blog summarising draft text EDPB–EDPS Joint Opinion 2/2026 – comments on machine‑readable signals
- Single EU‑wide harmonised cyber/data incident reporting portal
- The Digital Omnibus proposal outlines a single entry point for reporting cyber incidents and data breaches, consolidating reporting obligations under GDPR, NIS2, DORA, eIDAS and the Critical Entities Resilience (CER) Directive.TwoBirds analysis of single EU harmonised incident reporting Excello Digital article on “one portal for every cyber incident report”
- Organizations would submit one report, which would then be routed to the relevant authorities under the different regimes, instead of filing separate notifications under each regime.Nixon Peabody alert on Omnibus streamlining overlapping reporting
- Narrowing / clarifying personal‑data concept at terminal‑equipment level
- Commentaries note that Article 88a focuses specifically on “personal data” on or from terminal equipment, which may clarify the boundary between device identifiers / technical data and personal data, though the GDPR’s general personal‑data definition remains unchanged.EDPB–EDPS Joint Opinion – concern about “personal data” scope in 88a(3) Kennedys overview of how Omnibus ties terminal‑equipment rules to personal‑data processing
Compliance Challenges
Because the Omnibus is not yet final, most challenges are inferred from existing analyses and stakeholder commentary.
- Interpreting consent vs. “service explicitly requested” exemptions
- Organizations will struggle to determine when cookies and similar technologies fall under “service explicitly requested” (no consent) versus marketing / tracking (consent required).EDPB–EDPS Joint Opinion – critical reading of consent exceptions AesirX breakdown of four no‑consent purposes in Article 88a
- Similar ambiguity has already caused compliance issues under the current ePrivacy regime, where organizations mis‑categorise analytics or personalisation cookies as “strictly necessary”.EDPB Guidelines 03/2022 on deceptive design patterns in social media (GDPR context) European Commission ePrivacy factsheet – guidance on consent for cookies
- Transition from cookie banners to device/browser‑level signals (and partial rollback)
- If Article 88b (or any successor mechanism) is adopted, controllers will need to integrate with browser/OS signal frameworks, yet Council negotiations have already removed key parts, creating uncertainty about technical standards and investment decisions.Lukasz Olejnik – analysis of machine‑readable consent signals concept PPC.land – Council removal of cookie signal provision after lobbying
- Consent‑management platforms and publishers must anticipate multi‑year timelines and possible non‑adoption, complicating product roadmaps.Usercentrics overview of EU Digital Omnibus package and consent changes
- Coordinating incident reporting across multiple regimes
- Organizations already face challenges reconciling GDPR breach reporting, NIS2 “incident” criteria, and DORA “major ICT incidents”, each with different thresholds and timelines.Official NIS2 Directive (EU) 2022/2555 text DORA Regulation (EU) 2022/2554 text
- The Omnibus proposal’s single portal does not eliminate the need for accurate classification under each law; mis‑classification risks under‑reporting or over‑reporting.TwoBirds analysis of harmonised incident reporting regimes Nixon Peabody alert on overlapping reporting obligations
- Operationalising consent exceptions for first‑party analytics
- The proposal introduces broader exemptions for provider’s own audience measurement, but only under specific conditions (aggregated, non‑profiling, first‑party).AesirX article – “own aggregated audience measurement” conditions Arnold & Porter advisory – consent exceptions for audience measurement
- Organizations may find it difficult to ensure their analytics stack truly meets these conditions (e.g., avoiding cross‑site tracking, profiling, or re‑use for marketing).
- Example: Publishers and ad‑tech ecosystem
- Analyses indicate that large publishers relying on behavioural advertising face significant compliance risk: making tracking conditional on article 88a consent could reduce available ad data, while uncertain browser‑signal rules complicate user experience.PPC.land – economic impact estimate EUR 40–50bn at stake NOYB Digital Omnibus report – impacts on tracking and profiling (PDF)
Implementation Best Practices (Preparing for Potential Adoption)
Because the Omnibus is not yet final, these are pre‑implementation best practices aligned with the current direction of travel.
- Map all terminal‑equipment interactions and classify purposes
- Create an inventory of all cookies, SDKs, local‑storage entries, and device identifiers used in your services, and map them to the four proposed purposes (communication, requested service, audience measurement, security) or to consent‑dependent uses.EDPB–EDPS Joint Opinion – Article 88a purposes AesirX Article 88a breakdown
- This is consistent with existing GDPR records of processing obligations under Article 30 GDPR and ePrivacy guidance on cookie categorisation.GDPR Regulation (EU) 2016/679 – Article 30 European Commission ePrivacy information on cookies and consent
- Design consent flows for single‑click refusal and cooldowns
- Draft texts and commentaries emphasise single‑click refusal and a cooldown period (e.g., six‑month moratorium on re‑prompting) after refusal.ConsentModeHQ explanation of single‑click refusal and cooldown in Article 88a Usercentrics overview of consent fatigue and Omnibus changes
- UX and consent‑management design should anticipate these constraints, avoiding dark patterns and ensuring granular choices, in line with EDPB design‑pattern guidelines.EDPB Guidelines 03/2022 on deceptive design patterns
- Prepare technical capability to read and honour machine‑readable signals (even if final scope changes)
- Build or procure tools capable of detecting and interpreting browser/OS preference signals (e.g., potential successors to Do Not Track or GPC), and binding those to your consent records.Lukasz Olejnik blog – possible technical implementations in browsers/OS/ID wallet AesirX explanation of machine‑readable refusal signals
- Even if the final Article 88b is diluted, similar mechanisms may appear via industry standards or other EU initiatives (e.g., the EU Digital Identity Wallet).Regulation (EU) 2024/1183 establishing the European Digital Identity Framework – official text
- Build an internal “single reporting playbook” aligned with Omnibus concepts
- Develop a central incident reporting procedure that aligns thresholds and definitions across **GDPR, NIS2 and D
Recent developments
- — Analysis of the 1,840 amendments tabled on the Digital Omnibus package, detailing how it simultaneously modifies GDPR, ePrivacy, NIS2, DORA, the Data Act, eIDAS and the Critical Entities Resilience Directive, with a focus on simplifying and harmonizing digital obligations and breach reporting.[9] (source)
- — European Parliament “Legislative Train” update on the Digital Omnibus proposal, situating it within the broader digital rulebook reform and describing the consolidation of single market data rules into the Data Act and the streamlining of overlapping privacy, cybersecurity and resilience requirements.[7] (source)
- — European Commission digital strategy update outlining the Digital Omnibus as part of an agile EU digital rulebook, including the creation of a single-entry point for all cybersecurity incidents and data breach reports and the merging of several data and open‑data instruments into a restructured Data Act.[12] (source)
- — News article describing how the Digital Omnibus consolidates reforms to GDPR, the AI Act, NIS2, ePrivacy and the Data Act into one package, including a new unified reporting interface allowing businesses to satisfy notification duties under GDPR, NIS2, DORA, eIDAS and CER through a single secure portal.[11] (source)
- — Policy blog commentary on the February 2026 developments of the Digital Omnibus, explaining how incident reporting will be centralised via a common EU portal that routes reports under GDPR, NIS2, DORA and related regimes to the competent authorities, reducing duplicate notifications and administrative burden.[6] (source)
- — Summary of the EDPB–EDPS Joint Opinion 2/2026 on the Digital Omnibus, welcoming simplification such as a single European notification portal and common DPIA methodology while warning that raising breach notification thresholds and extending deadlines must not weaken data‑subject protection under GDPR and related regimes.[1] (source)
- — Industry-focused explainer on the Digital Omnibus package describing how it amends GDPR, the Data Act, AI Act, NIS2, ePrivacy and DORA to eliminate overlapping requirements, streamline incident reporting into a single ENISA‑managed portal, and recalibrate consent and cookie mechanisms to reduce friction while maintaining compliance.[4] (source)
- — Law firm overview of the Digital Omnibus proposal detailing the central operational reform of a single EU entry point for incident notifications across GDPR, NIS2, CRA, DORA, eIDAS and CER, and explaining implications for privacy, cybersecurity and operational resilience governance in regulated sectors.[5] (source)
Related regulations
- EU AI Act - Annex III High-Risk System Requirements (2 Dec 2027) — European Union, Upcoming, effective 2027-12-02
- EU Data Act — European Union, Phased, effective 2025-09-12
- EU Cyber Resilience Act (CRA) — European Union, Phased, effective 2027-12-11
- EU AI Act - GPAI Model Obligations (2 Aug 2025) and Enforcement (2 Aug 2026) — European Union, Active, effective 2025-08-02
- EU Digital Omnibus on AI (Regulation (EU) 2026/1744) — European Union, Active, effective 2026-07-27
- EU AI Act - Synthetic Media Transparency and New Prohibitions (2 Dec 2026) — European Union, Upcoming, effective 2026-12-02
- EU AI Act - Annex I High-Risk Systems (2 Aug 2028) — European Union, Upcoming, effective 2028-08-02
- EU Cyber Resilience Act - Vulnerability and Incident Reporting (11 Sep 2026) — European Union, Active, effective 2026-09-11
Put it into practice
- Generate the policy: GDPR policy generator (generatepolicy.com)
- Buy the policy pack: GDPR Complete Bundle (cyberpolicy.shop)
- Build it yourself: GDPR & DPIA Compliance Workbook (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates