Regulatory dossier

GDPR reform in the Digital Omnibus

The proposed GDPR and ePrivacy changes, the legislative file’s development, and my published assessments. Covers personal data, AI, cookies, data-subject rights, scientific research, practical compliance and enforcement, with a selected Council comparison and timeline.

First published
8 September 2026
Last updated
8 September 2026
Current version
1.0
Editor
Mikołaj Barczentewicz
Download as Markdown

A convenient format for sharing this dossier with AI agents.

Where the file stands

The Digital Omnibus proposes changes to the GDPR’s scope, data-subject rights, AI processing, scientific research, device access and compliance procedures.

In my April 2025 essay GDPR reform: what should it achieve, I argued that reducing administrative burdens would be insufficient without changes to the enforcement framework. My July update supported guidance with legal force and stronger presumptions of compliance.

September: a new compromise is reported

Júlia Tar reports in MLex that a 3 September 2026 compromise would clarify when pseudonymised data falls outside the GDPR while leaving its general definition unchanged, restore an AI legitimate-interest provision, revise cookie rules and add a limited exemption for measuring contextual advertising. Her report is dated 7 September. The accompanying 4 September explanatory note reportedly requests written comments by 15 September.

The Council’s meeting notice (CM 3890/26) independently schedules discussion for 11 September and identifies the revised compromise (ST 12535/26) and explanatory note (WK 13065/26). I have not examined either September text, so the detailed comparison below covers the May–July Council texts. Neither a Presidency compromise nor a request for comments establishes an agreed Council position.

The Council comparison starts with the 21 May Presidency compromise (ST 9547/26) and includes the 18 June text (ST 10677/26) on pseudonymisation, rights, research, compliance and fraud exceptions. Ireland’s 9 July discussion note names the June text as its reference while inviting governments to revisit outstanding questions before a further revision. In my July update, I described Ireland as reopening the substance rather than carrying forward Cyprus’s approach. The note clarifies the continuity: the inherited text remained the reference document, while its substantive choices were reopened.

In Parliament, the 22 June joint ITRE–LIBE draft report is the rapporteurs’ opening text. The 27 July tabled amendments show competing operative proposals on personal data, individual rights, scientific research, AI, cookies, compliance and the Commission’s implementing powers. Separately, Piotr Müller’s amendment to the IMCO draft opinion would strengthen the legal effect of following Commission criteria. The issue sections examine representative alternatives; none establishes an adopted Parliament position.

My 30 July update reported that objections to Cyprus’s approach included Denmark, Germany, Italy, Poland and Sweden, and suggested insufficient simplification ambition as a possible reason. That remains my account of contemporary reporting, rather than a coalition established from national submissions here. The same essay reported a 15 July Parliament amendment deadline and more than a thousand submissions. The large amendment series and the opposing proposals examined below explain why the joint draft left the substantive outcome open.

The September developments above remain based on reporting checked on 8 September. Direct examination now includes selected July Parliament amendments, June national comments on contextual advertising, and selected June Council provisions. The September Council texts remain unexamined.

Scope of the assessment

The focus is the GDPR and ePrivacy part of the Commission proposal (COM(2025)837; procedure 2025/0360(COD)). The wider Data Act, cybersecurity and public-sector-data amendments receive only incidental treatment. The separate AI Omnibus is outside the comparison. All legislative changes discussed here remain proposals in the identified texts.

The dossier follows seven issue chapters: the scope of personal data; access, transparency and automated decisions; AI processing; device access and consent; scientific research; practical compliance; and enforcement. The research chapter covers legal bases, further processing and notice exemptions as well as the definition. The AI and cookie chapters examine objection rights, technical choices and the role of browser providers. The timeline records developments in the legislative file, separately from the publication history of this dossier.

How the Council approach changed

Each row compares one reform question across the dated texts, rather than reproducing whole articles. The cells cover selected May–July Council provisions. Parliament’s alternatives and the reported September compromise are discussed in the issue sections; the September texts remain unexamined.

Download CSV
Reform questionCommission · November 2025Council trajectory · May–July 2026Practical significance

When is information personal data for a recipient?

Add an express entity-relative test to Article 4(1), including a sentence on potential later recipients.

May: delete the Article 4 addition. June: Article 29a(2) expressly recognises that effective pseudonymisation may prevent identification by another recipient; paragraph 3 excludes processors. July: Ireland asks for positions on Article 29a and ways to achieve simplification and certainty.

The June text carries an operative entity-relative provision, subject to circumstances and effective measures. Moving the rule out of Article 4 changes its framing and conditions; it does not reject the recipient-relative outcome.

Who specifies the criteria, and with what legal effect?

Article 41a: Commission implementing acts with EDPB involvement. Compliance may be used as an evidential element.

May: replace Article 41a with an EDPB opinion under Article 29a. June: retain that opinion procedure and delete Commission implementing-act machinery. July: Article 29a remains a focus of questions to governments.

An EDPB opinion and a Commission implementing act are different instruments. Neither should be described as an unconditional safe harbour.

When may an access request be treated as excessive?

Article 12(5): add abuse for purposes other than data protection; permit reasonable grounds to believe a request excessive.

June: refer to demonstrated abusive intent; require the controller to demonstrate manifest unfoundedness or excessiveness, considering all relevant circumstances. Require proportionate fees and reasons for refusal.

The evidential burden and the treatment of additional motives determine how far controllers can use the exception.

When can a controller omit a privacy notice?

Replace Article 13(4): exempt paragraphs 1–3 for a clear, circumscribed, non-data-intensive relationship where specified information can reasonably be assumed known, subject to exclusions.

June: preserve paragraph 4 and add a conditional paragraph 5 covering paragraphs 1–2 only. Exclude complex processing, large amounts of data, Article 9 and 10 data, high risk, other recipients, third-country transfers and Article 22 decisions.

The existing already-has-information exception survives; the new exception leaves the different-purpose notice duty in paragraph 3 intact.

What does contractual necessity permit for automated decisions?

Article 22: allow decisions on the specified grounds and say expressly that a human alternative does not itself defeat contractual necessity.

June: retain the right not to be subject to such decisions unless a specified ground applies; delete the human-alternative phrase from the article but retain its substance in recital 38 and preserve human-intervention and sensitive-data safeguards.

Deletion from the article does not establish abandonment of the clarification. Contractual necessity and meaningful review remain separate requirements.

How is legitimate interest recognised for AI?

Article 88c: express recognition within Article 6(1)(f), with balancing, safeguards and an unconditional right to object.

May: delete Article 88c and retain a legitimate-interest statement in recital 33a, omitting the enhanced-transparency and unconditional-objection wording. July: Ireland asks whether the replacement supplies sufficient certainty.

The general Article 6(1)(f) route and GDPR rights remain. The May text loses both the operative AI-specific clarification and express safeguards; the Joint Opinion had recommended retaining the unconditional objection in Article 21.

How can AI developers handle residual sensitive data?

Article 9(2)(k) and (5): avoidance measures, removal when identified, and protection against output or disclosure where removal requires disproportionate effort.

May: limit the derogation to incidental and residual processing and tighten the remedial conditions. This row does not establish the content of a later Irish text.

The May recital distinguishes residual processing from deliberate processing for a sensitive-data purpose and expressly excludes sensitive data collected through prompts during deployment.

Which device-access operations need consent?

Move personal-data terminal-access rules into GDPR Article 88a, add limited exemptions, and introduce automated choices in Article 88b.

May: revise ePrivacy Article 5(3). June: strike its express fraud exception. July: Ireland confirms an extended whitelist under ePrivacy and omission of the centralised automated consent provision.

July’s note retains discussion of consent exemptions while recording the omission of the centralised and automated consent mechanism. MLex reports further cookie revisions in September.

Which activities qualify as scientific research?

Article 4(38): contribution to knowledge or its novel application, an aim of contributing to society’s general knowledge and wellbeing, ethical standards, and recognition of innovation and commercial interests.

May: put autonomy, independence, methodology and verifiable results in the operative definition; move commercial and innovation language into recital 28. June: the recital expressly allows research mandated and conducted by public or private entities, subject to a substantiated case-by-case assessment.

The Council recital contemplates private and commercial research while preserving qualifying criteria. Leiser argues that autonomy and independence can make private and collaborative R&D harder to classify.

What flexibility follows from scientific-research status?

Article 5(1)(b): compatible further processing independently of Article 6(4), under Article 89(1). Article 13(5): a conditional research notice exception.

June: retain the compatibility clarification with appropriate safeguards; confine the notice exception, renumbered 13(6), to further research processing by the same controller, where and insofar as its conditions apply.

Purpose compatibility, legal basis and exemption from individual information are separate questions; satisfying the definition does not answer all three.

Which breaches must be reported, when and through which channel?

Article 33: high risk; without undue delay and within 96 hours where feasible; proposed NIS2 single-entry point, with direct reporting until established.

June: retain high risk and 96 hours; substitute a national entry point under proposed NIS2 Article 23b, preserving direct reporting during transition. EDPB establishes template and high-risk/non-high-risk lists; Commission may adopt the template.

The threshold and timing survive this stage, while the reporting infrastructure and authority over common materials change. Breach documentation remains required.

Who establishes common DPIA lists and methodology?

Article 35: EDPB proposes lists, template and methodology; Commission may adopt them by implementing act. National lists remain until that act.

June: EDPB establishes the lists, template and methodology. Commission may adopt only the template by implementing act. National lists remain until the EDPB establishes their replacements.

Common lists concern when an assessment is required. The template-only Commission role is narrower than authority over those lists and the methodology.

When is information personal data for a recipient?

Commission · November 2025

Add an express entity-relative test to Article 4(1), including a sentence on potential later recipients.

Council trajectory · May–July 2026

May: delete the Article 4 addition. June: Article 29a(2) expressly recognises that effective pseudonymisation may prevent identification by another recipient; paragraph 3 excludes processors. July: Ireland asks for positions on Article 29a and ways to achieve simplification and certainty.

Practical significance

The June text carries an operative entity-relative provision, subject to circumstances and effective measures. Moving the rule out of Article 4 changes its framing and conditions; it does not reject the recipient-relative outcome.

Sources

Who specifies the criteria, and with what legal effect?

Commission · November 2025

Article 41a: Commission implementing acts with EDPB involvement. Compliance may be used as an evidential element.

Council trajectory · May–July 2026

May: replace Article 41a with an EDPB opinion under Article 29a. June: retain that opinion procedure and delete Commission implementing-act machinery. July: Article 29a remains a focus of questions to governments.

Practical significance

An EDPB opinion and a Commission implementing act are different instruments. Neither should be described as an unconditional safe harbour.

Sources

When may an access request be treated as excessive?

Commission · November 2025

Article 12(5): add abuse for purposes other than data protection; permit reasonable grounds to believe a request excessive.

Council trajectory · May–July 2026

June: refer to demonstrated abusive intent; require the controller to demonstrate manifest unfoundedness or excessiveness, considering all relevant circumstances. Require proportionate fees and reasons for refusal.

Practical significance

The evidential burden and the treatment of additional motives determine how far controllers can use the exception.

Sources

When can a controller omit a privacy notice?

Commission · November 2025

Replace Article 13(4): exempt paragraphs 1–3 for a clear, circumscribed, non-data-intensive relationship where specified information can reasonably be assumed known, subject to exclusions.

Council trajectory · May–July 2026

June: preserve paragraph 4 and add a conditional paragraph 5 covering paragraphs 1–2 only. Exclude complex processing, large amounts of data, Article 9 and 10 data, high risk, other recipients, third-country transfers and Article 22 decisions.

Practical significance

The existing already-has-information exception survives; the new exception leaves the different-purpose notice duty in paragraph 3 intact.

Sources

What does contractual necessity permit for automated decisions?

Commission · November 2025

Article 22: allow decisions on the specified grounds and say expressly that a human alternative does not itself defeat contractual necessity.

Council trajectory · May–July 2026

June: retain the right not to be subject to such decisions unless a specified ground applies; delete the human-alternative phrase from the article but retain its substance in recital 38 and preserve human-intervention and sensitive-data safeguards.

Practical significance

Deletion from the article does not establish abandonment of the clarification. Contractual necessity and meaningful review remain separate requirements.

Sources

How is legitimate interest recognised for AI?

Commission · November 2025

Article 88c: express recognition within Article 6(1)(f), with balancing, safeguards and an unconditional right to object.

Council trajectory · May–July 2026

May: delete Article 88c and retain a legitimate-interest statement in recital 33a, omitting the enhanced-transparency and unconditional-objection wording. July: Ireland asks whether the replacement supplies sufficient certainty.

Practical significance

The general Article 6(1)(f) route and GDPR rights remain. The May text loses both the operative AI-specific clarification and express safeguards; the Joint Opinion had recommended retaining the unconditional objection in Article 21.

Sources

How can AI developers handle residual sensitive data?

Commission · November 2025

Article 9(2)(k) and (5): avoidance measures, removal when identified, and protection against output or disclosure where removal requires disproportionate effort.

Council trajectory · May–July 2026

May: limit the derogation to incidental and residual processing and tighten the remedial conditions. This row does not establish the content of a later Irish text.

Practical significance

The May recital distinguishes residual processing from deliberate processing for a sensitive-data purpose and expressly excludes sensitive data collected through prompts during deployment.

Sources

Which device-access operations need consent?

Commission · November 2025

Move personal-data terminal-access rules into GDPR Article 88a, add limited exemptions, and introduce automated choices in Article 88b.

Council trajectory · May–July 2026

May: revise ePrivacy Article 5(3). June: strike its express fraud exception. July: Ireland confirms an extended whitelist under ePrivacy and omission of the centralised automated consent provision.

Practical significance

July’s note retains discussion of consent exemptions while recording the omission of the centralised and automated consent mechanism. MLex reports further cookie revisions in September.

Sources

Which activities qualify as scientific research?

Commission · November 2025

Article 4(38): contribution to knowledge or its novel application, an aim of contributing to society’s general knowledge and wellbeing, ethical standards, and recognition of innovation and commercial interests.

Council trajectory · May–July 2026

May: put autonomy, independence, methodology and verifiable results in the operative definition; move commercial and innovation language into recital 28. June: the recital expressly allows research mandated and conducted by public or private entities, subject to a substantiated case-by-case assessment.

Practical significance

The Council recital contemplates private and commercial research while preserving qualifying criteria. Leiser argues that autonomy and independence can make private and collaborative R&D harder to classify.

Sources

What flexibility follows from scientific-research status?

Commission · November 2025

Article 5(1)(b): compatible further processing independently of Article 6(4), under Article 89(1). Article 13(5): a conditional research notice exception.

Council trajectory · May–July 2026

June: retain the compatibility clarification with appropriate safeguards; confine the notice exception, renumbered 13(6), to further research processing by the same controller, where and insofar as its conditions apply.

Practical significance

Purpose compatibility, legal basis and exemption from individual information are separate questions; satisfying the definition does not answer all three.

Sources

Which breaches must be reported, when and through which channel?

Commission · November 2025

Article 33: high risk; without undue delay and within 96 hours where feasible; proposed NIS2 single-entry point, with direct reporting until established.

Council trajectory · May–July 2026

June: retain high risk and 96 hours; substitute a national entry point under proposed NIS2 Article 23b, preserving direct reporting during transition. EDPB establishes template and high-risk/non-high-risk lists; Commission may adopt the template.

Practical significance

The threshold and timing survive this stage, while the reporting infrastructure and authority over common materials change. Breach documentation remains required.

Sources

Who establishes common DPIA lists and methodology?

Commission · November 2025

Article 35: EDPB proposes lists, template and methodology; Commission may adopt them by implementing act. National lists remain until that act.

Council trajectory · May–July 2026

June: EDPB establishes the lists, template and methodology. Commission may adopt only the template by implementing act. National lists remain until the EDPB establishes their replacements.

Practical significance

Common lists concern when an assessment is required. The template-only Commission role is narrower than authority over those lists and the methodology.

Sources

Issue analysis

Personal data and practical legal certainty

The proposed entity-relative definition

The Commission would add three sentences to GDPR Article 4(1). Their central proposition is that information can be personal data for an organisation able to identify an individual, yet fall outside the GDPR for another organisation lacking reasonably likely means of identification. It would also say that the mere possibility of a later recipient being able to identify the person does not, by itself, make the information personal for the first organisation.

Consider a research team receiving records whose identification key remains with a hospital. Under the guidelines, the assessment considers identification routes reasonably likely to be available to that team: access to the key, linkage with other records, cooperation with another entity, or distinctive attributes within the dataset. Replacing names with codes cannot answer the question by itself.

The EDPB’s July draft guidelines expressly accept that information may be anonymous for one entity and personal for another. They also accept that successful anonymisation need not require deletion of the original data. The guidelines also set out conditions governing that assessment.

The authorities’ objections and qualifications

In its February Joint Opinion, the EDPB and EDPS opposed the Commission’s definition change. They argue that the proposed final sentence does not accurately reflect, and goes beyond, CJEU case law. Their objection concerns selective codification: a recipient’s capabilities cannot be considered without the rules governing disclosure, the original controller’s responsibilities and arrangements that leave identification possible in practice. The opinion recommends deleting the proposed definition change.

Three qualifications in the July guidelines are especially consequential:

  • A processor does not simply acquire an independent perspective. Where an organisation processes data on behalf of a controller, the guidelines apply the controller’s perspective. Outsourcing processing without handing over the identification key therefore does not automatically remove the processor from the GDPR.
  • Onward disclosure can change the assessment. The guidelines treat a reasonably likely transfer to a recipient with reasonably likely identification means as relevant to both the transfer and, indirectly, the transferor. The Commission’s proposed Article 4(1) refers to a mere potential later recipient, while recital 27 says that disclosure makes the information personal only for the identifying third party.
  • Separation must work in practice. Contracts and legal prohibitions matter, but they need to constrain the relevant actors effectively. Technical change and changes in the available auxiliary data can require reassessment. An organisation needs evidence about the arrangement it actually operates.

From Article 4 to Article 29a

The May Council compromise removed the Commission’s addition to Article 4(1) and recast the proposed Article 41a implementing power as an Article 29a centred on an EDPB opinion.

The 18 June compromise makes the replacement’s entity-relative effect explicit. Article 29a(2) says that pseudonymisation may, depending on the circumstances and effective technical and organisational measures, prevent people other than the controller from identifying the data subject. For those recipients, the subject may no longer be identifiable. Paragraph 3 preserves other applicable obligations and expressly excludes processors from paragraph 2. Paragraphs 4–5 require an EDPB opinion on pseudonymisation and anonymisation, including the relevant circumstances and measures; the Commission implementing-act machinery is deleted.

Ireland’s July note asks delegations for their position on Article 29a and how to achieve meaningful simplification and legal certainty. The discussion therefore concerns the conditions and institutional machinery of an operative replacement, not simply whether a recipient-relative outcome is possible.

September reporting. MLex reports that the new compromise would keep the general definition unchanged while clarifying the position of an organisation unable to identify the individual from pseudonymised data. The exact conditions and legal effect await inspection of ST 12535/26.

Parliament’s disagreements are now visible in text

The joint rapporteurs’ June draft report does not propose changing the Commission’s Article 4(1) addition or its GDPR Article 41a power. That leaves the Commission wording in the baseline for their draft, without establishing that both rapporteurs endorse it as their final position.

Two July amendments to recital 27 demonstrate the disagreement. Amendment 214, tabled by Marina Kaljurand and colleagues, reduces the recital to the general statement about targeted clarification and simplification while preserving protection. Amendment 216, tabled by Aura Salla and colleagues, retains the entity-relative explanation and adds objective factors such as identification costs, time and technological developments. It also qualifies the result: likely onward disclosure to an identifying recipient can make the information personal indirectly for the controller, and pseudonymised data should be treated as personal where the recipient’s identification means cannot be ruled out.

The tabled amendments to Article 4(1) make the operative choices visible:

  • Deletion. Kaljurand and colleagues’ Amendment 932 would delete the Commission’s three added sentences. Pernando Barrena Arza’s Amendment 929 and Julie Rechagneux and colleagues’ Amendment 935 propose the same deletion. The co-rapporteur’s own amendment makes her disagreement with Salla’s qualified-retention approach explicit.
  • Qualified retention. Salla and colleagues’ Amendment 940 retains an entity-relative rule depending on the circumstances, but makes the information personal where it is, or is likely to be, disclosed to someone with means reasonably likely to identify the individual.
  • A separate exclusion. Alice Teodorescu Måwe’s Amendment 947 would exclude certain data primarily relating to an enterprise or object, subject to three cumulative conditions: the person is associated only as an owner, employee or similar; processing is not specifically related to that person; and safeguards prevent person-specific use.

In my July update, I read the joint draft as an initial area of agreement and noted that both rapporteurs intended to pursue issues it left untouched. The recital and operative amendments now provide concrete examples of the divergence that the draft alone could not show.

My published assessment

In my November 2025 response to the leaked proposal, I welcomed an entity-relative definition and argued that separating identifying information from other processing could benefit both data minimisation and privacy.

My July 2026 update continued to support the clarification but described its significance as largely symbolic following the EDPB’s acceptance of the core principle. I put greater weight on Commission implementing powers and guidance capable of creating strong legal presumptions. This assessment predates the reported September compromise.

Access, transparency and automated decisions

Access requests: proving abuse or questioning the purpose?

The Commission proposes two changes to Article 12(5). First, an Article 15 access request could be treated as excessive where the individual abuses GDPR rights for purposes other than protecting their data. Second, the controller would need reasonable grounds to believe a request excessive, while still bearing the burden of demonstrating that a request is manifestly unfounded. The consequences remain a reasonable administrative fee or refusal to act. Recital 35 additionally treats overly broad and undifferentiated requests as excessive.

That combination matters when access helps a person pursue an employment dispute, consumer claim or another legal right. The EDPB and EDPS object to making the purpose of access decisive: individuals need not justify their request, and a purpose beyond data protection does not by itself establish abuse. They also oppose lowering the evidential burden and treating breadth alone as excessive. Their objection leaves room to address demonstrated abuse under the existing exception.

The 18 June Council text uses demonstrated abusive intent rather than the Commission’s reference to purposes other than data protection. It requires the controller to demonstrate that a request is manifestly unfounded or excessive, taking all relevant circumstances into account. It also requires a proportionate fee and reasons for refusal. This shifts the question towards evidence of abuse rather than the presence of an additional motive.

The joint rapporteurs’ draft removes the Commission’s addition about purpose and restores the controller’s burden of demonstrating excessiveness. It would also give the individual the choice between paying the fee and refusal. July amendments expose several alternatives:

  • Irena Joveva and colleagues’ Amendment 1076 deletes the proposed replacement of Article 12(5), retaining the existing provision.
  • Julie Rechagneux and colleagues’ Amendment 1087 specifies examples of abusive conduct, including obtaining commercially sensitive information, exerting pressure in unrelated proceedings and disproportionate disruption. Their Amendment 1088 separately protects good-faith checks of GDPR compliance and assistance under Article 80. The two proposals therefore distinguish asserted abuse from supported exercises of data-protection rights.
  • Pernando Barrena Arza’s Amendment 1093 protects requests made in support of other legitimate rights, including employment, consumer and journalistic purposes, and rejects breadth alone as proof of excessiveness. It requires an assessment based on objective, documented circumstances.

The practical dividing line is whether a controller must substantiate abusive conduct or may rely on a broader assessment of purpose and burden. These alternatives do not establish that an inconvenient or litigation-related request is automatically abusive.

Transparency: how much can a controller assume people know?

The existing Article 13(4) exception concerns information the individual already has. The Commission would replace it with an exemption from paragraphs 1–3 where data is collected in a clear, circumscribed relationship, the controller’s activity is not data-intensive, and there are reasonable grounds to assume the individual knows the information in Article 13(1)(a) and (c): the controller’s identity and contact details, and the purposes and legal basis. The exemption would be unavailable for transmission to other recipients, third-country transfers, Article 22 decisions or processing likely to create high risk.

Knowing those particulars is a narrower condition than already having the complete Article 13 notice. The proposal could therefore dispense with supplying information about matters such as retention and rights, even though the person has not received it. The EDPB and EDPS support the simplification objective but seek clearly limited conditions, clarification of a non-data-intensive activity, and removal of the reasonable-grounds assumption. They also recommend requiring full Article 13 information on request and informing individuals of that possibility.

The June Council text preserves paragraph 4 and places the new exception in paragraph 5. It exempts only paragraphs 1 and 2, leaving paragraph 3’s duty to inform before further processing for a different purpose. Its cumulative conditions require a direct, clear and circumscribed relationship; reasonable grounds to assume the specified information is known; no likely high risk; no complex processing, large amounts of data, special-category data or criminal-conviction data; and no other recipients, third-country transfers or Article 22 decisions.

July alternatives range from deletion to a broader exemption. Joveva and colleagues’ Amendment 1100 deletes the proposed Article 13(4) replacement. Gregorová’s Amendment 1103 preserves the already-has-information route and adds a conditional route for SMEs or organisations with fewer than 250 employees. Among its requirements are contractual necessity, no duty to appoint a DPO, exclusion of Article 9 and 10 data, and continuing availability of information. Wechsler and colleagues’ Amendment 1106 instead adds impossible or disproportionate effort, taking account of the controller’s size and resources, and permits transmission connected with the specified relationship, subject to its other exclusions and safeguards.

The differences concern both eligibility and the information withheld. A size-based rule, a low-risk relationship rule and an effort-based rule would relieve different controllers. The separate research notice exception is examined in the scientific-research section.

Automated decisions: contractual necessity and human review

The Commission would recast Article 22 as permission for solely automated decisions with legal or similarly significant effects only on three grounds: contractual necessity, authorisation by law with safeguards, or explicit consent. Its contractual ground says that the possibility of taking the decision by other means does not itself defeat necessity. Recital 38 adds that, among equally effective automated solutions, the less intrusive one should be used.

This clarification does not make every commercially useful automated decision contractually necessary. The human-intervention, expression-of-view and contestation safeguards for contractual or consent-based decisions remain, as do the limits on special-category data. The Joint Opinion recommends wording that states a prohibition with specified exceptions, preserving a right individuals can invoke. It would leave the human-alternative clarification in a recital, but also require that no equally effective and less intrusive means, automated or otherwise, be available.

The June Council text retains the right-not-to-be-subject formulation and the three grounds, deletes the human-alternative phrase from the operative contractual ground, and retains safeguards on human intervention and special-category data. Its recital 38 still contains the human-alternative clarification. The deletion from the article therefore does not establish rejection of the proposition altogether.

The joint draft similarly restores the rights-based formulation. Its Amendment 53 specifies meaningful human review by a person with the authority, knowledge and competence to change the decision, considering all relevant data.

In July, Agius Saliba’s Amendment 1149 deletes the human-alternative phrase from the article. His justification explicitly links the relocation to the authorities’ recommendation: “Moved to recital 38 as per EDPB-EDPS opinion, para. 72”. Kaljurand and colleagues’ Amendment 1150 makes the same operative deletion. The location of the clarification and the quality of human review remain separate negotiating questions.

AI development and residual sensitive data

Two legal obstacles, two proposed responses

The AI provisions address different problems. Proposed Article 88c concerns reliance on legitimate interests under Article 6(1)(f). Proposed Article 9(2)(k), read with new paragraph 5, concerns the separate restrictions on special-category data. A route through Article 9 does not remove the need for an Article 6 basis, and neither provision establishes that a dataset or model is anonymous.

Article 88c would expressly recognise that necessary processing for AI development and operation may pursue legitimate interests. It preserves the balancing test, the relevance of children’s interests and other laws requiring consent. It also specifies safeguards, including data minimisation and an unconditional right to object. This is a proposed clarification within the legitimate-interest framework, not a general exemption for AI.

The Council’s May text deleted Article 88c while retaining a statement about possible legitimate interests in recital 33a. The recital omits the proposed enhanced-transparency and unconditional-objection wording; general GDPR information duties and objection rights remain applicable. Ireland’s July note expressly describes the replacement and asks whether the resulting text offers sufficient certainty. The change therefore removes both the proposed operative clarification and some express safeguards, while leaving the general Article 6(1)(f) route available.

The Joint Opinion recommended explaining possible reliance on legitimate interests in a recital, but also welcomed the unconditional right to object and recommended retaining it in Article 21. It separately sought clarification of enhanced transparency. The May settlement follows the recital approach without carrying across that proposed objection right.

The proposed residual sensitive-data derogation

An AI developer may seek to exclude information about health, politics or other sensitive matters from a large training corpus and still encounter residual examples. The Commission’s proposal recognises that difficulty. It requires organisational and technical measures to avoid special-category data, removal when such data is identified, and effective protection against output or disclosure where removal would require disproportionate effort.

The May Council formulation narrows the derogation to incidental and residual processing. Its recital distinguishes that situation from deliberately processing sensitive data because it is necessary for the purpose, which still requires another applicable Article 9 route or other Union-law provision. Recital 33 also expressly excludes special-category data collected through prompts during deployment. The derogation thus addresses residue in AI development under specified safeguards, with an express limit on its use for deployment inputs.

In my July update, I identified this derogation as potentially the Commission proposal’s most directly consequential positive change. My argument is that large-scale training cannot guarantee the perfect exclusion of sensitive information despite filtering efforts.

The rule also creates a difficult question for open-weight models. If compliance depends on preventing later disclosures, what measures can a developer implement once others control the model? I raised that concern in my November response to the leaked text. The proposal does not itself establish a general prohibition on releasing model weights. Whether a particular release could satisfy the condition depends on the applicable safeguards.

Parliament’s competing amendments

My July update described amendments ranging from deletion to expansion of the AI provisions. For the special-category derogation, Marina Kaljurand and colleagues’ Amendment 1022 deletes Article 9(2)(k). Julie Rechagneux and colleagues’ Amendment 1024 would instead extend it beyond AI to innovative systems or technologies necessary for a controller’s or third party’s legitimate interests, while retaining paragraph 5’s conditions and adding AI Act qualifications. These alternatives concern the separate Article 9 prohibition, even though the latter also refers to legitimate interests.

Salla and colleagues’ Amendment 1025 combines a limitation with a wider express scope: it confines Article 9(2)(k) to incidental and residual processing, while naming development, training, testing, deployment and operation, including improvements and related products or services. Article 9(5)’s conditions remain. The shared “incidental and residual” wording therefore does not settle the dispute about which stages and activities the derogation should cover.

Article 88c’s two paragraphs also attract different treatments. Alex Agius Saliba’s Amendment 1577 deletes paragraph 2’s AI-specific safeguards; taken alone, it leaves paragraph 1 intact. His Amendment 1553 separately proposes deleting Article 88c as a whole. Rechagneux and colleagues’ Amendment 1569 instead generalises paragraph 1 beyond AI to processing necessary for a controller’s or third party’s legitimate interests, but expressly retains case-by-case assessment and rejects a presumption of lawfulness.

Axel Voss’s Amendment 1566 retains the Article 6(1)(f) structure and general balancing test, but removes the specific emphasis on children and narrows the express carve-out for laws requiring consent from Union or national laws to Union laws. These safeguards should therefore be distinguished from those in the Commission baseline described above.

Objection rights and technical opt-outs

The Commission’s unconditional objection right in Article 88c would go beyond an ordinary Article 21(1) objection, under which a controller may establish compelling overriding grounds or a need relating to legal claims. The Joint Opinion recommends retaining the stronger right in Article 21 even if the legitimate-interest clarification moves to a recital.

July proposals would alter that safeguard in different ways. Jana Nagyová and colleagues’ Amendment 1585 substitutes a reference to Article 21; Schenk and colleagues’ Amendment 1587, also co-signed by Salla, removes the express objection clause while retaining other measures and enhanced transparency; Salla and colleagues’ Amendment 1589 retains an express right to object but removes “unconditional”. These are changes to the additional AI safeguard, not proposals to abolish every general GDPR objection right.

Commission recital 31 also envisages respecting technical indications embedded in a service that limit third-party use of data for AI development. Henrik Dahl’s Amendment 275 removes that passage along with the recital’s additional safeguards and unconditional-objection language. A recital about technical indications, an operative right to object and a legal obligation to implement a particular technical standard have different effects. The Commission proposal should not be described as prescribing a complete AI opt-out protocol.

User-provided data and the limits of the sensitive-data route

Joveva and colleagues’ Amendment 1051 tightens Article 9(5): sensitive data identified in training datasets must be erased without undue delay before training ends. For an already trained system or model, the alternative applies where erasure is technically impossible, with documentation, supervisory notification and protective filtering or alignment. This substitutes technical impossibility for the Commission’s disproportionate-effort test.

The amendment also excludes sensitive data originating from information supplied by, or generated through the activity of, end users on online platforms or core platform services, referring to the DMA definitions. Its exclusion applies across development, training and operation. The wording refers to service categories rather than limiting the exclusion to designated gatekeepers. It is therefore distinct from May’s recital excluding sensitive data collected through deployment prompts, and should not be reduced to a generic prohibition on training with every kind of user-provided data.

September reporting

MLex reports that the 3 September compromise would reinstate an AI legitimate-interest provision. The available report does not establish that its wording or safeguards are identical to the Commission’s Article 88c. The May–July movement into a recital described above is therefore a historical stage, rather than the latest reported negotiating direction.

Cookies, device access and consent

Moving the rule does not settle its scope

The Commission proposed moving rules for storing or accessing personal data in terminal equipment into a new GDPR Article 88a. Its associated ePrivacy amendment would leave the separate terminal-equipment rule relevant to information outside that transfer. Classifying information as non-personal would not necessarily remove the consent requirement for accessing it. In my November critique, I identified this split as a central weakness of the proposal. The Joint Opinion also warns that dividing the framework between two instruments would add complexity and uncertainty.

The proposed GDPR provision includes exemptions for communications transmission, a service explicitly requested by the user, aggregated audience measurement for the controller’s own use, and specified security purposes. It also provides for easy refusal and a six-month period before asking again for the same purpose after refusal.

The Council’s trajectory is more specific than “cookie reform was dropped”

The May Council compromise kept the consent framework in Article 5(3) of the ePrivacy Directive and adjusted the exceptions. It also retained a browser-signals mechanism in a renumbered provision. By July, the Irish Presidency described a different settlement: the reference compromise no longer included the proposed centralised and automated cookie-consent provision, but it did include an extended whitelist under ePrivacy Article 5(3). Ireland asked governments for views on that list and the wording of each purpose.

The removal of browser consent therefore should not be reported as removal of every cookie amendment. Equally, the July note does not show that Ireland proposed restoring mandatory browser-level consent. It reopens discussion of the exemption architecture. These distinctions matter for following the negotiations and for understanding what website operators might eventually gain.

Analytics, fraud prevention and contextual advertising

Third-party audience measurement. The Commission’s own-use wording raises a practical question about services provided by an outside analytics supplier. The May Council approach expressly contemplated a third party acting with or on behalf of the service provider. Its operative exception calls for anonymous, aggregated information; recital 44 further describes restrictions on combining and sharing the data.

Fraud prevention. The May security exception mentions fraud, yet ties the exemption to the security of the interface or terminal equipment. Peter Craddock argues that this wording may fail to cover fraud against the broader service.

The 18 June compromise takes a further step: it strikes the proposed freestanding fraud exception from ePrivacy Article 5(3) and the parallel EUDPR provision. The surviving security clauses refer to technical security and no longer expressly mention fraud. By contrast, François-Xavier Bellamy’s July Amendment 1409 would add a separate GDPR Article 88a exception for detecting, preventing or mitigating fraud and money laundering, and combating terrorist financing. That proposed exception addresses the breadth of activity raised by Craddock’s criticism of May; it belongs to Parliament’s competing amendments to the Commission proposal.

Contextual advertising. The Joint Opinion itself recommended a consent exception for contextual advertising, subject to conditions.

The Council debate predates the July Parliament amendments. In the national comments compiled on 4 June, Denmark questions the removal of an earlier exemption for measuring contextual advertising, referring to the previous Article 5(3)(d). France supports an ePrivacy exemption, and the Czech Republic proposes detailed conditions for contextual advertising, ad-display limitation, audience measurement and audience-fraud prevention. Those conditions recur in Krutílek’s July Amendment 1404, with a different point label and legislative location. This establishes that the wording was already present in a Member State submission before it appeared in the Parliament amendment; it does not establish who originally drafted it or how it passed between participants.

September reporting. MLex reports revised cookie rules and a limited exemption for measuring contextual advertising in the 3 September compromise. That description concerns measurement; it does not establish an exemption for every contextual-advertising operation or the return of browser-level consent. It revisits a subject already debated in Council, but the September text remains unexamined, so its wording and conditions cannot yet be compared with the earlier proposals.

Browser signals create their own policy choices

The Commission’s Article 88b would require interfaces to recognise automated choices and would impose obligations on browser providers outside the SME category. It also includes a media-service-provider exception and a standardisation mechanism. These choices affect which services must accept signals, whose software conveys the user’s decision and how that decision maps onto particular purposes.

Parliament’s amendments span the policy choices

My July update described a spectrum from applying ordinary GDPR rules to expanding or restricting the consent exceptions. The tabled amendments make those alternatives concrete:

  • Ordinary legal bases. Tomas Tobé, Arba Kokalari and Jörgen Warborn’s Amendment 1371 would replace Article 88a(1)’s consent-only wording with processing under the GDPR on an Article 6 basis.
  • An added exception. Ondřej Krutílek’s Amendment 1404 would add contextual advertising, ad-display limitation, audience measurement and audience-fraud prevention. Its conditions exclude processing likely to pose a risk to rights and freedoms, profiling, retention beyond active use and links to past or future activity.
  • Tighter exceptions. Alex Agius Saliba’s Amendment 1382 would require non-consensual access and subsequent processing to be strictly necessary for the listed purposes.

Markéta Gregorová and Damian Boeselager, for the Greens/EFA group, propose a different architecture in Amendments 1365 and 1725. The first deletes GDPR Article 88a; the second replaces the proposed ePrivacy disapplication with rules for terminal-equipment information generally, addressing the personal/non-personal split. Their ePrivacy text permits non-consensual access only where strictly technically and solely necessary for listed purposes, with conditions on audience measurement and security updates. It also provides for single-click refusal, limits repeat requests, bars denial of access over unnecessary storage or access, and applies the Article 88b signal mechanism. Its justification expressly seeks to avoid protecting non-personal information more strongly than personal data.

The automated-choice mechanism is equally contested. Angelika Niebler and Monika Hohlmeier’s Amendment 1444 deletes Article 88b. Markéta Gregorová and Damian Boeselager’s Amendment 1535, for the Greens/EFA group, expands paragraph 6 from non-SME browser providers to providers of browsers, applications and operating systems, adds withdrawal and permits default refusal or objection signals. These are competing tabled amendments to the joint draft report.

Browser competition, smaller providers and media services

Automated consent could make browser and operating-system providers important intermediaries between people and websites. That is an explicit concern in Moratti, Salini and Martusciello’s Amendment 1448, which deletes Article 88b: its justification argues that the mechanism would strengthen dominant undertakings and gatekeepers. This is the amendment’s stated competition concern, rather than an established market effect of the proposal.

Gregorová and Boeselager’s Amendment 1540 responds through access for independent providers. Where a provider covered by paragraph 6 qualifies as a DMA gatekeeper, it must enable structurally and economically independent third parties to convey the individual’s choices. The duty does not require access to browser data or functionality beyond what is necessary to convey those choices. The proposal would therefore retain automated signals while limiting exclusive control over the means of transmitting them.

The SME exception raises a different question: who must supply the choice mechanism? The Commission excludes SME browser providers from paragraph 6’s obligation. Amendment 1535 removes that size qualification as it extends coverage to applications and operating systems. Its scope is broader than a rule aimed only at large browsers or designated gatekeepers. The provider duty should also be distinguished from paragraph 2’s obligation on controllers to respect signals.

The media exception concerns the receiving side. Commission Article 88b(3) exempts media service providers from paragraphs 1 and 2 for the provision of a media service; it does not exempt them from the GDPR generally. Gregorová and Boeselager’s Amendment 1498 deletes that exception, arguing that consent-exempt audience measurement should be distinguished from permission to disregard signals. Salla and colleagues’ Amendment 1505 expands it to all processing by or on behalf of a media service provider connected with providing the service. Her Amendment 1506 separately gives specific consent expressed directly to a controller precedence over a conflicting automated signal.

These alternatives address three distinct decisions: which providers must offer controls, whether independent software can carry the choices, and when a website may depart from a received signal. Each would affect the reach of automated consent even if the underlying device-access exceptions were unchanged.

My published assessment

In Europe is not “so back”, I argued that the November proposal would leave banners in place, both because it retained consent rules for non-personal information and because privacy enforcers would interpret the analytics and security exemptions narrowly. My examples included standard third-party analytics and advertising-fraud prevention. Those were predictions about the November proposal and its enforcement, not an assessment of September’s wording.

My earlier response to the leaked text called for any terminal-integrity protection to target specific risks more precisely. I also gave reasons to retain targeted protections, including device security and protection against state-mandated incursions.

The July update described Ireland as reopening discussion of the consent whitelist, while noting uncertainty about browser-level consent. The July primary document discussed above confirms the distinction between those two issues; the September report records a further negotiating stage.

Scientific research and commercial R&D

A definition controls access to several kinds of flexibility

The proposed definition of scientific research has consequences across the GDPR: purpose compatibility, storage, information duties and some restrictions on individual rights. The associated safeguards, particularly Article 89(1), remain part of the framework.

The Commission’s definition expressly includes research that can support innovation and acknowledges that it may further a commercial interest. It also requires a contribution to knowledge or novel application of knowledge, the aim of contributing to society’s general knowledge and wellbeing, and adherence to ethical standards. Treating it as an unrestricted exemption for anything called product development would omit those conditions.

The disagreement is about the qualifying criteria

The EDPB and EDPS welcome a definition but recommend placing methodological standards, autonomy and independence, and verifiable and transparent results in the operative text. They regard support for innovation and commercial interest as context rather than useful criteria for distinguishing scientific research. Their reasons include the risk of excluding genuine humanities or social-science research that does not fit an innovation-based description.

The May Council compromise follows that direction. It moves the commercial and innovation language into recital 28 while using autonomy, independence, methodology and verifiable results in the definition. That does not establish a blanket exclusion of commercial research: the recital still contemplates it. It does create a question about how proprietary and collaborative research will satisfy the operative conditions.

Mark Leiser’s criticism is that those criteria may fit private R&D and public–private collaborations poorly, producing classification uncertainty rather than a clear ban. A pharmaceutical sponsor and an independent academic laboratory can both conduct rigorous research, but their funding arrangements, control over publication and commercial objectives differ. If “independence” is left undefined, the qualification may depend on a regulator’s view of those arrangements rather than on the quality of the research method.

June clarification and Parliament’s alternatives

The Council’s 18 June recital 28 expressly says that autonomy and independence do not exclude research mandated and conducted by public authorities or private entities, including SMEs, in academic, industrial or other settings. Outcomes may serve public, private or commercial purposes. The same recital requires controllers to assess and substantiate scientific-research status case by case from the activity’s objective characteristics, with Article 89 safeguards. This clarifies the intended inclusion of private research in a recital while retaining the need to meet the qualifying criteria.

The joint rapporteurs’ July amendments take different approaches to Article 4(38):

  • Kaljurand and colleagues’ Amendment 965 requires autonomous and independent research, a methodological and systematic approach, recognised ethical and scientific standards, and evidence-based, testable, transparent and published results. Its stated aims concern public knowledge, the public interest or serving humanity; it omits the Commission’s express commercial-interest clause.
  • Salla and colleagues’ Amendment 970 defines creative and systematic work to increase knowledge, covering both foundational research without a particular application in view and investigation directed at a practical objective. It retains an express allowance for commercial interest and does not include an autonomy or independence criterion.

Other amendments address the uncertainty identified by Leiser more directly. Alex Agius Saliba’s Amendment 961 qualifies independence with a requirement that research not be subject to undue external influence, alongside methodological, ethical, results and public-knowledge criteria. It also allows subsequent commercial interests. Piotr Müller’s IMCO Amendment 351 retains the Commission’s conditions and adds that private funding, research within a commercial undertaking or later commercial use do not, by themselves, remove an activity’s scientific character. These are different proposed ways of specifying research eligibility; Müller’s amendment belongs to IMCO’s draft-opinion procedure.

Compatibility and a lawful basis are different questions

The Commission would make research further processing compatible with the initial purposes independently of Article 6(4)’s compatibility conditions, subject to Article 89(1). The June Council text retains that approach and expressly refers to appropriate safeguards. This addresses whether an existing dataset may be used for a new research purpose; it does not itself supply every condition for lawful processing.

The Joint Opinion asks for clearer treatment of the relationship between compatibility and the original legal basis. Niebler and Hohlmeier’s Amendment 1008 makes the intended consequence express: compatible further processing may rely on the initial legal basis without a separate one. That proposal concerns reuse of a basis, rather than a freestanding research exemption from the GDPR.

There is also disagreement over expressly recognising legitimate interests for research. Commission recital 32 does so, and the Joint Opinion supports that clarification subject to the other GDPR conditions. Kaljurand and colleagues’ Amendment 283 removes the recital’s express recognition while retaining balancing and Article 89 safeguards. Deleting that recital language would not itself delete Article 6(1)(f).

Research notices: an exemption with its own boundaries

The proposed Article 13(5) would excuse individual information where providing it proves impossible, involves disproportionate effort under Article 89(1)’s conditions and safeguards, or would render the research impossible or seriously impair it. Appropriate protections, including making information publicly available, remain required. Recital 37 explains the difficulty of contacting people when later research was not anticipated at collection.

June relocates this exception to Article 13(6) and confines it to further research processing by the same controller, where and insofar as the conditions are met. That is a narrower operative scope than the Commission’s reference to processing for research purposes generally.

The July alternatives illustrate why the definition alone cannot resolve research eligibility. Barrena Arza’s Amendment 1118 deletes the proposed research notice exception. Joveva and colleagues’ Amendment 1122 retains a qualified exception for further processing, but excludes commercial product development, advertising, marketing, profiling and training models for commercial deployment. It also addresses inability reasonably to obtain contact details, documentation of reliance on the exception, public information and informing individuals once the conditions cease. An activity could therefore qualify as scientific research yet remain outside this particular notice exemption.

Breach reporting and practical compliance

Breach notification: threshold, time and destination

The Commission proposes notifying supervisory authorities of breaches likely to result in high risk, within 96 hours of awareness where feasible and without undue delay. Compared with the existing Article 33 threshold and 72-hour period, this would reduce the class of notifiable breaches and extend the outer reporting period. The obligation to document breaches remains; the proposal does not turn 96 hours into a waiting period.

The EDPB and EDPS support the higher threshold and longer period. The June Council text and joint rapporteurs’ draft retain both. Agreement on those two elements, however, does not establish an adopted Parliament position: Kaljurand and colleagues’ Amendment 1183 returns to an ordinary-risk threshold and 72 hours.

The reporting channel is a separate choice. The Commission routes notification through the proposed NIS2 single-entry point, with direct reporting to the competent supervisory authority until it is established. June substitutes a national entry point under proposed NIS2 Article 23b and preserves that transitional route. The competent data-protection authority remains the destination. A common submission channel does not by itself align the triggers, deadlines or content of every reporting obligation; the Joint Opinion calls for clarity about how the regimes interact.

Common lists and templates: who determines their content?

Under the Commission proposal, the EDPB would prepare a common breach-notification template and a list of circumstances likely to create high risk. The Commission could adopt these by implementing act. June instead has the EDPB establish and publish the template and lists covering both high-risk and non-high-risk circumstances; the Commission may adopt the template by implementing act. The joint draft makes the same distinction between EDPB materials and an optional Commission act for the template.

For data protection impact assessments (DPIAs), the Commission proposes common lists of operations requiring and not requiring an assessment, together with a common template and methodology. The EDPB would propose the materials and the Commission could adopt them by implementing act. Existing national lists would remain valid until that act.

June gives the EDPB responsibility for establishing the lists, template and methodology within the specified nine-month period and reviewing them at least every three years. National lists remain until the EDPB establishes the replacements. The Commission’s optional implementing role is confined to the template, excluding the lists and methodology. The joint draft follows this allocation.

July Amendment 1221, tabled by Gregorová, offers another instrument: a Commission decision giving general validity to the EDPB’s lists, template and methodology. This goes beyond June’s template-only Commission role.

For a controller operating across Member States, common lists could reduce the need to reconcile different national requirements. But a template governs the form of an assessment, while lists govern which processing requires one. Describing all of these changes as standardised paperwork would miss the allocation of authority over substantive risk judgments. The enforcement section examines the related dispute over pseudonymisation criteria and their legal effect.

Other targeted changes

The June text removes the requirement to communicate a DPO’s contact details to the supervisory authority, while retaining publication of those details. Ireland identifies this among the inherited simplifications in its July note.

The Commission’s separate biometric-verification derogation is conditional on the individual’s sole control of the biometric data or the means needed for verification. The Joint Opinion welcomes its direction but recommends attention to less intrusive alternatives. That conditional permission should not be read as covering biometric identification generally.

Binding criteria and accountable enforcement

Criteria need a defined legal effect

The Commission’s proposed Article 41a would allow it to adopt implementing acts specifying when pseudonymised data is no longer personal for particular entities. The EDPB would be closely involved and give an opinion on the draft; Member States would participate through the examination procedure. This is a different allocation of responsibility from relying on EDPB guidance alone.

The Commission’s proposal gives compliance a limited evidential role. Paragraph 3 says that compliance with the criteria may be used as an element demonstrating that data cannot lead to reidentification. It does not expressly make compliance conclusive, create general immunity from enforcement or prescribe a rebuttable presumption.

The Joint Opinion asks whether compliance would create a rebuttable presumption or merely supply one factor among others, and recommends deleting Article 41a.

In my July update, I argued for strengthening Commission implementing powers so that following the resulting guidance can create strong legal presumptions of lawful behaviour.

Piotr Müller’s Amendment 398 takes a step in that direction. It would replace Article 41a(3)’s evidential rule with a presumption that data will not lead to reidentification where the implementing act’s means and criteria are implemented. Its justification calls this a rebuttable presumption of compliance, but the operative text states a presumption about non-reidentification, not compliance with the GDPR generally. This is an amendment tabled to IMCO’s draft opinion, separate from the joint ITRE–LIBE lead-committee procedure.

The Council chose a different instrument. The May compromise replaced Article 41a with Article 29a; the June text combines an operative provision on the entity-relative effect of pseudonymisation with an EDPB opinion procedure. It excludes processors from that entity-relative provision and deletes the Commission implementing-act machinery.

Expertise and institutional responsibility

The EDPB and EDPS oppose Article 41a partly because the criteria affect the reach of data-protection law and, in their view, should remain within the framework of the independent supervisory authorities.

The Commission’s proposal provides for EDPB participation while assigning adoption of the implementing act to the Commission.

In A serious target for improving EU regulation: GDPR enforcement, I argued that the enforcement structure favours privacy-maximalist interpretations and leaves insufficient room for other rights and economic interests. I proposed an independent, multidisciplinary tribunal with binding decision-making and fining powers.

My July update acknowledged the EDPB’s acceptance of entity-relative anonymity but argued that its qualifications made the guidance operationally difficult to use. I treated this as evidence of an institutional inability to provide the practical guidance needed, and argued for Commission powers capable of producing guidance with legal force. The guideline provisions themselves are described in the personal-data section.

Parliament’s draft requires a more precise account

The joint draft’s compliance amendments concern Articles 33, 35 and 70, as discussed in the practical-compliance section; they leave Article 41a unchanged. The July amendments then expose the dispute directly: Amendment 1244, tabled by Marina Kaljurand and colleagues, deletes Article 41a, while Ondřej Krutílek’s Amendment 1255 retains Commission implementing acts and clarifies non-personal status for entities not reasonably likely to identify the person. These are competing tabled proposals, alongside Müller’s distinct IMCO proposal, rather than a settled Parliament position.

Salla co-signs Amendment 1289 with Oliver Schenk and colleagues. It retains the rule that implementing the criteria may be used as an evidential element, adding references to technical and organisational measures and non-reidentification in a specific case. It therefore differs both from Kaljurand’s deletion and from Müller’s proposed presumption.

Francesco Torselli’s Amendment 1287 proposes a stronger legal consequence for a narrower setting: within a group of undertakings, pseudonymised data would cease to constitute personal data for an undertaking meeting specified conditions. Binding arrangements and effective technical and organisational measures must prevent access, or reasonably likely access, to identifying information held elsewhere in the group, prohibit reidentification attempts and rule out other reasonably likely identification means. The undertaking must demonstrate that those arrangements and measures work. This is a conditional rule about personal-data status, distinct from an evidential presumption.

My broader enforcement proposal

In my February 2025 essay, I proposed keeping investigation with DPAs while assigning consequential and cross-border decisions to an independent EU tribunal. Its proposed membership would include economists, business experts and generalist judges. Decisions would explicitly balance data protection with other rights and interests; I also proposed review of EDPB guidance and opinions.

In GDPR reform: what should it achieve, I reiterated that an agenda focused on recordkeeping would miss the structural enforcement problem. These institutional proposals form part of my published reform agenda. They are not presented here as amendments agreed or tabled in the Digital Omnibus.

Legislative timeline

  1. Commission publishes the Data/Digital Omnibus proposal

    COM(2025)837 supplies the baseline for the GDPR and ePrivacy reforms examined here. The separate AI Omnibus has a different proposal number and is outside this comparison.

  2. Cyprus circulates early discussion material

    WK 250/2026 prepares the 16 January discussion, including questions about the personal-data definition and the proposed implementing power. It records issues for negotiation rather than an agreed text.

  3. EDPB and EDPS announce their Joint Opinion

    The authorities welcome parts of the simplification agenda but oppose the personal-data definition change and Article 41a. Their positions provide a substantive institutional response to the Commission proposal.

  4. A revised Council compromise changes the reform’s instruments

    The Presidency text supplies the detailed May comparison in this dossier. It recasts personal-data clarification, pseudonymisation criteria and AI legitimate interest. A contemporary public MLex summary describes disagreement among countries over pseudonymised data, AI and cookies; the full subscription article is not relied on.

  5. Member State comments are compiled

    WK 7876/2026 compiles national comments on the revised compromise. Denmark objects to removal of an earlier contextual-advertising measurement exception; France supports an exemption; Czech proposed conditions later recur in Parliament Amendment 1404. These are Member State submissions rather than an agreed Council text.

  6. Cyprus circulates another revised compromise

    ST 10426/26 is prepared for the 15 June Antici Group meeting. It becomes the previous text identified on the cover of the subsequent 18 June compromise.

  7. The later Cyprus reference text is issued

    ST 10677/26 follows the 15 June meeting and anticipates Coreper consideration on 26 June. Article 29a recognises the entity-relative effect of pseudonymisation, excludes processors from that provision and requires an EDPB opinion. Express fraud exceptions are struck from ePrivacy and the parallel EUDPR provision. Ireland later names this compromise as its reference.

  8. Parliament’s joint rapporteurs issue their draft report

    Aura Salla and Marina Kaljurand’s PE786.818 contains amendments 1–78. It is the starting point for further amendments and committee work, not an adopted Parliament position.

  9. The planned Council mandate vote is postponed — reported

    26 June was the intended Coreper date stated in ST 10677/26. Ellen O’Regan’s public LinkedIn summary for POLITICO reported that the vote had been removed after Germany gathered support for postponement, with discussion to continue under Ireland. This entry dates the planned meeting, not the reporter’s post or the decision to remove the item.

  10. EDPB adopts draft anonymisation guidance for consultation

    Version 1.0 of Guidelines 02/2026 accepts that anonymity can depend on the entity’s perspective and sets out important conditions. The guidance informs the legislative debate; it does not enact the proposed GDPR amendments.

  11. Ireland asks governments whether the compromise delivers enough

    WK 10233/2026 prepares the 16 July discussion. It asks about pseudonymisation, AI, compliance and ePrivacy exemptions, while expressly using ST 10677/26 as the reference text. These are questions to delegations, not a new negotiated settlement.

  12. Müller proposes a stronger non-reidentification presumption

    Amendment 398 to the IMCO draft opinion would make non-reidentification presumed where the Commission implementing act’s means and criteria are implemented. IMCO has opinion competence; the amendment is separate from the joint lead-committee report.

  13. Tabled Parliament amendments expose competing approaches

    The joint ITRE–LIBE amendment series runs from 79 to 1840, following draft-report amendments 1–78. Selected operative amendments propose deletion, qualified retention or expansion on personal data, individual rights, scientific research, AI, cookies, practical compliance and Commission implementing powers. Kaljurand and Salla table contrasting definitions of scientific research. The issue sections examine these alternatives.

  14. New Presidency compromise — document date reported by MLex

    MLex’s 7 September report dates the compromise to 3 September and describes changes on pseudonymisation, AI legitimate interest and cookies, including contextual-advertising measurement. The official meeting notice identifies the revised compromise as ST 12535/26; its text has not been inspected here.

  15. Explanatory note accompanies the compromise — reported

    The excerpt of Tar’s report available to me dates the accompanying explanatory note to 4 September and says it requests written comments by 15 September. CM 3890/26 identifies the explanatory note as WK 13065/26, without reproducing it.

  16. Antici discussion of the revised compromise — scheduled

    CM 3890/26 schedules an exchange of views based on the Presidency revised compromise. As of 8 September, this is an upcoming meeting, not a completed discussion or Council agreement.

  17. Written comments requested — reported deadline

    Tar’s report says the explanatory note requests Member State comments by 15 September. This is a reported negotiating deadline, not a deadline for businesses or evidence that comments have been submitted.

Evidence coverage

The Commission proposal supplies the legislative baseline. The 21 May Council text supports the detailed comparison of several provisions. The 18 June text was checked against the original PDF, including its insertions and deletions, for recital 28 on scientific research (pp. 20–21), recital 38 on automated decisions (p. 29), research further processing, rights and compliance provisions (pp. 107–114), Article 29a (pp. 115–116), and the EUDPR and ePrivacy fraud exceptions (pp. 127 and 130).

Ireland’s July discussion note names the June compromise as its reference and reopens substantive questions. It independently records Article 29a, the replacement of Article 88c with a recital, and the omission of centralised and automated consent alongside retention of ePrivacy exemptions.

The full joint ITRE–LIBE draft report and tabled-amendment series, numbered 1–1840, were consulted, together with relevant IMCO and JURI material. This dossier examines selected operative amendments on Articles 4(1), 4(38), 5, 9, 12, 13, 22, 33, 35, 41a, 88a, 88b and 88c, and the corresponding ePrivacy alternatives, alongside recital amendments and the June joint draft. It also examines Müller’s IMCO Amendments 351 and 398. The documents consulted are broader than the textual assessment: the examples establish the available alternatives, without classifying every amendment or anticipating the committee compromise.

National comments compiled on 4 June establish the earlier Council discussion of contextual advertising and contain the Czech conditions later found in Parliament AM1404. Matching wording establishes a documented sequence, without establishing authorship or transmission.

The timeline uses official documents where available. The POLITICO item and May MLex item are journalists’ public LinkedIn summaries. September coverage uses the public preview of Júlia Tar’s 7 September MLex report and the further excerpt available to me; the full subscription article was not inspected. The official meeting agenda identifies ST 12535/26 and WK 13065/26 and schedules 11 September discussion. The September reporting was checked on 8 September; this revision extends selected June and July primary-text analysis.

The September compromise and explanatory note remain the principal missing primary texts. Other limitations include the unreviewed June provisions, parliamentary amendments outside the selected examples, and research alternatives beyond those identified in the issue section. The reported national coalition and July amendment deadline are carried from my July essay, without independent verification from national submissions or a deadline notice here.

Sources

My publications

  1. A serious target for improving EU regulation: GDPR enforcement

    Mikołaj Barczentewicz · EUTechReg essay · 27 February 2025

    https://eutechreg.com/p/a-serious-target-for-improving-eu

    My broader institutional reform proposal. It is not a description of amendments agreed or tabled in this legislative file.

  2. GDPR reform: what should it achieve

    Mikołaj Barczentewicz · EUTechReg essay · 1 April 2025

    https://eutechreg.com/p/gdpr-reform-what-should-it-achieve

    Early reform objectives, definitions and enforcement.

  3. Leaked GDPR reform: some good ideas but what about enforcement?

    Mikołaj Barczentewicz · EUTechReg essay · 9 November 2025

    https://eutechreg.com/p/leaked-gdpr-reform-some-good-ideas

    Commentary on the leaked draft, before the official 19 November proposal.

  4. GDPR reform alive again? July update

    Mikołaj Barczentewicz · EUTechReg essay · 30 July 2026

    https://eutechreg.com/p/gdpr-reform-alive-again-july-update

    The July public assessment. The dossier uses newly acquired Council documents to refine the chronology and the distinction between browser consent and ePrivacy exemptions.

Legislation

  1. Digital Omnibus proposal, COM(2025)837 final — procedure 2025/0360(COD)

    European Commission · Legislative proposal · 19 November 2025

    https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=COM:2025:837:FIN

    The main Data/Digital Omnibus proposal. Distinct from COM(2025)836 on the AI Act and from the accompanying staff working document. GDPR amendments are in Article 3; ePrivacy amendments in Article 5.

  2. WK 250/2026 INIT — Digital Omnibus Presidency discussion material

    Council of the European Union · Presidency discussion document · 9 January 2026

    https://data.consilium.europa.eu/doc/document/WK-250-2026-INIT/en/pdf

    Early discussion material for the 16 January Antici Group meeting, not a Council mandate.

  3. ST 9547/26 — Presidency revised compromise text on the Digital Omnibus

    Council of the European Union · Presidency compromise text · 21 May 2026

    https://data.consilium.europa.eu/doc/document/ST-9547-2026-INIT/en/pdf

    LIMITE text for the 27 May Antici Group meeting. Draft, not an agreed Council position. The marked insertions and deletions in the official PDF were consulted. The comparison covers selected provisions rather than the whole text.

  4. WK 7876/2026 INIT — Member State comments on the revised Digital Omnibus compromise

    Council of the European Union · Member State comments · 4 June 2026

    https://data.consilium.europa.eu/doc/document/WK-7876-2026-INIT/en/pdf

    Inspected as an official-PDF text extraction. Comments are negotiating input, not a common Council position.

  5. ST 10426/26 — Presidency revised compromise text on the Digital Omnibus

    Council of the European Union · Presidency compromise text · 10 June 2026

    https://data.consilium.europa.eu/doc/document/ST-10426-2026-INIT/en/pdf

    LIMITE text for the 15 June Antici Group meeting. Inspected as extracted text from the official PDF. Formatting and tracked changes require checking against the original.

  6. ST 10677/26 — Presidency revised compromise text on the Digital Omnibus

    Council of the European Union · Presidency compromise text · 18 June 2026

    https://data.consilium.europa.eu/doc/document/ST-10677-2026-INIT/en/pdf

    The cover announces a Coreper package for 22 June and intended consideration on 26 June. Ireland subsequently names this 18 June text as its reference. Selected tracked passages were checked against the original PDF: recitals 28 and 38 (pp. 20–21 and 29), research, rights and compliance provisions (pp. 107–114), Article 29a (pp. 115–116), and the EUDPR and ePrivacy fraud exceptions (pp. 127 and 130).

  7. Joint ITRE–LIBE draft report, PE786.818v01-00, on COM(2025)837

    European Parliament — Aura Salla and Marina Kaljurand · Rapporteurs’ draft report · 22 June 2026

    https://www.europarl.europa.eu/doceo/document/CJ72-PR-786818_EN.pdf

    Contains rapporteur amendments 1–78. It is not an adopted committee report or Parliament position. GDPR Article 41a must be distinguished from similarly numbered amendments to other instruments.

  8. WK 10233/2026 INIT — Presidency Discussion Note on Omnibus VII (Digital)

    Irish Presidency / Council of the European Union · Presidency discussion note · 9 July 2026

    https://data.consilium.europa.eu/doc/document/WK-10233-2026-INIT/en/pdf

    For the 16 July Antici Group meeting. Sections 1–4 ask about pseudonymisation, AI, compliance and ePrivacy exemptions. This is the Irish questionnaire, not a revised compromise or mandate. Inspected as official-PDF extracted text.

  9. IMCO tabled amendments 329–532, PE791.061v01-00

    European Parliament — Committee on the Internal Market and Consumer Protection · Tabled amendments to draft opinion · 16 July 2026

    https://www.europarl.europa.eu/doceo/document/IMCO-AM-791061_EN.pdf

    Piotr Müller’s Amendments 351 (pp. 16–17) and 398 (p. 46) are analysed. IMCO has opinion competence; this document is separate from the joint ITRE–LIBE report.

  10. CJ72 tabled amendments 79–250, PE786.820v01-00

    European Parliament — joint ITRE–LIBE procedure · Tabled amendments to draft report · 27 July 2026

    https://www.europarl.europa.eu/doceo/document/CJ72-AM-786820_EN.pdf

    Selected recital amendments, particularly 214 and 216, are analysed. These competing amendments are not adopted law or an agreed committee position.

  11. CJ72 tabled amendments 251–400, PE790.967v01-00

    European Parliament — joint ITRE–LIBE procedure · Tabled amendments to draft report · 27 July 2026

    https://www.europarl.europa.eu/doceo/document/CJ72-AM-790967_EN.pdf

    Amendments 275 and 283 are analysed for AI safeguards, technical indications and the research legitimate-interest recital.

  12. CJ72 tabled amendments 401–526, PE790.968v01-00

    European Parliament — joint ITRE–LIBE procedure · Tabled amendments to draft report · 27 July 2026

    https://www.europarl.europa.eu/doceo/document/CJ72-AM-790968_EN.pdf

    Acquired PDF and searchable text. Used for the document sequence and coverage statement; this dossier does not analyse every amendment in the pack.

  13. CJ72 tabled amendments 777–1052, PE791.072v01-00

    European Parliament — joint ITRE–LIBE procedure · Tabled amendments to draft report · 27 July 2026

    https://www.europarl.europa.eu/doceo/document/CJ72-AM-791072_EN.pdf

    Selected operative amendments to Articles 4(1), 4(38), 5(1)(b) and 9 checked against the PDF.

  14. CJ72 tabled amendments 1053–1260, PE791.073v01-00

    European Parliament — joint ITRE–LIBE procedure · Tabled amendments to draft report · 27 July 2026

    https://www.europarl.europa.eu/doceo/document/CJ72-AM-791073_EN.pdf

    Selected amendments to Articles 12, 13, 22, 33 and 35 examined alongside Amendments 1244 and 1255 on Article 41a.

  15. CJ72 tabled amendments 1261–1564, PE791.873v01-00

    European Parliament — joint ITRE–LIBE procedure · Tabled amendments to draft report · 27 July 2026

    https://www.europarl.europa.eu/doceo/document/CJ72-AM-791873_EN.pdf

    Selected operative amendments to Articles 41a, 88a, 88b and 88c checked against the PDF, covering legal effects, exemptions, automated choices, browser competition, media services and deletion.

  16. CJ72 tabled amendments 1565–1740, PE791.874v01-00

    European Parliament — joint ITRE–LIBE procedure · Tabled amendments to draft report · 27 July 2026

    https://www.europarl.europa.eu/doceo/document/CJ72-AM-791874_EN.pdf

    Amendments 1566, 1569, 1577, 1585, 1587 and 1589 checked for Article 88c’s scope and safeguards; Amendment 1725 checked for the ePrivacy alternative.

  17. CJ72 tabled amendments 1741–1840, PE791.883v01-00

    European Parliament — joint ITRE–LIBE procedure · Tabled amendments to draft report · 27 July 2026

    https://www.europarl.europa.eu/doceo/document/CJ72-AM-791883_EN.pdf

    Previously acquired pack. Its numbering is not a count of all tabled amendments: the rapporteurs’ draft report contains amendments 1–78.

  18. CM 3890/26 — Antici Group (Simplification), notice of meeting and provisional agenda

    Council of the European Union · Meeting notice and provisional agenda · 3 September 2026

    https://data.consilium.europa.eu/doc/document/CM-3890-2026-INIT/en/pdf

    Schedules 11 September discussion and identifies ST 12535/26 (revised compromise) and WK 13065/26 (explanatory note), both listed as to be issued. Does not reproduce their substantive wording.

Administrative proceedings

  1. Digital Omnibus: EDPB and EDPS support simplification and competitiveness while raising key concerns

    European Data Protection Board · Publication announcement · 11 February 2026

    https://www.edpb.europa.eu/news/news/2026/digital-omnibus-edpb-and-edps-support-simplification-and-competitiveness-while_en

    Used to establish the public announcement date, rather than infer an adoption date from the converted opinion.

  2. Guidelines 02/2026 on Anonymisation, version 1.0

    European Data Protection Board · Guidelines adopted for public consultation · 7 July 2026

    https://www.edpb.europa.eu/system/files/2026-07/edpb_guidelines_202602_anonymisation_v1_en_0.pdf

    The July consultation version is the version analysed. Paragraph numbers are used for citations. It is guidance, not an amendment to the GDPR.

  3. EDPB–EDPS Joint Opinion 2/2026 on the Digital Omnibus proposal

    European Data Protection Board and European Data Protection Supervisor · Joint opinion

    https://www.edpb.europa.eu/system/files/2026-02/edpb_edps_jointopinion_202602_digitalomnibus_en.pdf

    Published in February 2026; the separate announcement dated 11 February supports the timeline date.

Other sources

  1. When “Scientific Research” Stops Being Scientific

    Mark R Leiser · Legal commentary · 16 February 2026

    https://digidata.substack.com/p/when-scientific-research-stops-being

    Analysis of the proposed research definition and the EDPB–EDPS recommendations, including consequences for commercial and collaborative research.

  2. Council ePrivacy evolutions — public post on the May compromise

    Peter Craddock · Legal commentary on LinkedIn · 26 May 2026

    https://www.linkedin.com/posts/petercraddock_eprivacy-gdpr-dataprotection-share-7465033972763279360-kZRI/

    Critique of the fraud-prevention wording and other May ePrivacy changes.

  3. EU governments revise GDPR pseudonymized data rules in new digital package compromise

    Júlia Tar, MLex · News report · 7 September 2026

    https://www.mlex.com/mlex/articles/2522216/eu-governments-revise-gdpr-pseudonymized-data-rules-in-new-digital-package-compromise

    Public preview retrieved 8 September; I supplied a further excerpt identifying the 4 September note and 15 September deadline. The full subscription article and the September compromise and explanatory note were not inspected. Document dates are reported by MLex; CM 3890/26 independently identifies the documents and meeting.

  4. Key digital omnibus vote gets postponed — public LinkedIn summary

    Ellen O’Regan, POLITICO · Journalist’s public LinkedIn post

    https://www.linkedin.com/posts/ellenoregan_key-digital-omnibus-vote-gets-postponed-activity-7475995453004808193-0SCT

    The public post reports removal of the planned Friday vote and quotes the Cyprus Presidency on continuation under Ireland. The underlying subscription article was not inspected. The timeline uses 26 June as the planned meeting date, established by ST 10677/26.

  5. EU countries divided on Digital Omnibus — public summary concerning national comments

    Júlia Tar, MLex · Journalist’s public LinkedIn post

    https://www.linkedin.com/feed/update/urn:li:activity:7463644751062446082/

    The public post describes division over pseudonymised data, AI and cookies. The underlying MLex article was not inspected, and the post's approximate date is not used as an event date.