EU Digital Omnibus Sparks Privacy Backlash Over AI Data Access
The EU's Digital Omnibus amends GDPR to ease AI access to personal data, drawing criticism.
Why it matters: Legal teams must navigate evolving EU data privacy rules amid AI innovation pressures, preparing for increased compliance risks and potential disputes.
- Digital Omnibus released on 19 November 2025 introduces GDPR amendments favoring AI data use.
- Personal data may be lawfully used for AI without explicit consent under the new rules.
- Privacy advocate Max Schrems warns this enables 'digital expropriation' by AI companies.
- European Data Protection Board and Supervisor oppose narrowing personal data definition and other key changes.
- High-risk AI Act compliance postponed until December 2027 to ease implementation pressures.
- A single EU interface for cybersecurity and data breach reporting aims to reduce company burdens.
On 19 November 2025, the European Commission unveiled the Digital Omnibus, a legislative package intended to modernize EU digital regulations by amending the GDPR and AI Act. This initiative aims to facilitate AI innovation by easing restrictions on personal data use in AI contexts, potentially allowing companies to access European users' data without requiring explicit consent. The Irish Times reports this could mark a significant shift in data privacy.
Privacy advocates have voiced strong opposition. Max Schrems warned that "everything we have ever entered into digital systems... becomes fair game for AI corporations to use," characterizing the proposal as a "digital expropriation." This critique highlights concerns about unprecedented AI access to personal data without sufficient safeguards.
Adding to the pushback, the European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) issued Joint Opinion 2/2026 on 11 February 2026, opposing the proposed narrowing of the definition of personal data and questioning the necessity of several Digital Omnibus reforms. Their joint stance emphasizes risks to established data protection safeguards. NoYB details these objections.
Alongside privacy adjustments, the Digital Omnibus also introduces a streamlined single EU reporting interface for cybersecurity and personal data breach notifications. This intends to reduce administrative burdens for companies by centralizing reporting requirements, as noted by Baker McKenzie.
Furthermore, the EU has deferred obligations for high-risk AI systems under the AI Act until December 2027, with extensions for particular sectors. This reprieve aims to give organizations more time to comply amid the regulatory transformation. Orrick provides an in-depth analysis of these compliance timelines.
For legal teams, these evolving rules require careful monitoring to adjust compliance strategies and manage potential legal challenges linked to AI data usage and privacy rights in the EU.
By the numbers:
- 19 November 2025 — Date Digital Omnibus legislative package was released.
- December 2027 — Deadline for mandatory compliance with high-risk AI obligations under AI Act.
- 11 February 2026 — Date of the EDPB and EDPS Joint Opinion 2/2026 opposing GDPR changes.
Yes, but: While the Digital Omnibus seeks to foster AI innovation by reducing compliance burdens, authorities warn that weakening data protections risks undermining privacy rights and trust.
What's next: Legal professionals should track final legislative adoption details and monitor further guidance or amendments from EU data protection authorities.