For most of its life, GDPR has been treated as a fixed target: a set of rules published in 2016, applied from 2018, and amended only at the margins since. That's now changing โ just not as cleanly as the European Commission originally hoped. In November 2025, the Commission published its Digital Omnibus package, proposing the most substantial set of amendments to GDPR since the regulation took effect. Three changes matter most: a much wider exemption from formal record-keeping, a redesigned cookie banner with a one-click reject option, and new language confirming legitimate interest can support AI processing.
None of it is law yet, and as of August 2026, the three proposals are no longer moving at the same speed. The record-keeping exemption has institutional backing and is the part most likely to survive intact. The cookie banner redesign and the AI legitimate-interest clarification hit a wall in the Council in June 2026 and were dropped from the working text member states were negotiating โ not killed, but stalled, with their fate now sitting with a Parliament that isn't expected to finish its own position until an October 2026 impact study lands. Here's what's actually on the table, what's stuck, and what to do about it in the meantime.
Why the Commission Is Doing This Now
The Digital Omnibus didn't emerge in a vacuum. Since 2018, a persistent complaint from businesses โ particularly mid-sized and growing companies โ has been that GDPR's compliance burden scales unevenly. A company with 240 employees enjoys meaningful exemptions from formal record-keeping requirements; the same company at 260 employees does not, despite being only marginally larger. The Commission has described this as a "cliff edge" problem: businesses hit a wall of new obligations right at the moment they're trying to scale.
At the same time, the Commission has faced pressure from a different direction: complaints that cookie consent banners have become so manipulative โ designed to make "accept all" the path of least resistance โ that they've stopped functioning as genuine consent mechanisms. And overlaying both concerns is the rise of AI, which has forced regulators to clarify how legitimate interest, one of GDPR's six lawful bases for processing, applies to a category of processing that barely existed when the regulation was drafted.
The Digital Omnibus tries to address all three at once. It's actually two draft regulations: a general "Digital Omnibus" amending GDPR, the ePrivacy Directive, NIS2 and the Data Act (sometimes called the "Data Omnibus" in legal commentary), and a separate "Digital Omnibus on AI" focused on the EU AI Act. That distinction matters for the timeline โ the AI Act half has already cleared the Council and Parliament and takes legal effect on Official Journal publication, expected in mid-2026. The GDPR half has not, and is the subject of this article.
Expanding the Records of Processing Exemption
Under current GDPR rules, Article 30 requires most organizations to maintain detailed records of their processing activities โ what personal data they collect, why, how long they keep it, and what security measures are in place. Article 30(5) provides a narrow exemption for organizations with fewer than 250 employees, provided their processing doesn't meet certain risk conditions, including any processing of special category data.
The Digital Omnibus would expand this considerably, in two ways. First, the employee threshold would rise from fewer than 250 to fewer than 750 โ provided the organization also stays under financial ceilings of โฌ150 million in annual turnover or โฌ129 million on the balance sheet. A great many mid-sized companies that currently must maintain full Article 30 documentation would, under the new threshold, qualify for the lighter-touch regime.
Second, the proposal changes what disqualifies an organization from the exemption in the first place. Today, any processing of special category data โ health information, biometric data, data revealing political opinions or religious beliefs โ automatically excludes an organization, regardless of actual risk. The Digital Omnibus would replace that blanket exclusion with a risk-based standard: the exemption would only be unavailable where processing is "likely to result in a high risk" to individuals โ the same threshold that already triggers a Data Protection Impact Assessment under Article 35.
It's worth being precise about what this does and doesn't change. It reduces documentation burden; it doesn't reduce underlying obligations around lawful processing, data subject rights, or security. Organizations that fall under the expanded exemption will still need to run a DPIA where required โ the risk assessment used to determine exemption eligibility is itself a DPIA-adjacent exercise. This is the one piece of the Digital Omnibus that has clear institutional support: the European Data Protection Board and European Data Protection Supervisor welcomed the record-keeping simplification in a joint opinion as early as July 2025, and reaffirmed broad support for it โ while raising other concerns, including around the Omnibus's proposed narrowing of the definition of personal data โ in a fuller joint opinion on the whole package published in February 2026.
Editable DPA pack, SAR response toolkit, and Article 30 RoPA register โ the documents regulators actually ask for first. โฌ39โโฌ59 each or โฌ99 for all three, instant download.
The Cookie Banner Redesign โ and Why It Just Stalled
The second strand of the Digital Omnibus addresses one of the most criticized features of the current GDPR landscape. As originally proposed, it would have required websites to let users reject all non-essential cookies in a single click, directly on the first layer of the banner, with that reject option given equal visual prominence to accept โ closing the long-standing loophole where "accept all" is one button and "reject" means navigating into a settings panel and unchecking toggles one by one.
The original proposal went further still: exempting low-risk cookie categories from needing a consent banner at all โ internal audience measurement, cookies necessary to deliver a service the user explicitly requested, security and fraud-prevention cookies โ and introducing "automated and machine-readable" browser-level signals, so a user could set tracking preferences once and have sites respect that signal automatically. Where consent was still asked for and given, sites would have had to honor that choice for at least six months before asking again.
In the Council's June 10, 2026 compromise text, the articles carrying the one-click reject button and the browser-signal mechanism were deleted outright, after member states' ambassadors failed to agree on them two days earlier. Even that pared-back compromise didn't get the qualified majority it needed and was pulled from formal approval at the end of June.
That doesn't mean cookie banner design is now a free-for-all. Separately from the Digital Omnibus, existing GDPR enforcement guidance already treats an "accept all" button that's easier to find or click than "reject" as a dark pattern โ a design flaw regulators pursue under the rules as they stand today, with or without the Omnibus. What's actually stuck in Brussels is the specific mechanism (single click, browser-level signals, the low-risk exemptions) โ not the underlying expectation that reject has to be genuinely as easy as accept.
Legitimate Interest and AI Processing โ Also Stalled
The third element speaks to one of the most contested questions in current data protection practice: can legitimate interest, as a lawful basis under Article 6, support processing personal data to train or operate AI systems? Today, organizations relying on legitimate interest for AI processing operate with a degree of ambiguity โ running their own balancing tests without explicit GDPR language confirming the approach is sound.
The Digital Omnibus, as originally drafted, would have added language explicitly recognizing that legitimate interest can support AI processing โ conditionally, not unconditionally. The existing safeguards that make legitimate interest valid in any context โ necessity, proportionality, a genuine balancing test against individuals' rights, transparency, and an unconditional right to object โ would still have to be genuinely intact. It was framed as a clarification of scope, not a loosening of the standard.
That clarifying language was one of the provisions removed alongside the cookie articles in the Council's June 2026 compromise text. The practical effect for now: organizations still don't have an explicit GDPR provision confirming that legitimate interest covers AI processing. The underlying legal position hasn't changed โ Article 6(1)(f) already applies if the balancing test is genuinely done and documented โ but the hoped-for regulatory confirmation is no closer than it was in November 2025.
Where Things Actually Stand, in Order
- November 2025 โ European Commission publishes the Digital Omnibus proposal, covering GDPR, ePrivacy, NIS2, and the Data Act.
- February 2026 โ EDPB and EDPS issue their joint opinion on the full package: broadly supportive of the record-keeping simplification, while raising concerns elsewhere, including the proposed narrower definition of personal data.
- June 8โ10, 2026 โ Council ambassadors fail to agree on the cookie consent and AI legitimate-interest provisions; the presidency's compromise text deletes those articles outright.
- Late June 2026 โ Even the pared-back compromise text is withdrawn from formal Council approval, short of a qualified majority.
- Now (August 2026) โ The European Parliament is still finalizing its own position, with an impact study expected in October 2026. Final adoption of the GDPR-related half of the package isn't expected before late 2026 at the earliest โ meaning real implementation is more plausibly a 2027 story, and could stretch further depending on what Parliament and Council still need to reconcile.
Meanwhile, the AI Act half of the Digital Omnibus package โ a separate proposal, unrelated to the legitimate-interest question above โ has already cleared both the Council and Parliament and takes effect on Official Journal publication. It's easy to conflate the two halves of the Digital Omnibus; only one of them has actually landed.
Preparing Now for Rules That Aren't Final
That uncertainty isn't a reason to wait, but it is a reason to be selective about where you spend effort.
- Track the RoPA threshold, but don't act on it yet. If your organization sits between 250 and 750 employees, the expanded exemption could materially change your compliance workload โ but the threshold, and the financial ceilings attached to it, are still subject to negotiation. Know where you'd land, and hold your current Article 30 records in good order until the final text is settled.
- Don't redesign your cookie banner around a mechanism that's currently deleted from the negotiating text. Building a single-click reject flow around a specific article that Council members couldn't agree on in June is premature. What isn't premature: making sure your existing "reject" option is genuinely as easy to find and click as "accept" โ that's an enforcement expectation under GDPR today, independent of the Omnibus.
- Keep documenting your legitimate-interest balancing tests for AI processing as if the clarification isn't coming soon โ because it currently isn't. The safeguards (necessity, proportionality, a real balancing assessment, transparency, the right to object) are what make legitimate interest defensible now, with or without an explicit AI provision in the text.
- Revisit this in October 2026, when Parliament's impact study is due and its own negotiating position should start to firm up. That's the next point at which the shape of the final text โ rather than the November 2025 proposal โ becomes clearer.
The Bottom Line
The Digital Omnibus is still a genuine attempt to fix three real problems with GDPR as it currently works โ but as of August 2026, it's moving at three different speeds. The record-keeping simplification has EDPB and EDPS backing and is the piece most likely to become law close to its current form. The cookie banner redesign and the AI legitimate-interest clarification are both stuck, pulled from the Council's working text after member states couldn't agree, with Parliament's own position not expected until October. Treat the RoPA exemption as worth watching closely, and treat the other two as background noise until there's a text to actually react to.
Book a free consultation with GDPRGard โ
Sources
- EDPB โ Digital Omnibus: EDPB and EDPS support simplification and competitiveness while raising key concerns (Feb 2026)
- EDPB โ Targeted modifications of the GDPR: record-keeping simplification (July 2025)
- Noerr โ Proposal for simplification of GDPR record-keeping for organisations under 750 employees
- Secure Privacy โ What Article 88a Changes for Cookie Consent (2026)
- Addleshaw Goddard โ EU Digital Omnibus on AI: Council and Parliament agreed positions
Also read:
- GDPR in 2026: record fines, a reform in motion, and what to do now
- The 5 most common cookie banner mistakes โ and how to fix them
- GDPR now formally covers AI training data