If you've heard that GDPR is finally getting easier, you've heard half the story. The European Commission's Digital Omnibus package promises real relief on some of the rules that have made compliance feel like death by a thousand cuts: cookie banners, breach notification, even what counts as personal data. At the same time, enforcement has never been busier, and it is no longer only Big Tech in the crosshairs.
For small and medium-sized businesses across Europe, 2026 is the year the rules started changing and the stakes kept going up — at the same time. Here's what is actually easier, what is only proposed, and what that means for your compliance work this autumn.
One Omnibus, Two Very Different Timelines
Most coverage talks about "the Omnibus" as a single package moving through Brussels. It isn't, and the difference decides what you can act on today.
- The Digital Omnibus on AI is already law. It amends the EU AI Act, was published in the Official Journal on 24 July 2026 and entered into force on 27 July.
- The GDPR half is still a proposal. The part amending GDPR, the ePrivacy rules and NIS2 is still in preparatory discussions in the Council. Parliament's lead committee has not adopted a negotiating position, trilogue talks between the institutions haven't started, and final adoption isn't expected before late 2026 at the earliest.
So everything below about cookies, breach notification and the definition of personal data describes where the law might go. Everything about the AI Act describes where it already is.
What the GDPR Proposal Would Make Easier
The Commission's proposal is the biggest shake-up of EU data protection law since 2018, and it's aimed squarely at the administrative weight smaller organisations struggle with most.
Cookie banners. Consent would no longer be needed for cookies used to transmit a communication, to deliver a service the user asked for, to measure the audience of your own site in aggregate, or to keep the service secure — the categories that make up most of what a typical SMB website sets. Where consent is still required, refusing would have to take a single click, and a refusal would have to be respected for six months instead of re-prompting on every visit. Browsers would also be able to send the user's choice automatically.
Breach notification. Today, a controller must notify its supervisory authority within 72 hours of any breach unless it is unlikely to result in a risk — a threshold that pushes many organisations to over-report minor incidents out of caution. The proposal would require notification only where a breach is likely to result in a high risk, extend the deadline to 96 hours, and route reports through a single EU entry point instead of separate channels under GDPR, NIS2 and other frameworks.
What counts as personal data. The proposal writes a controller-centric test into the law: information would not be personal data for an organisation that cannot reasonably identify the person behind it, even if another party could. For businesses holding pseudonymised or aggregated datasets, that could narrow what falls under GDPR in the first place.
AI training. The proposal would confirm that legitimate interest can be the legal basis for processing personal data to develop and operate AI systems, provided safeguards such as data minimisation and a right to object are in place.
| Area | Rule today | What's proposed |
|---|---|---|
| Cookies | Consent for everything not strictly necessary | No consent for low-risk purposes; one-click refusal respected for 6 months |
| Breach notice | 72 hours, unless risk is unlikely | 96 hours, only for high-risk breaches, one EU portal |
| Personal data | Broad, objective identifiability test | Judged from the controller's own position |
| AI training | Legitimate interest argued case by case | Legitimate interest confirmed, with safeguards |
Not all of this will survive. The Council's working text dropped the cookie redesign and the AI legitimate-interest clause in June 2026, and privacy advocates are campaigning against the package as deregulation dressed up as simplification. A compliance programme built around the Commission's original draft may have to be rebuilt once the final text lands.
The AI Act Changes That Are Already Law
The AI half of the package is settled, and it gives businesses building or deploying AI real breathing room:
- High-risk deadlines moved. Rules for high-risk AI systems listed in Annex III — hiring, credit scoring, education and similar uses — now apply from 2 December 2027 instead of 2 August 2026. Systems covered by EU product-safety legislation (Annex I) follow on 2 August 2028.
- AI literacy softened, not scrapped. Businesses no longer have to guarantee a particular level of AI literacy for each member of staff, and the Commission and Member States take a bigger role in promoting it. You are still expected to take measures that support it, so keep your training records.
- Bias detection. Organisations may process special categories of personal data where that is necessary to detect and correct bias, subject to strict safeguards.
What didn't move: the bans on prohibited AI practices, in force since February 2025. And none of this changes GDPR. An AI tool that processes customer or employee data still needs a legal basis, a privacy notice that mentions it and, in many cases, a DPIA — today, not in 2027.
What Isn't Getting Easier: Enforcement
While the rulebook is being renegotiated, regulators keep enforcing the existing one — and the numbers are not tapering off.
The headline fines still carry familiar names. TikTok was fined €530 million in 2025 over transfers of European users' data to China, following Meta's record €1.2 billion penalty in 2023 for EU-to-US transfers. The more important trend for smaller businesses is where enforcement is spreading.
Regulators no longer wait for complaints. Authorities run their own sweeps of websites for cookie and transparency failures, and fines increasingly land on organisations in finance, healthcare, telecoms and the public sector. The violations drawing attention are foundational: the Article 5 principles such as data minimisation, purpose limitation and storage limitation, plus the transparency duties in Articles 12–14 that the EDPB made its coordinated enforcement theme for 2026. These are exactly the areas where organisations without a dedicated compliance team tend to have gaps — starting with not knowing where all their personal data actually lives.
Five Things to Do Now
The honest summary isn't "GDPR is getting easier" or "GDPR is getting stricter". It's getting more specific, while enforcement widens. That calls for a few moves now rather than a wait-and-see approach:
- Don't rip out your cookie consent setup. The proposed exemptions aren't law, the Council has already dropped them from its working text once, and regulators are sweeping banners today. Fixing the common banner mistakes pays off under both the old rules and the new ones.
- Write down your breach response plan. Whether the deadline ends up at 72 or 96 hours, it's not enough time to work out who decides, who notifies and what gets logged. A documented, rehearsed plan is what makes either deadline achievable.
- Map where your personal data lives. A current record of processing and data map is the foundation for every other obligation — and the first thing an authority asks for.
- Document your legal basis for AI. If you build or buy AI tools, record your Article 6 basis and your legitimate interest assessment now. If the proposed clause survives, regulators will soon be testing how "legitimate" that interest really is in practice.
- Use the AI Act delay, don't bank it. If you are in scope for high-risk rules, December 2027 is roughly 15 months away — about the time a proper risk management and documentation programme takes to put in place.
The Bottom Line
"Simplification" is not "less scrutiny". The AI Act has bought businesses time, but the GDPR changes are still being negotiated, and supervisory authorities are testing websites without waiting to be asked. The businesses that come out ahead in 2026 will be the ones that fix what is enforced today while tracking what might change tomorrow.
For SMBs without in-house legal or compliance teams, this is the moment when structured, up-to-date guidance is worth more than a generic GDPR checklist — because the checklist itself is being rewritten. Run the free GDPRGard site audit → to see where your website stands today, or book a free consultation.
Sources
- European Commission — AI Omnibus enters into force
- European Parliament — Legislative Train: the Digital Omnibus regulation proposal
- DLA Piper — GDPR Fines and Data Breach Survey, January 2026
- GDPR — Article 33, notification of a personal data breach
- GDPR — Article 5, principles relating to processing of personal data
Also read:
- Inside the EU's Digital Omnibus: what's actually changing for GDPR
- GDPR in 2026: record fines, a reform in motion, and what to do now
- GDPR and AI governance in 2026: one half of the reform is already law