Prefer to listen? Click play for AI narration

If you've heard that GDPR is finally getting easier, you've heard half the story. The European Commission's Digital Omnibus package promises real relief on some of the rules that have made compliance feel like death by a thousand cuts: cookie banners, breach notification, even what counts as personal data. At the same time, enforcement has never been busier, and it is no longer only Big Tech in the crosshairs.

For small and medium-sized businesses across Europe, 2026 is the year the rules started changing and the stakes kept going up — at the same time. Here's what is actually easier, what is only proposed, and what that means for your compliance work this autumn.

One Omnibus, Two Very Different Timelines

Most coverage talks about "the Omnibus" as a single package moving through Brussels. It isn't, and the difference decides what you can act on today.

So everything below about cookies, breach notification and the definition of personal data describes where the law might go. Everything about the AI Act describes where it already is.

What the GDPR Proposal Would Make Easier

The Commission's proposal is the biggest shake-up of EU data protection law since 2018, and it's aimed squarely at the administrative weight smaller organisations struggle with most.

Cookie banners. Consent would no longer be needed for cookies used to transmit a communication, to deliver a service the user asked for, to measure the audience of your own site in aggregate, or to keep the service secure — the categories that make up most of what a typical SMB website sets. Where consent is still required, refusing would have to take a single click, and a refusal would have to be respected for six months instead of re-prompting on every visit. Browsers would also be able to send the user's choice automatically.

Breach notification. Today, a controller must notify its supervisory authority within 72 hours of any breach unless it is unlikely to result in a risk — a threshold that pushes many organisations to over-report minor incidents out of caution. The proposal would require notification only where a breach is likely to result in a high risk, extend the deadline to 96 hours, and route reports through a single EU entry point instead of separate channels under GDPR, NIS2 and other frameworks.

What counts as personal data. The proposal writes a controller-centric test into the law: information would not be personal data for an organisation that cannot reasonably identify the person behind it, even if another party could. For businesses holding pseudonymised or aggregated datasets, that could narrow what falls under GDPR in the first place.

AI training. The proposal would confirm that legitimate interest can be the legal basis for processing personal data to develop and operate AI systems, provided safeguards such as data minimisation and a right to object are in place.

AreaRule todayWhat's proposed
CookiesConsent for everything not strictly necessaryNo consent for low-risk purposes; one-click refusal respected for 6 months
Breach notice72 hours, unless risk is unlikely96 hours, only for high-risk breaches, one EU portal
Personal dataBroad, objective identifiability testJudged from the controller's own position
AI trainingLegitimate interest argued case by caseLegitimate interest confirmed, with safeguards

Not all of this will survive. The Council's working text dropped the cookie redesign and the AI legitimate-interest clause in June 2026, and privacy advocates are campaigning against the package as deregulation dressed up as simplification. A compliance programme built around the Commission's original draft may have to be rebuilt once the final text lands.

The AI Act Changes That Are Already Law

The AI half of the package is settled, and it gives businesses building or deploying AI real breathing room:

What didn't move: the bans on prohibited AI practices, in force since February 2025. And none of this changes GDPR. An AI tool that processes customer or employee data still needs a legal basis, a privacy notice that mentions it and, in many cases, a DPIA — today, not in 2027.

What Isn't Getting Easier: Enforcement

While the rulebook is being renegotiated, regulators keep enforcing the existing one — and the numbers are not tapering off.

€7.1B
Cumulative GDPR fines since May 2018
€1.2B
Fines issued in 2025, matching 2024
443
Breach notifications per day across Europe
+22%
Year-over-year rise in daily notifications

The headline fines still carry familiar names. TikTok was fined €530 million in 2025 over transfers of European users' data to China, following Meta's record €1.2 billion penalty in 2023 for EU-to-US transfers. The more important trend for smaller businesses is where enforcement is spreading.

Regulators no longer wait for complaints. Authorities run their own sweeps of websites for cookie and transparency failures, and fines increasingly land on organisations in finance, healthcare, telecoms and the public sector. The violations drawing attention are foundational: the Article 5 principles such as data minimisation, purpose limitation and storage limitation, plus the transparency duties in Articles 12–14 that the EDPB made its coordinated enforcement theme for 2026. These are exactly the areas where organisations without a dedicated compliance team tend to have gaps — starting with not knowing where all their personal data actually lives.

Five Things to Do Now

The honest summary isn't "GDPR is getting easier" or "GDPR is getting stricter". It's getting more specific, while enforcement widens. That calls for a few moves now rather than a wait-and-see approach:

  1. Don't rip out your cookie consent setup. The proposed exemptions aren't law, the Council has already dropped them from its working text once, and regulators are sweeping banners today. Fixing the common banner mistakes pays off under both the old rules and the new ones.
  2. Write down your breach response plan. Whether the deadline ends up at 72 or 96 hours, it's not enough time to work out who decides, who notifies and what gets logged. A documented, rehearsed plan is what makes either deadline achievable.
  3. Map where your personal data lives. A current record of processing and data map is the foundation for every other obligation — and the first thing an authority asks for.
  4. Document your legal basis for AI. If you build or buy AI tools, record your Article 6 basis and your legitimate interest assessment now. If the proposed clause survives, regulators will soon be testing how "legitimate" that interest really is in practice.
  5. Use the AI Act delay, don't bank it. If you are in scope for high-risk rules, December 2027 is roughly 15 months away — about the time a proper risk management and documentation programme takes to put in place.

The Bottom Line

"Simplification" is not "less scrutiny". The AI Act has bought businesses time, but the GDPR changes are still being negotiated, and supervisory authorities are testing websites without waiting to be asked. The businesses that come out ahead in 2026 will be the ones that fix what is enforced today while tracking what might change tomorrow.

For SMBs without in-house legal or compliance teams, this is the moment when structured, up-to-date guidance is worth more than a generic GDPR checklist — because the checklist itself is being rewritten. Run the free GDPRGard site audit → to see where your website stands today, or book a free consultation.

Sources

Share this article

Also read:

⚠️ This article is for informational purposes only and does not constitute legal advice. The Digital Omnibus amendments to GDPR are still under negotiation and may change before adoption — verify your own position with a qualified data protection professional.