The most consequential privacy legislation currently in motion anywhere in the world is not a new law. It’s a rewrite of an existing one — the Digital Omnibus, the European Commission’s package to “simplify” the GDPR, ePrivacy, the Data Act, NIS2, and DORA.
As of late July 2026, the GDPR portion of it is stuck.
What happened at the end of June
In the final days of the Cyprus Presidency, the Council’s compromise text was withdrawn from the COREPER II approval process on June 30, 2026. The reason was straightforward: it had become clear the text did not command the support of a qualified majority of member states.
The Council did not settle its position before the presidency rotated to Ireland on July 1. Ireland inherited an unresolved file.
This is a meaningful failure. Council presidencies are heavily invested in closing files during their six months, and a text pulled from COREPER at the buzzer signals that the disagreements are substantive rather than technical.
Analysts tracking the negotiation describe a Council that has moved a long way from the Commission’s original proposal, with several simplification measures “weakened, removed or redirected towards future guidance rather than being resolved in the legislative text itself.”
That phrase describes a specific and familiar legislative outcome: a package sold as delivering legal certainty that instead defers the hard questions to guidance documents produced later by someone else. If the Omnibus lands that way, businesses get a disruptive amendment process without the clarity it was meant to purchase, and individuals get weakened protections in exchange for nothing.
What’s actually on the table
The Digital Omnibus is a broad package, and the parts that matter most for ordinary people:
Cookies and consent. The proposal introduces single-click accept/reject, a six-month moratorium after a user refuses (so a site can’t re-ask immediately), and browser-level preference signals that sites would have to honor. This is the most genuinely popular element. The current consent banner regime is a failure by any measure — it produces click-fatigue, dark patterns, and consent that nobody meaningfully gives. Machine-readable preferences expressed once, at the browser, and respected everywhere is the right architecture. It’s essentially the Global Privacy Control model, and it works.
Breach notification. The Commission argues the current 72-hour regime produces enormous volumes of low-value notifications. There’s evidence for that: European data protection authorities now receive 443 breach notifications per day, up 22% year over year. Whether the fix is proportionality or simply a higher threshold that lets more incidents go unreported is the disputed question.
The definition of personal data. Narrowing this is the single highest-stakes item in the package. The GDPR’s expansive definition — anything relating to an identified or identifiable person — is the load-bearing element of the entire regulation. Everything else follows from what counts as in scope. Narrow it, and large categories of data processing simply exit the regulation’s reach.
AI and scientific research. Proposals to create a workable basis for training AI systems on personal data — most contentiously, expanding legitimate interest as a lawful basis for AI training, and adjusting how special category data (health, biometrics, political opinions, sexual orientation) is treated when it appears incidentally in training corpora.
Access requests. Provisions targeting “abusive” data subject access requests. Defensible in principle — some requests are genuinely vexatious or used as litigation leverage — but the drafting determines whether it addresses abuse or simply gives controllers a reason to refuse.
noyb’s objection
Max Schrems’s noyb has been unambiguous, publishing under the headline that the “EU Commission [is] about to wreck core principles of the GDPR.”
The core of the civil society argument is that the package is mislabeled. “Simplification” implies reducing administrative burden without changing substantive protection — better forms, clearer guidance, proportionate paperwork. But narrowing the definition of personal data, broadening legitimate interest for AI training, and loosening special category rules are substantive rollbacks of protection, presented under a procedural banner.
That framing matters politically, because “cutting red tape” polls well and “reducing your data protection rights” does not. When the same legislative text can be described both ways, the description that gets used determines who shows up to argue about it.
Context: the AI Omnibus already passed
While the GDPR file stalled, its sibling moved. The AI Omnibus — postponing the AI Act’s high-risk deadlines — was adopted by the Council on June 29, 2026 and takes effect in July.
The sequencing is instructive. The package that delays obligations on AI developers completed its passage. The package that would restructure data protection did not, because member states cannot agree on how far to go.
Read charitably, that’s the Council refusing to rush a rewrite of the GDPR. Read less charitably, it’s an EU that finds it much easier to relieve industry of deadlines than to resolve what individuals are actually owed.
Why this matters outside Europe
The GDPR is the most widely copied privacy law in history. Brazil’s LGPD, South Africa’s POPIA, Japan’s APPI amendments, India’s DPDP Act, and substantial portions of US state law all borrow its structure — data subject rights, lawful bases, controller/processor distinctions, breach notification.
More practically, the GDPR set the global operational floor. Multinationals generally build one privacy program to the strictest applicable standard, and for a decade that standard has been European. If Europe narrows the definition of personal data or broadens legitimate interest for AI training, that floor drops everywhere — including for people in jurisdictions that never got a vote.
This is the Brussels Effect running in reverse, and it’s the reason a Council working party disagreement in July concerns anyone with an internet connection.
Where it goes from here
Ireland holds the presidency through December 2026. To close the file it needs a text that secures qualified majority support in Council, then a trilogue negotiation with the European Parliament — where the political composition is meaningfully more protective of the GDPR than the Council’s is.
Realistic outcomes:
- A narrowed package. The cookie and consent reforms — which are genuinely popular and technically sound — pass, while the contested definitional changes get dropped or deferred.
- A weak compromise. Everything passes in watered-down form, delivering neither simplification nor protection, with the substance pushed to future EDPB guidance.
- Continued stalemate. The file slips into 2027 and the next presidency.
The first outcome is the good one. It’s also the least likely, because the industry pressure driving this package is aimed squarely at the AI training and personal data definition provisions — which is to say, at exactly the parts that would need to be dropped.
What to do in the meantime
The GDPR is still fully in force. Nothing has changed yet. If you’re in the EU or EEA:
- Use your access rights. Article 15 requests remain available, and noyb publishes templates. Requests filed now are also the best evidence base for whether the “abusive request” problem is real.
- Use erasure and objection rights, particularly against data brokers and ad tech.
- Support the organizations doing the work. noyb, EDRi, and Access Now are the entities actually reading the compromise texts and publishing what’s in them. This negotiation is happening in working party documents that essentially nobody outside Brussels reads.
Everywhere: enable Global Privacy Control in your browser. It’s the same mechanism the Omnibus would make binding in the EU, and it’s already legally enforceable in California, Colorado, Connecticut, and Texas.
The pattern
The GDPR passed in 2016 in the aftermath of Snowden, at a high-water mark of political will for data protection. It’s being renegotiated in 2026 in the middle of an AI investment boom, with competitiveness as the framing and simplification as the label.
The specific text matters enormously and almost nobody is reading it. That gap — between the stakes of the drafting and the attention paid to it — is where privacy protections have historically been lost. Not in a dramatic repeal, but in a definitional adjustment on page 340 of a package titled “simplification.”
Cyprus couldn’t get it through. Ireland has five months to try. The parts to watch are the definition of personal data and the legitimate interest basis for AI training — everything else in the package is negotiable detail by comparison.
Sources:
- Digital Omnibus Negotiations (GDPR) – July 2026 Update — Privacy Next
- EU Commission about to wreck core principles of the GDPR — noyb
- GDPR under revision: Key takeaways from the Digital Omnibus Regulation proposal — White & Case
- The EU Commission’s Digital Package: reforming GDPR, e-Privacy, Data Act, AI, and Cybersecurity — Reed Smith
- EU proposes sweeping reforms to the GDPR, cookie rules, Data Act, and breach reporting — McDermott



