EU Digital Omnibus Hands the Wheel to the Referee
The Digital Omnibus was supposed to make European Union data law simpler, clearer, and less allergic to reality. Instead, the Council of the European Union appears to be turning it into something more familiar: a reform that trims the statute, fattens the recitals, and hands more interpretive power to the same regulators whose maximalist readings made reform necessary in the first place.
In March, the International Center for Law & Economics (ICLE) submitted comments to the European Commission on the General Data Protection Regulation (GDPR) and ePrivacy provisions of the Digital Omnibus. The GDPR is the European Union’s main privacy law. The ePrivacy rules govern confidentiality of communications and device-access rules, including the cookie-consent regime that has trained a continent to click “accept” while learning nothing substantial.
We made four core arguments.
First, policymakers should adopt the proposed entity-relative clarification of the personal-data definition—that is, they should ask whether the particular organization holding the data can realistically identify someone, not whether someone, somewhere, with some imagined tool, might be able to do so.
Second, the package’s artificial-intelligence (AI) provisions represented a necessary legislative settlement of questions that the European Data Protection Board (EDPB), the EU body that coordinates national privacy regulators, had deliberately left unresolved.
Third, the proposed cookie-consent reforms pointed in the right direction, but did not go far enough.
Finally, the package’s greatest weakness was its silence on enforcement architecture. Without institutional reform, we argued, the same authorities that had interpreted the GDPR into a “law of everything” would read the new exemptions just as narrowly.
Three months later, the two sister components of the Digital Omnibus have diverged sharply. The AI Omnibus (COM(2025) 836) reached a provisional trilogue agreement on May 7. A trilogue is the closed-door negotiation among the Commission, Parliament, and Council that often determines the final shape of EU legislation. The Data Omnibus (COM(2025) 837)—which contains the GDPR and ePrivacy reforms—remains before the Council, where the Cypriot Presidency has circulated successive compromise texts, most recently on May 21 (Council document 9547/26).
That latest compromise deletes three of the Commission’s four principal GDPR reforms: the entity-relative personal-data test, the relocation of cookie consent into the GDPR, and the legitimate-interest basis for AI processing. It also removes the Commission’s proposed authority to define pseudonymization criteria. Pseudonymization means replacing direct identifiers, such as names, with substitutes, while keeping the possibility of re-identification under controlled conditions.
What remains of those reforms has largely migrated into recitals and EDPB guidance. Recitals are the explanatory passages that accompany EU laws. They can influence interpretation, but they are not the same as binding operative text. At the same time, the compromise expands the EDPB’s own mandate.
The concern at the heart of our March comments—that textual reform without enforcement reform would underperform—now looks almost understated. The Council appears poised to deliver less reform than the Commission proposed, while leaving the EDPB stronger than before.
This post examines how the Council compromise affects each of the issues addressed in our comments, and what it means as the file moves to the European Parliament.