The European regulatory landscape is undergoing its most consequential recalibration since the General Data Protection Regulation came into force in 2018. The EU’s Digital Omnibus proposal — with a compromise text dated 21 May 2026 — would amend core GDPR obligations across four critical domains: cookie consent, data breach notification, AI governance, and SME compliance burden. For mid-market companies navigating cross-border data flows, AI deployment, and digital analytics, this is not a peripheral development. It is a structural shift that demands immediate attention from legal, technology, and finance leadership.
From Cookie Banners to Consent Architecture: A Meaningful Simplification
One of the most operationally significant elements of the Digital Omnibus concerns terminal-equipment and cookie rules, currently governed separately under the ePrivacy Directive. The proposal would fold these provisions directly into the GDPR framework and introduce new consent exemptions for low-risk processing purposes, including audience measurement and website statistics — categories that have historically required explicit opt-in under strict interpretations of Article 5(3) of the ePrivacy Directive.
For digital businesses, this represents a genuine reduction in consent fatigue — both for users and compliance teams. Browser-based consent signals, aligned with the evolving Global Privacy Control standard, are expected to replace the fragmented banner ecosystem that has generated both user friction and regulatory inconsistency across EU member states. Companies relying on analytics infrastructure for commercial decision-making should begin auditing their current consent management platforms now, as the transition will require reconfiguration rather than simple policy updates.
The broader implication for enterprise risk management is clear: organisations that have over-engineered consent flows under the most conservative ePrivacy interpretations may find competitive relief, while those that have under-invested in consent architecture face a narrow window to remediate before harmonised enforcement benchmarks solidify.
Breach Notification and Cybersecurity Convergence: A Single-Point Model Emerges
The Digital Omnibus would raise the personal-data breach notification threshold, limiting mandatory reporting to incidents likely to create a high risk to individuals — a materially higher bar than the current standard under GDPR Article 33, which triggers notification for any breach likely to result in risk. This change, combined with a harmonised notification template aligned with NIS2, the Cyber Resilience Act, and DORA, signals a deliberate regulatory move toward a single-point notification model.
For General Counsel and Chief Risk Officers, this convergence has significant operational value. Today, a single cybersecurity incident can trigger parallel notification obligations under GDPR, NIS2, and — for financial institutions — DORA, each with different timelines, formats, and supervisory recipients. The proposed harmonisation would reduce duplicative reporting without diminishing accountability. Boards should treat this as an opportunity to consolidate incident response governance under a unified framework, rather than maintaining siloed legal and IT security protocols.
Critically, the raised threshold does not signal regulatory leniency. Supervisory authorities are expected to retain broad investigative powers, and the convergence with NIS2 and DORA means that cybersecurity governance will remain a board-level matter — particularly for companies in financial services, critical infrastructure, and healthcare.
AI Governance and the Legitimate Interest Clarification
Perhaps the most strategically consequential element for technology-forward organisations is the Digital Omnibus’s treatment of AI and personal data. The draft would clarify that companies may rely on legitimate interest as a lawful basis for using personal data to train and operate AI systems, subject to enhanced safeguards and an unconditional right to object for data subjects.
This directly intersects with obligations under the EU AI Act, which entered into force in August 2024 and imposes tiered requirements based on AI system risk classification. Together, these frameworks are shaping a coherent — if still evolving — European AI governance architecture. For CTOs and data science teams, the practical implication is that AI development pipelines must now be designed with dual compliance logic: GDPR-aligned data provenance and AI Act conformity assessments running in parallel.
Companies building proprietary AI tools or deploying third-party AI platforms that process personal data should conduct a legitimate interest assessment now, mapping existing data flows against the proposed safeguard requirements, rather than waiting for the final text.
Implications for Business: What Decision-Makers Should Do Now
- Audit consent management infrastructure against the proposed cookie exemptions and browser-signal standards to identify reconfiguration requirements.
- Consolidate incident response protocols across GDPR, NIS2, DORA, and the Cyber Resilience Act in anticipation of the single-point notification model.
- Conduct legitimate interest assessments for all AI systems processing personal data, documenting enhanced safeguards and objection mechanisms.
- Reassess record-keeping obligations if your organisation falls within the SME or small mid-cap thresholds that the Omnibus proposes to ease — this may reduce administrative overhead during scaling phases.
- Engage external counsel to monitor the final compromise text, as the 21 May 2026 draft remains subject to trilogue negotiation and member state transposition timelines.
Key takeaway: The EU Digital Omnibus is not a deregulatory exercise — it is a rationalisation of overlapping obligations into a more coherent, enforceable architecture. Mid-market companies that treat this as an opportunity to modernise their data governance and AI compliance frameworks will be better positioned than those waiting for final text before acting. The direction of travel is clear; the window for proactive alignment is now.