The European Commission’s proposed Digital Omnibus simplification package marks the most significant recalibration of GDPR’s operational framework since the regulation entered into force in 2018. For CFOs, General Counsel, and Chief Compliance Officers, the reforms arriving in 2026 are not merely administrative housekeeping—they represent a structural shift in how data privacy obligations are balanced against innovation, commercial efficiency, and cross-border regulatory enforcement.
Understanding the precise scope of these changes, and acting on them before the January 2026 deadlines, will separate organisations that lead on enterprise risk management from those that absorb avoidable enforcement exposure.
AI Training, Legitimate Interest, and the New Compliance Calculus
One of the most consequential elements of the Digital Omnibus is the explicit clarification that AI providers may rely on legitimate interest as a lawful basis for using personal data in AI model development—subject to enhanced safeguards, including mandatory user objection rights. This directly addresses a long-standing tension between the EU AI Act‘s data governance requirements and GDPR’s restrictive interpretation of lawful processing bases.
For enterprises deploying or procuring AI systems, this development has immediate implications:
- Vendor due diligence must now include verification that AI providers have implemented compliant legitimate interest assessments (LIAs) and robust objection mechanisms—not merely consent frameworks.
- Internal AI initiatives involving customer or employee data require updated Records of Processing Activities (RoPAs) and refreshed Data Protection Impact Assessments (DPIAs) aligned to the new lawful basis.
- Board-level oversight of AI governance should be elevated, given that regulators are simultaneously tightening enforcement timelines (see below) and expanding the scope of permissible AI data use.
The CNIL’s recent €1.7 million fine against Nexpublica for inadequate security in PCRM software is a pointed reminder that expanded permissions do not dilute security obligations under data privacy law—they intensify scrutiny of the safeguards surrounding them.
Accelerated Cross-Border Enforcement and the UK Adequacy Extension
Effective January 1, 2026, a new GDPR enforcement regulation will require cross-border data protection authorities to issue resolution proposals within 12 to 15 months of case initiation. This compresses what has historically been a multi-year process, fundamentally altering the risk timeline for multinationals operating across EU member states.
For M&A Directors and transaction counsel, this acceleration has direct implications for deal structuring and post-merger integration. Data protection liability—previously a slow-burn risk—now crystallises faster, making pre-close GDPR audits and warranty negotiations more commercially urgent.
Simultaneously, the EU’s adoption of two new adequacy decisions for the UK under both GDPR and the Law Enforcement Directive, valid until December 27, 2031, provides a stable six-year window for EU-UK data flows. For organisations with post-Brexit operational footprints spanning both jurisdictions, this removes a significant near-term compliance uncertainty—though the adequacy decisions remain subject to political and regulatory review, and contingency planning for their potential lapse remains sound corporate governance.
The ongoing warnings from Spanish and Norwegian authorities regarding TikTok’s data transfers to China further underscore that third-country transfer risk remains a live enforcement priority, particularly where state-access provisions in non-adequate jurisdictions are concerned.
SME and Mid-Cap Relief: Operational Efficiency with Residual Obligations
The Digital Omnibus extends record-keeping derogations to companies with fewer than 750 employees—a significant expansion beyond the existing SME threshold—projected to reduce annual administrative costs across the EU by approximately €300 million. Additionally, roughly 60% of low-risk cookie use cases will no longer require explicit user consent, streamlining digital operations for mid-market businesses.
While these measures reduce compliance friction, mid-cap organisations should resist interpreting them as a wholesale relaxation of regulatory compliance obligations. Core accountability requirements, DPIAs for high-risk processing, and security standards remain fully applicable. The risk of under-investing in compliance infrastructure on the basis of simplified rules has historically preceded enforcement incidents.
Implications for Business: Priority Actions Before 2026
Decision-makers should initiate the following workstreams now:
- Audit AI processing activities to determine whether legitimate interest can replace or supplement existing consent frameworks, and document LIAs accordingly.
- Revise cross-border enforcement response protocols to reflect the compressed 12–15 month resolution timeline—legal and compliance teams must be positioned to respond faster.
- Update cookie consent architectures in anticipation of the 60% consent reduction, while ensuring remaining high-risk cookies retain compliant consent mechanisms.
- Review M&A due diligence checklists to incorporate the new enforcement velocity and UK adequacy decision parameters into deal risk assessments.
Key Takeaway
The EU’s Digital Omnibus is not a deregulatory signal—it is a strategic rebalancing of GDPR’s compliance architecture to accommodate AI development, reduce SME burden, and accelerate enforcement effectiveness. For boards and executive leadership, the 2026 implementation window is shorter than it appears. Organisations that treat these reforms as an opportunity to modernise their data governance frameworks—rather than simply adjust existing procedures—will be better positioned across both regulatory risk and competitive advantage.