Skip to content

Privacy Group Slams EU for Changing Data Protection Rules to Cater to AI Under the Digital Omnibus and GDPR Overhaul

Getting your Trinity Audio player ready...

Europe’s most prominent privacy watchdogs are sounding the alarm over a sweeping package of legislative changes the European Commission says will simplify the continent’s digital rulebook, but which critics argue is quietly rewriting core data protection principles specifically to make life easier for AI developers. The Digital Omnibus, published by the Commission on November 19, 2025, and still moving through negotiations between the European Parliament and the Council of the EU, has drawn sharp criticism from privacy organizations including noyb and European Digital Rights, both of which say the reforms favor large technology companies at the expense of the protections the GDPR was built to guarantee.

Noyb, the Vienna-based privacy advocacy group founded by activist Max Schrems, has been among the most vocal critics of the package, describing it as opening many new loopholes for Big Tech and calling it the biggest attack on Europeans’ digital rights in years. European Digital Rights, a pan-European network of civil society organizations, characterized the plans in similarly stark terms, warning in its own assessment that what the Commission presents as simplification amounts to deregulation in effect, one that weakens fundamental rights safeguards, increases legal uncertainty, and has advanced through a process the group says falls short of standard democratic lawmaking practices.

At the center of the controversy sits a proposed change to how the GDPR defines personal data itself, a shift that legal experts describe as far more consequential than its technical framing suggests. The Digital Omnibus proposes that pseudonymized data, information where directly identifying details have been replaced with aliases or codes, should not necessarily count as personal data if the party holding it is not reasonably likely to be able to re-identify the individuals involved. Currently, pseudonymized data remains fully subject to GDPR protections regardless of how difficult re-identification might be in practice. According to analysis from the Jacques Delors Centre, narrowing that definition would mean considerably less data falls within the GDPR’s scope going forward, a shift that could directly benefit companies by making more data legally available for training AI systems without needing to satisfy the regulation’s stricter requirements.

Real More:  The Oracle Cloud Roles Hit Hardest by Layoffs as AI Data Center Spending Reshapes the Company's Workforce

The European Data Protection Board and the European Data Protection Supervisor, the EU’s own official privacy oversight bodies, have themselves pushed back against this specific change, criticizing it as going far beyond a mere technical amendment. That pushback from within the EU’s own regulatory apparatus adds weight to the external criticism from noyb and EDRi, since it suggests the concerns extend beyond advocacy groups with an inherent institutional interest in opposing deregulation.

Beyond the personal data definition itself, the Omnibus introduces specific new exceptions tailored directly to AI development. According to analysis from law firm Jones Day, the proposal would exempt residual processing of special category data, sensitive information covering things like health, biometric or political data, when that processing occurs incidentally during the development and operation of AI systems or models. Separately, the package proposes that where sensitive data ends up incidentally present in an AI training dataset, its mere presence would not automatically trigger the GDPR’s stricter rules governing sensitive data processing, a carve-out specifically designed to address the reality that large training datasets often inadvertently sweep up sensitive personal information without any deliberate targeting of that data.

Amnesty International has framed the broader stakes of these changes in blunt terms, arguing that the Commission’s reforms play into a false dichotomy between regulation and innovation that the organization says is championed primarily by large technology companies seeking a rules-free environment prioritizing profit over consumer protection. The group specifically warned that the proposed redefinition of personal data could allow major tech firms to harvest more personal data for both training and operating AI systems, framing the change as a direct transfer of regulatory leverage from individuals toward the companies building AI products.

Real More:  AMD Hits $1 Trillion Market Cap for the First Time as Stock Rides a 5-Day AI Chip Rally

The Digital Omnibus package extends beyond GDPR changes alone into a broader restructuring of the EU’s digital rulebook. A companion proposal, the Digital Omnibus on AI, focuses specifically on the EU AI Act and has already moved further through the legislative process, with a provisional agreement reached between the Commission, Parliament and Council on May 7, 2026. That agreement pushes back key compliance deadlines for high-risk AI systems considerably, delaying obligations originally set to begin August 2, 2026, to December 2, 2027, for most high-risk systems, and to August 2, 2028, for AI systems integrated as safety components in products regulated separately under the EU’s Machinery Regulation. The Commission has justified the delay by pointing to its own slower-than-expected progress developing the harmonized technical standards needed to make the high-risk obligations enforceable in practice.

The GDPR and ePrivacy portions of the package, sometimes referred to as the Data Omnibus, remain further behind in the legislative process, with negotiations still underway as of recent reporting and final adoption not expected before late 2026 at the earliest. That slower timeline has given privacy advocates additional time to organize opposition, and more than 125 civil society organizations, coordinated through a campaign called Stop the Digital Omnibus, have publicly sounded alarms about the package since leaked documents first surfaced ahead of its official November 2025 unveiling.

Real More:  Nvidia Supplier Wistron's Shares Drop 6% After Announcing $1.5 Billion Global Stock Sale to Fund AI Server Expansion

The European Commission, for its part, has defended the package as necessary modernization rather than deregulation, estimating the changes could save businesses up to €5 billion by 2029 through eliminating duplicate reporting requirements and streamlining consent processes that have grown increasingly complex and overlapping since the GDPR first took effect in 2018. Whether that efficiency argument ultimately prevails against the sustained criticism from noyb, EDRi, Amnesty International and the EU’s own data protection oversight bodies will likely become clearer as the GDPR and ePrivacy portions of the package move through final negotiations over the coming months. Continuing coverage of how EU regulation is adapting to the AI era is available on Business Tech. Additional detail on the criticism is available through European Digital Rights’ official assessment, and further background on noyb’s position can be found through the organization’s official site.

Leave a Comment