Digital Omnibus, GDPR, and the AI Act: What's Changing for Businesses

Digital Omnibus: Between Reducing the Burden and Protecting Fundamental Rights

Digital Omnibus – Will Data Protection Become Easier Now?

When Reducing Bureaucracy Clashes with the Protection of Fundamental Rights

Data protection has a strange reputation in companies. Some consider it indispensable, while others think it’s just the sound a form makes when it falls on top of another form.

Now, changes are set to be made to the European regulatory framework. Under the banner of the “Digital Omnibus,” the EU is working to streamline digital law. Among other areas, this affects data protection, AI regulation, data access, and electronic communications.

At first glance, the goal sounds appealing: less bureaucracy, less duplicate regulation, and rules that are more practical.

But data protection isn't like an old cable in the basement that you can just cut off because it looks messy. If you want to streamline the process, you need to know exactly where bureaucracy ends and the protection of fundamental rights begins.


Digital Omnibus

What is the Digital Omnibus?

The Digital Omnibus is a package of legislation through which the European Commission aims to simplify and better harmonize digital regulations. Among other things, it focuses on the General Data Protection Regulation, the AI Act, the Data Act, and regulations on electronic communications.

The background is understandable: In recent years, a dense network of digital regulations has emerged in Europe. The GDPR, AI Act, Data Act, Data Governance Act, DSA, DMA, NIS2, and other regulations sometimes overlap, sometimes coexist, and occasionally do so in such a way that companies must look very closely to determine which obligation is coming from which source.

This is challenging for large legal departments. For small and medium-sized businesses, it can quickly become confusing.

The Digital Omnibus is intended to alleviate these issues: eliminate technical ambiguities, reduce duplication, and simplify procedures.

That's the positive takeaway. The less positive one is: It's going to remain complicated.

Why the GDPR Is the Focus

The GDPR has been Europe’s primary data protection framework for years. It protects personal data, grants rights to data subjects, and requires companies to ensure transparency, purpose limitation, data security, and accountability.

At the same time, it is not always easy to apply in business practice. Documentation requirements, disclosure obligations, data protection impact assessments, reporting requirements, and the question of exactly when a particular legitimate interest applies regularly give rise to discussions.

As part of the reform discussion, various measures to ease the burden are therefore being considered. These include, for example, more practical rules for small and medium-sized enterprises, risk-based simplifications, and a reduction in duplicate efforts associated with digital obligations.

For companies, this would generally be good news.

If a requirement doesn’t provide any real benefit in terms of protection but merely adds to the number of Excel spreadsheets, it’s worth reviewing. Data protection should be effective. It shouldn’t just generate paperwork that looks organized but, upon closer inspection, has simply been punched with great confidence.

Data Protection and AI: The Tough Knot to Untangle

The issue becomes particularly sensitive where data protection and artificial intelligence intersect.

AI systems need data. Data protection raises the following questions: What data? For what purpose? On what legal basis? How transparent? For how long? What rights do data subjects have?

Those two don't always go together very well.

There is intense political and legal debate, particularly regarding the training of AI models, the use of personal data, pseudonymized data, and the processing of special categories of personal data.

Greater clarity would be helpful for companies. After all, many AI projects fail not because of a lack of interest, but because of uncertainty: Are we allowed to use this data? Is anonymization sufficient? Is it still the same purpose? Do we need consent? Or a legitimate interest? And what happens if an AI system is later used for a purpose other than what was originally planned?

A well-designed digital omnibus could actually be helpful here.

But only if simplification doesn't mean: We'll call it innovation and hope no one asks for the data.

Criticism: Relief or a Reduction in the Level of Protection?

Opinions on the reform plans vary.

Business associations and many companies welcome the approach of making digital regulation clearer and more practical. Simplifications can be particularly beneficial for small and medium-sized enterprises (SMEs), nonprofit organizations, noncommercial activities, or low-risk data processing.

Data protection advocates and civil rights organizations, however, warn against a potential weakening of data protection. Their concern is that, under the friendly-sounding term “simplification,” rules that have so far protected fundamental rights could be weakened.

Both sides have a point.

  • Yes, data protection must not be undermined by excessive complexity.
  • And yes, data protection must not be gutted under the guise of reducing bureaucracy.

The key lies in striking a balance: less unnecessary effort, but no compromise on fundamental rights.

What Companies Should Do Now

It is important for companies to understand that the Digital Omnibus is not a free pass and is not a reason to discontinue existing data protection processes.

As long as reforms have not been finalized and implemented, the existing obligations remain in effect. And even if simplifications are introduced, key principles will remain: lawfulness, transparency, purpose limitation, data minimization, storage limitation, security, and accountability.

Companies should therefore not hope for “less data protection,” but rather focus on improving their structure.

The most important thing to do right now is:

  • Which data protection obligations are truly time-consuming?
  • Which processes are overdocumented but taken for granted?
  • Which AI projects are hampered by unclear legal frameworks?
  • Which data processing activities are low-risk, and which are not?
  • Where are there overlaps between data protection, information security, AI governance, and compliance?
  • And what changes coming out of Brussels could be relevant to your own business model?

Effective monitoring is more important here than frantic, knee-jerk reactions.

What This Means for AI Governance

The Digital Omnibus also shows that data protection and AI governance will become even more closely intertwined in the future.

Companies cannot view AI in isolation. Those who use AI often have to deal with data protection, information security, labor law, copyright law, product safety, and the AI Act all at once.

That's why we need clear lines of responsibility. It doesn't necessarily have to be a new department with three hyphens in its name, but a role that keeps track of everything.

  • What AI systems are used?
  • What data is included?
  • What is the legal basis for the processing?
  • What risks do those affected face?
  • What transparency requirements apply?
  • And who evaluates changes when tools, models, or purposes change?

This is exactly where governance comes into play.

Conclusion

The Digital Omnibus could be an opportunity. If it makes digital regulation easier to understand, reduces duplicate obligations, and eases the burden on companies engaged in low-risk activities, much would be gained.

But simplification is not an end in itself.

Good regulation must be practical. Poor simplification is only welcome until the first fundamental right falls by the wayside.

For companies, this means: monitor, assess, and prepare. The GDPR isn’t going away. Neither is the AI Act. But both could change in certain respects.

Anyone who gets their data protection and AI governance in order now will be better prepared, regardless of the final wording of the law.

After all, in the end, it's not about finding bureaucracy appealing.

The goal is to create order without compromising protection.

```