Default

The Digital Omnibus: Trading Fundamental Rights for Corporate Profits?

Dual-panel editorial graphic contrasting corporate AI data harvesting on the left with a digital privacy shield protecting citizens on the right. Features text overlay referencing the EU Digital Omnibus, GDPR guardrails, €5 billion in claimed savings, Pirate MEP Markéta Gregorová, and the European Pirates.
The EU Digital Omnibus pits corporate AI data harvesting against fundamental GDPR privacy protections.

The Digital Omnibus was pitched as an effort to simplify compliance and reporting rules. The question is: at what cost? When we first looked at the Digital Omnibus in November 2025, the proposal was still at an early stage. Since then, the debate has moved forward, with particular attention turning to changes affecting data protection and privacy. Proposed by the European Commission, the EU Digital Omnibus aims to streamline tech frameworks like the GDPR, AI Act, and Data Act, but critics warn that this administrative simplification is a disguised push for corporate deregulation.


The end goal is to support European digital businesses’ competitiveness in the AI race and in the wake of the Draghi report. While the Commission boasts €5 billion in ‘saved compliance costs,’ by 2029, civil society groups warn this represents a broader push toward EU tech deregulation that removes essential guardrails protecting European rights. The Digital Omnibus is being criticised even by sympathetic bodies such as Digital Europe, first and foremost because it bundles together a multitude of changes in varying areas with too little time to legislate. The EP (European Parliament) has time until February 2027, but will it be enough to properly assess all 1750 amendments? Can we afford what is at stake to fall through the cracks of the fine print? As our MEP Markéta Gregorová said, “Changing the scope of a regulation cannot happen in an omnibus.”

Deregulation Disguised as Simplification

Split into the Omnibus on Data and the Omnibus on AI, the Digital Omnibus aims to simplify overlapping tech rules across the GDPR, ePrivacy, Data Act, NIS2, DORA, and Data Governance Act, additionally amending timelines and compliance procedures for the AI Act. While the AI Omnibus entered into force in mid-2026, the negotiations on the Data Omnibus are ongoing, with lawmakers aiming for a committee vote before February 2027.
On September 24, EDRi (European Digital Rights) published an open letter pushing back against the latest version of the EU’s Digital Omnibus on Data. The accompanying statement cites mounting worries that the new Omnibus might erode privacy rights for the sake of competitiveness in the AI race. The European Pirates have also repeatedly voiced their concerns about increased dangers of cyber fraud, endangered privacy, and weaker net neutrality.

Turning Personal Privacy into Free AI Capital

The relaxation of the GDPR’s definition of personal data and legitimate interest allows companies to access and retain our personal data to train AI models without strict consent to correct biases against minoritized groups in LLMs. It is true that AI development requires humongous amounts of data that the internet has already been virtually fully scraped, and synthetic data can only help so much. But it is not worth jeopardizing our privacy by giving our most sensitive data to entities that are unaccountable and loosely regulated. This relaxation opens a backdoor to constant corporate surveillance, government meddling, hacks, and further types of cybercrime. The possibility of mining so much personal data, with so little ownership, consent, and oversight of its uses, dangerously opens to employee surveillance and the leaking of personal data. Allowing companies to claim legitimate interest to scrape user data for AI models risks converting our digital lives into an unpaid and unconsented harvest for Big Tech in the name of surviving the AI race to the bottom.

The Pseudonymization Loophole Under the Omnibus’ Changes to the GDPR

Under the current proposal, GDPR rules apply to pseudonymized data based on the estimated capacity of a given company to trace data back to a single individual. However, companies don’t work in a vacuum: they constantly exchange data along their value chains, whilst claiming no responsibility over such data. If a company can claim to operate legitimately outside of GDPR but downstream buyers combine datasets to re-identify users, no one is liable, but citizens carry the risks to their privacy and cybersecurity.

What happens to non-GDPR personal data outside of the EU?

According to the GDPR, our data can be moved and stored in data centers overseas when the European Commission decides a country outside the EU ensures an adequate level of data protection. But if our personal data is no longer subject to GDPR and gets moved outside of the EU, it will be much harder to guarantee its safety and the accountability of those who are profiting from such data.
The Digital Omnibus risks giving big companies the upper hand and free rein both over smaller enterprises and over citizens – until an incident happens and it’s too late. But it doesn’t have to be that way.

The European Pirates Push Back

The next months will surely unfold with a flurry of details, analysis, and objections to the various parts of the Digital Omnibus. Some examples include the changes to cookie banners, the sharing of European tax data outside of the EU, the horizontal sharing obligations to manufacturers of digital products, and the threat to Net Neutrality. It will be important to remain tuned in, because our hard-fought rights don’t deserve to wither in the shadow of business competitiveness. Corporate competitiveness is being pitched against fundamental rights, and privacy laws are being pictured as a deadweight.

European Pirates works with volunteers across Europe to contribute to debates on digital rights and represent citizens’ interests in shaping Europe’s digital future. We are working to block the amendment that would consider pseudonymized data “non-personal” based purely on whether a single company claims it lacks the capacity to re-identify an individual. We oppose attempts to allow tech companies to use “legitimate interest” as a blanket legal pass to process personal data for AI training without consent.

You can meet us on October 17th at our Think Twice Conference in Brussels, bringing together different perspectives on AI, governance, and the choices that Europe faces ahead.

Want to know more?

You can also reach out, donate, read our positions, and find several volunteering opportunities.

1 comment on “The Digital Omnibus: Trading Fundamental Rights for Corporate Profits?”

Leave a Reply

This website generates anonymous visitor statistics to measure user engagement. You agree by using the website further.

Privacy policy