Simplification for whom? Open letter to EU Member States to uphold GDPR protections in Digital Omnibus on Data

Over the past months, the European Commission's Digital Omnibus on Data has turned into a wider discussion about how much protection the data – and with it, the rights – of people in the EU should receive in the name of AI, innovation and competitiveness. That discussion has now reached a critical stage in the Council.

By EDRi · September 24, 2026

European Commission’s Digital Omnibus on data pits data protection against AI and “competitiveness”

EU governments are now discussing critical issues like whether data should sometimes fall outside the General Data Protection Regulation (GDPR) depending on who holds the data, whether AI deserves special treatment when companies want to reuse personal data, and whether people should receive less information about how their data are used. The Irish Presidency’s compromise of 3 September has raised serious concerns across the board. A revised text circulated on 21 September seemingly attempted at improving some parts of it, but leaves the most fundamental questions unresolved. Just as the Commission’s Proposal, this is deregulation of substance, not simply less paperwork, it is happening very quickly, and the legal drafting is quite worrying.

Your name disappears, but you don’t.

The Council has stepped back from directly rewriting the GDPR’s definition of ‘personal data,’ and this may sound reassuring. But it is not: the new Article 25a and the accompanying Recitals 27 still risk changing the answer to the same basic question: when does the GDPR apply?

To understand why, it helps to distinguish pseudonymisation from anonymisation. Pseudonymisation means replacing obvious identifiers, such as a name, with something else, like a code or an ID number. That can make data safer, because the information linking the code back to the person is kept separately. But the person is still there behind the code, and the data, together with the rights attached to them, are still meant to remain protected.

This is not an abstract scenario. Much of today’s online tracking already works through pseudonymous identifiers rather than people’s names. Cookie IDs, advertising IDs, device identifiers and similar codes are used to recognise people over time, link their behaviour across services, build profiles and decide what content, prices or adverts they see. In many contexts, knowing that someone is ‘User 15051948’ is actually more useful for tracking and targeting them than knowing their name.

Anonymisation is different. Data are anonymous only when a person can no longer realistically be identified from them, including by combining them with other information that is reasonably available. Anonymous data fall outside the GDPR. Pseudonymised data do not simply become anonymous because one company cannot immediately put a name to the person.

The Council’s approach risks blurring exactly that line, between data that are still being used to single out and act on a person, and data that are genuinely anonymous. Under Article 25a, the same pseudonymised data could be treated as personal data for one actor but as non-personal data for another if that actor is considered unable to identify the person. In practice, this can produce something very close to narrowing the definition of personal data itself. That creates two problems.

The first issue is about rights. If a company treats the data as outside the GDPR, many of the protections attached to the GDPR may disappear with it: the duty to keep data secure, people’s right to know how data are used, the right to access or correct them, or to object to certain uses.

The second is about legal certainty. Digital data rarely sit with one company. They move through long chains of service providers, advertisers, analytics companies, cloud providers and data brokers that disproportionately depend on distributed data processing: different actors hold different pieces of information (all of them surely pseudonymised) and have different technical capabilities. So the legal status of the same dataset will change depending on who is holding it at a given moment. That means companies, regulators and individuals may first have to work out who can identify whom, with which data and at which point in the chain, before they can even answer the basic question of whether the GDPR applies. And there is an obvious incentive problem here: actors already argue that they are not responsible because they cannot themselves identify the person behind an identifier, or because another actor in the chain holds the information needed to do so. Article 25a risks giving those arguments considerably more legal weight.

For a law supposedly being ‘simplified,’ that is a remarkable amount of new uncertainty.

AI gets its own invitation

The GDPR already contains several possible legal grounds for using personal data. One of them is called ‘legitimate interest.’ It does not mean that a company can simply say ‘this is useful for our business’ and carry on: it has to identify a legitimate interest, the processing has to be necessary for that interest, and that interest has to be balanced against the rights and interests of the person whose data are being used.

The Council text would now specifically say that processing personal data for the development and operation of AI may be carried out for a legitimate interest. That raises a fairly obvious question: why does AI need a special mention at all?

And this is not only about training large language models. AI systems already sit behind many of the systems that profile, rank, recommend and target people online. Recommender systems shape what we see on social media, advertising systems decide who gets shown what, and automated tools are increasingly being used in workplaces, finance and other areas of everyday life. A broadly drafted AI provision can therefore reach far beyond the current debate about scraping data to train chatbots.

That is exactly why the category is so problematic. Developing a system to diagnose cancer, generating targeted advertisements, analysing workers, building a recommender system and training a chatbot are very different activities. ‘AI’ describes the technology being used but tells us very little about whether a particular use of people’s data is justified. Yet the Council, following the Commission’s dangerous lead, text would single out this enormous category of processing in legislation.

This also creates a bad incentive. If attaching an AI system to a processing activity makes it easier to argue that legitimate interest applies, companies may have reasons to frame more and more processing as being ‘in the context of AI.’ That is the opposite of technology-neutral regulation.

The concern is not that these words automatically legalise every use of personal data involving AI: the rest of the GDPR still matters. The concern is the direction they give to companies, regulators and courts. AI development and operation are expressly identified by lawmakers as activities for which legitimate interest may be used. At a time when access to data is becoming one of the most valuable resources in the AI economy, that is not a small signal.

‘But Big Tech is already doing it’

Another argument is becoming increasingly common: large technology companies are already using enormous amounts of data for AI, so EU companies and public authorities need to be allowed to do the same. That is a peculiar way to make law.

If companies are stretching, contesting or ignoring existing rules, the answer should be better enforcement. Their behaviour should not become the new legal baseline.

It also does very little for the EU companies supposedly being helped, because looser data rules do not suddenly give an EU start-up twenty years of search histories, location information, photographs, social connections and behavioural data. A few days ago, we learnt that a Microsoft executive privately called AI scraping ‘the largest theft of labour in human history.’

The actors best placed to benefit are those that already possess enormous data reserves and the infrastructure to exploit them, and deregulating access to data will therefore only make the biggest data empires stronger. These are also the same players that will benefit from the legal uncertainty created by other parts of the package. That is not much of a level playing field.

And somehow cookie banners survive

There is a particularly strange irony in all of this. Ask almost anyone what they would actually like simplified about EU privacy and data protection, and one answer comes quickly: cookie banners. The Commission had proposed a mechanism that could allow people to communicate some choices automatically, instead of clicking the same buttons again and again: automated privacy signals.

The Council continues to delete that provision. At the same time, it is considering more exceptions allowing access to information on people’s phones, computers and other devices (yes, storing your most intimate information) without consent or information.

In fact, the latest draft would even require the Commission to review the use of ‘privacy-enhancing technologies’ for accessing terminal equipment, with the possibility of proposing further changes to the rules later. Privacy-enhancing technologies (so-called PETs) are tools designed to reduce privacy risks. Pseudonymisation can be one. Other techniques can minimise, separate or protect information. Companies should invest in them, but increasingly, we hear a strange argument: if a company has invested in privacy-enhancing technology, the law should recognise that by relaxing the rules that apply to the resulting data. That turns the logic upside down: a safety measure should not become a ticket out of the law.

The political contradiction

EU governments are simultaneously talking about the dangers of AI, cybersecurity, addictive design and protecting children online. Every one of those issues involves data: who collects them, who combines them, what can be inferred from them, what they are used to optimise, who gets access to them?

Weakening the horizontal rules governing those practices, while promising to address their consequences elsewhere and with dangerous sledgehammers such as age verification, is a very strange policy choice.

The good news? There is still time to reconsider it. The 21 September text shows that Member States can improve the drafting when concerns are taken seriously, and can and should stop this deregulatory madness to put both rights and legal certainty at the centre. They should keep doing so rather than rushing towards an agreement on changes that touch the foundations of European data protection law, the cornerstone of our digital rulebook. Read our call to EU member state representatives.