# The EU Digital Omnibus: what changes for data protection

The **Digital Omnibus GDPR** package presented on 19 November 2025 could reshape data protection in Europe. Behind the label of administrative simplification sit deep changes to cookies, artificial intelligence and sensitive data. For small companies, understanding them is no longer optional: it is a question of compliance, competitiveness and conscious risk management.

## Simplification meets controversy

The proposal starts from a shared need: reduce regulatory fragmentation and lighten the bureaucratic burden on European companies, especially smaller ones. The 2024 Draghi report stated plainly how much European regulatory complexity risks stifling innovation, particularly against the United States and China.

The documents leaked in the weeks before the official presentation triggered a wave of concern. More than 127 civil society organisations, trade unions and digital rights groups sent an open letter to the Commission calling the Digital Omnibus the largest rollback of fundamental digital rights in the history of the European Union. The Austrian organisation noyb, led by Max Schrems, called it a fast-track attack on the GDPR, criticising the lack of transparent consultation and of an adequate impact assessment.

These are not ideological positions: the debate concerns substantial changes to fundamental pillars of European data protection.

## The three key changes

### Cookies: from opt-in to opt-out

The first change concerns consent for tracking cookies. Today the framework requires explicit consent before non-essential cookies are installed. This principle, based on the ePrivacy directive, is why consent banners appear almost everywhere.

The Digital Omnibus proposes moving cookie regulation from the ePrivacy directive to the GDPR, in practice introducing an opt-out regime instead of opt-in. For most cookies, prior consent would no longer be required. Companies could install them automatically, provided the user can object.

For a small company running an e-commerce site or using digital marketing tools, this could remove the need for consent management platforms, cutting licence costs and management complexity. The obligation to document the legitimate interest that justifies the tracking does not disappear, however. It becomes a different responsibility, less visible but no less binding. The same principle applies to direct marketing, where [consent for email and SMS](/en/ecorner/2026/email-sms-marketing-business.html) must stay specific and documented.

### Artificial intelligence: training on data without consent

The second change concerns the use of personal data to train artificial intelligence models. Today, processing personal data for machine learning requires a solid legal basis, in most cases the explicit consent of the data subject.

The proposal introduces legitimate interest as an admissible legal basis for training AI systems. In substance, companies could use personal data already in their possession to train algorithms without new consent, provided they can show that the use falls under a legitimate interest and that data subjects' rights do not override it.

This fits a wider context: the market for generative AI and large language models grows at exponential rates, and access to data is its main fuel. For SMEs adopting generative tools for internal automation, customer support or predictive analysis, this could look like a simplification.

There is a catch: documenting legitimate interest requires a careful balancing assessment between business interests and data subjects' rights. It is a substantial obligation that, handled badly, exposes a company to complaints and sanctions. The absence of explicit consent can also create friction with customers who are increasingly sensitive to privacy, especially in sectors where trust is a competitive asset.

### Sensitive data: redefining the protected categories

The third change concerns the definition of sensitive data. Article 9 of the current GDPR identifies special categories (racial or ethnic origin, political opinions, religious beliefs, genetic and biometric data, health, sexual life or orientation) that enjoy reinforced protection and can be processed only in exceptional cases.

The Digital Omnibus proposes restricting protection to data that directly reveals those characteristics. In other words, data from which sensitive information can be inferred through processing, correlation or algorithmic analysis might no longer fall into the special category.

A concrete example: if an AI system infers a person's political orientation by analysing social media interactions or purchase behaviour, under the new definition that data might not be considered sensitive, because the information is not directly revealed.

This has deep implications. In recent years, the ability of algorithms to infer sensitive information from apparently neutral data has grown enormously. Academic studies have shown it is possible to deduce sexual orientation, mental health conditions, political affiliation and even genetic predispositions with good accuracy by analysing digital behavioural data.

For a small company managing a CRM or using profiling tools for marketing campaigns, this introduces a grey zone: what happens when the algorithm used to segment customers infers sensitive categories? Responsibility still sits with the company, while the legal framework becomes more opaque.

## What it means for Italian SMEs

Small and medium businesses make up more than 70% of the Italian entrepreneurial fabric. For them, GDPR compliance was never simple. A 2024 analysis found that many small companies still treat privacy requirements as bureaucracy rather than an opportunity for organisational improvement. The Italian Data Protection Authority has repeatedly noted how widespread the reactive approach is — adapting only after a data breach.

The Digital Omnibus presents itself as an opportunity for simplification, but the reality is more nuanced. Some procedures may become lighter: removing cookie banners could reduce the cost of consent management platforms. At the same time, the new responsibilities around documenting legitimate interest and handling regulatory grey zones require specific expertise.

Take a professional practice that manages clients' personal data and is considering an AI-based virtual assistant to automate answers to frequent requests. Under the new rules, the practice could train the model on data it already holds without asking clients for new consent. Apparently a simplification. But how is legitimate interest documented? How do you show that data subjects' rights do not override it? And how do you communicate the choice to clients without undermining trust?

Or consider a manufacturing company with an e-commerce site that uses analytics to track user behaviour. Moving to opt-out, it could install profiling cookies without prior consent. But if a customer complains or the Authority inspects, the company must show it correctly balanced its commercial interests against the user's rights. That requires documentation, impact analysis and clear policies.

The risk is to read simplification as a waiver of obligations, when it is in fact a reconfiguration of responsibilities.

## The Italian framework: what we know

At the time of writing, the Italian Data Protection Authority has not issued a specific official position on the Digital Omnibus. Its recent enforcement, however, shows a line of growing rigour.

In February 2025 the Authority fined an energy company 300,000 euros for using omnibus consents — generic and non-selective — to transfer data to third parties for marketing. The principle is clear: consent must be free, specific and granular. The user must be able to choose precisely which product categories to accept (energy, telephony, insurance) and through which channels (phone, email, SMS). Generic formulas are not allowed.

This approach matters because it suggests particular sensitivity to the concrete protection of data subjects' rights, beyond formal simplification. If the Digital Omnibus lightens certain obligations at European level, the Italian Authority is likely to keep high attention on the actual methods of processing and on transparency towards users.

In other words, for an Italian SME it will not be enough to adapt to the letter of the new European rules. It will be necessary to interpret them in light of national authorities' orientation, which has historically privileged substance over form.

## Navigating uncertainty: the preparation window

The legislative path of the Digital Omnibus has just started. The proposal must pass through the European Parliament and the Council. Early indications suggest the most radical changes to the GDPR could meet significant resistance, with some parliamentary groups already signalling substantial amendments or even removing the GDPR changes from the package.

This means Italian SMEs have a window to prepare, but also a context of regulatory uncertainty. The question many owners ask is what to do now.

The first consideration is to avoid paralysis. Waiting for the final outcome without doing anything could prove a mistake. The changes, even if approved in amended form, will have an impact. And even if some proposals are rejected, the public debate is already shaping user expectations and market practice.

The second is to avoid the opposite: hasty changes to business processes based on drafts that could change radically. The risk is ending up non-compliant with the final framework.

The answer lies in strategic analysis rather than immediate operational action.

First, this is the right moment to map accurately the personal data processing the company currently carries out. This is a concrete understanding of which data is collected, for what purposes, on which legal bases and who has access, rather than a formal exercise. Many SMEs adopted the GDPR reactively in 2018, producing documentation that has since become obsolete or stayed on paper without reflecting operations.

Second, it is worth assessing current or planned use of AI tools. If the company already uses chatbots, recommendation systems, predictive analysis or other AI, it must check how training data is handled. If it is considering such tools, now is the time to treat privacy implications as a design element rather than a constraint to work around.

Third, analyse current cookie and online tracking management. Many Italian SMEs use analytics, tracking pixels for advertising campaigns and remarketing systems, mostly based on opt-in consent. If the Digital Omnibus introduces opt-out, what would the practical implications be? Can legitimate interest be documented for each of those trackings? And how can it be communicated transparently to users?

Finally, do not underestimate the interpretive complexity. The GDPR is already complex, requiring continuous balancing between operational needs and rights protection. The proposed changes add new nuances, exceptions and grey zones. The idea that administrative simplification automatically means fewer responsibilities is misleading.

## Why do-it-yourself can cost dear

A frequent mistake among SMEs is to approach privacy compliance with a checklist. Find a template online, fill in a notice, create a processing register and consider the chapter closed. That could work, with limits, in a stable regulatory context. In a transition phase like the one ahead, it becomes risky.

The main risk is not the immediate sanction — the Italian Authority has historically favoured an educational approach towards SMEs that show good faith and commitment. The real risk is a structural non-compliance that emerges only when it is too late: during a data breach, after a customer complaint or in an inspection.

Consider a company that decides on its own to adopt an opt-out model for cookies, reading the Digital Omnibus drafts as a green light. But it does not document legitimate interest properly, does not update its privacy notice and does not provide clear ways for users to object. If the final text introduces stricter requirements than the drafts, the company is exposed. If the final text confirms opt-out but the Italian Authority still requires transparency and easy objection, the company can still be challenged.

Or take AI. A company decides to train a model on customer data, relying on the legitimate interest introduced by the Digital Omnibus. But it does not run an impact assessment, does not consider customers' reasonable expectations and does not provide objection mechanisms. Even if the legal basis were formally valid under the new rules, the absence of a substantial approach to data protection could still be a breach.

Privacy compliance is not only formal conformity with written rules. It is risk management, customer trust and corporate reputation. And it is an area where an interpretive error can have significant consequences: GDPR sanctions can reach 4% of annual global turnover or 20 million euros, whichever is higher.

For an Italian SME, even a sanction of a few thousand euros can have a real impact. Beyond the financial penalty sits reputational damage. A company sanctioned for a privacy breach, in a market increasingly attentive to these issues, risks losing customers and commercial opportunities.

## Real simplification or disguised complexity?

The Digital Omnibus is an ambitious attempt to modernise the European data protection framework. The stated intent — lighten the bureaucratic burden on SMEs and favour innovation — is reasonable. The gap between intent and practical effect remains to be seen.

For Italian SMEs, the key message is that regulatory simplification does not equal simpler responsibilities. In many cases it introduces new interpretive challenges and new areas of risk. The shift from opt-in to opt-out for cookies, the introduction of legitimate interest for AI training and the redefinition of sensitive data all require a deep understanding of the practical implications.

Over the coming months, as the European legislative process advances, clarifications, guidelines and interpretations will emerge from national authorities. SMEs that start now to think strategically about their data practices will be in a stronger position: to avoid sanctions, and to build a relationship of trust with their customers based on transparency and respect for rights.

In a market where privacy is becoming a competitive factor — consumers increasingly choose providers that take data protection seriously — investing in compliance that is substantial as well as formal is no longer a cost but a strategic investment. The safest route, in this period of regulatory transition, is to rely on specialist expertise that can combine legal, technical and organisational knowledge.

## Frequently asked questions

**What is the Digital Omnibus?**
A package of regulatory changes presented by the European Commission to simplify European digital rules, including the GDPR. It covers cookies, the use of personal data for AI training and the definition of sensitive data.

**What changes for cookies?**
The proposal moves cookie regulation from the ePrivacy directive to the GDPR and introduces an opt-out regime instead of opt-in for most cookies, while keeping the obligation to document the legitimate interest behind the tracking.

**Can personal data be used to train AI without consent?**
The proposal introduces legitimate interest as a possible legal basis, provided the company can show that the use falls under a legitimate interest and that data subjects' rights do not override it. Documenting that balance is a substantial obligation.

**What changes for sensitive data?**
Protection would be restricted to data that directly reveals special categories. Data from which sensitive information can be inferred through algorithmic analysis might no longer fall under the special category, creating grey zones for profiling.

**What should a small company do now?**
Map current data processing, review the use of AI tools and their training data, analyse cookie and tracking management, and prepare documentation. Waiting for the final text without any preparation is the riskiest option.

## Sources

European Commission — Digital Omnibus package, proposal of 19 November 2025 — https://digital-strategy.ec.europa.eu/en/policies/digital-omnibus
noyb — open letter and analysis on the Digital Omnibus and the GDPR — https://noyb.eu/en
Italian Data Protection Authority — enforcement on omnibus consents (February 2025) — https://www.garanteprivacy.it
Regulation (EU) 2016/679 (GDPR), Article 9 — special categories of personal data — https://eur-lex.europa.eu/eli/reg/2016/679/oj
Draghi report on the future of European competitiveness (2024) — https://commission.europa.eu/topics/eu-competitiveness_en
