On 19 November 2025, the European Commission unveiled two Digital Omnibus proposals alongside a Digital Fitness Check, signalling a broad deregulation push across EU digital policy. The initiative targets major pillars of the bloc's regulatory architecture, including the General Data Protection Regulation (GDPR), the ePrivacy Directive and the Artificial Intelligence (AI) Act. Critics contend that reopening these frameworks threatens to dismantle protections that took decades to establish, potentially undermining the human rights and technology governance foundations that underpin EU policy.

ePrivacy and Device Access Overhaul

The Omnibus proposal restructures ePrivacy safeguards by transferring device access rules into the GDPR framework. While consent requirements persist for most tracking activities, the revision introduces expansive carve-outs permitting companies to access device data without explicit permission. A privacy signal mechanism represents the proposal's sole protective feature, offering individuals a mechanism to block such access. However, this tool only takes effect after a two-year delay and excludes numerous media platforms from its scope.

GDPR Modifications and AI Training

The proposal substantially modifies core GDPR provisions. A revised recital narrows what qualifies as personal data, effectively allowing organisations to self-regulate their compliance obligations. The text further permits unrestricted deployment of sensitive personal information for artificial intelligence model training. Additionally, the proposal alters rules governing automated decision-making systems, loosening restrictions to enable broader deployment despite heightened risks of discriminatory outcomes.

Cumulative Impact on Privacy and Equity

Collectively, these modifications expand authority for both governmental bodies and commercial enterprises to gather and analyse personal information with diminished accountability mechanisms and reduced public visibility. Citizens will forfeit conventional protections previously guaranteed by law, while marginalised populations face intensified vulnerability to data profiling, algorithmic decision systems and pervasive surveillance practices.

Source: EDRi (European Digital Rights)