While debate over the Digital Omnibus has centred on privacy rollbacks—prompting warnings from more than 130 civil society groups and unions that it represents the largest retreat from digital rights the Union has pursued—a quieter but potentially far-reaching change lurks in the text. For the first time, the EU would codify what counts as "scientific research" in the General Data Protection Regulation.

The stakes extend well beyond data protection alone. Currently, no EU legal instrument provides an operative definition of research, yet copyright rules invoke the concept repeatedly when carving out exceptions for text and data mining and when addressing research institutions. The Commission is now consulting on a harmonized copyright exception for research that will require such a definition, as will the forthcoming European Research Area Act. Whatever definition emerges from GDPR negotiations could serve as a template for future EU legislation.

In November 2025, the Commission tabled its own proposal as a new Article 4(38) GDPR:

any research which can also support innovation, such as technological development and demonstration. These actions shall contribute to existing scientific knowledge or apply existing knowledge in novel ways, be carried out with the aim of contributing to the growth of society´s general knowledge and wellbeing and adhere to ethical standards in the relevant research area. This does not exclude that the research may also aim to further a commercial interest.

Commission proposal

The European Parliament's Industry, Research and Energy (ITRE) and Civil Liberties, Justice and Home Affairs (LIBE) Committees are jointly handling the file, with MEP Aura Salla (European People's Party, Finland) and MEP Marina Kaljurand (Socialists and Democrats, Estonia) as rapporteurs. Their June 2026 joint draft report retained much of the Commission's language, but since then the two rapporteurs have put forward competing versions. Salla's definition follows the OECD template for research and development, while Kaljurand's removes the commercial-interest clause and narrows research to autonomous, public-interest activities. The real battle is now playing out in amendments, which the committees must navigate.

For researchers, universities and libraries represented by Knowledge Rights 21, the definition will determine which activities qualify for the data-protection freedoms attached to research under the GDPR, and which do not. The amendments cluster around five central tensions.

1. Should there be a definition at all?

Some MEPs propose striking the definition entirely, arguing that it would create a basis for lighter GDPR obligations and thus weaker data protection. The concern has merit. Yet removing the definition forces regulators and courts to draw boundaries on a case-by-case basis—the very uncertainty that researchers currently face. A statutory definition could actually offer greater legal certainty than leaving such judgments to ad-hoc interpretation.

2. Does building and testing AI count as research?

The Commission's proposal makes no explicit mention of artificial intelligence. Several amendments would add language confirming that developing, training, testing and validating AI systems qualify as scientific research when general conditions are satisfied.

Conversely, amendments from far-left and far-right parties would explicitly exclude AI development, training or optimization from the research definition.

This tension sits uneasily alongside the Commission's own messaging elsewhere. When Executive Vice President Henna Virkkunen unveiled the AI Continent Action Plan in April 2025, she highlighted Europe's talent advantage, noting the continent has 30 percent more AI researchers than the United States. Commissioner Ekaterina Zaharieva has spent the same period promoting Europe as a destination for science, with a Choose Europe for Science package now approaching 1 billion euros. In November, the two jointly launched RAISE, a virtual institute for AI in science.

The Commission is actively recruiting AI researchers to Europe and treating them as a strategic asset. A GDPR definition that excludes core AI development, training or testing from "scientific research" would create friction with that recruitment and investment strategy.

3. Research, or research and development?

The most fundamental disagreement concerns how far downstream the definition should reach. The Commission's text explicitly encompasses activity supporting innovation—including technological development and demonstration—and states that research remains research even when it also serves commercial ends. One bloc of amendments preserves this breadth, with some explicitly confirming that privately funded research is covered, adding references to competitiveness, or clarifying that work inside a company or feeding into later commercial use still counts as research.

MEP Axel Voss takes the broadest position, arguing that research should be defined "by its purpose, methodology and contribution to knowledge, not by whether it is carried out by academia, public bodies or companies".

Other amendments pull in the opposite direction, with the Greens and the European Socialist Party removing references to innovation to keep the definition narrower and more focused on core research.

Knowledge Rights 21 has long argued this point. European copyright law already distinguishes commercial from non-commercial research in ways that Europe's main competitors—the US, China, Japan and Singapore—do not, making university-industry collaboration harder than necessary. A GDPR definition that keeps commercially oriented research within the boundary, as the Commission's does, offers a sounder foundation.

4. Method, and the problem of legislating intention

Another set of amendments would introduce criteria for what type of research qualifies. Proposals from the Socialists and Democrats and the Greens would require research to be methodical and systematic. Two European People's Party amendments would add that it be "creative and systematic", documented and traceable, pointing to the OECD's Frascati Manual as the standard reference for defining R&D.

Other proposals call for mandatory publication following peer review, ensuring results can be independently verified. Much of this aligns with a joint opinion from the EU's two data-protection authorities, which requested systematic methodology, independent conduct and verifiable results. Related amendments would assess research by intent, asking whether it is "genuinely intended" to produce such outcomes.

One point commands broad agreement: the Commission's text already requires research to follow the ethical standards of its field, with amendments from various MEPs adding respect for participant autonomy and consent. These are the safeguards that protect people. The danger lies in tests that a regulator or rights holder could use to second-guess whether a project is "genuine" enough—the kind of subjective judgment that discourages researchers and gives leverage to anyone seeking to restrict access to their work. Objective, method-based criteria work. Subjective tests of intention do not.

5. Autonomy and independence

A recurring theme in amendments from the Socialists and Democrats, Renew and the Greens is that research should be conducted autonomously and free from improper pressure.

A recital from the Renew group would allow commercial and private interests while requiring that data processing be kept "functionally separated from commercial monetization, tracking, or profiling." Independence is indeed a legitimate research principle worth articulating.

Applied too strictly, however, a functional-separation test could catch ordinary public-private research that EU funding policy actively promotes. Language on this point should shield researchers from interference, not treat collaboration itself as a disqualifying factor.

What the committees should hold onto

A workable definition need not be complicated. It should cover research that supports innovation and allows research institutions to partner readily with start-ups, scale-ups and industry. It should explicitly state that developing and testing AI can constitute research. It should rest on objective, method-based criteria rather than subjective judgments about researcher intent. And it should treat independence as a safeguard for researchers rather than a disqualification of their collaborators.

This closely resembles what the Commission proposed: inclusion of development and innovation, an open approach to methods, focus on overall goals, and adherence to ethical standards.

The importance of getting this right stems from the fact that the GDPR will not be the last place this definition appears. Once adopted, it could become a reference point whenever the EU legislates on research, data or copyright, since no other instrument currently offers such a definition. The two committees are not merely deciding how data-protection rules treat science. They are establishing, for the rest of EU law to draw upon, what Europe means by research.

The Omnibus is currently under negotiation in both the European Parliament and the Council of Member States, with a target of concluding the file by year's end. Given the numerous potential political flashpoints, reaching sufficient consensus may require additional time.