The European Commission has released the Digital Omnibus proposal, introducing a narrower definition of personal data (Art. 4(1)), a broader research exemption (Arts. 4(38), 5(1)(b), 13, 89), and new AI‑related rules (Arts. 9(2)(k), 9(5), 88c). It also limits the right of access (Arts. 12, 15), adds an SME exemption from privacy policies (Art. 13), and revises access to terminal equipment under the ePrivacy rules (Arts. 88a, 88b, 5(3)).
Why it matters: The proposal could significantly reshape GDPR obligations across the EU, affecting data controllers, processors, and AI developers.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.