Skip to main content

Nixon Peabody LLP

  • People
  • Capabilities
  • Insights
  • About
Trending Topics
    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    • Contact Us
    Practices

    View All

    • Affordable Housing
    • Community Development Finance
    • Corporate & Finance
    • Cybersecurity & Privacy
    • Entertainment & Media
    • Environmental
    • Franchising & Distribution
    • Government Investigations & White Collar Defense
    • Healthcare
    • Intellectual Property
    • International Services
    • Labor, Employment, and Benefits
    • Litigation
    • Private Wealth & Advisory
    • Project Finance
    • Public Finance
    • Real Estate
    • Regulatory & Government Relations
    Industries

    View All

    • Aviation
    • Cannabis
    • Consumer
    • Energy
    • Financial Services
    • Healthcare
    • Higher Education
    • Infrastructure
    • Manufacturing
    • Nonprofit Organizations
    • Real Estate
    • Sports & Stadiums
    • Technology
    Value-Added Services

    View All

    • Alternative Fee Arrangements

      Developing innovative pricing structures and alternative fee agreement models that deliver additional value for our clients.

    • Continuing Education

      Advancing professional knowledge and offering credits for attorneys, staff and other professionals.

    • Crisis Advisory

      Helping clients respond correctly when a crisis occurs.

    • DEI Strategic Services

      Providing our clients with legal, strategic, and practical advice to make transformational changes in their organizations.

    • eDiscovery

      Leveraging law and technology to deliver sound solutions.

    • Environmental, Social, and Governance (ESG)

      We help clients create positive return on investments in people, products, and the planet.

    • Global Services

      Delivering seamless service through partnerships across the globe.

    • Innovation

      Leveraging leading-edge technology to guide change and create seamless, collaborative experiences for clients and attorneys.

    • IPED

      Industry-leading conferences focused on affordable housing, tax credits, and more.

    • Legal Project Management

      Providing actionable information to support strategic decision-making.

    • Legally Green

      Teaming with clients to advance sustainable projects, mitigate the effects of climate change, and protect our planet.

    • Nixon Peabody Trust Company

      Offering a range of investment management and fiduciary services.

    • NP Capital Connector

      Bringing together companies and investors for tomorrow’s new deals.

    • NP Second Opinion

      Offering fresh insights on cases that are delayed, over budget, or off-target from the desired resolution.

    • NP Trial

      Courtroom-ready lawyers who can resolve disputes early on clients’ terms or prevail at trial before a judge or jury.

    • Social Impact

      Creating positive impact in our communities through increasing equity, access, and opportunity.

    • Women in Dealmaking

      We provide strategic counsel on complex corporate transactions and unite dynamic women in the dealmaking arena.

    1. Home
    2. Insights
    3. Alerts
    4. EU Digital Omnibus proposal will change AI, data, and cyber compliance

      Alerts

    Alert / Technology

    EU Digital Omnibus proposal will change AI, data, and cyber compliance

    Dec 9, 2025

    LinkedInX (Twitter)EmailCopy URL

    The proposal aims to reshape GDPR, AI Act, cookies, cloud, and cybersecurity rules—learn what could change and how to prepare for EU compliance.

    What’s the impact?

    • European Commission seeks big-picture changes across privacy, AI, cookies, cloud, and cybersecurity regulations.
    • Proposed changes include clearer rules, simpler processes, and more predictable timelines for teams responsible for compliance.
    • Businesses can prepare by prioritizing what to fix now and assessing what to plan for later.

    DOWNLOAD

    EU Digital Omnibus proposal will change AI, data, and cyber compliance (PDF)

    Authors

    • Troy Lieberman

      Counsel
      • Office+1 617.345.1306
      • tlieberman@nixonpeabody.com
      Troy Lieberman

    The European Commission recently announced its “Digital Omnibus” proposal, a sweeping package to recalibrate and streamline the EU’s digital regulatory landscape. The legislation is designed to encourage innovation and reduce administrative burden and would impact cornerstone EU laws on AI, data protection, data sharing, cloud portability, platform regulation, cybersecurity, and product safety, including the GDPR, ePrivacy rules, the Data Act, cybersecurity reporting regimes, and the implementation timeline for the EU AI Act.

    While the Digital Omnibus remains at the proposal stage and will evolve through the legislative process, it offers clear insight into the Commission’s regulatory direction: simplifying overlapping obligations, introducing risk-based flexibility, and aligning AI compliance timelines with technical standards. It is a very positive development for businesses that are operating or are planning to operate in the EU and should be closely monitored as it evolves in the legislative process.

    This alert outlines practical impacts for businesses, based on the proposal as published.

    GDPR adjustments: Clearer scope, more flexibility for AI development

    The proposal suggests targeted amendments to the GDPR that could impact how companies classify data, build AI models, and manage individual rights requests, including:

    REFINED DEFINITION OF “PERSONAL DATA”

    Data that cannot be linked back to an individual without additional information possessed and that cannot be reasonably obtained, may fall outside the scope of GDPR. This may expand the categories of analytics and measurement data treated as non-personal but will largely depend on technical and organizational measures.

    LEGITIMATE INTEREST BASIS FOR AI DEVELOPMENT

    AI development and operation can serve as legitimate interests, with safeguards. Certain uses of special-category data for AI development may also be permitted under defined conditions. Thus, businesses relying on EU data to train or improve models could gain a more predictable legal basis, but robust governance and documentation would still be necessary.

    ABILITY TO DECLINE “ABUSIVE” OR ILL-MOTIVATED REQUESTS

    Controllers could more easily refuse data subject access requests (DSARs) used for purposes unrelated to data protection. This potentially reduces resource strain, but companies would need clear internal criteria and consistent processes.

    SIMPLIFIED PRIVACY NOTICE OBLIGATIONS FOR LOW-RISK PROCESSING

    Certain low-risk, contextual processing operations may no longer require full notice delivery. This provides opportunities to streamline employee and customer-facing disclosures without changing core compliance controls.

    ePrivacy and cookies: Additional consent exemptions for low-risk uses

    The proposal would partially align ePrivacy cookie rules with the GDPR’s risk-based approach, including:

    • Expanded categories of cookies/trackers permitted without consent (e.g., certain aggregated analytics, security-related tools)
    • Streamlined treatment for low-intrusion technologies

    Businesses may be able to reduce banner complexity and increase reliance on exempt analytics practices. Consent-based advertising, profiling, and cross-site tracking would remain unchanged.

    Data Act adjustments: Trade-secret protection and cloud switching relief

    The proposal includes refinements aimed at addressing business concerns raised since the Data Act’s adoption, including:

    • Stronger mechanisms to protect trade secrets when responding to data access or sharing requests
    • Exemptions from cloud switching requirements for certain custom-built services and for smaller providers

    Data holders would gain clearer grounds for declining or conditioning data-sharing requests that pose confidentiality risks. Cloud migration obligations may become more manageable, but companies should still expect detailed contract and technical-architecture reviews.

    Cybersecurity: Toward a single incident-reporting portal

    The proposal aims to streamline overlapping reporting obligations across GDPR, NIS2, DORA, and other cybersecurity statutes, including:

    • One EU-level “front door” for incident notifications
    • Extension of the GDPR breach reporting timeline from 72 to 96 hours

    This could materially simplify crisis-response workflows. Companies should expect to update playbooks, escalation paths, and tooling well before a unified portal is operational.

    AI Act timelines and governance: More time, more risk-based activation

    The separate Digital Omnibus on AI proposes to adjust dates and governance structure for the EU AI Act, including:

    • Delayed activation of high-risk AI obligations, tied to the availability of technical standards or Commission guidance, with backstop dates
    • Additional grace periods for certain legacy and pre-August-2026 generative AI systems
    • Expanded ability to process limited sensitive data for bias detection and mitigation
    • Clarification that some systems reclassified as non-high-risk need not be entered in the EU database (but must still maintain documentation)
    • Greater central role for the EU AI Office in oversight of general-purpose AI and high-impact use cases

    Businesses should anticipate more flexibility in structuring compliance programs but also more operational reliance on forthcoming standards, guidance, and engagement with the AI Office. This is a strong signal to invest in internal AI governance frameworks that can adapt to multiple implementation timelines.

    European Business Wallet: Streamlining digital identity across the EU

    The package also includes a proposed European Business Wallet, extending the EU digital identity framework to companies, including:

    • A unified digital identity to authenticate with EU authorities
    • Potential integration with regulatory filings, incident reporting, licensing processes, and cross-border compliance workflows

    Businesses with multinational EU operations may ultimately treat the Business Wallet as a foundational identity layer for regulatory interactions.

    What businesses should do now

    Even at this preliminary stage, businesses should explore several steps:

    REASSESS DATA TAXONOMY AND PSEUDONYMIZATION DESIGNS

    If the definition of personal data evolves, your ability to rely on it will hinge on the strength of your data maintenance, technical separation of identifiers, and access controls.

    UPDATE AI COMPLIANCE ROADMAPS WITH ALTERNATIVE TIMELINES

    Build “baseline” and “Omnibus-adjusted” scenarios for high-risk AI implementation and documentation.

    REVIEW DSAR, NOTICE, AND COOKIE WORKFLOWS

    Identify where resource-intensive processes could be simplified under the proposed amendments—without altering current compliance until the rules stabilize.

    RE-EVALUATE DATA ACT AND CLOUD TRANSITION STRATEGIES

    Revisit contracting, vendor management, and data-sharing playbooks to align with potential exemptions around trade secrets and cloud switching.

    PREPARE FOR CONSOLIDATED INCIDENT REPORTING

    Legal, privacy, and security teams should begin exploring unified reporting models that could be adapted quickly once an EU portal becomes available.

    MONITOR LEGISLATIVE NEGOTIATIONS CLOSELY

    The specific proposals are likely to shift, but the direction is clear: simplification, risk-based flexibility, and standard-driven AI implementation.

    Practices

    Cybersecurity & PrivacyCorporate & FinanceMergers, Acquisitions, and Corporate Transactions International ServicesEuropean Union

    Industries

    TechnologyConsumer

    Insights And Happenings

    • Alert

      CMS announces new value based payment model for technology-enabled care

      Dec 3, 2025
    • Video

      Protecting AI innovations: Patents vs. trade secrets

      Artificial Intelligence IP
      Oct 24, 2025
    • Article

      Conducting a health check on cloud-based supplier agreements in light of the AWS outage

      Oct 22, 2025
    The foregoing has been prepared for the general information of clients and friends of the firm. It is not meant to provide legal advice with respect to any specific matter and should not be acted upon without professional counsel. If you have any questions or require any further information regarding these or other related matters, please contact your regular Nixon Peabody LLP representative. This material may be considered advertising under certain rules of professional conduct.

    Subscribe to stay informed of the latest legal news, alerts, and business trends.Subscribe

    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    • Contact Us
    • Cookie Preferences
    • Privacy Policy
    • Terms of Use
    • Accessibility Statement
    • Statement of Client Rights
    • Purchase Order Terms & Conditions
    • Nixon Peabody International LLP
    • PAL
    © 2025 Nixon Peabody. All rights reserved