iStockphoto-gorodenkoffDigital Omnibus
Parliament calls for simplification without compromising safeguards
AS – 07/2026
On 22 June, the European Parliament’s Committees on Industry, Research and
Energy (ITRE) and Civil Liberties, Justice and Home Affairs (LIBE) presented
their draft report on the Digital Omnibus. The initiative aims to simplify the
EU’s digital legislation and make it easier to apply by improving the
consistency between key digital laws. The draft report proposes numerous
amendments to the Commission’s proposal and will serve as the basis for the
Parliament’s further deliberations.
Simplification – but not at the expense of data protection
The rapporteurs, Aura Salla (Finland, EPP) and Marina Kaljurand (Estonia,
S&D), support the objective of strengthening Europe’s technological
competitiveness through a more coherent and streamlined digital regulatory
framework. At the same time, they stress that simplification must not come at
the expense of the protection of personal data, which they regard as essential
for maintaining citizens’ trust in digital technologies.
In the field of the data economy, the rapporteurs welcome the Commission’s
proposal to establish a Single Entry Point as a central portal for reporting
and information obligations. However, they argue that a common portal alone
will not be sufficient. The underlying reporting requirements should also be
further harmonised, and duplicate reporting obligations across different pieces
of legislation should be eliminated in order to provide meaningful
administrative relief for businesses. While simplification measures are
generally welcomed, they should not undermine the interests of small and
medium-sized enterprises (SMEs) or weaken consumer protection.
Data protection and competitiveness dominate parliamentary debate
On 14 July, the draft report was discussed during a joint meeting of the
ITRE and LIBE Committees. For the EPP Group, Europe’s competitiveness was the central issue. Members
argued that Europe needs a more favourable regulatory environment for
artificial intelligence and easier access to data in order to remain
competitive with the United States and China. Several Members called for a
coherent, risk-based legal framework that reduces legal uncertainty arising
from the interaction between the General Data Protection Regulation (GDPR), the
AI Act, and the Data Act. At the same time, they emphasised that simplification
should primarily benefit SMEs while preserving well-established safeguards.
The S&D Group supported the objective of reducing administrative
burdens but placed particular emphasis on protecting fundamental rights.
Members warned against weakening the definition of personal data. The Renew
Europe Group focused on strengthening Europe’s digital sovereignty and
achieving the right balance between innovation and the protection of privacy.
Members of the Greens/EFA Group, by contrast, criticised what they considered
to be insufficient justification for the proposed amendments to the GDPR, the
absence of viable solutions for cookie banners, and the risk of creating
additional legal uncertainty.
In their opinions, the associated committees IMCO and JURI likewise
highlighted the importance of maintaining a high level of data protection,
carefully assessing the proposed amendments to the GDPR and the Data Act,
safeguarding consumer rights, and strengthening SMEs operating on digital
platforms.
Overall, the debate demonstrated broad support for the objective of
simplification. At the same time, Parliament made it clear that data
protection, fundamental rights and fair competition should not be sacrificed in
the pursuit of deregulation.
Relevance for social security institutions
Social security institutions process large volumes of sensitive personal
data, including information on health, employment and insurance histories. At
the same time, they increasingly rely on digital and automated procedures.
Changes to the data protection framework could therefore have a direct impact
on the design and operation of their digital administrative processes.
Under the draft report, the processing of biometric data for identity
verification would only be permitted in narrowly defined exceptional cases.
Such processing would be subject to the condition that individuals retain
control over their personal data and that high technical security standards are
met.
Furthermore, personal data should be used exclusively for the provision of
the specific value-added service for which it was collected. Its use for other
purposes—particularly advertising, profiling or the training of artificial
intelligence systems—should be prohibited.
The rapporteurs also oppose any limitation of individuals’ rights under
data protection law. In particular, the right of access under the GDPR and the
fundamental right to the protection of personal data enshrined in Article 8 of
the Charter of Fundamental Rights of the European Union should remain fully
safeguarded in the context of simplification. Automated individual
decision-making must likewise not undermine the rights of data subjects.
Council remains divided – discussions continue
During the next stage of the legislative process, the political groups in
the European Parliament will table amendments before entering into
negotiations.
In the Council, however, Member States were unable to reach agreement on a
general approach at the meeting of 26 June. According to information from the
negotiations, significant differences remain regarding both the scope of the
proposed simplification measures and specific amendments relating to data
protection and cybersecurity legislation. Discussions will therefore continue
under the Irish Presidency of the Council.