Parliament calls for simplification without compromising safeguards

AS – 07/2026

On 22 June, the European Parliament’s Committees on Industry, Research and Energy (ITRE) and Civil Liberties, Justice and Home Affairs (LIBE) presented their draft report on the Digital Omnibus. The initiative aims to simplify the EU’s digital legislation and make it easier to apply by improving the consistency between key digital laws. The draft report proposes numerous amendments to the Commission’s proposal and will serve as the basis for the Parliament’s further deliberations.

Simplification – but not at the expense of data protection

The rapporteurs, Aura Salla (Finland, EPP) and Marina Kaljurand (Estonia, S&D), support the objective of strengthening Europe’s technological competitiveness through a more coherent and streamlined digital regulatory framework. At the same time, they stress that simplification must not come at the expense of the protection of personal data, which they regard as essential for maintaining citizens’ trust in digital technologies.


In the field of the data economy, the rapporteurs welcome the Commission’s proposal to establish a Single Entry Point as a central portal for reporting and information obligations. However, they argue that a common portal alone will not be sufficient. The underlying reporting requirements should also be further harmonised, and duplicate reporting obligations across different pieces of legislation should be eliminated in order to provide meaningful administrative relief for businesses. While simplification measures are generally welcomed, they should not undermine the interests of small and medium-sized enterprises (SMEs) or weaken consumer protection.

Data protection and competitiveness dominate parliamentary debate

On 14 July, the draft report was discussed during a joint meeting of the ITRE and LIBE Committees. For the EPP Group, Europe’s competitiveness was the central issue. Members argued that Europe needs a more favourable regulatory environment for artificial intelligence and easier access to data in order to remain competitive with the United States and China. Several Members called for a coherent, risk-based legal framework that reduces legal uncertainty arising from the interaction between the General Data Protection Regulation (GDPR), the AI Act, and the Data Act. At the same time, they emphasised that simplification should primarily benefit SMEs while preserving well-established safeguards.


The S&D Group supported the objective of reducing administrative burdens but placed particular emphasis on protecting fundamental rights. Members warned against weakening the definition of personal data. The Renew Europe Group focused on strengthening Europe’s digital sovereignty and achieving the right balance between innovation and the protection of privacy. Members of the Greens/EFA Group, by contrast, criticised what they considered to be insufficient justification for the proposed amendments to the GDPR, the absence of viable solutions for cookie banners, and the risk of creating additional legal uncertainty.


In their opinions, the associated committees IMCO and JURI likewise highlighted the importance of maintaining a high level of data protection, carefully assessing the proposed amendments to the GDPR and the Data Act, safeguarding consumer rights, and strengthening SMEs operating on digital platforms.

Overall, the debate demonstrated broad support for the objective of simplification. At the same time, Parliament made it clear that data protection, fundamental rights and fair competition should not be sacrificed in the pursuit of deregulation.

Relevance for social security institutions

Social security institutions process large volumes of sensitive personal data, including information on health, employment and insurance histories. At the same time, they increasingly rely on digital and automated procedures. Changes to the data protection framework could therefore have a direct impact on the design and operation of their digital administrative processes.


Under the draft report, the processing of biometric data for identity verification would only be permitted in narrowly defined exceptional cases. Such processing would be subject to the condition that individuals retain control over their personal data and that high technical security standards are met.


Furthermore, personal data should be used exclusively for the provision of the specific value-added service for which it was collected. Its use for other purposes—particularly advertising, profiling or the training of artificial intelligence systems—should be prohibited.


The rapporteurs also oppose any limitation of individuals’ rights under data protection law. In particular, the right of access under the GDPR and the fundamental right to the protection of personal data enshrined in Article 8 of the Charter of Fundamental Rights of the European Union should remain fully safeguarded in the context of simplification. Automated individual decision-making must likewise not undermine the rights of data subjects.

Council remains divided – discussions continue

During the next stage of the legislative process, the political groups in the European Parliament will table amendments before entering into negotiations.

In the Council, however, Member States were unable to reach agreement on a general approach at the meeting of 26 June. According to information from the negotiations, significant differences remain regarding both the scope of the proposed simplification measures and specific amendments relating to data protection and cybersecurity legislation. Discussions will therefore continue under the Irish Presidency of the Council.