News

Will the Digital Omnibus Actually Pass? A Quick Reality Check

Will the Digital Omnibus Actually Pass? A Quick Reality Check

The European Commission published the Digital Omnibus package on November 19, 2025. This ambitious initiative aims to update several existing digital laws, including the GDPR, with the goal of reducing administrative burdens, encouraging innovation, and accelerating AI innovation across Europe. The Commission has a dual goal: easing what it considers overly burdensome obligations for organizations, while also strengthening European competitiveness against the U.S. and China.

Behind this “regulatory cleanup” lie deep changes in how sensitive data is handled, particularly in healthcare and health research. The proposal aims to clarify key notions and simplify obligations specifically for smaller businesses, but the protection of personal data is being redefined, creating new areas of uncertainty.

The text still needs to go through the European Parliament and Member States, with debates expected to intensify from 2026. For Life Sciences stakeholders, anticipating and preparing for these changes is crucial to protect patients while remaining compliant.

The publication of the Digital Omnibus package marks a pivotal moment: it aims to reshape how personal data, and especially health data, will be handled. As frontline experts, we share our analysis, flag potential risks, and reaffirm our commitment to protecting patients and clients.

Our aim with this article is to share our expert perspective, highlight potential risks, and reaffirm our commitment to the Life Sciences sector.

Life Sciences on the Frontline

This reform goes beyond administrative matters. It represents a strategic and operational turning point where simplification must be paired with strong patient protection. While the recitals are filled with good intentions about improving the GDPR framework, very little of this is actually translated into the substance of the proposed amendments. Five areas deserve close attention:

Redefining “personal data” and new conditions for processing “sensitive data”:

The reform introduces a contextual approach to identifiability: data may fall outside the GDPR when an organization has no means reasonably likely to re-identify the individual. The proposal narrows the notion of health data to information that directly reveals health status. This creates grey zones where pseudonymized elements (technical IDs, device identifiers, study codes) might be treated as non-personal. If data are considered outside the Regulation, mandatory IT-security, breach notification and accountability requirements would no longer apply, exposing both organizations and individuals to greater risk. Yet in clinical research, pseudonymized datasets remain highly re-identifiable even without access to the key, because auxiliary information, rare disease patterns, genomic structure, timelines or linkage with leaked databases can allow identity reconstruction. Past cybersecurity breaches have repeatedly shown that pseudonymized datasets, sometimes far less detailed than clinical trial data, were successfully re-identified once exposed. By suggesting that parts of these datasets could be “non-personal”, the reform risks giving researchers false expectations and may prematurely lower protection standards in environments where re-identification risk is structurally high. For patients, this could mean a tangible weakening of safeguards at a time when cyberattacks on health and research infrastructures are steadily increasing.

The reform would broaden the legitimate interest basis, allowing AI models to be developed and trained on personal data without explicit consent under certain conditions. This requires revising impact assessments, contracts, and data governance while maintaining strict safeguards to prevent misuse.

Reducing operational burden:

Some obligations, such as breach notifications, informing individuals, and conducting impact assessments, would be simplified or clarified, easing daily compliance. While beneficial, these measures must not weaken patient protection if misapplied.

Extending and strengthening simplification measures so that small businesses and start-ups:

Simplification measures for small businesses are welcome; yet in Life Sciences, small biotechs acting as clinical-trial sponsors and start-ups developing health apps often handle exceptionally sensitive datasets (including genomic data) and cannot be treated as low-risk by default.

Cookies and banner:

The reform proposes reducing, or even removing, some cookie banners. Certain trackers could be used without prior consent. In healthcare, this raises questions: how can true transparency be ensured? How will this interact with ePrivacy rules? How can misuse be prevented?

AI Requirements, significant adjustments:

Requirements for high-risk AI systems could be postponed by 1-2 years, giving stakeholders more preparation time. Training AI models on personal data without explicit consent would be allowed under certain conditions.

These changes could have tangible effects: more AI projects in healthcare, increased pressure on the availability and quality of patient datasets, and greater risks if safeguards are not maintained alongside these relaxations.

Our position

YES to operational simplification. In principle, we fully support the goal of simplification especially for non-sensitive businesses. Reducing complexity, harmonizing requirements, and streamlining documentation are necessary steps forward for the Life Sciences sector as well: our clients face a heavy administrative burden on a daily basis, which can hinder innovation and scientific research. These measures will streamline clinical trials, accelerate cross-border procedures, and strengthen collaboration between stakeholders, giving more time and flexibility to focus on scientific projects. More readable and effective regulation is essential to support sustainable and responsible innovation in Europe, and this is a goal we fully support.

NO to lowering patient data protection. Simplification must never mean weakening protection. For MyData-TRUST, protecting patients and their data remains non-negotiable. We identify several major risks. First, a decline in protection: after years of efforts to harmonize the application of the GDPR, the rapid introduction of this Digital Omnibus could create legal gray areas, generate divergent interpretations, and increase risks for patients. The limited and rushed consultation process does not allow for the specific requirements related to health data, which require caution, expertise, and a long-term vision. Simplification cannot be used as a pretext for disguised deregulation. For us, each measure must be assessed in terms of patient safety and trust in healthcare systems, and not solely on the basis of administrative efficiency or competitiveness.

NO to missing the opportunity to design a data-protection framework that both stimulates responsible research and protects patients. Aside from defining scientific research and clarifying the presumption of compatibility for secondary use, none of the other recital promises (such as transparency, harmonization of research conditions, or workable indirect information mechanisms) are actually implemented in the proposed GDPR amendments.

While it could make sense for non-sensitive businesses, the real question humming in everyone’s inbox is simple: Does this thing actually stand a chance of being adopted?

Why it could pass? ✅

Political appetite for simplification: EU institutions have been drowning in regulatory patchwork for years. Businesses complain, regulators groan, legal teams weep. A tidy consolidation is politically attractive, it signals efficiency without shouting “deregulation.”

Strong support from powerful lobbies: There is strong support from major digital-market actors, who have long called for greater coherence, signals that tend to carry weight in EU policymaking. As AI momentum intensified and the fear of falling behind grew, these voices gained even more prominence… When business lobbies and innovation-minded Member States cheer, EU lawmakers tend to listen.

Timing works in its favor: With the next political cycle pushing digital competitiveness as a priority, an Omnibus promising clarity lands at the perfect moment. Brussels loves a good “future-proofing” narrative.

Why it could crash and burn? 🔥

Civil-rights groups are on high alert: Privacy orgs and digital-rights advocates are already ringing the alarm bell about possible rollbacks, from weakened safeguards to vaguer definitions of personal data. If they succeed in framing the Omnibus as a threat to rights, Parliament might get skittish.

The EDPB’s interpretation of identifiability is already extremely strict. In Life Sciences, even coded datasets are often not considered as effectively pseudonymized. EDPB’s opinion could strongly influence how the final text is shaped.

Member States don’t vibe with all the same priorities: Some want lighter rules for innovation; others treat data protection like a sacred text. Anything touching GDPR-adjacent territory triggers passionate monologues and very long negotiation nights.

The file is huge: The Omnibus isn’t a tweak, it’s a regulatory remix album. The more articles it touches, the more veto points it creates. Big files can get slowed, sliced, or quietly “reconsidered” (EU code for: bye).

And here’s the uncomfortable question hanging in the Brussels air: at a time when data-protection laws worldwide are getting stricter (from Brazil to California to India), would the EU really choose this moment to backpedal?

So… Will it pass?

The proposal is credible, politically anchored, and backed by influential actors. But it’s likely to emerge from the legislative oven heavily amended, trimmed, softened, or with protective layers re-added after negotiations.

Expect a long dance (not a sprint) and a final law that still looks like the Digital Omnibus, but… after a makeover, three compromises, and a few “constructive trilogue dialogues.”

Next steps

The text must still pass through the European Parliament and Member States, with debates expected from 2026. MyData-TRUST will monitor these developments closely, focusing on patient protection, AI project compliance, and impacts on R&D and operations across the sector.

Let’s connect

Are you a sponsor, CRO, hospital, biotech, medtech, or another Life Sciences stakeholder?
Our expert teams are ready to help you navigate the Omnibus implications and ensure compliance in this evolving context.

MyData-TRUST: who are we?

MyData-TRUST is a consulting firm specializing in Data Protection for the Life Sciences sector. Since 2017, we have supported clinical trial sponsors, laboratories, biotechs, CROs, medtechs, and hospitals in securing sensitive data and ensuring regulatory compliance. Our strength lies in our multidisciplinary team, hands-on expertise in clinical trials, R&D, and AI, an international presence, and an approach focused on flexibility and robust project security.