October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

European Commission Proposes Looser GDPR Rules for AI and Cookies—But Most Changes Are Not Law Yet

The European Commission’s Digital Omnibus could reshape AI training rules and reduce cookie-banner fatigue, but its GDPR and cookie reforms are still proposals. The separate AI Omnibus is already in force—and is not the same law.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The European Commission has proposed changes that could make some AI-data processing and cookie controls easier, but it has not yet rewritten the GDPR. The November 19, 2025 Digital Omnibus remains subject to the EU legislative process. For businesses and consumers, existing GDPR and cookie rules remain the practical baseline.

The short version

  • The Commission proposed the Digital Omnibus on November 19, 2025.
  • The package would amend parts of the GDPR and ePrivacy-related cookie rules.
  • It could clarify when companies may use personal data for AI development or training, including under a legitimate-interest analysis.
  • It could create clearer exemptions for some low-risk cookies and device-access operations and support browser-level privacy preferences.
  • Those GDPR and cookie changes are proposals—not a current exemption from European privacy law.
  • A separate AI Omnibus entered into force on July 27, 2026. That does not mean the GDPR and cookie reforms were also adopted.

What the Commission proposed

The Digital Omnibus is a broad simplification package, not a single “GDPR rollback.” Its data-related measures would amend the GDPR and move or align parts of the ePrivacy framework, including rules governing cookies and access to information stored on a user’s device.

The Commission says the goal is to reduce duplicated paperwork, improve legal certainty and help European companies compete without lowering fundamental-rights protections. It estimated that the wider package could reduce administrative costs by up to €5 billion by 2029. That is the Commission’s forecast, not an independently measured saving. Commission announcement

The proposed package includes targeted GDPR amendments, simplified documentation and compliance mechanisms, clarification around pseudonymised or difficult-to-identify information, and possible rules for machine-readable privacy choices. The important distinction is between administrative simplification—such as standardised forms—and substantive changes to when companies may process personal data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What could change for AI training?

The proposal should not be read as “AI companies can now train on personal data without consent.” Instead, it seeks to clarify when existing GDPR legal bases, potentially including legitimate interest, could support certain AI-development and training activities.

Under the Commission’s explanation, processing would still need to comply with the GDPR and applicable EU or national law. That means companies would still need to assess necessity and proportionality, provide appropriate transparency, apply safeguards and respect relevant data-subject rights, including the right to object where it applies. Commission Digital Package FAQ

That distinction matters. Legitimate interest is not automatic permission. A company generally needs to identify a genuine interest, show that the processing is necessary, balance it against individuals’ rights and freedoms, and provide information and safeguards. Sensitive personal data creates additional restrictions.

The questions AI companies would still need to answer

  • Is the information personal data, including when several data points could identify someone indirectly?
  • Does pseudonymisation reduce risk without removing the information from GDPR coverage?
  • What is the precise purpose: scraping, dataset creation, pre-training, fine-tuning, evaluation, retrieval, synthetic-data generation or user profiling?
  • Is the processing necessary for that purpose, or could a less intrusive dataset be used?
  • How will people be informed and exercise access, erasure, restriction or objection rights?
  • Are special categories of data present, deliberately or accidentally?
  • How long will the data be retained, who receives it and where is it processed?
  • Can the company document its reasoning and respond to regulators?

Publicly accessible information is not automatically free of privacy obligations. Information found online can still be personal data, and pseudonymised data can remain personal data where re-identification is reasonably possible. The proposal’s final wording will determine how much additional certainty AI developers receive and whether that certainty changes practical compliance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What could change for cookies and tracking?

The Commission proposed bringing rules currently associated with Article 5(3) of the ePrivacy Directive into a more unified GDPR framework. Some low-risk storage or device-access operations could receive clearer exemptions, while higher-risk activities would still require consent or another legally valid route. Commission strategy document

The stated aim is to reduce “consent fatigue”: the endless succession of banners and repeated requests that users encounter across websites. The package contemplates simpler, potentially one-click choices, stronger respect for recorded preferences and machine-readable signals from browsers, operating systems, plug-ins or similar tools.

But fewer banners would not necessarily mean unrestricted tracking. The legal result would depend on which operations qualify as low risk and whether analytics, advertising, personalisation or profiling remain subject to affirmative choice. A cookie is also not automatically harmless: the regulatory analysis concerns both access to a device and the subsequent processing of information.

Browser-level privacy signals remain unsettled

The Commission proposed mechanisms through which a browser, operating system or similar service could communicate a user’s consent or objection. Council compromise material published in April 2026 discussed obligations for providers transmitting those signals and limits on using choice data for unrelated purposes. Council compromise material

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The final form of that mechanism remained subject to negotiations. It is therefore too early to say that cookie banners will disappear or that every website will have to accept a particular browser setting. The unresolved issues include interoperability, default choices, user comprehension and whether a technical signal represents an informed choice for each purpose.

Why some critics call the proposal a GDPR rollback

The Commission describes the package as targeted simplification, harmonisation and legal certainty while preserving data-protection standards. Privacy advocates and some policy analysts take a different view.

Their concern is that a framework can become materially less protective even if its headline principles remain intact. Potential pressure points include broader exceptions for device access, greater reliance on legitimate interest for AI activity, a narrower practical understanding of personal data, and the transfer of privacy controls to browsers or large technology platforms.

The European Parliament’s research service distinguishes administrative simplification from possible substantive recalibration of safeguards across data, privacy, cybersecurity and AI. European Parliament research study Whether the package is a rollback therefore depends on its final text and its practical effect—not simply on the Commission’s description or its critics’ headline.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What has actually become law?

Measure Status Practical meaning
Digital Omnibus GDPR and cookie reforms Proposed and under negotiation Do not treat the proposal as a current exemption.
Council compromise work Negotiations continued in 2026 Compromise language is not the same as a final, effective law.
Separate AI Omnibus Entered into force July 27, 2026 Changes AI Act implementation and administration; it does not automatically enact the GDPR or cookie reforms.

The separate AI Omnibus was proposed alongside the wider digital package, received political agreement in May 2026 and entered into force on July 27, 2026. European Commission: AI Omnibus enters into force Its adoption should not be reported as proof that the data and privacy provisions have also become law. The European Parliament’s material continued to describe the broader Digital Omnibus as a proposal. European Parliament answer

What businesses should do now

  1. Keep following current law. Continue applying the existing GDPR, cookie and device-access rules until any amendments are formally adopted and become applicable.
  2. Do not implement proposed exemptions early. A Commission proposal is not a legal safe harbour.
  3. Map AI data across its lifecycle. Review scraping, dataset construction, training, fine-tuning, evaluation, retrieval and deployment—not just model training.
  4. Document legal bases and safeguards. For legitimate-interest processing, record the purpose, necessity analysis, balancing assessment, transparency measures and objection process.
  5. Check for sensitive data. Accidental inclusion in large datasets can create obligations that a general AI-training policy does not solve.
  6. Audit consent technology. Verify that tags are blocked or permitted according to current choices, withdrawals are honoured and records are retained appropriately.
  7. Prepare without assuming. Consent-management systems may eventually need to process machine-readable signals, but companies should not assume a particular signal is already mandatory.
  8. Track the final text. Pay attention to definitions of low-risk operations, pseudonymised data, AI purposes, transition periods and regulator powers.

A consent-management platform can display choices, record preferences, block tags and support withdrawals. It cannot make unlawful processing lawful. The controller remains responsible for the legal basis, notices, contracts, retention, security and actual tracker configuration.

What users may notice

If the proposal is adopted in a similar form, users could see fewer repetitive banners, more persistent browser-level preferences and fewer prompts for genuinely low-risk technical operations. They could also encounter more processing justified through legitimate interest, making clear explanations and easy objection mechanisms especially important.

For now, users should not assume that a smaller banner means less data collection. Check whether a site is asking about analytics, advertising, personalisation or only essential functionality. Existing rights to information, access, deletion, restriction and objection continue to depend on the current law and the specific processing activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The open questions

  • How broad will the final AI-training provisions be?
  • How will pseudonymised and difficult-to-identify data be treated?
  • Which cookie and device-access operations will qualify as low risk?
  • Will browser or operating-system signals be required, and how will defaults work?
  • Will advertising and profiling still require affirmative consent?
  • What transition periods will apply?
  • Will national data-protection authorities retain their existing enforcement role?
  • How will the final rules interact with the AI Act, copyright law, the Data Act, national law and future ePrivacy changes?

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.