This year’s BigBrotherAward in the “EU” category goes to
the European Commission
for the “Digital Omnibus”. This legal package is part of the “deregulation agenda” – a term that sounds as harmless as “restructuring” or “efficiency improvements”. And that is no coincidence. Because behind this term is the largest assault on European data protection standards since the General Data Protection Regulation1 was passed.
What is this about – and why is it called an “omnibus”?
The EU Commission has initiated an agenda of 13 “omnibus” packages in total.2 These are called “omnibus” because each package changes not just one, but several regulations and directives at once. It is described as removing burdens from business. But in fact, the substance of protective rights is being hollowed out in critical places – not just with respect to climate protections or supply chains, but also in the realm of data protection.
The Omnibus VII, the so-called “Digital Omnibus”3, alters nine pieces of legislation and abolishes four of them. This ranges from the Open Data Directive via the Data Governance Act to none other than the GDPR. This is why it has been given the hilarious moniker of the “Big Beautiful Data Bill”.
These changes reach the very heart of European data protection law – the definition of what is to be treated as “personal” data. This definition has never been simple – but the principle was: If anyone were able to identify a person from the data, then this data is personal and therefore protected.
It does not matter here if someone can find the name or date of birth, or in other words, the civil identity. It is enough if it were possible to subsequently recognise that this is the same person, for example through a browser cookie. This is called “singling out” – and it makes it possible to connect the data to a person, even without their name. We clarified this in the GDPR at the time.4
The Commission now wants to transform this principle into a “relative” concept: The same data is to be regarded as personal for one organisation, but not for another – depending on who is holding the data at any given time.5 Lobbyists from the advertising industry have publicly admitted that with this new definition, they will finally be able to stop treating their tracking cookies and advertising IDs as personal data. Online services will be able to say: “We cannot identify the subscriber behind an IP address, so data protection law simply doesn’t apply to us anymore.”
And the Commission wants to also empower itself to decide, via implementing acts, whether pseudonymised data can suddenly be regarded as anonymous – and therefore, where data protection law still applies and where it does not.6
Information refusal rights
With regard to data subject’s information rights – one of the fundamental rights through which affected persons can find out what a company actually knows about them – the Commission also intends to turn an important dial. Even today, companies can refuse information requests that are clearly unfounded. What is new is that an “abuse” of information rights is to be added as grounds for refusal.7
According to the Commission, “abuse” would already exist if the data were subsequently used for other purposes. For example, trade unions have used information requests to determine how much overtime an employee has logged. Of course the purpose was not to verify conformity with data protection but to press for the payment of overtime. To label this as abuse is just impudent. Especially since Article 8 of the Charter of Fundamental Rights of the European Union does not provide for such a purpose limitation of information rights in any way.8
Big Data and AI above all else?
The Commission also wants to classify the training of “artificial intelligence” with personal data as a “legitimate interest” of the processing party. This means it would no longer be necessary to ask the affected persons for their permission.9
And the privilege of research is to be expanded practically without limits. According to the GDPR, data that already exists can be subsequently processed for scientific research or statistical analyses. The Commission is now suggesting a definition of “scientific research” that would make anything that somehow facilitates innovation fall under this umbrella. It would not even be necessary to generate any new knowledge. Applying existing knowledge to new places would suffice.10
If, for example, an existing AI model were used in a new context, this would already qualify as “scientific research” and it would be allowed to process personal data for this purpose without any further permission from the affected persons. There is no mention of scientific standards like peer review and no requirement to publish results. It’s only about the mantra of “innovation”.
Maladministration
How does the Commission justify all this? By pointing to “competitiveness”. European businesses are to be supported in the global race against the USA and China, according to the report of former European Central Bank president Mario Draghi on European competitiveness from 2024.11 We can observe an increasing radicalisation taking place. “Competitiveness” was turned into “simplification”, but Commission President Ursula von der Leyen now talks openly about “deregulation”.12 That sounds like a reduction of bureaucracy at first, but it is about abolishing rules that we introduced to protect our fundamental rights – such as the General Data Protecton Regulation. I would like to point to the BigBrotherAward on “cutting bureaucracy” and the award speech by Rena Tanges from last year.13
How all of this is supposed to help European businesses against the competition from the USA or China, who would be affected by the same relaxation of rules, even European companies themselves are not able to explain. What lies behind this is massive lobbying pressure from Big Tech and the Trump administration. And, sadly, it is working. According to the EU transparency register14, the lobbying budget for this amounted to 150 million in 2025 alone. Statistically there was more than one visit per day by Big Tech lobbyists to the European Commission.15
The strategy is remarkable in itself: Although fundamental pillars of European data protection law are to be dismantled, the Commission has not put forward an impact assessment, as they normally would. And the public consultation, which was open until a year ago, only asked about cookie banners that are now at least due to be reined in.16 There was no word anywhere about the definition of “personal data”, about “scientific research” or an “abuse” of information rights. The EU ombudsperson, Teresa Anjinho has already talked about “maladministration” in this context.17
Where do we stand?
The impact of this agenda will not be limited to Europe alone. The so-called “Brussels effect”18 has in past years caused countries from Japan to Brazil to align their own data protection law with the role model of the GDPR. If European Standards were to be razed to the ground, it will not only be people in Europe who will lose their protections – the effect will probably be felt across the world.
A broad alliance of NGOs, trade unions, environmental and human rights groups – from European Digital Rights via the Lithuanian police union to bee-keeping associations – has now stepped up to confront this agenda – whether it is about digital rights, climate protections or responsibilities across full supply chains.19 We will see if this resistance will suffice to stop what is currently being negotiated under the friendly guise of “simplification”.
The negotiations in the European Parliament have just started, about 1000 amendments have been tabled just for the data protection part of the Omnibus package.20 The Council of Ministers has made much more progress. According to recent leaks21, the current Irish Presidency of the Council is living up to its reputation. It has long been known to be extremely friendly towards Big Tech.
The “Digital Omnibus” therefore threatens to erode core elements of European data protection law and the protective standards it upholds.
Congratulations, dear EU Commission, on this BigBrotherAward.
Laudatio
1 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), ABl. L 119, 2016‑05‑04, p. 1-88, http://data.europa.eu/eli/reg/2016/679/oj
2 https://commission.europa.eu/law/law-making-process/better-regulation/simplification-implementation-and-enforcement/simplification_en#omnibus-proposals
3 Proposal for a Regulation of the European Parliament and of the Council amending Regulations (EU) 2016/679, (EU) 2018/1724, (EU) 2018/1725, (EU) 2023/2854 and Directives 2002/58/EC, (EU) 2022/2555 and (EU) 2022/2557 as regards the simplification of the digital legislative framework, and repealing Regulations (EU) 2018/1807, (EU) 2019/1150, (EU) 2022/868, and Directive (EU) 2019/1024 (Digital Omnibus), COM/2025/837 final, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52025PC0837
4 See Recital 26.
5 Article 3(1) of the Omnibus proposal.
6 Article 3(10) of the Omnibus proposal, new Article 41a.
7 Article 3(4) of the Omnibus proposal.
8 https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:12012P/TXT#d1e167-393-1
9 Article 3(15) of the Omnibus proposal, new Article 88c.
10 Article 3(1)(b) of the Omnibus proposal, new definition (38).
11 https://commission.europa.eu/topics/competitiveness/draghi-report_en
12 Speech by Ursula von der Leyen at the Copenhagen Competitiveness Summit, 2025‑10‑01, Video: https://www.youtube.com/watch?v=Cc_gTlfaibc, Manuscript: https://luxembourg.representation.ec.europa.eu/actualites-et-evenements/actualites/speech-president-von-der-leyen-copenhagen-competitiveness-summit-2025-10-01_en?prefLang=en
13 https://bigbrotherawards.de/en/2025/cutting-bureaucracy
14 https://transparency-register.europa.eu/index_en
15 Corporate Europe Observatory: Big Tech lobby budgets hit record levels, 2025‑10‑29, https://corporateeurope.org/en/2025/10/big-tech-lobby-budgets-hit-record-levels
16 https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/14855-Simplification-digital-package-and-omnibus_en
17 „Ombudsman finds maladministration in how Commission prepared urgent legislative proposals“, Press release no. 01/25, 27.11.2025, https://www.ombudsman.europa.eu/en/press-release/en/215989.
18 The term goes back to Anu Bradford: The Brussels Effect. Northwestern University Law Review, Vol. 107, No. 1, 2012, https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2770634. About the Brussels Effect in data protection, see e.g. James Tamim: The Brussels Effect and the GDPR: EU Institutions as Catalysts for Global Data Protection Norms, June 2024, Researchgate, https://www.researchgate.net/publication/381480613_The_Brussels_Effect_and_the_GDPR_EU_Institutions_as_Catalysts_for_Global_Data_Protection_Norms
19 „470 organisations united against the deregulation campaign ahead of von der Leyen’s State of the Union speech“, Press release, 9 September 2025, https://www.epsu.org/article/470-organisations-united-against-deregulat…
20 See all tabled amendments here: https://oeil.europarl.europa.eu/oeil/en/procedure-file?reference=2025/0360(COD)#section6
21 https://hub.edri.org/index.php/s/Gtg6ejfMGW9HTZw?dir=%2F&openfile=true