Privacy Week 2026:

What’s Next for EU Data Protection

Privacy week

Privacy Week 2026


Published: 
As part of Privacy Week 2026, Albert Castellanos, Digital Law & Privacy Director at BDO Legal Spain, provides an overview of the European Commission’s proposed Digital Omnibus Regulation.

Published in November 2025, the proposal aims to modernise key aspects of EU data protection and digital
governance
. For organisations working with data intensive services, digital platforms or AI, the changes—if
adopted—could offer clearer, more practical compliance pathways.

This article summarises the elements most relevant to businesses and public bodies, offering a concise view of what
may be on the horizon.

A More Practical Definition of Personal Data

The proposal offers long-awaited clarification on when information should be treated as personal data.

Under the new approach:

  • Data is not considered personal data for a given organisation if it cannot identify an individual and is not reasonably likely to gain the means to do so.
  • Information does not become personal data simply because a future recipient could identify the person.

Why this matters for organisations

  • Some GDPR obligations may no longer apply where identification is genuinely

impossible.

  • Organisations must document and periodically review their assessment of no

identifiability.

Targeted Flexibility for Sensitive Data

The proposal introduces two narrowly tailored exemptions for processing special categories of data:

a) Identify verification

Biometric data may be processed solely to verify identity when the method remains fully under the person’s control (e.g. device-based authentication). This supports secure digital access without invoking the full sensitive data regime.

b) AI development & operation

Residual, unintentional processing of sensitive data during AI system development or use may be permitted, if organisations:

  • Take proactive measures to avoid collecting such data, and
  • Delete it immediately when found.

Streamlined Article 13 Information Requirements

To reduce unnecessary administrative effort, the proposal allows limited exemptions from providing full privacy notices in simple, low-risk scenarios, where individuals can reasonably be expected to understand who is collecting their data and for what purpose.

However, the exemption cannot be used when:

  • Data is shared externally (particularly outside the EU),
  • Automated decision-making is involved, or
  • The processing may pose high risks.

A separate exemption exists for scientific research where contacting individuals is impossible or disproportionate.

Automated Decision Making: Clarifying Article 22 GDPR

The proposal confirms that automated decisions may still be considered “necessary for a contract”, even if a human could theoretically make the same decision.

This benefits:

  • Digital onboarding processes,
  • Automated risk analysis, and
  • Operational efficiency in digital workflows.

Individual safeguards under the GDPR remain fully applicable.


Personal Data Breaches: More Time & Greater Consistency

Two operational improvements stand out:

  •  The notification deadline for high-risk breaches extends from 72 to 96 hours. 
  • An EU wide standard notification template and future single EU entry point will promote harmonisation. 

For multinational organisations, this could significantly ease reporting burdens.

EU Level Harmonisation of DPIA Lists

The proposal would replace national Data Protection Impact Assessment lists with single EU harmonised lists that specify when a DPIA is or is not required. 

This shift aims to: 

  • Improve predictability
  • Reduce divergent national interpretations, and 
  • Simplify compliance for organisations operating across borders.


Legitimate Interests for AI Development

To support innovation, the proposal clarifies how legitimate interests (Article 6(1)(f) GDPR) can be used as a basis for processing personal data in AI development and operation. 

Controllers must ensure: 

  • The processing is necessary for AI development or operation, 
  • A rigorous balancing test is completed, and 
  • Enhanced safeguardsare applied, including:
    • Strict data minimisation,
    • Clear transparency measures, and 
    • An unconditional right to object. 

This provides a clearer legal pathway for organisations seeking to build or deploy AI systems responsibly.

Final Thoughts: Privacy Week 2026 Perspective

The Digital Omnibus Regulation represents a broader effort to adapt GDPR implementation to emerging technological realities, including AI, digital authentication, and cross‑border data practices. 

Overall, the amendments aim to simplify certain obligations by introducing clearer definitions, limited scenarios where transparency duties can be relaxed, additional clarity around automated decision‑making, adjusted breach notification processes, and harmonised DPIA triggers across the EU.

At the same time, the proposal acknowledges that interpretation may still vary. As a result, strong internal governance, consistent documentation, and auditable controls remain essential, particularly in AI‑related data flows and other areas where uncertainty may persist.

The Digital Omnibus Regulation represents a broader effort to adapt GDPR implementation to emerging technological realities, including AI, digital authentication, and cross‑border data practices.

Albert Castellanos

Albert Castellanos Rodríguez

Director of Digital Law
View bio