Digital Omnibus: EUTA leads industry coalition urging Council to honour simplification commitments

Ahead of the COREPER vote on 26 June, the European Tech Alliance (EUTA) is leading a broad coalition of 15 European tech and digital associations, representing startups, scale-ups, retailers, and the wider European digital economy across Germany, France, Italy, Spain, the Netherlands, Lithuania, Sweden, Denmark, Portugal, and beyond.

The coalition strongly supports the proposal’s stated objective to reduce compliance burdens so that European companies can spend more time building and scaling. Getting the file right matters more than getting it done quickly.

Welcoming the removal of browser-level cookie consent

EUTA and co-signatories welcome the decision to keep centralised, browser-level cookie consent (Art. 88b) out of the text. This avoids handing new leverage to a handful of gatekeeper browsers and preserves the direct relationship between European digital services and their users.

Preserving a workable legal basis for AI training

The coalition urges Member States to reconsider the apparent decision to drop legitimate interest as a legal basis for AI training. Without a workable legal basis, one that, like all legal bases, requires full GDPR compliance including balancing tests, safeguards, transparency and the right to opt out, AI development on European data risks leaving Europe. Companies will be pushed towards smaller, less diverse datasets and, ultimately, lower-quality AI. Codifying this legal basis would itself deliver meaningful legal certainty and simplification for European innovators.

Clarifying when the GDPR applies to data

A new provision (Art. 29a) risks undermining the EU data economy and runs counter to longstanding CJEU case law, including the recent SRB case. As drafted, it leaves unclear when the GDPR applies and when it does not, rather than confirming that data which does not relate to an identifiable individual falls outside its scope. This fails to deliver the legal certainty that European companies need to invest and innovate with confidence.

A single entry point for breach notifications

One harmonised breach notification mechanism, aligned with NIS2, in place of 27 fragmented national contact points is essential. It would let companies focus their incident response on containment and user protection, rather than on filing duplicate notifications across different reporting schemes.

The following can be attributed to Stella Meyer, EUTA Policy Officer:

“The foundations of a stronger European data economy are within reach. A workable legal basis for AI training, clarity on the scope of the GDPR, and a single entry point for breach notifications are not technical details. They are the building blocks of European competitiveness and key to delivering on the simplification promise.”

The following can be attributed to Victoria de Posson, EUTA Secretary General:

“The Digital Omnibus was designed to make the EU’s digital rulebook work better for European companies. Simplification on paper is not the same as simplification in practice and negotiation speed cannot come at the expense of getting it right. European companies are watching, and they need a text they can actually build on.”

👉🏻 Read our joint letter