Bay Area Business Lawyers | Primum Law

GDPR Compliance

Should I Wait for the EU’s Digital Omnibus Before Updating My GDPR Compliance?

Should I Wait for the EU’s Digital Omnibus Before Updating My GDPR Compliance?

Do I build a full GDPR program now, or wait for Brussels to make it easier?

That question matters if you have EU users, EU customers, or an EU expansion plan.

On November 19, 2025, the European Commission proposed the Digital Omnibus, a package of amendments covering the GDPR, ePrivacy rules, the Data Act, and the AI Act. Its stated goal is to cut administrative burden by at least 25% for all businesses and 35% for small and medium enterprises by 2029.

Part of the proposal would allow companies with fewer than 250 employees to use a simplified recordkeeping model if their processing does not involve high risk data categories.

But there is a catch.

This is still a proposal. It needs approval from the European Parliament and the Council of the EU. The GDPR related changes are not expected to become final law before late 2026 at the earliest, and current GDPR enforcement does not stop while the proposal is being negotiated.

What the Digital Omnibus Actually Proposes

The Digital Omnibus is not limited to GDPR.

It covers several EU digital laws and focuses heavily on reducing paperwork and documentation requirements rather than removing the core privacy rights protected by the GDPR.

The proposal includes:

  • Simplified recordkeeping for companies with fewer than 250 employees.
  • A burden reduction target of 25% overall and 35% for SMEs by 2029.
  • Changes affecting the ePrivacy rules, Data Act, and AI Act alongside GDPR.

For a smaller company, that could eventually reduce some compliance paperwork.

But it does not mean you can stop your GDPR program today.

The Proposal Is Not Law Yet

A European Commission proposal is only the beginning of the legislative process.

The proposal still needs to pass through the European Parliament and the Council, and either body can change the text before adoption.

That creates a common founder mistake.

You hear “GDPR simplification” and decide to postpone compliance work.

But there is no guarantee that the final rules will match the current proposal or that the changes will take effect on your preferred timeline.

Until the law changes, your company needs to operate under the rules that apply today.

What Does Not Change

The proposed simplification does not remove the core GDPR obligations.

You still need to consider:

  • A lawful basis for processing personal data.
  • Consent requirements when consent is the legal basis you rely on.
  • Data subject rights, including access, deletion, and portability.

This distinction matters.

The proposal may reduce certain recordkeeping requirements for qualifying smaller businesses.

It does not create a general exemption from GDPR.

If your company processes EU personal data today, you still need to understand why you are processing it and what rights individuals have.

Your Business May Be Affected Today

The timing is important if you are already doing business in Europe.

If you are selling into the EU, raising money from EU investors, or handling EU user data, your compliance exposure exists under the current rules.

A future simplification does not protect your company from a compliance gap that exists today.

That means your GDPR work should continue while the Digital Omnibus moves through the legislative process.

If the final rules reduce your documentation burden later, you can adjust your program then.

Check Whether You Could Qualify for Simplified Recordkeeping

If your company has fewer than 250 employees, the proposed simplified recordkeeping model may be relevant.

But employee count is not the only consideration.

The proposal ties the relief to whether the company’s processing involves high risk data categories.

So do not assume: “We have fewer than 250 employees, therefore we are exempt.”

The actual data processing activities still need to be reviewed.

Start by mapping what personal data your company collects, where it goes, where it is stored, and what systems or vendors have access to it.

Common Founder Mistakes

  • Treating the proposal as already in effect: Some founders pause GDPR work as soon as they hear that the EU plans to simplify compliance. But the Digital Omnibus is still moving through the legislative process. Its text can change, and there is no guaranteed final date. Stopping compliance work now means operating under today’s GDPR requirements with an avoidable gap while waiting for a law that may look different when adopted.
  • Assuming the proposal creates a full GDPR exemption: The proposed relief focuses on recordkeeping and documentation for qualifying smaller businesses. It does not remove core obligations around lawful bases, consent where required, or data subject rights. A founder who interprets “simplified recordkeeping” as “no GDPR” is going far beyond what the proposal actually says.
  • Putting all privacy work on hold: The Digital Omnibus covers several areas beyond GDPR, with changes touching ePrivacy, the AI Act, and the Data Act. Treating the entire privacy and digital compliance program as paused because one legislative package is under negotiation can leave unrelated obligations unattended. Review each requirement separately rather than assuming every EU compliance issue will change at the same time.
  • Failing to map EU personal data: Founders may know that their product has European users without knowing exactly what personal information moves through the business. Data can pass from the product to internal systems, cloud providers, analytics tools, payment processors, and other vendors. Without mapping collection, storage, and transfers, it becomes difficult to determine what GDPR requirements apply or whether any future simplified recordkeeping model could actually help.

10-Minute GDPR Self-Check

Before waiting for the Digital Omnibus, ask:

  • What EU personal data does my company process today?
  • Do I have a documented lawful basis for each type of processing?
  • Am I relying on consent anywhere?
  • Do I have processes for access, deletion, and portability requests?
  • Do we have fewer than 250 employees?
  • Does our processing involve high risk data categories?
  • Have we mapped where EU personal data moves from collection through storage and transfer?
  • Am I tracking the Digital Omnibus as a proposal rather than treating it as current law?

If you cannot answer these questions, your GDPR program needs attention now.

Bottom Line

The Digital Omnibus may eventually reduce the administrative burden for smaller companies.

But it is not law yet.

The European Commission proposed it on November 19, 2025, and the GDPR related changes are not expected to become final before late 2026 at the earliest. Until then, your company remains subject to the GDPR requirements that apply today.

The sensible approach is to build your compliance program around the current rules.

If the final Digital Omnibus reduces your recordkeeping obligations, adjust your program when those changes actually take effect.

Do not make today’s compliance posture depend on a proposal that can still change.

Do You Know Where Your Company’s Data Actually Lives?

Download our free Data Mapping Worksheet to identify where personal information is collected, stored, and transferred throughout your business.

Mapping your data before updating your privacy documentation helps your policies reflect how your product actually works.

Get the free worksheet: https://primumlaw.com/data-mapping-worksheet/?post_type=page 

Scroll to Top