
Council negotiations on the GDPR elements of the Digital Omnibus resume in September, with the first new compromise text of the Irish Presidency expected shortly.
Before the summer break, the Presidency used the Antici Group (Simplification) meeting on 16 July to take a fresh look at some of the key outstanding issues. Its discussion paper expressly recognised calls from some Member States to increase the level of ambition of the GDPR reforms and deliver more concrete simplification benefits for businesses, while maintaining an appropriate level of protection. Importantly, the Presidency asked whether the existing Council approach was actually providing the legal certainty that organisations need.
That question was particularly explicit in relation to the scope of personal data. The Cyprus Presidency had moved away from the Commission’s proposal to clarify the definition of personal data itself, instead developing a new Article 29a dealing with pseudonymisation and identifiability. In July, Ireland invited Member States to reconsider whether that approach delivers meaningful simplification and legal certainty.
The same is true for AI. The June compromise removed the Commission’s proposed operative provision on processing personal data in the development and operation of AI and replaced it principally with a recital stating that such processing may, in appropriate cases, constitute a legitimate interest under Article 6(1)(f). The Irish Presidency specifically asked Member States whether this provides sufficient legal certainty and invited proposals for further measures to facilitate compliance for organisations developing and operating AI systems.
Privacy Next understands that Member States were subsequently invited to submit additional written comments and that a new compromise text is expected to be circulated during the first week of September, ahead of the next Antici Group discussion scheduled for 11 September. The Council calendar confirms a further Antici Group meeting on that date.
The new text will therefore be an important indication of how the Presidency intends to bridge the remaining differences. Alongside personal data and AI, compromises are still needed on scientific research, where the June text introduced a considerably more prescriptive definition and conditions around matters including transparency, verifiability and research independence, and on abusive data subject requests, where the Council has continued to refine when controllers should be able to refuse or charge for excessive or abusive requests.
For Privacy Next, the test remains whether the eventual Council position delivers genuine reform: clearer rules on when the GDPR applies, a workable legal framework for AI and scientific research, and proportionate tools for organisations dealing with misuse of data protection rights. September may tell us whether the Council is moving closer to finding that balance.
Privacy Next will continue to follow the negotiations closely and advocate for reforms that protect personal data while giving European businesses greater legal certainty and the space to innovate and compete.
01 September, 2026