Law / European Union

Digital Omnibus Regulation Proposal, GDPR and ePrivacy Reform

COM(2025) 837 final

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

Proposed: draft of 19 November 2025.

In committee, dated 27 July 2026, as of 12 September 2026.

A comprehensive regime rule binding public and private bodies.

As of 23 August 2026.

Where it has got to

The text described here is Proposal for a Regulation, COM(2025) 837 final. That print is COM(2025) 837 final, 2025/0360(COD), published 19 November 2025.

Locally, this stage is ITRE-LIBE joint committee (Industry, Research and Energy / Civil Liberties, Justice and Home Affairs), European Parliament first reading.

The stage above is recorded at oeil.secure.europarl.europa.eu.

More on this stage

The Legislative Observatory records the procedure as awaiting a committee decision, with no Council general approach or trilogue recorded.

What it requires

  • This proposal has not been enacted and does not currently bind. The General Data Protection Regulation (GDPR)'s existing rules on breach notification, consent, processing records, and automated decision making remain in force in full until it is adopted.

If you get it wrong

Criminal exposureNo

What it reaches

Obligation class

Consent, Breach notice, Governance, DPIA, Data subject rights

Who checks it

Audit expectation

none

Also on the record

EEA status

Reason
Proposal
Status
Not incorporated
Source link
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:52025PC0837

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

This proposal has not been enacted and does not currently bind. Published by the European Commission on 19 November 2025, it would amend the General Data Protection Regulation (GDPR) alongside the ePrivacy Directive, NIS2 and other digital legislation to fold cookie consent into the GDPR, raise and simplify the breach notification threshold, ease processing record and impact assessment duties, and adjust the Article 22 automated decision safeguards.

It remains in the ordinary legislative procedure as of the date shown, with the Council still circulating compromise texts and several of the Commission's central proposals under active negotiation; most observers do not expect adoption before late 2026 at the earliest.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

Read the law

European Commission legislative proposal text, EUR-Lex
procedural status confirmed via EUR-Lex procedure file 2025/0360/COD

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app