Digital Omnibus Regulation Proposal, GDPR and ePrivacy Reform
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
Proposed: draft of 19 November 2025.
In committee, dated 27 July 2026, as of 12 September 2026.
A comprehensive regime rule binding public and private bodies.
As of 23 August 2026.
Where it has got to
The text described here is Proposal for a Regulation, COM(2025) 837 final. That print is COM(2025) 837 final, 2025/0360(COD), published 19 November 2025.
Locally, this stage is ITRE-LIBE joint committee (Industry, Research and Energy / Civil Liberties, Justice and Home Affairs), European Parliament first reading.
The stage above is recorded at oeil.secure.europarl.europa.eu.
The Legislative Observatory records the procedure as awaiting a committee decision, with no Council general approach or trilogue recorded.
What it requires
- This proposal has not been enacted and does not currently bind. The General Data Protection Regulation (GDPR)'s existing rules on breach notification, consent, processing records, and automated decision making remain in force in full until it is adopted.
If you get it wrong
Criminal exposureNo
What it reaches
Obligation class
Consent, Breach notice, Governance, DPIA, Data subject rights
Who checks it
Audit expectation
none
Also on the record
EEA status
- Reason
- Proposal
- Status
- Not incorporated
- Source link
- https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:52025PC0837
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
This proposal has not been enacted and does not currently bind. Published by the European Commission on 19 November 2025, it would amend the General Data Protection Regulation (GDPR) alongside the ePrivacy Directive, NIS2 and other digital legislation to fold cookie consent into the GDPR, raise and simplify the breach notification threshold, ease processing record and impact assessment duties, and adjust the Article 22 automated decision safeguards.
It remains in the ordinary legislative procedure as of the date shown, with the Council still circulating compromise texts and several of the Commission's central proposals under active negotiation; most observers do not expect adoption before late 2026 at the earliest.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
European Commission legislative proposal text, EUR-Lex
procedural status confirmed via EUR-Lex procedure file 2025/0360/COD
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.