Last updated: June 2025

The EU Digital Omnibus GDPR Reform 2026 Is Rewriting Your Compliance Playbook: Here Is What Actually Changes

Updated 2026-07-19
Key Takeaways: The EU Digital Omnibus proposal amends five core GDPR obligations (ROPA, DPIA, breach notification, DPO scope, and DSR handling) affecting every multi-entity privacy program.

The European Commission's omnibus simplification package proposes the most significant amendments to the GDPR since 2018. If you manage privacy across multiple entities or jurisdictions, some of these changes will directly affect your ROPA, DPIA processes, breach notification timelines, and DPO obligations. This page breaks down what's confirmed, what's proposed, and what you should be doing right now.

Download the EU Digital Omnibus GDPR Impact Checklist

Used by privacy teams at organizations across 15+ countries to manage multi-entity GDPR compliance.

Trusted by 50+ privacy teams across 14 countries
Healthcare
Aviation
Energy
Legal
Technology
Zurzach logo
AXA logo
Openmedical logo
Glencore logo
Pilatus logo
Liferay logo
CareerFairy logo
Voicepoint logo
Kellerhals Carrard logo
Aclaris logo
Avantec logo
Diakonie Bethanien logo
Liferay logo
CareerFairy logo
Zurzach logo
Voicepoint logo
Openmedical logo
Kellerhals Carrard logo
AXA logo
Aclaris logo
Avantec logo
Diakonie Bethanien logo
What the EU Digital Omnibus Actually Changes

Five Compliance Areas Your Privacy Program Needs to Reassess Before 2027

The omnibus proposal does not remove obligations; it reshapes them. Each of these changes creates a different kind of complexity for organizations managing privacy across multiple entities and jurisdictions.

ROPA Changes

Records of Processing Activities May Become Conditional

The proposed reform introduces new thresholds that could exempt certain entities from maintaining full ROPA based on employee count and processing risk level. For multi-entity groups, this means some subsidiaries may qualify for exemption while others do not, requiring entity-by-entity assessment rather than a blanket group policy.

Aircraft manufacturer reduced ROPA admin time by 60% with automated entity-level recertification

Aircraft manufacturer, measured over first 6 months of Priverion deployment

DPIA Restructuring

Impact Assessments Are Being Streamlined, Not Eliminated

The omnibus proposal recalibrates which processing activities trigger a full DPIA versus a lighter-touch review. Organizations with extensive DPIA workflows will need to re-evaluate every assessment trigger and determine whether existing DPIAs can be simplified or must be maintained under the new framework.

Medtec saved 200+ hours preparing for ISO 27001, including DPIA documentation

Medtec, ISO 27001 preparation using Priverion's audit-ready evidence packages

Breach Notification

The 72-Hour Window and Materiality Thresholds May Shift

Proposed adjustments to breach notification timelines and reporting thresholds mean your incident response playbooks may need rewriting. For organizations operating across multiple jurisdictions, the challenge compounds: each subsidiary's breach workflow needs to reflect the updated requirements while maintaining audit-ready documentation.

Tapeze manages 24/7 incident response across multiple entities through a single Priverion dashboard

Tapeze, multi-entity DPO support including incident management workflows

DPO Scope

DPO Appointment Rules and Mandates Are Under Review

The proposal may adjust which organizations are legally required to appoint a DPO and redefine the formal scope of DPO responsibilities. For group-level DPOs covering dozens of subsidiaries, this could mean a fundamental rethink of resource allocation, mandate documentation, and the operational tools they rely on daily.

AXA achieved 100% ROPA recertification rate, fully automated, freeing DPO capacity for strategic work

AXA, automated recertification across all entities via Priverion

Data Subject Rights

DSR Handling Rules Could Include New Fee Structures and Timelines

Proposed changes to Data Subject Access Request handling may introduce fee mechanisms for manifestly unfounded or excessive requests, and adjust response timelines. Organizations processing DSARs across multiple entities will need updated workflows that reflect these new parameters while preserving audit-ready evidence of compliance.

Zurzach Care achieved 100% vendor risk assessment coverage across all processing relationships

Zurzach Care, comprehensive third-party management via Priverion

Not sure which changes affect your group?

Our entity-level impact checklist maps every proposed change to your specific organizational structure.

Download the Impact Checklist

Based on the European Commission's published omnibus proposal as of June 2025. Final provisions may change during the legislative process. This page is updated as new developments emerge.

200+

Hours saved on ROPA management

Medtec reclaimed 200+ hours during ISO 27001 preparation by replacing manual ROPA tracking with automated recertification workflows.

60%

Lower cost vs. OneTrust

Based on published pricing comparisons for mid-market organizations managing 10+ entities. No per-user fees, no per-module expansion traps.

3 mo

Ahead of schedule on ISO 27001

Medtec accelerated their ISO 27001 certification timeline by three months using Priverion's audit-ready evidence packages and automated documentation.

Comparison

Why mid-market teams are leaving OneTrust behind

OneTrust was serving a broad buyer profile including Fortune 500 organizations with larger dedicated GRC teams. If you're managing privacy across 5 to 50 subsidiaries, you're paying for complexity you don't need and fighting a UI designed for someone else.

The OneTrust experience

Per-user, per-module pricing

Costs escalate every time you add a subsidiary, a team member, or a new module. Budget predictability disappears.

US-headquartered, global infrastructure

Post-Schrems II, storing privacy program data with a US provider creates the exact cross-border transfer risk you're trying to manage.

Enterprise UI complexity

Built for teams of 20+ compliance specialists. If your DPO wears three hats, the learning curve alone costs months of productivity.

200+ shallow integrations

Impressive connector count, but most require custom configuration and ongoing maintenance that mid-market teams can't staff for.

Months-long implementation

Enterprise onboarding timelines that assume dedicated project teams and external consultants.

The Priverion experience

Predictable, entity-based pricing

One price based on companies and organizational size. Add team members without watching your invoice grow. No per-module expansion traps.

Swiss-built, Swiss-hosted

European data residency is not a checkbox; it is our identity. All data processed within Swiss infrastructure, beyond the reach of US surveillance frameworks.

Built for the multi-hat DPO

Clean interface designed for teams of 1 to 5, not 20. Aircraft manufacturer's DPO was operational in weeks, not months, and reclaimed 60% of admin time in the first 6 months.

Aircraft manufacturer case study, first 6 months post-implementation

Deep integrations where it counts

We connect deeply with HR, procurement, and IT asset management systems, the workflows that actually drive privacy compliance, instead of maintaining hundreds of shallow connectors.

Operational in weeks

No army of consultants required. AXA reached 100% ROPA recertification with fully automated workflows. Medtec saved 200+ hours preparing for ISO 27001.

AXA and Medtec customer-reported outcomes

An honest note: We don't cover ESG, ethics hotlines, or cookie consent. If that's what you need, OneTrust may be the right fit. We are built for one thing: group-wide privacy program management. And we do it exceptionally well.

Book a 30-min walkthrough
Free Resource

Download the EU Digital Omnibus GDPR Impact Checklist

Map every proposed GDPR change to your specific group structure. This checklist covers ROPA thresholds, DPIA triggers, breach notification updates, DPO mandate changes, and DSR workflow adjustments, organized by entity type so you know exactly which subsidiaries are affected.

We'll send the checklist to your email. No spam, no drip campaigns. Your data is processed within Swiss infrastructure under Swiss law.

Stop managing privacy in spreadsheets

See what group-wide privacy compliance looks like when it actually works

In 30 minutes, we'll walk through how organizations like Aircraft manufacturer and Zurzach Care replaced manual processes across dozens of subsidiaries with automated, audit-ready privacy programs, and how the same approach maps to your group structure.

60%

less compliance admin time

Aircraft manufacturer, first 6 months

200+

hours saved on ISO 27001 prep

Medtec

100%

automated ROPA recertification

AXA

Book a 30-minute walkthrough

No commitment required. We'll map our platform to your group structure and show you time-to-value in weeks, not months.

Swiss-built and Swiss-hosted

Predictable pricing, no per-user traps

AI-assisted, human-decided

The Privacy Compliance Briefing

Monthly insights on GDPR enforcement, Swiss FADP updates, and automation strategies for DPOs and compliance teams.

No spam. Unsubscribe anytime.

About this page: references, definitions, and FAQs

Key Takeaways: EU Digital Omnibus GDPR Reform 2026

The European Commission's Digital Omnibus simplification package proposes the most significant amendments to the GDPR since its adoption in 2016. Five core compliance areas (ROPA, DPIA, breach notification, DPO scope, and data subject rights) are being reshaped. Multi-entity organizations must conduct entity-level impact assessments now, as some subsidiaries may qualify for exemptions while others will not. Final legislative adoption is expected by 2027.

Definitions

What is the EU Digital Omnibus?

The EU Digital Omnibus (formally the Omnibus Simplification Package) is a legislative proposal by the European Commission to reduce regulatory burden on businesses by amending multiple EU regulations, including the GDPR. It was published as part of the Commission's 2025 simplification agenda. GDPR full text, EUR-Lex

What is a Record of Processing Activities (ROPA)?

ROPA is the mandatory register of all personal data processing activities required under Article 30 GDPR. The omnibus proposal introduces conditional thresholds that may exempt certain smaller entities from maintaining full ROPA.

What is a Data Protection Impact Assessment (DPIA)?

A DPIA is a risk assessment required under Article 35 GDPR for processing operations likely to result in a high risk to individuals' rights and freedoms. The omnibus proposal recalibrates DPIA triggers without eliminating the obligation.

What is a Data Protection Officer (DPO)?

A DPO is an independent compliance role required under Articles 37 to 39 GDPR. The omnibus may adjust which organizations must appoint a DPO and redefine the formal scope of DPO responsibilities.

Frequently Asked Questions

What is the EU Digital Omnibus and how does it change the GDPR?

The EU Digital Omnibus is a simplification package proposed by the European Commission in early 2025 that amends the GDPR for the first time since its original adoption. It reshapes obligations around Records of Processing Activities (ROPA), Data Protection Impact Assessments (DPIA), breach notification timelines, DPO appointment rules, and Data Subject Request handling. According to the European Commission, the goal is to reduce administrative burden, estimated at up to 25% for SMEs, while maintaining core data protection standards. GDPR, EUR-Lex

When will the EU Digital Omnibus GDPR changes take effect?

The European Commission published the omnibus proposal in early 2025. It must pass through the ordinary legislative procedure: European Parliament first reading, Council position, and potential trilogue negotiations. Most analysts expect final adoption and a transition period extending into 2027, meaning organizations should begin gap assessments and workflow updates now rather than waiting for final text.

How does the EU Digital Omnibus affect ROPA requirements?

The proposal introduces new thresholds that could exempt certain entities from maintaining full Records of Processing Activities based on employee count and processing risk level. For multi-entity corporate groups, this creates a fragmented compliance landscape: some subsidiaries may qualify for ROPA exemption while others do not, requiring entity-by-entity assessment rather than a blanket group policy. According to the IAPP, organizations with 10+ entities should map each subsidiary's status against the proposed thresholds.

Will DPIAs still be required under the reformed GDPR?

Yes. DPIAs are not eliminated by the omnibus proposal. Instead, the reform recalibrates which processing activities trigger a full DPIA versus a lighter-touch review. Organizations with extensive DPIA workflows will need to re-evaluate every assessment trigger and determine whether existing DPIAs can be simplified or must be maintained under the new framework. The EDPB is expected to issue updated guidance once the final text is adopted.

How does the omnibus proposal change breach notification rules?

Proposed adjustments may shift the 72-hour notification window established under Article 33 GDPR and introduce updated materiality thresholds for determining when a breach must be reported to supervisory authorities. Organizations operating across multiple jurisdictions will need to update incident response playbooks for each subsidiary to reflect the revised requirements while maintaining audit-ready documentation.

What should multi-entity organizations do now to prepare?

Organizations should: (1) conduct an entity-level impact assessment mapping each proposed change to their specific corporate structure; (2) review ROPA and DPIA workflows for potential simplification under the new thresholds; (3) update breach notification playbooks to reflect proposed timeline and materiality changes; (4) evaluate DPO mandate documentation and resource allocation; and (5) adopt a centralized privacy management platform to ensure consistent compliance across all subsidiaries during the transition period.

Statistics and Context

According to the IAPP-EY 2023 Privacy Governance Report, the average organization spends over 1,000 hours annually on GDPR compliance activities. The European Commission estimates that the omnibus simplification package could reduce administrative burden by up to 25% for small and medium-sized enterprises. The EDPB's 2024 annual report noted that supervisory authorities across the EEA processed over 160,000 data breach notifications since the GDPR took effect in May 2018. According to Article 30 GDPR, ROPA obligations currently apply to all controllers and processors with more than 250 employees, or those processing sensitive data regardless of size.

Comparison: Current GDPR vs. Proposed Omnibus Changes

Compliance AreaCurrent GDPR (2018)Proposed Omnibus Change
ROPARequired for all controllers/processors with 250+ employees or high-risk processing (Art. 30)New conditional thresholds based on employee count and processing risk; some entities may be exempt
DPIARequired for high-risk processing (Art. 35)Recalibrated triggers; lighter-touch review option for lower-risk activities
Breach Notification72-hour window to supervisory authority (Art. 33)Potential timeline adjustments and updated materiality thresholds
DPO AppointmentRequired for public bodies, large-scale monitoring, special categories (Art. 37)Adjusted appointment criteria and redefined scope of responsibilities
Data Subject Rights (DSR)Free of charge, 1-month response (Art. 12)Possible fee mechanisms for manifestly unfounded/excessive requests; adjusted timelines