Digital Omnibus: Overview of GDPR and AI Act changes for SMEs

Last updated:
18.06.2026
Your ISO 27001 audit is approaching, NIS2 implementation is underway, and your ROPA is up to date – and then this: with the "Digital Omnibus," the EU Commission has introduced a legislative package that could reshape key pillars of data protection and compliance management for SMEs, while also impacting AI regulations.
Digital Omnibus: Overview of GDPR and AI Act changes for SMEs
Key Takeaways
  • The EU Commission's Digital Omnibus is intended to simplify current digital legislation in Europe.
  • Potential consequences of the reform project include longer deadlines for reporting data breaches, lower barriers to the use of personal data, and greater freedom for companies in their use of AI.
  • Under the "Digital Omnibus on AI," initial changes affecting the AI Act were provisionally adopted in May 2026.
  • Data protection advocates fear disadvantages for affected individuals and increased liability risks for companies.
  • SMEs should keep an eye on developments surrounding the Digital Omnibus and seek expert advice on the necessary steps to take.

Background: What is the Digital Omnibus?

In recent years, various laws and regulations have come into force aimed at strengthening data protection and cybersecurity within the EU. In practice, however, these requirements have primarily led to increasing complexity in procedures, deadlines, and obligations.  

The "Digital Omnibus" is the EU Commission's attempt to simplify European digital law: On November 19, 2025, the EU Commission presented two legislative packages designed to adapt and streamline several existing legal acts. These include the General Data Protection Regulation (GDPR), the Data Act and the AI Act.

But while Brussels talks about cutting red tape, over 130 organizations are warning of the "greatest setback for digital fundamental rights in EU history to date." For compliance officers, the planned reform could primarily mean legal uncertainty , and at a time when predictability is essential.  

What does the reform entail, and what has already been implemented? Key changes for your compliance management

The planned changes include, among other things, adjusted reporting deadlines, simplified reporting procedures, and adjustments to the definition of personal data and AI regulation. They would, for example, have a direct impact on the Record of Processing Activities (ROPA), technical and organizational measures (TOMs), and ongoing certifications such as ISO 27001 certification.

GDPR reporting obligations

For data breaches, the draft reform proposes a notification period of 96 hours instead of the current 72 hours. Furthermore, this obligation is intended to apply only to data breaches involving a "high risk." In addition, a single-entry point is planned, which would serve as a central reporting office. Currently, different supervisory authorities may be responsible depending on the branch location.

Potential consequences: The current 72-hour deadline forces companies to have clear processes and respond quickly. Extending the deadline to 96 hours makes it easier for companies to meet their reporting obligations, especially in complex situations like cyberattacks. However, in certain cases, the extended notification period could also increase risks for those affected, as supervisory authorities may be delayed in taking action on their behalf.

Personal data

Another change concerns the definition of personal data. The draft clarifies that, in the future, data will only be considered personal if the company can identify the person behind it. Whether third parties, such as data providers, could do so will no longer be a factor.  

Potential consequences: For data processors, the commercial use of data for analytics or AI training could become easier. However, data providers must continue to comply with data protection requirements. In addition, processing companies must assess and document for themselveswhether or not they are able to identify an individual. In the event of an incorrect assessment, all GDPR obligations would still apply, and SMEs would need to revise their records of processing activities accordingly.

AI Regulation

To simplify AI regulations, the European Parliament and the EU Council reached an agreement in May 2026 on the "Digital Omnibus on AI," thereby establishing a clear timeline for the implementation of high-risk AI regulations set.  

What is changing:  

Deadlines for high-risk AI systems: Regulations for AI systems used in high-risk areas such as biometrics or critical infrastructure will now apply not from summer 2026, but only from December 2, 2027. For AI systems used as safety components in elevators or toys, the regulation will not take effect until August 2, 2028 .  

New ban: AI systems that generate intimate or sexually explicit content without consent are prohibited. Providers of affected systems have until December 2, 2026, to bring their systems into compliance.

Transparency obligations: The transition period for transparency obligations regarding AI-generated content has been set for December 2, 2026. This applies to generative AI systems already on the market before August 2, 2026. Deepfake labeling and transparency for content in the public interest remain mandatory as of August 2, 2026.

AI literacy requirement remains in place: The obligation to promote AI literacy remains unchanged.  

Relief for SMEs and Small Mid-Cap Enterprises (SMCs): In addition to SMEs, SMCs—companies that have grown beyond the SME threshold but are not yet large enterprises—now receive targeted relief. This includes simplified technical documentation, flexible quality management requirements, and reduced maximum fines.

Potential consequences: On one hand, companies gain more flexibility and can better plan internal AI projects. The EU Commission has also published drafts for classification guidelines that provide practical examples for high-risk classification and support SMEs in self-assessment. On the other hand, companies bear full liability if they incorrectly classify an AI application as not high-risk.

Special relevance of the AI Omnibus for mechanical engineering

For companies in the mechanical engineering sector, the Digital Omnibus on AI offers a unique advantage: Machinery Regulation (EU) 2023/1230 is explicitly excluded from the direct applicability of the AI Act. This eliminates the previously looming threat of double regulation for AI systems integrated into machinery.

Those integrating AI systems into machines—for tasks such as control functions or predictive maintenance—no longer need to automatically comply with both sets of regulations in parallel. Instead, only the limited provisions under Art. 2 (2) of the AI Act apply. The full high-risk requirements of the AI Act no longer apply to these systems by default.

However, this exemption is not a blanket rule: if an AI system in a machine poses a risk not covered by the Machinery Regulation, individual requirements of the AI Act may still apply. Furthermore, general obligations such as transparency, documentation, and AI literacy requirements remain binding for machine manufacturers.

What does the Digital Omnibus mean in concrete terms for the work of SMEs?

With the planned adjustments to AI regulations and potential GDPR simplifications, compliance officers in German companies will face numerous tasks .

How would the Digital Omnibus affect existing certifications?

Anyone operating an ISMS according to ISO 27001 has established the corresponding measures based on specific assumptions regarding reporting obligations, fine risks, and data subject rights. If these parameters were to change, companies with an ISMS would need to adjust their risk assessments.  

The situation is similar for TISAX®: The VDA ISA catalog contains an independent data protection module with four control questions that explicitly verify GDPR compliance. If the GDPR definition of personal data or the reporting obligations change, companies would need to update their ROPA documentation. The TISAX® assessor would then verify whether the updated processes continue to meet the catalog requirements.

What does the reassessment of personal data status mean for SMEs?

A central point is the new, recipient-oriented assessment of personal data. In the future, companies would need to systematically document

  • which data they process, for example, pseudonymized analysis data, cloud logs, or usage statistics,
  • via which identification means they possess themselves, such as key databases or access to real names, and
  • whether re-identification is realistically possible using their own resources.

This assessment requires structured documentation similar to a Data Protection Impact Assessment and an update to the Record of Processing Activities (ROPA).

Overview: What specifically changes with the Digital Omnibus

| Aspect | Current | Planned | Tasks and Obligations for SMEs | | :--- | :--- | :--- | :--- | | **Data breach notification deadline** | 72 hours | 96 hours (only for high risk) | Review incident response process | | **Reporting authority** | different authorities depending on branch/location | Single entry point (centralized) | Simplified communication, unified processes | | **Personal data** | clear definition under Art. 4 GDPR | Softening of the definition planned | ROPA and legal bases need revision | | **AI high-risk system** | Conformity assessment from summer 2026 | Postponed to December 2027 or August 2028, exemptions for mechanical engineering | Classify AI systems, adjust compliance roadmap |

What SMEs can do now

The EU's digital law reform has not yet been passed. The AI adjustments also still need to be formally adopted. You could wait and only react once the Digital Omnibus gains momentum. Or, you can start processes now that prepare you for new legal requirements – because the GDPR, NIS2, and the AI Act have shown that companies are repeatedly confronted with new and adjusted regulations.

  • Establish responsibilities: Define who on your team will monitor developments regarding data protection and information security.
  • Stay informed: Use reliable sources of information such as your data protection officer, the Stiftung Datenschutz, or the Proliance newsletter so you don't miss any updates.
  • Review compliance-relevant processes: Which processing activities are based on legal grounds that could change? Which technical and organizational measures (TOMs) relate to reporting obligations or data definitions? Which AI applications in the company would need to be re-evaluated as high-risk?

Outlook: Between pragmatism and adherence to principles

Some describe the Digital Omnibus as a dilution of data protection standards, while others see the planned reform as a chance to cut red tape and increase competitiveness for European companies.

For compliance officers, the Omnibus discussion primarily means uncertainty. That is exactly why it is important neither to fall into knee-jerk reactions nor to put the issue on the back burner. Instead, the rule is: observe, evaluate, and prepare.

Focus on the requirements that are already in effect and work with experts such as your data protection officer or Proliance to ensure that you do not lose any timewhen making necessary changes to your data protection processes. Proliance supports you, for example, with AI consulting or with compliance management software for centralized compliance.

Frequently Asked Questions

Still have questions? We have the answers.

What is the EU Digital Omnibus and which laws are affected?

The Digital Omnibus is an EU reform package aimed at simplifying European digital law, presented by the EU Commission in November 2025. Two legislative packages adapt key legal acts: the General Data Protection Regulation (GDPR) with amended reporting obligations and data definitions, the Data Act for commercial data use, and the AI Act with postponed high-risk rules. The goal is to reduce bureaucracy and enhance competitiveness. However, over 130 organizations warn of the biggest setback for digital fundamental rights. For SMEs, the reform means legal uncertainty for ongoing compliance projects such as ISO 27001, TISAX®, or NIS2. Proliance provides information on current developments.

What changes for GDPR reporting obligations with the Digital Omnibus?

The Digital Omnibus plans to extend the reporting deadline for data breaches from 72 to 96 hours. In the future, the reporting obligation will only apply to high-risk data breaches, instead of all incidents. Also planned: a single entry point as a central reporting office, replacing various supervisory authorities depending on the establishment. Advantage: Simplified reporting for complex cyberattacks due to an increased time buffer. Disadvantage: Increased risks for affected individuals due to a delayed response from supervisory authorities. SMEs must review their incident response processes and adapt their documentation. Proliance Data-Breach-Management documents data breaches in a timely, traceable, and legally compliant manner.

How does the Digital Omnibus affect ISO 27001 and TISAX® certifications?

ISO 27001 ISMS controls are based on assumptions about reporting obligations, fine risks, and data subject rights. If these parameters change due to the Digital Omnibus, companies must adjust their risk assessment. The TISAX® VDA ISA catalog includes a data protection module with four control questions on GDPR compliance. A changed GDPR definition of personal data or new reporting obligations require the revision of the VVT documentation. The TISAX® assessor checks whether the updated processes comply with the catalog requirements. Recertification might become necessary. SMEs should proactively review compliance-relevant processes: Which processing activities, TOMs, and AI applications are affected? Proliance supports with adaptation and certification preparation.

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
70+ Expert:innen
Book a consultation
Topics
Editorial
Sabrina Schaub
Freelance Editor
Leveraging her content expertise, Sabrina supports the Proliance team in communicating complex topics clearly. As a freelance writer, she understands the data privacy requirements across different sectors and translates even complex information into content tailored to specific target audiences.
Zum Autorenprofil
Zum Expertenprofil
Hischam El-Danasouri
Privacy Manager
Hischam El-Danasouri is Privacy Manager at Proliance and a certified AI Governance Professional. As a data protection and AI expert, he supports companies in implementing data protection-compliant AI strategies and the secure use of modern technologies in compliance with the GDPR.
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us