Throwing your rights under the Omnibus: How the EU's reform agenda threatens to erase a decade of digital rights

Thomas Lohninger, Ralf Bendrath

39th Chaos Communication Congress (39C3): Power Cycles · Day 1 · Saal Zero

Overview

This talk, delivered by Thomas Lohninger of APE Center Works and Ralf Bendrath of the European Parliament, critically examines the European Union's ambitious "simplification agenda," particularly its "omnibus laws," which threaten to significantly weaken the digital rights framework painstakingly built over the past decade. The speakers argue that under the guise of enhancing competitiveness and reducing "red tape," the European Commission is proposing widespread deregulation that targets cornerstone legislation such as the General Data Protection Regulation (GDPR) and the Artificial Intelligence (AI) Act. This initiative, they contend, is a politically driven attempt to dismantle progressive protections, lacking democratic mandate and potentially undermining the EU's global standing as a leader in digital regulation.

Watch on YouTube

Visual summary for Throwing your rights under the Omnibus: How the EU's reform agenda threatens to erase a decade of digital rights by Thomas Lohninger, Ralf Bendrath
Visual summary for Throwing your rights under the Omnibus: How the EU's reform agenda threatens to erase a decade of digital rights by Thomas Lohninger, Ralf Bendrath

Key moments

  1. 0:00 Introduction to digital rights and omnibus laws
  2. 1:00 What are EU omnibus laws and their purpose?
  3. 2:00 Mario Draghi's report sparks simplification agenda
  4. 3:10 Concrete examples of deregulation's harmful proposals
  5. 4:20 Protections reframed as 'red tape' for competitiveness
  6. 5:40 EU officials openly admit deregulation agenda
  7. 7:00 How 'small mid-caps' omnibus weakens GDPR

Throwing your rights under the Omnibus: How the EU's reform agenda threatens to erase a decade of digital rights

Speakers: Thomas Lohninger, Executive Director, APE Center Works; Ralf Bendrath, European Parliament

Conference: 39C3

YouTube: https://www.youtube.com/watch?v=fGBagTrRaqk

Overview

This talk, delivered by Thomas Lohninger of APE Center Works and Ralf Bendrath of the European Parliament, critically examines the European Union's ambitious "simplification agenda," particularly its "omnibus laws," which threaten to significantly weaken the digital rights framework painstakingly built over the past decade. The speakers argue that under the guise of enhancing competitiveness and reducing "red tape," the European Commission is proposing widespread deregulation that targets cornerstone legislation such as the General Data Protection Regulation (GDPR) and the Artificial Intelligence (AI) Act. This initiative, they contend, is a politically driven attempt to dismantle progressive protections, lacking democratic mandate and potentially undermining the EU's global standing as a leader in digital regulation.

The presentation delves into specific, alarming proposals embedded within two key "digital omnibuses." These include fundamental changes to the definition of personal data, the reclassification of pseudonymized data, a broadened scope for "scientific research" that could legitimize commercial AI training without consent, and a significant pause in the enforcement of critical AI safety regulations. Lohninger and Bendrath highlight the strategic implications of these reforms, pointing to external pressures from the United States and the pervasive influence of Big Tech lobbying, which risk eroding the "Brussels effect"—Europe's ability to set global standards for digital governance.

The talk serves as a urgent call to action, informing the public about the severe consequences of these legislative changes for individual privacy, consumer protection, and the responsible development of AI. It emphasizes the need for informed public discourse and active engagement with lawmakers to resist what they describe as a "bad faith attempt to deregulate" and to preserve the integrity of Europe's digital rights landscape.

Background

▶ Watch: Introduction to digital rights and omnibus laws (0:00)

The concept of an "omnibus" in EU lawmaking refers to a legislative package that bundles diverse, often unrelated topics into a single bill, to be voted on en bloc. This approach, while not new, has taken on a new and concerning dimension within the EU's current "simplification agenda." The genesis of this agenda can be traced back to former European Central Bank director Mario Draghi, who was tasked in 2023 with preparing a report on the future of European competitiveness. This report, published in September 2024, aimed to address the perceived economic stagnation in Europe, exacerbated by factors like the COVID-19 pandemic, the war in Ukraine, energy price hikes, and global competition from the US and China.

Draghi's recommendations for enhancing competitiveness have since been translated by the European Commission into a sweeping legislative program. This program, spanning the current five-year legislative term, comprises 17 "simplification laws," 13 of which are "omnibuses." While initially framed around competitiveness, the overarching narrative for these packages has shifted to "simplification" and, more explicitly, "deregulation." Speakers Thomas Lohninger and Ralf Bendrath contend that this agenda is essentially a "wish list of the European People's Party," the conservative bloc, aiming to reverse progressive policies adopted over the last decade. Examples cited include proposals that could weaken child labor protections, extend the use of cancer-causing pesticides, delay mandatory car safety features, and renegotiate the phase-out of combustion engine cars. The narrative reframes these existing protections—safeguarding labor rights, environmental standards, and digital freedoms—as mere "red tape" that hinders economic growth and competitiveness.

Crucially, the speakers emphasize a profound lack of democratic backing for these proposed reforms. Surveys indicate that two-thirds of Europeans actually favor strong enforcement of existing laws against Big Tech, even if it strains transatlantic relations. Despite this public sentiment, the Commission, influenced by a new right-wing majority in the European Parliament and intense lobbying efforts, is pushing forward with deregulation. This has galvanized a broad coalition of civil society organizations, including unions, labor rights groups, environmental and digital rights NGOs, law enforcement unions, and even European beekeepers associations, all united in opposing the comprehensive rollback of protections. The talk specifically focuses on two "digital omnibuses" that directly target Europe's digital rulebook, including the GDPR and the AI Act, threatening to erode a decade of advancements in digital rights.

Key Findings

▶ Watch: Mario Draghi's report sparks simplification agenda (2:00)

The core of the talk reveals how the EU's simplification agenda specifically targets and threatens to dismantle established digital rights through two primary legislative packages: the Small Midcaps Omnibus and the Seventh Omnibus (Digital Simplification Package).

The Small Midcaps Omnibus, presented in May 2025, proposes significant exemptions from the General Data Protection Regulation (GDPR). It introduces a new category of companies, "small midcaps," defined as having between 250 and 749 employees and an annual turnover up to €150 million (with discussions to potentially extend this to 1,500 employees). For these companies, the Commission proposes to scrap the fundamental GDPR obligation to keep a record of processing activities. This is a critical concern, as even small companies like WhatsApp (which had 55 employees when acquired by Meta for $19 billion with hundreds of millions of user data) can process vast amounts of personal data. The speakers argue that while a road construction company might not need extensive records for employee payroll, a company whose core business model is data processing should absolutely retain this foundational record-keeping duty to ensure compliance with other GDPR rules and data subject requests.

The Seventh Omnibus, also known as the Digital Simplification Package, unveiled on November 19th, is even more far-reaching. It amends multiple key laws, including the GDPR, the Data Act, the Data Governance Act, the Open Data Directive, and the Network and Information Security (NIS) Directive, alongside simplifying the Artificial Intelligence (AI) Act.

Regarding data protection, the Seventh Omnibus proposes radical changes to the very definition of personal data. The GDPR currently defines it as "any information relating to an identified or identifiable natural person," emphasizing that identifiability can be direct or indirect, even by "singling out" an individual. The Commission's new proposal adds language that information is "not necessarily personal data for every other person or entity merely because someone else can identify that natural person." This means data could be considered personal for one entity but anonymous for another in the same supply chain, effectively removing many actors from GDPR obligations. The speakers argue this misinterprets the European Court of Justice's SRB judgment and contradicts previous rulings like Briar (IP addresses are personal data) and Scania (vehicle identification numbers are personal data). Furthermore, a new Article 41A would grant the Commission the power to define pseudonymized data as anonymous data (which falls outside GDPR's scope) through mere implementing acts, bypassing proper legislative scrutiny and undermining the GDPR's clear distinction that pseudonymized data remains personal data.

The package also introduces a new, highly problematic definition of scientific research, expanding it to include "any research which can also support innovation or even apply existing knowledge in novel ways" and may "further a commercial interest." This broad definition, which ignores academic standards like peer review and publication, is seen as a "gift to the AI bros," designed to make vast amounts of data available for commercial AI training. This is reinforced by a proposed new Article 88C in the GDPR, which explicitly states that training artificial intelligence systems with personal data is in your legitimate interest. While ostensibly still subject to GDPR safeguards, this provision raises serious concerns about the feasibility of enforcing data subject rights, such as the right to correction for information generated by Large Language Models (LLMs) like ChatGPT, where data is "in the statistical wide noise." Public surveys, such as one cited indicating only 7% of Meta users want their data used for AI training, contradict the Commission's AI hype curve. Finally, the ability to exercise fundamental rights, like the right to access data, could be refused if deemed "abusive," potentially curtailing legitimate uses by entities like labor unions seeking overtime compensation.

For the AI Act, the proposals seek to stall its implementation. While prohibited AI uses (e.g., emotional recognition in classrooms, social scoring, predictive policing) are already in effect, many member states have delayed appointing national regulators, leaving these devastating systems unchecked. For high-risk AI systems (e.g., in law enforcement, migration, judicial systems), the proposal asks to "stop the clock" on enforcement for 16 months (until August 2026). This creates a dangerous loophole, allowing companies to rush risky AI systems onto the market, establishing them in a regulatory gray zone before protective measures (like bias prevention and higher duties of care) become enforceable. An example cited is the use of facial recognition at Budapest Pride. Compounding this, the proposal removes an existing transparency requirement for companies that self-declare their high-risk AI systems as non-high-risk, eliminating a crucial patch for accountability and making it impossible for regulators or civil society to know which systems are exploiting this loophole.

Lastly, the Open Data Directive is also targeted. The existing obligation for public sector bodies to publish information under open licenses (like Creative Commons) is proposed for removal. Instead, public bodies would be allowed to negotiate payment with Big Tech for access to this data. This fundamentally undermines the "anyone" principle of open data, creating a massive split in the "open universe" and potentially entrenching dominant platforms by allowing them to pay for privileged access to public data, while making it harder for smaller entities or the general public to benefit from open government information.

Beyond these specific findings, the speakers highlight the broader geopolitical context, including US pressure to soften the EU's digital rulebook and the significant lobbying power of Big Tech, which meets with the European Commission almost daily and has a combined budget of €151 million for 2025. This concerted effort risks undermining the "Brussels effect," Europe's strategic advantage in setting global regulatory standards, and could lead to a rollback of protections that have inspired similar laws in over 100 countries worldwide.

Technical Deep Dive

▶ Watch: Concrete examples of deregulation's harmful proposals (3:10)

The technical deep dive into the proposed legislative changes reveals a systematic attempt to redefine core concepts in EU digital law, primarily impacting the General Data Protection Regulation (GDPR) and the Artificial Intelligence (AI) Act. These changes, while presented as "simplification," fundamentally alter the scope and enforceability of digital rights.

A central point of contention in the Seventh Omnibus is the proposed amendment to the definition of personal data under GDPR. The existing GDPR, in Article 4(1), clearly defines personal data as "any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person." Recital 26 further clarifies that "to determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used, such as singling out, either by the controller or by any other person." This "singling out" principle is crucial: even if a controller doesn't know who an individual is, if they can distinguish them from others and treat them uniquely (e.g., for targeted advertising), that data is personal.

The Commission's proposal, however, seeks to add new sentences: "information relating to a natural person is not necessarily personal data for every other person or entity merely because someone else can identify that natural person and such information does not become personal for that entity merely because a potential subsequent recipient like further down in the supply chain has means reasonably likely to be used to identify." This proposed redefinition creates a fragmented legal landscape where the same piece of data could be personal for one entity (e.g., the original data collector) but anonymous for another in the same processing chain, thereby exempting downstream processors from GDPR obligations. Ralf Bendrath argues this is a misinterpretation of the European Court of Justice's (ECJ) SRB judgment (Single Resolution Board), which dealt with a very specific context of data transfer to Deloitte for analysis, where identifiers were linked to comments, not individuals. This contrasts sharply with prior ECJ rulings like the Briar judgment, which established IP addresses as personal data even for website operators who don't directly know the user's identity, and the Scania case, where Vehicle Identification Numbers (VINs) were deemed personal data even if Scania itself didn't link them to specific users, because registration authorities could. The core principle of "singling out" is a cornerstone of the GDPR's broad definition of personal data, and its erosion would significantly weaken privacy protections.

Further weakening the GDPR, the Commission proposes a new Article 41A, granting itself the power to decide, through implementing acts, when pseudonymized data can be considered anonymous data for certain parties. Under the current GDPR, pseudonymized data is explicitly recognized as personal data because the possibility of re-identification still exists. Implementing acts are typically for technical details, not for altering the core definitions or scope of primary EU law. This move is seen as an overreach, allowing the Commission to unilaterally reclassify data types, effectively removing them from GDPR protection without proper legislative debate.

The proposed new definition of scientific research is another critical technical change. The GDPR allows for further processing of data for scientific research purposes, even if the initial collection was for a different purpose. However, the new definition broadens "scientific research" to include "any research which can also support innovation or even apply existing knowledge in novel ways" and explicitly states it "may further a commercial interest." This effectively divorces the concept of scientific research from traditional academic standards like peer review and publication of results, instead legitimizing commercial activities, particularly those related to Artificial Intelligence (AI) training, as "research." This is directly linked to the proposed new Article 88C in the GDPR, which declares that training artificial intelligence systems with personal data is in your legitimate interest. While the GDPR's Article 6 allows for processing based on legitimate interest, it requires a balancing test against the data subject's rights and interests. The automatic classification of AI training as a "legitimate interest" significantly tips this balance. Moreover, it fails to address the practical challenges of upholding other data subject rights, such as the right to rectification (Article 16) or the right to erasure (Article 17), when personal data is embedded within complex, statistical models like Large Language Models (LLMs). As Ralf Bendrath illustrates with his own example with ChatGPT (GPT-3) providing incorrect information about his academic affiliation, correcting such "data" within an LLM's vast, diffuse knowledge base is technologically non-trivial, if not impossible, under current paradigms.

Beyond GDPR, the AI Act is impacted by proposals to "stop the clock" on enforcement for high-risk AI systems for 16 months (until August 2026). The AI Act employs a risk-based approach, with strict rules for high-risk applications (e.g., in law enforcement, migration, judiciary) that mandate specific duties of care, risk mitigation measures, and bias prevention. This delay creates a regulatory vacuum, allowing developers to deploy potentially harmful AI systems before these crucial safeguards become legally binding. Furthermore, the removal of the requirement for companies to register high-risk AI systems in a transparency database—even if they self-declare them as non-high-risk—eliminates a vital mechanism for public and regulatory oversight, making it impossible to track systems that exploit this loophole.

Finally, the Open Data Directive faces a critical technical shift. The existing directive obliges member states to publish public sector information under open licenses, ensuring universal accessibility. The proposed changes remove this obligation, instead allowing public sector bodies to negotiate payment with Big Tech for data access. This directly conflicts with the foundational principle of "anyone" being able to use open data, as enshrined in widely used Creative Commons licenses (e.g., CC BY SA). This could lead to a fragmentation of the "open universe," where access to valuable public data becomes monetized and exclusive, favoring large corporations over smaller innovators and the general public. The speakers suggest a model like Wikipedia's enterprise API, which charges for heavy-load access while maintaining open licensing for general use, as a more appropriate alternative.

Demo / Proof of Concept

▶ Watch: EU officials openly admit deregulation agenda (5:40)

This talk did not feature a traditional technical demonstration or proof of concept in the sense of showcasing vulnerabilities, exploits, or new security tools. Instead, the speakers focused on presenting a detailed analysis of proposed legislative changes, their potential impacts on existing digital rights frameworks, and advocating for public engagement. Their "demonstration" was primarily through a clear exposition of legal texts, policy implications, and real-world examples of how these changes could manifest, such as the implications for data subject rights in AI systems like ChatGPT or the use of facial recognition technologies. The call to action for contacting representatives and supporting NGOs served as an implicit "proof of concept" for collective action in policy advocacy.

Defensive Implications

▶ Watch: How 'small mid-caps' omnibus weakens GDPR (7:00)

The sweeping changes proposed within the EU's "simplification agenda" carry profound defensive implications for individuals, organizations, and the broader digital rights landscape. Understanding these implications is crucial for mounting an effective response.

For individuals, the most immediate defensive measure is to be acutely aware of the potential erosion of their fundamental rights. The weakening of the personal data definition and the reclassification of pseudonymized data directly threaten the scope of GDPR protection, potentially leaving more of their data vulnerable to unregulated processing. The proposed ability to refuse data access requests if deemed "abusive" could curtail legitimate exercises of rights. Individuals should consider exercising their rights under the existing GDPR while they remain robust. Furthermore, the talk's mention of the "do not track" standard potentially becoming legally binding offers a glimmer of hope for browser-level privacy controls, which users should actively adopt and advocate for.

For organizations, particularly those involved in data processing or AI development, the proposed changes introduce significant legal uncertainty rather than simplification. While some might initially see deregulation as a benefit, the speakers argue it could lead to increased liability and a less predictable regulatory environment. Companies currently relying on robust GDPR compliance frameworks might find themselves in a gray area, where the status of data (personal vs. anonymous) shifts depending on the entity. Organizations whose core business involves data processing should strongly resist the removal of record-keeping obligations, as this foundational practice ensures compliance and accountability. For AI developers, the declaration that AI training with personal data is a "legitimate interest" (Article 88C GDPR) might seem advantageous, but it sidesteps the complex issues of data subject rights (e.g., right to correction for LLMs). This could expose companies to legal challenges if they cannot practically fulfill these rights.

Civil society organizations (CSOs) and NGOs are positioned as a primary line of defense. The speakers emphasize that collective action and public pressure are paramount. This involves:

  1. Informing oneself and others: Understanding the specifics of the legislative proposals and their impacts.
  2. Contacting representatives: Directly engaging with Members of the European Parliament (MEPs) and national government officials through emails, phone calls, and social media. Tools like drme.eu are highlighted for facilitating this. The success of the "chat control" campaign is cited as a precedent for effective civil society pressure.
  3. Supporting NGOs: Providing financial and active support to digital rights, environmental, and labor rights organizations working on these issues, especially given the challenging funding landscape.

From a regulatory and policy perspective, the defensive implications are about preserving the integrity of the EU's legislative framework and its global leadership. The criticism from within the EU institutions (e.g., the EU Ombudsman's finding of "maladministration" for lack of impact assessment, and internal Commission dissent) indicates that the process itself is flawed. Defenders must insist on proper impact assessments for any proposed changes. Strategically, the argument must shift from "Europe vs. progressive agenda" to "Europe protecting its citizens against Big Tech and external pressures," thereby leveraging the strong public support for digital rights. Preventing the weakening of the Brussels effect—Europe's ability to set global standards—is a key defensive goal, as a diluted regulatory framework will cease to inspire similar protections worldwide.

Specifically, defensive actions should focus on:

  • Preventing the weakening of the personal data definition: Maintaining the "singling out" principle and resisting fragmented data classification.
  • Blocking Article 41A: Preventing the Commission from reclassifying pseudonymized data as anonymous through implementing acts.
  • Rejecting the broadened "scientific research" definition and Article 88C: Ensuring that commercial AI training adheres to robust data protection principles and consent requirements.
  • Preserving the right to access data: Ensuring fundamental rights cannot be arbitrarily refused as "abuse."
  • Opposing the 16-month pause on AI Act enforcement: Demanding immediate and full implementation of safeguards for high-risk AI systems.
  • Reinstating transparency for high-risk AI systems: Ensuring public oversight of AI deployments.
  • Protecting open licensing in the Open Data Directive: Preventing the monetization and privatization of public data.
  • Vigilance against net neutrality repeal: Monitoring the upcoming Digital Networks Act.

In essence, the defense strategy is multi-layered, requiring technical understanding, legal advocacy, and broad public mobilization to counteract a politically driven push for deregulation that threatens to roll back a decade of digital rights advancements.

Key Takeaways

  • The EU's "simplification agenda," driven by a conservative political shift and framed as reducing "red tape," is a deliberate attempt to deregulate and weaken foundational digital rights laws like the GDPR and the AI Act.
  • Proposed amendments to the GDPR include a narrower, fragmented definition of personal data, the reclassification of pseudonymized data as anonymous via implementing acts, a commercially oriented redefinition of "scientific research," and the assertion that training AI systems with personal data is a legitimate interest, potentially undermining data subject rights.
  • The AI Act faces a proposed 16-month delay in enforcing rules for high-risk AI systems and the removal of a crucial transparency database, creating regulatory loopholes that allow potentially harmful AI to proliferate without adequate oversight.
  • Changes to the Open Data Directive threaten to remove the obligation for public sector bodies to use open licenses, allowing them to monetize public data for Big Tech and undermining the principle of universal access.
  • These legislative rollbacks are occurring despite strong public support for robust digital protections, and are influenced by significant Big Tech lobbying and external geopolitical pressures, risking the erosion of the EU's global regulatory leadership known as the "Brussels effect."
  • Active public engagement, including informing oneself, sharing information, contacting elected representatives through platforms like drme.eu, and financially supporting digital rights and civil society organizations, is crucial for defending existing digital rights and preventing this widespread deregulation.

About the Speaker(s)

Thomas Lohninger is the Executive Director of APE Center Works, a Vienna-based digital rights organization. He has been actively involved in EU digital policy for the past 15 years, advocating for the protection of digital freedoms and privacy. APE Center Works also maintains a booth on the second floor of the conference, offering further information about their work.

Ralf Bendrath works for the Greens in the European Parliament. He has a deep personal connection to the subject matter, having worked as a staff member for the chief negotiator, Jan Philip Albrecht, during the drafting of the General Data Protection Regulation (GDPR) approximately 10 years ago. Bendrath holds an academic background, having conducted academic research for a decade after his graduation. He is also noted for having an Internet Movie Database (IMDB) entry due to his appearance in the documentary "Democracy."

All talks from 39th Chaos Communication Congress (39C3): Power Cycles