{"id":24932,"date":"2026-05-17T08:14:01","date_gmt":"2026-05-17T08:14:01","guid":{"rendered":"https:\/\/www.europesays.com\/spain\/24932\/"},"modified":"2026-05-17T08:14:01","modified_gmt":"2026-05-17T08:14:01","slug":"regulatory-simplification-the-digital-omnibus-package-as-a-first-step","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/spain\/24932\/","title":{"rendered":"Regulatory Simplification: the digital omnibus package as a first step?"},"content":{"rendered":"\n<p>Last November 19th, the European Commission released its simplification <a href=\"https:\/\/ec.europa.eu\/commission\/presscorner\/detail\/en\/ip_25_2718\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">Digital Omnibus package<\/a>. It covers EU rules related to cybersecurity and data (<a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/digital-omnibus-regulation-proposal\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">Digital Omnibus Regulation Proposal<\/a>, on the acquis), AI (<a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/digital-omnibus-ai-regulation-proposal\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">Digital Omnibus on AI<\/a>), a new European Business Wallet (<a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/proposal-regulation-establishment-european-business-wallets\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">Regulation<\/a>) and a Data Union Strategy (<a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/data-union-strategy-unlocking-data-ai\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">Communication<\/a> and a <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/draft-recommendation-non-binding-model-contractual-terms-data-access-and-use-and-non-binding\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">Recommendation<\/a> on model contractual terms on data access and use, and standard contractual clauses on cloud computing), with the aim of reducing administrative burdens. The package of digital rules will now be submitted to the European Parliament and the Council for discussion and adoption. The adopted acts are <a href=\"https:\/\/ec.europa.eu\/info\/law\/better-regulation\/have-your-say\/initiatives\/14855-Simplification-digital-package-and-omnibus_en\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">open for feedback until January 20th, 2026<\/a> where all feedback received will be summarised by the European Commission and presented to the European Parliament and Council with the aim of feeding into the legislative debate.<\/p>\n<p>At the same time, the Commission has launched a consultation on the <a href=\"https:\/\/ec.europa.eu\/info\/law\/better-regulation\/have-your-say\/initiatives\/15554-Digital-fitness-check-testing-the-cumulative-impact-of-the-EUs-digital-rules_en\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">Digital Fitness Check<\/a> open until 11 March 2026. It aims to examine the interplay between different rules, their impact on businesses EU competitiveness, with additional simplification measures expected to be proposed in the first quarter of 2027.<\/p>\n<p>In a separate report, the Commission has identified areas of potential duplications between the <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/report-application-article-33-regulation-eu-20222065-dsa-and-interaction-regulation-other-legal\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">Digital Services Act and other digital\u00a0rules<\/a>. And finally, the Commission has\u00a0published\u00a0its <a href=\"https:\/\/ec.europa.eu\/commission\/presscorner\/detail\/en\/ip_25_2730\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">2030 consumer agenda<\/a>. . In January 2026, the EC also plans to <a href=\"https:\/\/protect.checkpoint.com\/v2\/r02\/___https:\/ec.europa.eu\/info\/law\/better-regulation\/have-your-say_en___.YzJlOnRlbGVmb25pY2Fjb3Jwb3JhY2lvbjpjOm86MmYxYjljZmE0NzFmY2VkNzZiY2UzOWJjZTRmODlhZGY6NzpmM2ZhOmEzYjEyMGY5NDRjODA5M2UzMGI4MDJiZTExMThiMmRkZmZlNDE5OWFkZGRmYjQzZmJhZmIzNjIyZjE4MDE3OTM6aDpGOk4\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">launch a consultation<\/a> on the Guidelines on reasonable compensation for mandatory business-to-business data sharing.<\/p>\n<p>Ultimately, a significant wave of digital regulation proposals was published in a single week, totaling 22 documents and over 1,200 pages (in English), across more than 9 web pages.<\/p>\n<p>The value of regulatory simplification <\/p>\n<p>As we underlined in our <a href=\"https:\/\/www.telefonica.com\/en\/communication-room\/blog\/regulatory-simplification-agenda-europe-longer-delay\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">last post<\/a>, simplifying means recognising that regulation should add value, not undermine it, and that Europe cannot afford another cycle of unproductive complexity.<\/p>\n<p>This is a first step, but greater ambition is still needed. Among other aspects, a key opportunity remains to streamline cybersecurity overlaps and withdraw the <a href=\"https:\/\/eur-lex.europa.eu\/eli\/dir\/2002\/58\/oj\/eng\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">ePrivacy Directive<\/a>, resolving its duplication with the GDPR and the asymmetric treatment of telecom providers.<\/p>\n<p>The Parliament and the Council, in the context of the data acquis simplification, can still choose to remove this outdated and increasingly counterproductive ePrivacy Directive, which generates fragmented and overlapping rules with GDPR and undermines efforts to combat fraud.<\/p>\n<p>They will also need to consider the necessary timeframe to accommodate the proposed delays in the application of the AI Act and to address what the Commission has overlooked: the effective repeal of national laws linked to the amended EU directives, thereby promoting consistency and genuine simplification. It will also be essential to avoid duplication in incident management at both the national and European levels, which would undermine the very purpose of a simplification initiative.<\/p>\n<p>Digital Omnibus \u2013 Cybersecurity incident reporting <\/p>\n<p>The <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/digital-omnibus-regulation-proposal\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">Digital Omnibus<\/a> proposes that incident notifications under <a href=\"https:\/\/protect.checkpoint.com\/v2\/r02\/___https:\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:02022L2555-20221227___.YzJlOnRlbGVmb25pY2Fjb3Jwb3JhY2lvbjpjOm86MWJkNjhjN2M1ZTVhMjA2YzgzYWNiNjliNDMwN2ZiYzg6NzpkMWVmOmZmZDcxYzhhZjI1ZGY1NWNjZDRiM2Y5MGM4NDc4MWU0OTBmNjk0YThhNjViYzUyYzI0NTIwZTE2Mzg5NmQ3OWY6aDpUOk4\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">NIS2<\/a>, <a href=\"https:\/\/protect.checkpoint.com\/v2\/r02\/___https:\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:02016R0679-20160504___.YzJlOnRlbGVmb25pY2Fjb3Jwb3JhY2lvbjpjOm86MWJkNjhjN2M1ZTVhMjA2YzgzYWNiNjliNDMwN2ZiYzg6NzpjNTFkOjgyZGI3Mjk1NzhjOWNjY2Q1ZDA4MTYzZWM4ZjllMTJlYTIwMzZkYTAzODY1NTZhNGZhMWI1Y2IwNjdiOTJlMzY6aDpUOk4\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">GDPR<\/a>, <a href=\"https:\/\/protect.checkpoint.com\/v2\/r02\/___https:\/eur-lex.europa.eu\/eli\/reg\/2022\/2554\/oj\/eng___.YzJlOnRlbGVmb25pY2Fjb3Jwb3JhY2lvbjpjOm86MWJkNjhjN2M1ZTVhMjA2YzgzYWNiNjliNDMwN2ZiYzg6Nzo1NjM1OmFjODBhZTczM2QyOWEyNWY1OTllOTIzY2RkNzE4NTQ1OTEyZjRkYjM2YWRiOTAyODg0OWI3YmM5Mzg0NGJmM2U6aDpUOk4\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">DORA<\/a>, <a href=\"https:\/\/eur-lex.europa.eu\/eli\/dir\/2022\/2557\/oj\/eng\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">CER<\/a> (with <a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2024\/1183\/oj\/eng\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">eIDAS2<\/a> incidents still unclear and AI incident reporting not yet included) be submitted via a EU single entry-point platform, established and maintained by the EU cybersecurity agency (ENISA), to national competent authorities.<\/p>\n<p>Each Member State shall ensure that essential and important entities notify, without undue delay, its CSIRT or, where applicable, its competent authority in accordance with paragraph 4 of this Article of any incident that has a significant impact on the provision of their services as referred to in paragraph 3 of this Article (significant incident) via the single-entry point established pursuant to Article 23a<\/p>\n<p>The European Commission estimates that \u201cmaintaining the single-entry point would require 8 FTEs within ENISA,\u201d which appears insufficient given the scope: 24\/7 coverage for 27 countries, in 24 official languages, interacting with multiple authorities and companies across at least four laws, covering incidents in 18 critical sectors, as well as data breaches affecting all businesses. It appears, therefore, that ENISA\u2019s role would be primarily limited to maintaining the platform (which would need different languages) and providing access-related support (and possibly reporting aggregated statistics), while national competent authorities handle the actual incident data and assist companies with incident resolution.<\/p>\n<p>ENISA will need to work with Member States and the private sector to determine the types and formats of information to be notified, which will subsequently be formalised through implementing acts. Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act. The single-point-of-entry would only take effect once the proper functioning of the platform has been thoroughly assessed by Member States.<\/p>\n<p>We advocate for a <a href=\"https:\/\/www.telefonica.com\/en\/communication-room\/blog\/dora-nis2-cra-decoding-europes-cybersecurity-regulatory-landscape\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">\u201conce-only\u201d compliance approach across multiple regulations<\/a> and a \u201creport once, share many\u201d system for incident reporting, creating a single notification platform (with incidents mostly managed at national level), while empowering ENISA to ensure coherence and alignment. The single-entry point is a strong proposal, but it needs to be carefully structured to prevent multiple and inconsistent incident notifications to different platforms or authorities, define reasonable standardised formats and content for reporting, and ensure very high availability and confidentiality of the platform.<\/p>\n<p>ENISA\u2019s already limited resources would require a substantial increase to take on this new responsibility. The next missing regulatory step is the implementation of simplified \u201conce-only\u201d compliance.<\/p>\n<p>Digital Omnibus \u2013 Data rules <\/p>\n<p>The <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/digital-omnibus-regulation-proposal\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">Digital Omnibus<\/a> looks to consolidate all data rules mainly into two major laws: the <a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2023\/2854\/oj\/eng\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">Data Act<\/a>, and the General Data Protection Regulation (<a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj\/eng\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">GDPR<\/a>), which will remain central. It proposes repealing the <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/ALL\/?uri=CELEX%3A32018R1807\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">Free Flow of Non-personal Data Regulation<\/a>, the Platform-to-Business Regulation\u00a0(<a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2019\/1150\/oj\/eng\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">P2B<\/a>), the <a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2022\/868\/oj\/eng\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">Data Governance Act<\/a> and the <a href=\"https:\/\/eur-lex.europa.eu\/eli\/dir\/2019\/1024\/oj\/eng\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">PSI directive<\/a>.<\/p>\n<p>The Commission proposes to amend the privacy data protection framework in aspects such as the definition of personal data (e.g. pseudonymised data); simpler cookie requirements and \u2018whitelist\u2019 of harmless purposes to tackle the \u201ccookie consent fatigue\u201d; more flexibility to rely on the legitimate interest legal basis of GDPR for the processing of personal data for AI model training. It also proposes targeted amendments to help businesses overcome practical obstacles and limits and clarifies the scope of the business to government sharing provisions.<\/p>\n<p>But it stops short of fully repealing the <a href=\"https:\/\/eur-lex.europa.eu\/eli\/dir\/2002\/58\/oj\/eng\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">ePrivacy<\/a> Directive, leaving in place sector-specific rules that apply only to telecom providers (with also GDPR applying), even as cookie provisions are revised and moved under the GDPR. Repealing the directive and incorporating the remaining necessary provisions (e.g., confidentiality of communications) into broader legislation \u2013 such as the GDPR, the European Electronic Communications Code, or the DNA- represents the path forward.<\/p>\n<p>Digital Omnibus \u2013 AI Act <\/p>\n<p>The simplification measures proposed in the <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/digital-omnibus-ai-regulation-proposal\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">Digital Omnibus on the AI Act<\/a> are targeted amendments designed to address specific implementation challenges. The proposal:<\/p>\n<p> delays the application of the <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX%3A32024R1689\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">AI Act<\/a> provisions for high-risk AI systems, currently due to take effect in August 2026, by up to 16 months, linked to the availability of the 10 <a href=\"https:\/\/ec.europa.eu\/transparency\/documents-register\/detail?ref=C(2025)3871&amp;lang=en\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Open link in new tab\" class=\"link-ext\">AI standards<\/a> and support tools (e.g. 12 proposed guidelines). Once available, it allows a six-month window for Annex III systems and a twelve-month window for Annex I products.introduces a six-month transitional period (until 2 February 2027) for GPAI to comply with transparency obligations for synthetic audio, image, video, or text contentexpands the enforcement powers of the AI Office, centralising oversight of GPAI model systems or AI integrated into very large online platforms and very large search enginesexpands AI regulatory sandboxes and real-world testingextends existing regulatory simplification for SMEs to also small mid-caps (SMCs)reduces the registration burden for AI systems used in high-risk areas for tasks that are not considered high-risk (limited to narrow or procedural tasks)requires the Commission and the Member States to foster AI literacyenable more flexibility in post-market monitoring of high-risk AI systemsallows providers of high-risk AI systems to exceptionally use sensitive personal data for the purpose of bias detection and correction \u2013 also amending GDPRintroduces other targeted adjustments (eg. related to conformity assessment bodies) <\/p>\n<p>The proposal seeks a more workable AI Act, and it is positive that the timeline is tied to the availability of the necessary documents. However, it still sets a very short six-month implementation period, despite standards remaining unclear and key guidelines on high-risk not yet being available. Coherence between laws -such as the with RED Directive \u2013 also remains uncertain. And once again, the GDPR is set to be amended, yet the application of the ePrivacy Directive to operators, which is not addressed, would still hinder effective fraud or bias detection and correction.<\/p>\n<p>Securing Parliament and Council approval of the Omnibus by August 2026 will be challenging. Nevertheless, the upcoming debate presents a valuable opportunity to pursue a genuinely pragmatic simplification of the regulatory framework and to finally address the outdated ePrivacy Directive. Meaningful simplification is essential to fostering innovation and growth.<\/p>\n","protected":false},"excerpt":{"rendered":"Last November 19th, the European Commission released its simplification Digital Omnibus package. It covers EU rules related to&hellip;\n","protected":false},"author":2,"featured_media":24933,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[124],"tags":[809,1029,439,562,521,155],"class_list":["post-24932","post","type-post","status-publish","format-standard","has-post-thumbnail","category-telefonica","tag-artificial-intelligence","tag-consolidation-and-scale","tag-cybersecurity","tag-eu-2024-2029","tag-public-policy","tag-telefonica"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/spain\/wp-json\/wp\/v2\/posts\/24932","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/spain\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/spain\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/spain\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/spain\/wp-json\/wp\/v2\/comments?post=24932"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/spain\/wp-json\/wp\/v2\/posts\/24932\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/spain\/wp-json\/wp\/v2\/media\/24933"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/spain\/wp-json\/wp\/v2\/media?parent=24932"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/spain\/wp-json\/wp\/v2\/categories?post=24932"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/spain\/wp-json\/wp\/v2\/tags?post=24932"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}