Revised EU draft shortens the wait before websites can re-ask for cookie consent
A revised draft of the EU's Digital Omnibus, dated 2 October and seen by MLex, adds a review of data protection obligations, shortens the waiting period before websites can re-ask for cookie consent, strengthens trade-secret protections — and clarifies that developing or operating AI does not automatically justify processing personal data. Ambassadors in the Council were due to consider the text on the Wednesday after publication, according to MLex, as negotiations move toward a possible common position. At the same time, the most contested issues — the definition of personal data and the new proposal on pseudonymised data — remain open.
What the revised draft changes
The changes in the 2 October draft were reported by MLex (Júlia Tar), which has seen the document. The draft contains four concrete elements:
- A review of data protection obligations. Member states are to receive a review of the existing data protection obligations, MLex reports.
- A shorter waiting period for repeated consent requests. The waiting period before providers can put a new cookie-consent request will be shortened.
- Strengthened trade-secret protection. The text tightens protection of confidential business information.
- A clarification on AI. The draft clarifies that developing or operating AI does not in itself automatically justify the processing of personal data — a response to the AI-related questions several governments have raised.
The draft text itself is not publicly available in the available source material, and the MLex report does not specify how extensive the review of data protection obligations is to be, how long the shortened waiting period for consent requests is, or the exact wording on trade secrets. What is established is that all four changes are reported from the document dated 2 October.
Timing: ambassadors and a possible common position
According to MLex, the Council's national ambassadors (COREPER) were expected to consider the revised draft on the Wednesday after it was dated. The context is that the Council is moving toward a possible binding common position on the package. It is not, however, known what the outcome of the ambassadors' meeting was — whether the 2 October text managed to gather a majority, or whether further revisions are needed.
The timing makes the final days decisive. The written government comments of 17 September showed that member states divide over the proposed GDPR rules on AI, data transfers and pseudonymised data, according to written comments seen by MLex (Júlia Tar and Matthew Newman). The comments supported parts of the Irish compromise in the package, but called for changes to the AI, cookie and cyber-reporting rules. The 2 October draft can be read as a response to at least two of those requests: the clarification on AI and the adjustment of the rules on consent requests.
What the Digital Omnibus is
The Digital Omnibus was proposed by the European Commission in November 2025 as a simplification package amending the GDPR, the ePrivacy Directive, the Data Act and NIS2 in a single piece of legislation. The idea is to ease regulatory burdens across several rulebooks at once, but the framing has been contested from the start: more than 127 civil society organisations signed, in late 2025, a letter characterising the package as the biggest rollback of digital fundamental rights in the EU's history.
The package thus touches three regimes at once — privacy, electronic communications and cookies via the ePrivacy Directive, data sharing via the Data Act, and cybersecurity reporting via NIS2 — which makes the negotiations more complex than a simple GDPR revision.
The contested issues still open
The revised draft does not resolve the deepest conflicts in the package. Two stand out:
The definition of personal data. The Commission's proposal changes the central definition in the GDPR. The EU's own data protection authorities — the European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) — adopted a joint opinion in February 2026 in which they agreed that central provisions could weaken the level of protection for individuals. EDPB chair Anu Talus said the proposed changes to the definition of personal data were "not in line with the case law of the court and would significantly narrow the concept of personal data".
Article 25a on pseudonymised data. A contested new provision in the Council text proposes that pseudonymised data — information where obvious identifiers such as names are replaced with codes or ID numbers — may be treated as non-personal data for a company that itself cannot re-identify the person behind the code. For such companies, the data would in principle fall outside the GDPR's privacy requirements — a mechanism with significance for an advertising system that European Digital Rights (EDRi) values at around €59 billion. The MLex reports show that governments also disagreed on the pseudonymisation question as of 17 September, and nothing in the revised draft, as reported, indicates the question has been resolved.
The opposition from civil society
The opponents have not waited for the ambassadors. On 24 September, EDRi and a coalition of allied organisations published an urgent letter to EU member states urging them to halt what they call a wholesale rollback of the GDPR — precisely as the package moved toward a binding common position in the Council. The letter follows in the tracks of the late-2025 letter from over 127 organisations that described the package as the biggest rollback of digital fundamental rights in the EU's history.
The criticism targets the same points the authorities have flagged: the definition of personal data, Article 25a and the loosening of the cookie-consent rules. The last of these is particularly concrete — a shorter waiting period between consent requests means users could be asked to consent again more often, which critics say undermines the free and informed consent that is the foundational principle of the privacy rulebook.
What remains
Three questions are open after the 2 October draft. First: did the ambassadors' meeting on the Wednesday after 2 October produce a common position, or does the text need to change again? Second: how were the unresolved details handled — the scope of the review of data protection obligations, the length of the shortened waiting period for consent requests and the exact wording on trade secrets remain unknown outside MLex's reporting. Third: how was the most fundamental conflict handled — the tension between the Commission's narrowing of the personal-data concept and the EDPB/EDPS warning that it breaks with the EU court's case law?
Until a common position is in place, and later trilogue negotiations with the European Parliament, the final shape of the EU's biggest privacy overhaul remains open — both for the ad-tech industry hoping for lighter rules, and for the data protection authorities and civil society trying to stop it.

