Vb: Fwd: [EDRi-members] Urgent: Council close to agreement on a very dangerous Data Omnibus text
Kanske finns det någon reporter på listan som vill ta upp frågan? Eller så tipsa gärna någon som brukar bry sig om dessa frågor i media. Min tanke är att posta ett mail till EU-representationen från DFRI också. Min personliga åsikt är att GDPR inte är ett idealt regelverk, träffar inte helt målet och gör vissa saker krångligare än det behöver vara. Men det är ändå något som till viss del skyddar vår personliga data. Och att släppa persondata-hantering typ fritt för bigtech om de skriver AI på sitt projekt eller system, verkar inte bra. Ulrika, DFRI styrelsen ------- Forwarded Message ------- Från: Börje Ohlman via DFRI-intern <dfri-intern@lists.dfri.se> Datum: Den onsdag 16 september 2026 kl. 10:57 Ämne: Fwd: [EDRi-members] Urgent: Council close to agreement on a very dangerous Data Omnibus text Till: Intern DFRI <dfri@dfri.se>
Vidarebefordrat mejl:
Från: Itxaso Dominguez de Olazabal <itxaso.dominguez@edri.org> Datum: 16 september 2026 10:35:53 CEST Till: Eleftherios Chelioudakis via EDRi-members <edri-members@mailman.edri.org> Ämne: [EDRi-members] Urgent: Council close to agreement on a very dangerous Data Omnibus text
Dear all,
I know how incredibly busy everyone is, so apologies for adding another urgent ask to your inboxes. But we are reaching a very serious moment in the Council negotiations on the GDPR and ePrivacy related aspects of the Digital Omnibus, and this is one of those moments where numbers matter.
Member States are moving quickly towards an agreement on a text that raises major concerns for fundamental rights and the whole of the EU digital rulebook. In important respects, the latest compromise is much more worrying than the versions we saw before the summer.
The biggest concern is related to the definition of personal data and even though the proposed redefinition has been deleted, the approach to pseudonymisation and identifiability is incredibly dangerous. Article 25a, together with Recitals 27 to 27c, would create a much more developed actor-relative regime in which pseudonymised data may be treated as non-personal for some actors while remaining personal for others. This risks blurring the distinction between pseudonymisation and anonymisation, letting many companies across data chains, off the hook when it comes to respecting our rights, and creating huge legal uncertainty. This is about the very application of GDPR per se!
The text also reinstates an operative Article 88bis on AI development and operation (Commission proposed 88c). While it does not make AI-related processing automatically lawful, it explicitly singles out a broad understanding of AI processing as something that may rely on legitimate interests under Article 6(1)(f). We are very concerned about the signal this sends for large-scale reuse of personal data for AI, even more so when knowing how legitimate interest as a legal basis is already used as a carte blanche for ‘do whatever you want with data’ (and thus with our rights).
There are other important issues too, including new transparency exemptions, weaker safeguards around sensitive and biometric data, the continued deletion of the standalone privacy-signals provision (the only true simplification of the package), as well as new ePrivacy consent exemptions.
We have unfortunately seen that civil society joint letters do not tend to move capitals or the Council very much on their own. What can make a difference is several organisations, from several countries, contacting their own governments and Permanent Representations separately. And, as you can imagine, industry has been putting a huge amount of pressure on governments throughout this process. It would be very useful for Member States to hear clearly that civil society is watching this too.
It would therefore be extremely helpful if you could send an email to your government and/or Permanent Representation in Brussels over the coming week (until Wednesday September 23rd, albeit the sooner the better). We are very close to a Council agreement, so this is really the moment to intervene.
To make this as easy as possible, I am attaching:
-
a short email template, with very simple instructions at the beginning on how to use it https://hub.edri.org/index.php/s/ocGQKEwzMJRgsFw ;
-
an Excel file with contact details for the Permanent Representations https://hub.edri.org/index.php/s/fkSQKiz7a4c55iz .
It would also be really helpful to flag this to journalists in your country. There are some very concrete angles here that go far beyond a technical GDPR debate: data people in the EU thought was protected for years will suddenly be reused much more broadly for AI; Big Tech will mainly benefit from it all and it’s not a coincidence everything has gotten worse under the Irish Presidency; legal uncertainty will for years burden the very EU companies the Commission is using to justify all of this; pseudonymised data (whis is NOT anonymous data) will fall outside GDPR protection for many actors, and people will instantly lose control and rights; a package sold as ‘simplification’ is actually creating more legal uncertainty and fewer safeguards; and, of course, why are governments prepared to sign off on such major changes to fundamental rights law through a fast-track deregulation file with?
We would be very happy to help think through media angles or background if useful, although I know you already have excellent comms colleagues/expertise.
Please do let me know if you are planning any outreach, and of course I am here for anything you might need.
Many thanks,
Itxaso
P.S. please note that I haven’t used almost any caps, but that doesn’t mean this is not hyper important
ITXASO DOMINGUEZ DE OLAZABAL (She/Her)Policy Advisor
EUROPEAN DIGITAL RIGHTSRue Belliard 12, B-1040 Brussels Phone: +34 699305293
[www.edri.org](https://www.edri.org/) | [@edri](https://twitter.com/edri) | [PGP](https://keys.openpgp.org/vks/v1/by-fingerprint/36EC374FA81D28FB5AC076BC40A12...)
participants (1)
-
uvdfri