EU Digital Omnibus Proposal to Weaken GDPR Protections for AI and Cookie Tracking
The European Commission is preparing to introduce the "Digital Omnibus" legislative package, which includes significant amendments to the General Data Protection Regulation (GDPR) and related digital privacy laws. Leaked drafts of the proposal reveal changes that privacy advocates argue would create major loopholes, particularly by relaxing rules on pseudonymized data and shifting cookie regulation from the ePrivacy Directive to the GDPR. Critics, including Max Schrems and privacy groups like Noyb, warn that these reforms would undermine existing privacy protections, making it easier for companies—especially large tech and advertising firms—to exploit personal data for commercial purposes. The proposed amendments would also allow broader processing of cookie-derived data under a "closed list of low-risk purposes" or other legal bases, moving away from the current strict opt-in requirements.
Privacy experts contend that these changes could violate European Court of Justice rulings and the EU Charter of Fundamental Rights, representing the most significant attack on European privacy since the GDPR's inception. The official unveiling of the Digital Omnibus package is expected on November 19, 2025, and the reforms have sparked strong opposition from privacy advocates who believe the legislative process is being rushed and lacks proper oversight, potentially eroding the rights of EU citizens in favor of industry interests.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
2 events from the most recent confirmed update back to the earliest known activity.
Privacy activists criticize proposed GDPR reforms as favoring Big Tech
On 2025-11-11, privacy advocates publicly criticized the reported EU reform plans, arguing the changes would weaken data protection and benefit large technology companies. This marked an early public backlash to the proposed policy shift.
Leaked EU plans propose easing GDPR rules for AI and cookie tracking
Reports published on 2025-11-11 say the European Commission is planning reforms to relax parts of the GDPR affecting AI development and cookie-tracking requirements. The proposal was described as leaked or planned rather than adopted, indicating a policy initiative at the proposal stage.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


