Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.
EU Council Nears Deal That Privacy Regulators Say Would Gut GDPR Protections

The European Union is on the verge of rewriting the rulebook that made GDPR the global gold standard for data privacy, and the people who wrote the original law are furious about it.
European Digital Rights (EDRi), joined by a coalition of allied civil society groups, published an open letter on September 24 urging EU member states to halt what they call a sweeping rollback of the General Data Protection Regulation. The letter landed the same day EU ambassadors resumed technical talks in the Council's Antici Group on Simplification, according to Tech Times. A binding Council common position could come as soon as this week.
What's Actually in the Bill
The vehicle is called the Digital Omnibus. The European Commission proposed it in November 2025 as a single package simplifying GDPR, the ePrivacy Directive, the Data Act, and NIS2, according to Tech Times.
Three provisions are driving the fight. One would change the basic legal test for when GDPR applies at all. Another would give AI data processing a presumptive path around the regulation's toughest requirements. A third would cut back the information individuals are entitled to receive about how their data gets used.
The Commission has framed all of this as administrative housekeeping, per Tech Times' reporting. Critics don't buy that framing. More than 127 civil society organizations signed a letter in late 2025 calling the package the biggest rollback of digital fundamental rights in EU history.
Even the Regulators Are Objecting
This isn't just activists yelling into the void. The European Data Protection Board and the European Data Protection Supervisor, the EU's own official privacy watchdogs, adopted a joint opinion in February 2026 agreeing that key provisions could weaken protection for individuals.
EDPB Chair Anu Talus said the proposed changes to the definition of personal data were, in her words, not in line with the Court's case law and would significantly narrow the concept of personal data. The head of the body responsible for enforcing GDPR across all 27 member states is saying the law's foundational definition is being hollowed out.
The Tracking ID Loophole
The most technical fight is over a new Article 25a in the Council's current draft text. It concerns pseudonymised data, meaning information where obvious identifiers like names get swapped for codes or ID numbers.
Tech Times reports the provision would let pseudonymised data, including tracking IDs used across the ad-tech ecosystem, escape the full weight of GDPR's requirements. A company doesn't need your name to build a profile on you if it has a persistent code following you around the internet. Weakening the law's grip on that kind of data is exactly the loophole ad-tech firms have wanted since GDPR passed.
The Case for Simplification
There's a legitimate argument on the other side, even if it wasn't spelled out in named quotes in this reporting. GDPR compliance is genuinely expensive, especially for smaller companies and startups trying to build AI products in Europe while American and Chinese firms operate under lighter rules. The Commission's own branding of this package as simplification reflects a real policy goal: reducing legal uncertainty and paperwork burden so European companies aren't permanently boxed out of the AI race by their own regulators.
That's a fair concern. Overregulation kills innovation and jobs. But there's a difference between cutting red tape and quietly rewriting the legal definition of personal data so tracking IDs slip outside the law's reach. Nothing in the current reporting shows the Commission has offered a technical rebuttal to EDPB Chair Talus's specific claim that the new definition conflicts with existing EU Court of Justice case law.
What Happens Next
No final vote has been announced. The Council's Antici Group talks are described as technical discussions, not a formal ratification, and any common position still has to survive negotiation with the European Parliament before it becomes law.
The unresolved question is whether the Parliament, which has historically been more protective of GDPR than the Council, will accept a text its own data protection regulators have already flagged as legally inconsistent with EU court precedent. Anu Talus and the EDPB have not said what they'll do if the Council pushes the current draft forward unchanged.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.