Les DPO de la Santé
All articles
Regulation

Digital Omnibus: what the GDPR “simplification” changes (and does not change) for healthcare

Les DPO de la SantéPublished Updated 4 min
Digital Omnibus: what the GDPR “simplification” changes (and does not change) for healthcare

A redefined notion of personal data, legitimate interest for AI training, cookies brought into the GDPR, a postponed AI Act: the Omnibus package is shaking up European digital law. Where things stand in summer 2026 for healthcare players.

Presented by the European Commission on November 19, 2025, the “Digital Omnibus” package sets out to simplify European digital law — the GDPR, ePrivacy, the AI Act and the data acts. Where do things stand in summer 2026? The part postponing the AI Act’s “high-risk” obligations was approved by Parliament on June 16, 2026, endorsed by the Council on June 29, then published in the Official Journal on July 24 as Regulation (EU) 2026/1744, in force since July 27. The rest of the package is still working its way through the legislative process, with application envisaged around 2027-2028. Apart from that AI Act component, nothing is applicable yet — but everything is being decided now.

The three workstreams that matter for healthcare

First workstream: the very definition of personal data, which the proposal pushes towards a more “subjective” approach (pseudonymized data might no longer be personal data for a party unable to re-identify it). For health research and health data warehouses, the stakes are enormous — and the regulators’ reception has been icy: in their Joint Opinion 2/2026 of 10 February 2026, the EDPB and the European Data Protection Supervisor rejected this redefinition, seeing in it a risk of structurally weakening protection.

Second workstream: enshrining legitimate interest as a basis for training AI models. Careful: for health data, Article 9 of the GDPR and its exceptions remain the central lock today. The proposal does touch Article 9 (a contemplated exception for detecting and correcting bias, safeguards for residual sensitive data in training sets), but none of this has been adopted: as things stand, there is no free pass for sensitive data.

Third workstream: cookies brought back into the GDPR, with one-click refusal as easy as acceptance and a ban on asking for consent again for six months after a refusal. Healthcare websites, often overloaded with non-compliant banners, will have to fall into line.

What does not change — and what nobody says

The core of the GDPR remains: lawfulness, minimization, security, data subject rights, DPIAs, the framework for processors, breach notification. Health data remains sensitive data under the reinforced regime. Medical confidentiality, the HDS standard, the CNIL’s reference methodologies: none of these frameworks is repealed by the Omnibus.

“Preparing for simplification” by dismantling your compliance would be a dangerous misreading: the CNIL’s 2026 inspections are conducted under 2026 law.

Our reading

The Omnibus is a deep current that must be followed closely — that is precisely the DPO’s monitoring work — but it justifies no wait-and-see attitude. The right strategy: keep the GDPR foundation up to date, document your choices, and integrate the changes as they are actually adopted, not as they are announced.

Our subscribers receive a targeted alert at every milestone the legislative package passes: it is one of the deliverables of our regulatory watch.

The realistic timeline — and what it implies

Apart from the AI Act component (now enacted by Regulation (EU) 2026/1744), the package follows the ordinary legislative procedure: trilogue negotiations, adoption hoped for in 2027, then application deadlines. In other words, none of the GDPR “simplifications” is in force today, and their final content may still change significantly — the highly critical opinion of the EDPB and the European Data Protection Supervisor of February 10, 2026 will weigh on the negotiations.

The DPO’s role in this phase: follow every step (proposal, Parliament position, Council position, final text), assess the actual impact for the organization at each milestone, and above all prevent premature decisions — whether dismantling a consent mechanism on the grounds that it will “soon be simplified”, or conversely over-investing in requirements that may never see the light of day.

What this changes in practice for a healthcare player

For health data warehouses and research: nothing at this stage — the CNIL’s reference methodologies, Article 9 and the pseudonymization requirements remain the operative framework; the “subjective” redefinition of personal data, should it survive the negotiations, will be the subject of a dedicated analysis. For the websites of healthcare facilities and practices: the current cookie regime continues to apply, compliant banner included. For AI projects: the changes already enacted are those of Regulation (EU) 2026/1744 — postponement of Annex III (December 2027) and Annex I (August 2028), regulatory sandboxes pushed back to 2027, a softened Article 4 on AI literacy — and none of them exempts you from anything on the GDPR side. In short: monitoring intensifies, compliance does not move yet.

This article is provided for general information purposes and does not constitute personalized legal advice.

Turn your obligations into opportunities.

A free, no-obligation first conversation to review your compliance posture and identify your priorities — in English.

Response within 24 business hours · No obligation