
The EU’s Digital Omnibus initiative — aimed at simplifying digital regulations — has taken a notable turn.
A leaked Council draft (Feb 2026) shows that EU member states have removed the European Commission’s proposal to redefine “personal data” under the GDPR.
What was proposed?
In Nov 2025, the Commission suggested an “entity-relative” approach to pseudonymised data: Data might not qualify as personal data for an organization if it cannot reasonably identify the individual, even if another entity could.
Why was it dropped?
Regulators pushed back strongly. The EDPB and EDPS warned the change could narrow GDPR protections and weaken data subject rights.
As a result, the Council draft:
• Removes the redefinition of “personal data”
• Drops the mechanism allowing the Commission to declare when pseudonymised data falls outside GDPR
Key Takeaway
There is no change to the GDPR definition of personal data.
Organisations should continue taking a cautious approach — especially where re-identification may still be possible.
How S8fe.ai Can Help
S8fe.ai provides intelligent solutions to help companies assess data protection compliance, identify regulatory risks, and navigate complex cross-border privacy requirements.
Sources:
• https://captaincompliance.com/news/polands-data-protection-authority-hits-major-courier-firm-with-multi-million-zloty-gdpr-fines/
• https://www.grcreport.com/post/polands-data-protection-regulator-hits-dpd-polska-with-over-2-75-million-in-gdpr-fines
