25/06/2026: Every company working with cookies and similar techniques has been struggling with both GDPR and ePrivacy Directive and all local implementations. The Digital Omnibus proposes cookies and similar techniques with personal data, to be handled exclusively by the GDPR. Introduced by the European Commission on 19 November 2025, the Digital Omnibus is a broad legislative package that would amend several EU digital laws, including the GDPR, the ePrivacy Directive, the Data Act and the NIS2 Directive. It aims to simplify the increasingly complex EU digital rulebook.
This blog is part of a series exploring the proposals set out in the European Commission’s Digital Omnibus package. In a previous blog, we examined the Omnibus’s vision for a single-entry portal for incident reporting. In this post, we turn our attention to the proposal to bring all cookies and similar tracking technologies involving personal data under the unified framework of the GDPR, including the introduction of automated, machine-readable mechanisms for capturing and communicating data subjects’ preferences.
The proposal by the European Commission
Since May 2018, cookie consent banners have become a persistent source of frustration for internet users. Visiting almost any website means navigating yet another pop-up, clicking through layers of options, and repeating the process on every return visit. Users are fatigued, business bears significant compliance costs, and the privacy choices presented are often far from meaningful. Ultimately, few people have the time, nor the inclination, to review the dense legal language that typically accompanies these banners.
The European Commission has recognized this problem and is looking to address it by amending the rules governing cookies and similar tracking technologies. The proposed changes aim to encourage less intrusive forms of tracking, prioritize first-party data collection, and reserve strict consent requirements for more invasive tracking practices. In practice, this should lead to a significant reduction in unnecessary cookie banners, while giving users simpler, more meaningful control over their privacy.
This clearly fits a broader shift in the EU policy, from personal tracking to data minimization and from profiling to contextual insights.
The EDPB & EDPS's joint opinion broadly supports the objective of simplification and harmonization between the GDPR and ePrivacy Directive. They do have some concerns that simplification could lead to reducing the level of protection of fundamental rights. The ePrivacy Directive is tied to fundamental rights to privacy and confidentiality of communications. The GDPR is much smaller in scope, focusing exclusively on personal data. This means that ePrivacy Directive protects the terminal equipment and private sphere, not just personal data. It could be that by moving the regulation of cookies towards GDPR, the risk of losing broader protection logic becomes real.
They propose keeping the scope of the proposed changes to both cookies and similar techniques, to ensure the cookie rules remains broadly applicable. They are also worried that the proposed changes will weaken the consent requirements for tracking, even if simplification is the goal.
In short, the EDPB and EDPS say, simplifying the rules around cookies and tracking is a good idea where necessary, but do not use simplification to weaken consent, narrow scope, or dilute the fundamental privacy protections of the ePrivacy framework.
Practical proposed changes
There are two important changes the European Commission is proposing:
With the above proposal, cookie banners will not completely disappear, but they will decrease significantly.
Additionally, the categories of cookies and similar techniques that you can use without consent are extended:
You still need to ask for consent for advertising tracking, cross-site tracking and personalized profiling. For those purposes, cookie banners will remain.
Looking forward
Since most of the EU organs believe we should change things, future change appears inevitable. But what can you already do as an organization to prepare?
At Considerati, we will follow the legislative process closely and provide updates as things develop. If you have questions about how the Digital Omnibus may affect your organization's cookie policy, or about the package more broadly, we are happy to have an introductory call.
Do you have any questions about the above or are you looking for strategic Legal advice? Contact Considerati, we offer specialised advice and tailored support.
Our services ContactRecente blogs
The Dutch Data Protection Authority (AP) has imposed a fine of 6,000 euros on the recruitment company Ambitious People Group (APG) for not promptly responding…