15-06-2026 Most organizations still run separate playbooks for cyber incidents under NIS2 and personal data breaches under the GDPR. The Digital Omnibus proposes a single-entry point to reduce that duplication, but it also forces a more disciplined internal triage. Introduced by the European Commission on 19 November 2025, the Digital Omnibus is a broad legislative package that would amend several EU digital laws, including the GDPR, the ePrivacy Directive, the Data Act and the NIS2 Directive. Its aim is to simplify an EU digital rulebook that has become increasingly complex.
This blog is part of a series discussing the proposals in the European Commission's Digital Omnibus. A previous blog examined what the Omnibus means for the definition of personal data. This blog focuses on the proposal to introduce a Single-Entry Point for cybersecurity and data breach incident reporting, including how the proposed GDPR notification changes interact with existing obligations, and what it means in practice for organizations operating under multiple EU regulatory frameworks.
The proposal by the European Commission
The Single-Entry Point
The same incident, a ransomware attack that encrypts customer data for instance, can simultaneously trigger notification obligations under the GDPR, NIS2, DORA, eIDAS and the CER Directive, each with its own deadline, template and competent authority. The Digital Omnibus proposes to address this through a Single-Entry Point (SEP): an online platform developed and maintained by ENISA through which an organization submits a single notification, routed to whichever authorities are designated as recipients under each applicable law. The underlying obligations, who must report, what, and to whom, remain unchanged; what changes is the administrative channel. ENISA must establish SEP within 18 months of the Regulation entering into force, with a possible extension to 24 months.
GDPR Notification Changes
Alongside the SEP, the Omnibus proposal also introduces a targeted amendment to Article 33 GDPR, which governs the notification of personal data breaches to supervisory authorities. Two significant changes are proposed:
Taken together, these two changes meaningfully reduce the compliance burden on organizations. The extended deadline gives incident response teams more time to assess a breach before filing, while the raised threshold means that lower-risk incidents will no longer trigger a supervisory notification at all.
The EDPB's joint opinion broadly supports these changes, pointing to the sheer volume of breach notifications received by national data protection authorities as evidence that reducing lower-risk notifications will meaningfully ease administrative burden. However, it pointedly flags a timeline mismatch, observing that different deadlines apply under other reporting obligations, including NIS2 (24 or 72 hours), DORA (24 or 72 hours), eIDAS (24 hours), and the CER Directive (24 hours). On this point, the EDPB states it "would recommend more harmonization between the different notification obligations," a change that would allow organizations to operate a single, consistent incident response timeline across regulatory frameworks rather than managing competing clocks for the same event.
The operational reality
The SEP simplifies the reporting channel, but organizations will still need to navigate multiple legal frameworks during the early stages of incident response. A single cyber incident may trigger obligations under the GDPR, NIS2, DORA, and other sector-specific regimes, each with its own reporting threshold, assessment criteria, and notification timeline. As a result, incident response teams will still need to determine which frameworks apply, classify the incident under each regime, and organize their response around the earliest applicable deadline. The workflow below illustrates how this assessment may operate in practice.
The GDPR amendments nevertheless provide some operational relief. Organizations will likely face fewer GDPR notifications overall and gain additional time to conduct forensic analysis, involve internal stakeholders, and determine whether a supervisory authority notification is genuinely required. This may allow incident response teams to focus resources on genuinely high-impact incidents rather than lower-risk notifications submitted.
What remains unchanged
Looking forward
There are several practical measures organizations can already start preparing for:
At Considerati, we will follow the legislative process closely and provide updates as things develop. If you have questions about how the Digital Omnibus may affect your organization's incident response obligations, or about the package more broadly, we are happy to have an introductory call.
Do you have any questions about the above or are you looking for strategic Legal advice? Contact Considerati, we offer specialised advice and tailored support.
Our services ContactRecente blogs
The Dutch Data Protection Authority (AP) has imposed a fine of 6,000 euros on the recruitment company Ambitious People Group (APG) for not promptly responding…