15-06-2026 Most organizations still run separate playbooks for cyber incidents under NIS2 and personal data breaches under the GDPR. The Digital Omnibus proposes a single-entry point to reduce that duplication, but it also forces a more disciplined internal triage. Introduced by the European Commission on 19 November 2025, the Digital Omnibus is a broad legislative package that would amend several EU digital laws, including the GDPR, the ePrivacy Directive, the Data Act and the NIS2 Directive. Its aim is to simplify an EU digital rulebook that has become increasingly complex. 

This blog is part of a series discussing the proposals in the European Commission's Digital Omnibus. A previous blog examined what the Omnibus means for the definition of personal data. This blog focuses on the proposal to introduce a Single-Entry Point for cybersecurity and data breach incident reporting, including how the proposed GDPR notification changes interact with existing obligations, and what it means in practice for organizations operating under multiple EU regulatory frameworks. 

The proposal by the European Commission 

The Single-Entry Point 

The same incident, a ransomware attack that encrypts customer data for instance, can simultaneously trigger notification obligations under the GDPR, NIS2, DORA, eIDAS and the CER Directive, each with its own deadline, template and competent authority. The Digital Omnibus proposes to address this through a Single-Entry Point (SEP): an online platform developed and maintained by ENISA through which an organization submits a single notification, routed to whichever authorities are designated as recipients under each applicable law. The underlying obligations, who must report, what, and to whom, remain unchanged; what changes is the administrative channel. ENISA must establish SEP within 18 months of the Regulation entering into force, with a possible extension to 24 months. 

GDPR Notification Changes 

 

Alongside the SEP, the Omnibus proposal also introduces a targeted amendment to Article 33 GDPR, which governs the notification of personal data breaches to supervisory authorities. Two significant changes are proposed: 

  1. The notification deadline would be extended from 72 hours to 96 hours 
  1. The threshold for notifying supervisory authorities would be raised. The proposal aligns Article 33 more closely with Article 34 GDPR, which already applies a “high risk” threshold for notifying affected individuals. As a result, personal data breaches that are not likely to result in a high risk to individuals would no longer require notification to supervisory authorities.  

Taken together, these two changes meaningfully reduce the compliance burden on organizations. The extended deadline gives incident response teams more time to assess a breach before filing, while the raised threshold means that lower-risk incidents will no longer trigger a supervisory notification at all. 

The EDPB's joint opinion broadly supports these changes, pointing to the sheer volume of breach notifications received by national data protection authorities as evidence that reducing lower-risk notifications will meaningfully ease administrative burden. However, it pointedly flags a timeline mismatch, observing that different deadlines apply under other reporting obligations, including NIS2 (24 or 72 hours), DORA (24 or 72 hours), eIDAS (24 hours), and the CER Directive (24 hours). On this point, the EDPB states it "would recommend more harmonization between the different notification obligations," a change that would allow organizations to operate a single, consistent incident response timeline across regulatory frameworks rather than managing competing clocks for the same event.  

The operational reality 

The SEP simplifies the reporting channel, but organizations will still need to navigate multiple legal frameworks during the early stages of incident response. A single cyber incident may trigger obligations under the GDPR, NIS2, DORA, and other sector-specific regimes, each with its own reporting threshold, assessment criteria, and notification timeline. As a result, incident response teams will still need to determine which frameworks apply, classify the incident under each regime, and organize their response around the earliest applicable deadline. The workflow below illustrates how this assessment may operate in practice. 

The GDPR amendments nevertheless provide some operational relief. Organizations will likely face fewer GDPR notifications overall and gain additional time to conduct forensic analysis, involve internal stakeholders, and determine whether a supervisory authority notification is genuinely required. This may allow incident response teams to focus resources on genuinely high-impact incidents rather than lower-risk notifications submitted. 

What remains unchanged 

  • Materiality thresholds remain different across regimes: what qualifies as a significant incident under NIS2 is not the same as a high-risk personal data breach under the GDPR. 
  • Notification content may still vary: each framework can require different information, so a single submission channel does not guarantee a fully uniform notification. 
  • Processor-to-controller obligations are unchanged: processors must still notify controllers of all personal data breaches under Article 33(2) GDPR, regardless of risk level, and the Omnibus does not introduce a harmonized baseline for how or when this must happen across sectors. 
  • External notifications remain separate: communications to users, customers, and data subjects continue to sit outside the SEP and must still be handled independently. 

Looking forward 

There are several practical measures organizations can already start preparing for: 

  • Build a single internal incident-classification process now: organizations will increasingly need to assess GDPR, NIS2, DORA and other reporting obligations simultaneously rather than through separate workflows.  
  • Expect fewer GDPR notifications, but not less scrutiny: the proposed “high risk” threshold may reduce lower-risk notifications, but incidents that are reported will likely receive greater regulatory attention.  
  • Prepare for a possible extension of the GDPR notification deadline to 96 hours: while the proposal is not yet finalized, organizations should already consider how additional investigation time could be used to improve internal fact-finding, risk assessments and notification quality. 
  • Prepare for multi-authority visibility through the SEP: notifications submitted through the platform may be reviewed simultaneously by several regulators, making consistency and documentation increasingly important.  

At Considerati, we will follow the legislative process closely and provide updates as things develop. If you have questions about how the Digital Omnibus may affect your organization's incident response obligations, or about the package more broadly, we are happy to have an introductory call. 

 

Begüm Canoglu Consultant Legal & Compliance

Do you want to know more?

Do you have any questions about the above or are you looking for strategic Legal advice? Contact Considerati, we offer specialised advice and tailored support.

Our services orContact