15/05/2026: On 19 November 2025, the European Commission published a legislative proposal aimed at simplifying and streamlining the European Union’s digital regulatory framework. The proposal brings together a package of largely technical amendments across a range of EU digital laws, framed as an effort to ease practical burdens, improve regulatory clarity and support the EU’s competitiveness. To that end, it provides for simultaneous amendments to several key legislative instruments, including the GDPR, the ePrivacy Directive, the Data Act and the NIS2 Directive. 

This blog is part of a series discussing the proposals in the European Commission’s Digital Omnibus. The previous blog focused on what the Omnibus means for AI literacy. In this blog, we will examine another notable aspect of the Digital Omnibus, focusing on the proposal to amend the definition of personal data (Article 4 of the GDPR). We will discuss what this amendment entails and explore the practical implications it may have for organisations if the proposal is adopted in its current form. 

The proposal by the European Commission 

The proposal adds the following text to Article 4 of the GDPR: ‘Information relating to a natural person is not necessarily personal data for any other person or entity merely because another entity is able to identify that natural person. Information does not constitute personal data for a particular entity where that entity cannot identify the natural person to whom the information relates, taking into account the means that may reasonably be used by that entity. Such information does not constitute personal data for that entity merely because a potential subsequent recipient has means that may reasonably be used to identify the natural person to whom the information relates. 

The proposal clarifies that whether information qualifies as personal data depends on the specific position of the relevant controller or processor. If an organisation has the means to identify a person because they have additional datasets, the data that might not be directly linked to a person will still fall under GDPR. However, when an organisation only has that set of data that is not directly linked to a person and this party doesn’t have other datasets available to them, this will fall outside of the scope of GDPR. As a result, the same dataset may fall within the scope of the GDPR for an organisation that holds or can access identifying information, while remaining outside its scope for a recipient that lacks such means. 

This approach is particularly relevant where data has been pseudonymised. Pseudonymisation means that direct identifiers are removed from the data and stored separately, so that individuals can only be identified if that additional information is available. In such cases, the key question introduced by the proposal is whether the organisation handling the data has access to the additional information required for reidentification, which may differ between organisations in a datasharing arrangement.  

The proposal reflects the approach taken by the Court of Justice of the European Union in the SRB v EDPS case, which concerned the sharing of pseudonymised data. The Court emphasised that what matters is whether a particular organisation can identify someone with the information and resources available to it. 

The practical implications 

Taking a contextual approach to the definition of personal data may affect the position of companies, organisations and other parties. In certain circumstances, pseudonymised data may fall outside the scope of the GDPR, which could reduce compliance obligations and operational burdens.  

Under the Digital Omnibus, the qualification of data as personal data is assessed by reference to the organisation concerned and the context in which it operates. This has relevance for the handling and sharing of pseudonymised data. Where a recipient has no effective means of reidentifying individuals, the GDPR may not apply to that recipient, which can facilitate easier data sharing for purposes such as research or data analysis. 

At the same time, this approach requires careful substantiation. Organisations will need to assess, on a casebycase basis, whether reidentification is realistically excluded, considering technical measures as well as legal and organisational safeguards. 

This becomes particularly relevant in cooperation structures, for example where data is shared with service providers. In such cases, organisations may seek to limit the possibility of re-identification. For example, by keeping identifying information, such as keys or tables that link data back to individuals, separate from the dataset that is shared and restricting access to that information. They may also remove identifying elements altogether where no link with internal systems is required or limit the level of detail in the data so that it cannot easily be traced back to individuals.  

It will remain important to clarify roles and responsibilities through contractual arrangements. In addition, transparency and information obligations remain relevant for controllers where and to the extent that the data continue to qualify as personal data from their perspective. 

Overall, the amendment does not remove obligations as such but shifts the emphasis from a uniform assessment to a contextspecific evaluation that organisations must be able to justify and document.  

Final Notes 

The EDPB and the EDPS have expressed serious concerns about the proposed amendment to the definition of personal data. In their Joint Opinion published in February, they argued that the amendment would narrow the scope of the concept of personal data, thereby going beyond a technical amendment or a simple codification of the Court of Justice of the EU's case law. 

Furthermore, they emphasise that the definition of personal data should primarily describe what constitutes personal data rather than what falls outside its scope, as they believe this increases the risk of legal uncertainty. They also oppose the proposal to allow the Commission to determine, through implementing acts, when pseudonymised data no longer qualifies as personal data. This is because it directly affects the scope of the GDPR, which falls within the remit of supervisory authorities and courts. 

While the proposal draws on the approach taken by the Court of Justice, the EDPB and EDPS appear concerned that turning this casespecific reasoning into a more general rule, in particular by allowing it to be further specified through implementing acts, may have broader effects on the scope of the GDPR than the Court’s case law itself. It remains to be seen how these criticisms will influence the legislative process and whether the proposed amendment to the definition will ultimately be retained in the Digital Omnibus. 

For organisations, it’s already wise to check where they rely on pseudonymisation and see what the outcome of the changes could be for the organisation.  

At Considerati, we will monitor the legislative process closely to provide you with timely updates and practical advice. If you have any questions on how we could help support you with the implications of pseudonymization within your organization, or if you have any questions about the EU Digital Omnibus package in general, we’re happy to have an introductory call.  

Pien Kamps Legal Consultant

Want to know more? Get in touch!