The Digital Omnibus Regulation proposal, adopted by the European Commission in February 2026, is a package of targeted amendments to several EU digital laws including the GDPR. Its stated aim is to reduce administrative overhead, particularly for smaller organisations. For sovereign infrastructure operators serving government, finance, healthcare and legal clients, the proposal raises a counterintuitive problem: simplification, in the wrong places, erodes the very documentation architecture that makes sovereign compliance credible and auditable.
What the Digital Omnibus Proposes to Change in GDPR
The core GDPR amendments in the Digital Omnibus target documentation obligations, primarily the record of processing activities under GDPR Article 30, and seek to reduce sub-processor disclosure burdens for data processors under GDPR Article 28.
The proposal introduces a threshold-based exemption for organisations with fewer than 500 employees, allowing them to maintain a simplified, reduced-scope RoPA rather than the full record currently required. For data processors, the proposal contemplates a streamlined approach to sub-processor notification, potentially replacing the current requirement to inform controllers individually of sub-processor changes with a general notification mechanism or a publicly available register.
According to the European Commission’s own impact assessment accompanying the Digital Omnibus package, roughly 70 percent of GDPR compliance costs reported by SMEs relate to record-keeping and documentation obligations (European Commission Digital Omnibus Impact Assessment, 2026). The Commission presents simplification in this area as a competitiveness measure, particularly for technology firms and cloud service providers competing against non-EU incumbents.
The EDPB and EDPS Joint Opinion: Fundamental Rights Are Not Negotiable
The EDPB and EDPS responded to the Digital Omnibus proposals in a Joint Opinion published on 10 February 2026, and their position is unambiguous about the limits of permissible simplification.
The Joint Opinion states: “The proposed exemptions must not result in a lower level of protection for individuals. Fundamental rights are not a compliance burden that can be traded off against administrative simplification.” (EDPB/EDPS Joint Opinion on Digital Omnibus, February 2026, edpb.europa.eu)
The EDPS reinforced this in its separate commentary: “Simplification that removes documentation requirements does not remove the underlying data protection risks; it merely makes them less visible to supervisory authorities.” (EDPS, 2026, edps.europa.eu)
For CISOs and DPOs, these statements carry direct operational meaning. They signal that supervisory authorities will not interpret reliance on a simplified track as a defence if a breach or enforcement action reveals that the underlying processing activities carried risks the simplified documentation failed to capture. The Joint Opinion effectively advises against assuming that legislative simplification equals reduced enforcement exposure.
How Simplified RoPA Interacts with NIS-2 and DORA Documentation Duties
The Digital Omnibus does not amend NIS-2 (Directive 2022/2555, Article 21) or DORA. Both frameworks impose independent, overlapping documentation requirements on the same population of regulated entities that the Digital Omnibus would exempt from full Article 30 obligations.
NIS-2 Article 21 requires essential and important entities to document their cybersecurity risk-management measures, including information on supply chains, incident response procedures and access controls. DORA, applicable to financial entities and their critical ICT third-party providers, mandates a detailed ICT risk framework, register of third-party arrangements and audit trail documentation. In both cases, the required documentation substantially overlaps with what a complete GDPR Article 30 RoPA would contain when applied to a processor in those sectors.
| Obligation | Instrument | Threshold or scope | Affected by Digital Omnibus? |
|---|---|---|---|
| Record of processing activities (RoPA) | GDPR Article 30 | Proposed exemption below 500 employees | Yes, simplified track proposed |
| Sub-processor disclosure | GDPR Article 28 | All processors | Yes, streamlined notification proposed |
| Cybersecurity risk-management documentation | NIS-2 Article 21 | Essential and important entities | No |
| ICT third-party register and risk framework | DORA Articles 28-30 | Financial entities and critical ICT providers | No |
The practical result is that regulated organisations cannot use the Digital Omnibus simplified track to reduce their overall documentation burden: NIS-2 and DORA requirements independently compel documentation that is at least as extensive as a full Article 30 RoPA. The only entities for whom the Digital Omnibus simplification yields a genuine reduction are those outside the scope of sector-specific regulation, which excludes the primary readership of this knowledge base.
The Sovereign Audit Instrument Risk: What Simplification Destroys
For many organisations operating sovereign on-premises infrastructure, the full GDPR Article 30 RoPA has served a dual function. It satisfies the legal documentation requirement, and it functions as a living audit instrument: a structured record of which data is processed where, under which legal basis, with which sub-processors, retained for how long, and subject to which technical and organisational measures. When a DPA, external auditor, customer or regulator requests evidence of data sovereignty, a complete and well-maintained RoPA is the primary documentary response.
The EDPB reported that EU data protection authorities imposed fines totalling approximately EUR 2.1 billion under the GDPR between January and December 2023 (EDPB Annual Report 2023, edpb.europa.eu). A significant portion of major enforcement actions referenced inadequate records and insufficient documentation of processing activities as aggravating factors. Simplifying those records reduces their evidentiary value in exactly the enforcement scenarios they are designed to address.
Sovereign infrastructure operators should therefore treat the Digital Omnibus simplified track as an option that weakens rather than strengthens their compliance posture. Maintaining the full Article 30 structure, even if no longer strictly required for organisations below 500 employees, preserves the audit trail that differentiates a credible sovereign offering from a nominal one.
The Enforcement Procedural Regulation and Ongoing Cross-Border Cases
The GDPR Enforcement Procedural Regulation (Regulation 2024/1689) harmonises how supervisory authorities coordinate cross-border enforcement, including the handling of cases involving large US-based cloud providers. It entered into force in 2024 and introduces binding timelines and structured cooperation mechanisms for the one-stop-shop procedure.
The Digital Omnibus proposals do not amend Regulation 2024/1689. Cross-border enforcement against US cloud providers, including ongoing cases before several lead supervisory authorities regarding international data transfers under FISA 702 and the CLOUD Act, will continue under the procedural framework regardless of what GDPR documentation obligations apply to smaller operators. For sovereign infrastructure providers, this is relevant in two directions: their customers face continued enforcement risk if they rely on US-controlled cloud services, and the sovereign alternative gains demonstrable compliance value precisely because it does not carry that jurisdictional exposure.
Simplified GDPR obligations do not simplify the legal analysis of whether a data transfer to a US provider creates exposure under FISA 702. That analysis depends on the nature of the provider’s legal organisation and the technical access paths to data, not on the size of the data controller or the completeness of its internal documentation records.
Updating Data Processing Agreements for the Post-Digital Omnibus Landscape
Sovereign infrastructure providers should proactively revise their standard data processing agreements and sub-processor disclosure mechanisms in response to the Digital Omnibus proposals. The direction of travel should be toward greater contractual specificity, not toward reliance on simplified tracks.
Concretely, DPA templates should include an explicit clause stating that the processor maintains full GDPR Article 28-compliant obligations and that simplified compliance alternatives introduced by subsequent legislation do not apply to the contractual relationship unless the controller explicitly requests and documents a change. This protects regulated-sector customers, such as banks subject to DORA or hospitals subject to NIS-2, from inadvertently falling below the standards their sector regulators expect.
Sub-processor disclosure clauses should retain individual prior notification as the default, rather than adopting any general notification register that the Digital Omnibus may introduce. For a sovereign infrastructure provider, the ability to demonstrate that every sub-processor has been specifically disclosed, reviewed and contractually bound is a market differentiator, not merely a compliance obligation.
Audit-right clauses in DPAs should be strengthened to include the right to inspect processing records at least annually and following any significant change in processing activities. This clause structure remains fully compatible with GDPR Article 28(3)(h) and is unaffected by the Digital Omnibus proposals. Maintaining it signals to regulated-sector customers that the sovereign provider’s compliance posture is stable and independent of legislative volatility.
Practical Guidance for CISOs and DPOs Evaluating Simplified Compliance Tracks
Given the EDPB and EDPS Joint Opinion, the interaction with NIS-2 and DORA, and the enforcement trajectory under Regulation 2024/1689, the practical guidance for CISOs and DPOs in regulated sectors or those evaluating sovereign alternatives is straightforward.
First, do not redesign existing compliance architecture around a proposal that has not yet entered into force and that the EDPB has publicly flagged as potentially incompatible with fundamental rights obligations. Legislative processes at EU level involve Council and Parliament amendments that frequently alter Commission proposals substantially.
Second, treat the Digital Omnibus simplified track as a floor, not a ceiling. If your organisation qualifies for the simplified RoPA under the 500-employee threshold but operates in a regulated sector, your sector regulator’s expectations set a higher effective floor than the GDPR simplified track allows.
Third, use the Digital Omnibus debate as a prompt to audit and strengthen your existing Article 30 records rather than to reduce them. A well-maintained, complete RoPA is currently one of the strongest instruments available to demonstrate that processing is confined within sovereign jurisdiction and that no exposure to foreign law-enforcement access has occurred. That evidentiary value is independent of whether the simplified track eventually becomes law.
FAQ
Does the Digital Omnibus proposal eliminate the Article 30 RoPA requirement for organisations under 500 employees?
The proposal introduces a simplified, lighter-weight RoPA for organisations below the 500-employee threshold, but it does not fully eliminate the obligation. For regulated-sector entities subject to NIS-2 or DORA, overlapping documentation duties effectively mean a full RoPA remains the only defensible approach regardless of the simplified track.
If my organisation operates sovereign on-premises infrastructure, does the Digital Omnibus reduce our compliance burden?
In practice, very little. Sovereign infrastructure operators typically serve regulated-sector clients whose contracts, sector-specific regulators and audit obligations require full Article 28 and Article 30 documentation. The simplified track does not exempt the data controller customers those operators serve from their own obligations.
How does the GDPR Enforcement Procedural Regulation (Regulation 2024/1689) interact with the Digital Omnibus simplification proposals?
Regulation 2024/1689 harmonises how data protection authorities coordinate cross-border enforcement, including cases against large US cloud providers. Simplified GDPR obligations do not affect that enforcement mechanism. Cross-border cases will continue under the procedural regulation, reinforcing why documented sovereignty over data remains a risk-management advantage rather than a formality.
Should a sovereign data processor update its standard data processing agreement template in response to the Digital Omnibus proposals?
Yes, but in the direction of greater clarity rather than simplification. DPA templates should explicitly state that the processor maintains full Article 28-compliant obligations and that any simplified tracks introduced by the Digital Omnibus do not apply to the contractual relationship, protecting regulated-sector customers from inadvertently falling below required standards.
What is the EDPB and EDPS joint position on the Digital Omnibus GDPR changes?
In their Joint Opinion of 10 February 2026, the EDPB and EDPS expressed clear concern that threshold-based exemptions risk lowering the effective protection of individuals’ fundamental rights. They called on the co-legislators to ensure that any simplification measures do not reduce substantive data protection standards or weaken supervisory authority powers. Their statement is the authoritative reference point for any DPO or CISO assessing whether to rely on simplified compliance tracks.
Hoe Qsentinel dit oplost
Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.
