Omnibus and Digital Health: Simplification Objective and Resistance from Authorities and Member States
min readOn November 19, 2025, the European Commission published its proposal for a "Digital Omnibus" regulation, aimed at simplifying the European Union's digital regulatory framework, reducing the administrative burden on businesses, and strengthening European competitiveness. The text introduces, in particular, significant changes regarding data processing, including health data.
Structural Changes for Health Data Processing
The text proposes a redefinition of the concept of "personal data" that would exclude pseudonymized data from the scope of the GDPR where the data holder does not have the means to re-identify data subjects.
For stakeholders in medical research and AI in healthcare, the stakes are high.
The proposal also provides for a new article in the GDPR explicitly mentioning the development and deployment of artificial intelligence systems as activities that may be grounded on the legitimate interest legal basis, with a circumscribed derogation for the residual processing of sensitive data, including health data. For pharmaceutical and medical technology companies, these provisions would significantly facilitate the use of AI in the development of medical devices and clinical research.
The French Dimension: SNDS, Reference Methodologies, HDW Framework, and Health Data Hosting Regime
In France, any modification to the concept of personal data would have particularly significant consequences for the health research ecosystem, insofar as France has introduced additional conditions beyond those of the GDPR for the processing of health data.
Any change to the definition of personal data would have cascading effects on access to the SNDS (Système National des Données de Santé – National Health Data System), the CNIL's reference methodologies (MRs), the health data warehouse (HDW) framework, and potentially even the health data hosting (HDS) regime. This overhaul would come at a time when the CNIL is preparing to publish amended MRs, following nearly a year and a half of public consultations.
The European Dimension: The European Health Data Space
Similarly, the European Health Data Space (EHDS), adopted on February 11, 2025, distinguishes data access procedures based on the personal data qualification of pseudonymized data. Article 68 of the EHDS governs the issuance of data processing authorizations by health data access bodies, precisely because such data remain subject to the GDPR. Accordingly, the EHDS – the secondary use provisions of which will not begin to apply until 2029 – could be transformed before it is even deployed.
A Firm Response from European Data Protection Authorities and Member States
On February 11, 2026, the EDPB and the EDPS adopted a joint opinion which, while acknowledging the simplification objective, rejected or criticized several central proposals of the draft. Their position on the redefinition of personal data is categorical, calling on co-legislators not to adopt these amendments, considering that they go well beyond a targeted or technical modification of the GDPR. They stressed that the definition of personal data lies at the very core of European data protection law, including Article 8 of the Charter of Fundamental Rights. The authorities further regretted that the proposal was not accompanied by a full impact assessment and considered that insufficient attention had been paid to the adverse effects of certain amendments on fundamental rights.
The CNIL, within the EDPB, participated from December 2025 in the initial strategic discussions, emphasizing the protection of individuals' personal data. The French approach is consistent with the Helsinki Declaration of July 3, 2025, by which the EDPB had affirmed that compliance should not be achieved through a rewriting of the GDPR, but through better practical guidance for organizations.
In a first Council compromise text dated February 20, 2026, on the simplification proposal, the Commission's proposal to codify the CJEU's SRB judgment amending the definition of personal data was rejected by Member States on the grounds that it is "important to provide further clarification on when a natural person should be considered identifiable" through EDPB guidelines. Likewise, the provision allowing the Commission to adopt implementing acts to determine the definitional criteria related to pseudonymization was deleted. On the secondary use of data for scientific research purposes, the recitals were consistent with the guidelines subsequently published by the EDPB on April 15, 2026[1].
In a second Council compromise dated April 15, Member States took a position against the Commission's proposal allowing reliance on the legitimate interest legal basis to train AI systems with personal data. Regarding the amendment seeking to exclude pseudonymized data from the definition of personal data, the Council opposed it but invited the EDPB to adopt an opinion "no later than twelve months after the entry into force of the regulation" on pseudonymization and anonymization, in order to clarify the concept of "means reasonably likely to be used to identify [a person]."
The proposals are now in the hands of the European co-legislators for a vote scheduled in June 2026. According to a leaked Council compromise text, the proposal to redefine personal data would have been withdrawn. Nonetheless, the CJEU's SRB judgment of September 4, 2025, has gained traction and will continue to do so, whether or not it is transposed into regulatory text...