What the Leaked Council Documents Say About AI and Personal Data

Digital Omnibus: What the Leaked Council Documents Say About AI and Personal Data

On 21 September 2026, the privacy organisation noyb published leaked Council documents on the Digital Omnibus, along with a strongly worded assessment of their contents. The documents concern how personal data may be used to develop and operate AI systems under the GDPR.

This piece sets out what the published documents say, what the parties involved have said about them, and where the file currently stands. We take no position on the merits. The proposals are still under negotiation, and nothing described here is law.

Key Takeaways

The leaked text is Council document 12535/26, a Presidency revised compromise text dated 3 September 2026, covering the Digital Omnibus proposal that amends the GDPR among other instruments.

The provision at the centre of the debate is a recital stating that processing personal data to develop and deploy AI systems “may be regarded as” carried out for a legitimate interest, while preserving the override where the rights of the data subject prevail. noyb reads this as a general permission; the text itself retains the balancing language.

Nothing has changed in law. The GDPR applies in full, the file remains in Council and Parliament, and roughly 1,840 amendments were tabled in Parliament in August 2026.

What Documents Were Published?

noyb published two Council documents alongside its commentary.

The first is the Presidency revised compromise text, circulated as Council document 12535/26, dated Brussels, 3 September 2026 and marked LIMITE. It was prepared for a meeting on 11 September 2026 and revises an earlier compromise text, ST 10677/26. The document covers the Digital Omnibus proposal, interinstitutional file 2025/0360 (COD), which amends the GDPR along with several other regulations and directives.

The second is a set of written comments from Germany, circulated as WK 11020/2026 ADD 4 on 17 August 2026, submitted to the Council’s Antici Group.

noyb also references an article in Politico Pro, which is behind a paywall, as the original source of the leak.

What Does the AI Provision Say?

The provision drawing most attention is recital 33a of the compromise text. It reads, in relevant part, that processing personal data “in the context of the development and deployment of an AI system or of an AI model, may be regarded as carried out for a legitimate interest of the controller concerned” under Article 6(1)(f) GDPR, “except where such interests are overridden by the interests, or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child, or where other Union or national laws explicitly require consent.”

Two drafting features are worth noting for readers following the debate.

The text uses “may be regarded as” rather than a definitive statement, and it expressly preserves the override where the data subject’s rights prevail. That is the structure of the existing legitimate interest test in Article 6(1)(f).

It also sits in a recital. Recitals explain how the operative provisions should be read; they are not themselves binding obligations. The same text states that controllers remain obliged to choose an appropriate lawful ground under Article 6, and that any such processing remains subject to organisational and technical safeguards.

A separate recital, 33, addresses special categories of data. It would allow a derogation from the Article 9 prohibition, limited to special category data that ends up in training or validation sets “incidentally and residually,” where the controller has taken measures to avoid processing it, and erases it once identified. Where erasure would require re-engineering the model or is technically impossible, the controller must protect the data from further processing.

What Is noyb’s Position?

noyb’s assessment is considerably harsher than the drafting language suggests on its face, and the organisation sets out why.

Its central claim is that the provision amounts to a general permission. In noyb’s words, companies would be “automatically assumed to have an overriding ‘legitimate interest’ if they train or use any AI product,” with no requirement to ask users for consent, and covering data entered decades ago by people who were never customers of the company now using it.

Max Schrems, noyb’s chair, is quoted saying: “Under these proposals, the profits of AI companies would trump European’s fundamental right to privacy. This is nothing but a digital expropriation of Europeans.”

noyb makes a second argument about scope. It notes that the GDPR normally permits processing for specified purposes, while this provision attaches to a technology. Schrems is quoted: “It’s like saying anything goes, no matter what you do, as long as it’s done with a specific technology.”

The organisation also raises an industrial policy objection, arguing that companies holding the largest existing data sets would benefit most, and that European data and know-how would flow to providers in the United States and China.

noyb’s article names OpenAI, Anthropic, Google, Meta and SpaceX as the companies whose commercial interests it says would be prioritised. It also observes that Ireland, which holds the Council presidency for the second half of 2026, hosts the European headquarters of many of these companies. That observation is noyb’s own framing rather than a claim made in the documents.

What Else Is in the Compromise Text?

Two further elements of the document have drawn comment.

The first concerns the definition of personal data. The text states that information “is not to be considered personal data for a given entity where that entity does not have means reasonably likely to be used to identify the natural person to whom the information relates.” Where such data is later passed to a third party who does have those means, it becomes personal data for that third party. The text presents this as a clarification consistent with case law of the Court of Justice, and envisages the Commission and the European Data Protection Board setting technical criteria in an implementing act.

noyb’s concern is that most IT systems run on identifiers such as user IDs, tracking IDs and IP addresses, and that this drafting could move a substantial amount of routine processing outside the GDPR’s scope.

The second concern is data subject requests. The text develops the concept of requests that are “manifestly unfounded or excessive,” including where an “abusive intention on the part of the data subject” can be shown, such as requests made for purposes other than protecting their own data. noyb argues that assessments of this kind would in practice be made by the regulated companies themselves.

What Does Germany’s Document Propose?

The German comments are drafting suggestions on the earlier compromise text, shown as insertions and deletions.

They would remove wording from the safeguards paragraph, including a reference to data minimisation when selecting training sources and a reference to giving data subjects “an unconditional right to object” to the processing of their personal data.

They would also add a provision disapplying the obligations in Articles 14 and 16 to 18 GDPR where compliance “proves impossible or would involve a disproportionate effort.” In those cases, the controller would take alternative measures, including making information publicly available before training, explaining how to file an objection or request rectification, and applying technical measures after training to prevent disclosure or identification. The comments ask the Commission to issue guidelines on how to implement this.

noyb characterises the German document as a proposal for liberalisation of AI companies. Readers can compare that description against the text itself, which is published in full.

What Have the Data Protection Authorities Said?

The European Data Protection Board and the European Data Protection Supervisor issued Joint Opinion 2/2026 on the Digital Omnibus in February 2026. Their position is mixed rather than uniformly opposed.

They welcomed parts of the package, including proposals to harmonise and simplify personal data breach notification under Articles 33 and 34.

They objected firmly to the change to the definition of personal data, urging co-legislators not to adopt it on the basis that it goes beyond a targeted or technical amendment, does not accurately reflect the case law of the Court of Justice, and would significantly narrow the concept of personal data.

What Is the Commission’s Stated Rationale?

The Commission presented the Digital Omnibus on 19 November 2025 as a simplification and competitiveness measure. Its stated aim is to reduce administrative burden and compliance costs for businesses and public administrations, following the Draghi report on European competitiveness and the Competitiveness Compass. The associated target is to reduce administrative burden by at least 25% for companies generally and 35% for small and medium enterprises.

The Commission has said the package maintains a high level of protection for individuals. noyb disputes that characterisation, and notes that the proposal was handled under a fast-track procedure.

Is Industry United Behind the Proposals?

Not entirely, which is worth noting given how the debate is often framed.

Ecommerce Europe, an industry association, published an assessment on 7 September 2026 stating that several proposed articles, specifically 88a, 88b and 88c, “introduce new compliance layers rather than removing existing ones.” It points to a six-month mandatory re-consent cycle and narrower audience-measurement exemptions as increasing the operational burden for online retailers. The same assessment welcomes the single breach notification proposal.

Where Does the File Stand?

The Digital Omnibus package contained two proposals, and they have moved at different speeds.

The AI-focused omnibus was concluded quickly, driven by the approaching application dates of the AI Act. Co-legislators reached agreement in trilogue on 7 May 2026, and Parliament approved it on 16 June 2026.

The data-focused omnibus, which contains the GDPR amendments discussed here, remains under negotiation. Parliament issued its draft report in June 2026, and tabled roughly 1,840 amendments in August 2026. In Council, the Irish Presidency is circulating successive compromise texts, including the leaked 12535/26.

For organisations, the practical position today is unchanged. The GDPR applies in full. Legitimate interest as a basis for AI training still requires a documented balancing test, the existing definition of personal data still applies, and data subject rights still operate as they do now.

Conclusion

The gap between the drafting and the commentary is the key issue here. The compromise text retains the language of the legitimate interest balancing test and places the AI provision in a recital, while noyb reads the combined effect of these changes as removing meaningful limits in practice. Both readings are available from the same document, which is why the negotiation matters.

Organisations that process personal data for AI development have no reason to change their approach on the basis of a leaked compromise text. The file has months of negotiation ahead, a Parliament position that remains unsettled, and a data protection authority opinion on record opposing one of its central elements.

GDPRLocal will continue tracking the file. If you want to discuss how your current AI processing stands under the GDPR as it exists today, our data protection consultants can help.

Frequently Asked Questions

Has the GDPR changed?

No. The Digital Omnibus is a proposal under negotiation between the Council and the European Parliament. The GDPR applies in its current form, and the leaked documents are internal negotiating texts, not adopted law.

What is a Presidency compromise text?

It is a draft circulated by the member state holding the rotating Council presidency, attempting to find a position that delegations can agree on. Ireland holds the presidency for the second half of 2026. Compromise texts go through several revisions and carry no legal force.

Does the proposal remove consent requirements for AI training?

The recital in question says such processing “may be regarded as” resting on legitimate interest, subject to the data subject’s rights not overriding it and to other laws that explicitly require consent. noyb argues the practical effect would be a general permission. The competing readings of that text are part of what is being negotiated.

What is the difference between the AI omnibus and the data omnibus?

The Digital Omnibus package contained two proposals. The AI omnibus, which adjusted AI Act timelines, was agreed in May 2026 and approved by Parliament in June 2026. The data omnibus, which contains the GDPR amendments, is still in negotiation.

When might the proposals become law?

There is no confirmed date. Council and Parliament must agree on a common text through trilogue negotiations before adoption, and Parliament’s position remains under development, with a large number of amendments tabled.

Disclaimer: This blog post is intended solely for informational purposes. It does not offer legal advice or opinions. This article is not a guide for resolving legal issues or managing litigation on your own. It should not be considered a replacement for professional legal counsel and does not provide legal advice for any specific situation or employer.

About the Author

Zlatko Delev

Head of Commercial & Country Manager

Zlatko Delev is Head of Commercial and Country Manager at GDPRLocal, where he leads the company’s commercial strategy and market presence. He brings international experience across sales, marketing, and customer success, along with a legal background from his studies at Iustinianus Primus Law School in Skopje, Macedonia.

Zlatko sits at the front line of GDPRLocal’s client relationships, guiding organisations through the first stages of their compliance journey and helping them understand where they stand and where they need to go on GDPR, information security, and the emerging landscape of AI regulation. His role bridges commercial strategy with practical data protection knowledge, ensuring clients get clear, actionable direction from their very first conversation with GDPRLocal.

Alongside his commercial focus, Zlatko has trained extensively in project management and organisational leadership, including risk management, stakeholder communication, agile methodology, and digital marketing, a broad skill set that supports his structured, delivery-focused approach to growing GDPRLocal’s business internationally.