EU member states are expected to decide on Sunday, October 11, 2026 whether to adopt the Council's negotiating mandate on the Digital Omnibus, a 163-page text dated October 2, 2026 that would rewrite parts of the GDPR and the ePrivacy Directive. The document, prepared by the General Secretariat of the Council for the Permanent Representatives Committee, cuts to four months the period a website must wait before asking again for cookie consent after a refusal, exempts the measurement of contextual advertising from consent, and keeps a contested clause on tax data transfers that French campaigner Fabien Lehagre says the Council could remove in one line.

In Short

EU governments have agreed on draft wording for a large package of changes to Europe's privacy and data rules, and their ambassadors are expected to vote on it on October 11. For advertisers and publishers, the draft means sites could measure ads that are matched only to the page you are reading without asking for consent, and a site you said no to could ask again after four months instead of six. None of this is law yet, because the European Parliament still has to agree its own position and then negotiate a final text with the Council.

The document and the vote

The text is Council document 13886/26, classified LIMITE and addressed by the General Secretariat of the Council to the Permanent Representatives Committee. Its subject line covers amendments to eight existing laws, among them the GDPR (Regulation 2016/679), the ePrivacy Directive (2002/58/EC), the Data Act (Regulation 2023/2854) and the NIS2 Directive, plus the repeal of the Platform-to-Business Regulation, the Free Flow of Non-Personal Data Regulation, the Data Governance Act and the Open Data Directive. The interinstitutional file number is 2025/0360 (COD).

According to the cover note, the Antici Group (Simplification), the Council working party set up on February 21, 2025 to handle the simplification omnibus files, examined the proposal at ten meetings: January 16, February 13, February 27, April 24, May 8, May 27, June 15, July 16, September 11 and September 25. The Presidency, held by Ireland since July 1, 2026, circulated two revised compromise texts between July and September. The October 2 document underlines changes compared with the previous compromise text, dated September 21, 2026 (ST 13112/26), and marks changes against the Commission proposal in bold and strikethrough.

The timing has slipped. Agence Europe reported on October 5 that the Irish Presidency aimed to secure a mandate at the ambassadors' meeting on Wednesday, October 7. That did not happen. "Sunday, 11 October. EU ambassadors are now expected to decide on the Digital Omnibus, after Wednesday's meeting ended without a vote over the Data Act," Lehagre wrote on LinkedIn this week.

The cover note asks Coreper "to agree on the text of the mandate for negotiations with the European Parliament, as set out in the Annex to this Note, to enable the Presidency to conduct those negotiations." It adds that, in line with a transparency approach endorsed by Coreper on July 14, 2023, "the text of the mandate thus agreed will be made public unless the Permanent Representatives Committee objects."

The background is political pressure from the top. According to the cover note, the European Council on March 19, 2026 called for agreement on "all pending Omnibus packages" before the end of 2026. The AI part of the Digital Omnibus had already been split off: the Council approved it on June 29, 2026, following negotiations with Parliament. PPC Land reported the provisional agreement on that AI file on May 7, 2026, which pushed high-risk deadlines to 2027.

Cookies stay in the ePrivacy Directive

The Commission's proposal of November 2025 would have moved consent rules for device access out of the ePrivacy Directive and into the GDPR, as a new Article 88a, with a companion Article 88b obliging websites to honour machine-readable consent signals set in browsers. The Council dismantled that structure over the summer. Its June 18 text removed the browser signal in Article 88b, and by the September 3 compromise, PPC Land found, both Articles 88a and 88b had been deleted and the rules returned to Article 5(3) of the ePrivacy Directive.

The October 2 text keeps that architecture. The cover note says the rules "applicable for the placing of cookies online have been further clarified under the ePrivacy Directive." Under the rewritten Article 5(3), storing or reading information on a subscriber's or user's device remains allowed only with consent, "in accordance with Regulation (EU) 2016/679." Member states would have to designate their GDPR supervisory authority to enforce the cookie rules, under a new Article 15a(5) of the Directive. That would consolidate supervision in countries where a telecoms or consumer regulator currently handles cookies.

Because the rules stay in a directive, they need national transposition. The amended Article 17 gives member states 24 months after adoption to adopt and publish the necessary laws. The final provisions of the omnibus, however, state that its Article 5(2) - the ePrivacy amendment - "shall enter into application 6 months after the publication in the Official Journal of the European Union." The two dates sit uneasily together, and the text does not explain how a directive provision can apply before member states have transposed it. The same tension was present in the September draft.

The operative text contains no provision obliging websites to honour browser-level consent signals. Nothing in the cover note suggests the Presidency has responded to the open letter from 19 organisations, published on September 10, 2026, which asked the Irish Presidency to re-insert Article 88b. The cover note does record that the Permanent Representatives Committee discussed the proposal on June 8, 2026, giving guidance on, among other things, "the proposed new provision mandating an automated and centralised consent signal for the placing of cookies and the absence of impact assessment in this regard."

The heart of the change for advertisers is a closed list. Article 5(3) would allow device access without consent, along with "subsequent processing of personal data for the same purpose," to the extent it is "solely related to and strictly necessary for" six purposes:

  • transmission of an electronic communication over a network;
  • providing a requested service, including its functionality, explicitly requested by the subscriber or user;
  • first-party audience measurement that creates anonymous aggregated information about the use of an online service, carried out by the provider or a third party on its behalf;
  • media audience measurement performed in compliance with Article 24 of the European Media Freedom Act, Regulation 2024/1083;
  • maintaining or restoring the technical security of the service or the terminal equipment;
  • measuring the display and performance of contextual advertising.

Each of those carries conditions. The first-party measurement exemption applies only where "the data collected for the purpose of aggregating the information are not processed for another purpose, shared with third parties or combined with data from third parties." The recital explaining it, recital 44d, rules out combination "with data from other services from the provider of the online service or from a third party, such as analytics information from other websites." That language would appear to exclude analytics setups in which a vendor pools data across client sites for benchmarking or modelling.

The media measurement exemption is wider in one respect. It allows audience measurement "provided that personal data are pseudonymised after collection and not processed for another purpose, that the processing of personal data does not involve tracking the activity of the subscriber or user outside of the service or the media content to be measured, and that any information shared with third parties other than those acting either on behalf of or jointly together with that provider does not contain personal data." Recital 44e ties this to joint industry committees and independent measurement bodies "acting as joint controllers," and says the exemption "should contribute to the sustainability of the media ecosystem."

The service exemption is spelled out in recital 44c, which lists examples: memorising "language settings, configuration choices, items placed in shopping baskets, information to facilitate filling in of online forms, or functionalities of a requested service related to information on vehicles."

The contextual advertising exemption

The sixth exemption is new to the Council's text, and it has a history. Iubenda reported in May 2026 that a Council compromise circulated around May 21 had dropped a proposed carve-out for contextual ad measurement. It is back, and the cover note presents it as an addition: "an additional purpose has been added allowing for the placing of cookies without consent for the purpose of measuring the performance of contextual advertising."

The scope is set by recital 44g. "The simple display of contextual advertising does not typically require access to or storing of information on a user or subscriber's device," it reads. "Contextual advertising is placed solely on the basis of the immediate content displayed on the subscriber or user's online interface - such as a website or an app - during an individual visit or on the basis of a single search query."

The recital then names the technologies the Council has in mind. "At the same time, the effectiveness of such advertising often relies on the possibility to measure the display and the performance of the advertisement displayed such as capping cookies and advertising measurement cookies." That puts frequency capping inside the exemption, provided the conditions hold. The measurement must be carried out "by the provider of an online service, including jointly with others, or on behalf of that provider," the data must be "pseudonymised after collection, as a key security measure," and they must not be "processed for another purpose including profiling or providing programmatic advertising." The measurement must also not involve "processing of data relating to the subscriber or user's past or future activity, including activity across sites, apps or services."

Two details matter for ad tech. First, the reference to programmatic advertising in the recital means data gathered under the exemption cannot feed bidding. Second, a frequency cap by definition remembers that a device has already seen an ad, which is information about past activity. Whether a cap limited to a single site and a single campaign falls inside "past or future activity" is a question the recital does not fully settle. The operative article prohibits processing relating to past or future activity "including activity across sites or services," which suggests the cross-site case is the main target, but supervisory authorities will have to interpret the boundary.

The exemption also covers search. A "single search query" is listed as a basis for contextual placement, which would bring measurement of keyword-matched search ads within reach, as long as no user history is involved.

Four months, not six

The provision that gives this article its headline is short. Under the rewritten Article 5(3), the subscriber or user "shall be able to refuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means." If consent is given, the provider cannot ask again for the same purpose "for the period during which the controller can lawfully rely on the consent." If consent is refused, "the provider shall not make a new request for consent for the same purpose for a period of at least" four months.

The Commission had proposed six months, and the Council's September 3 text kept six. The cover note confirms the change: "if a user refuses consent, a new request for consent for the same purpose shall not be made for a period of at least four months." Agence Europe reported the same cut on October 5.

Recital 45 sets out the reasoning and the exceptions. Users who refuse "are often confronted with a new request to give consent each time they visit the same" service, it says, which "may have detrimental effects" because they "may consent just in order to avoid repeating requests." The obligation applies to any provider accessing the device, "including so-called third-party cookie." A provider may ask again within the period "where a new request for consent is necessary, for example if the purpose of processing changes," such as when "a new service is offered or where substantial changes to the service are made." A new request is also allowed when the record of the user's choice "is no longer valid for reasons beyond the service provider's control, including when the user has deleted the cookies."

That last exception has practical weight. Many browsers clear site storage on schedules the publisher does not control, and Safari's tracking prevention caps the lifetime of some script-set storage. A refusal stored in a cookie that disappears would release the publisher from the four-month wait.

The French advertising trade body Alliance Digitale had asked for the re-request ban to be deleted entirely in its May 21, 2026 position paper. It was not deleted, but the Council has shortened it by a third.

Recital 45 also contains a sentence that publishers will read closely: the amendments "should not be understood as setting out conditions relating to the online revenue streams of media services providers." That appears aimed at keeping pay-or-consent models outside the scope of the cookie reform, though the recital does not use that term.

Privacy-enhancing technologies and a review

A new paragraph in Article 18 of the Directive tasks the Commission with a report, due 12 months after adoption, "reviewing and assessing the use of privacy-enhancing technologies, including in relation to the storing of, or gaining access to information on terminal equipment." The stated aim is "to provide incentives and legal certainty for service providers in deploying such technologies," with legislative proposals to follow "where appropriate." That leaves the door open to a later exemption for measurement approaches built on aggregation or on-device processing, without committing to one.

Personal data becomes relative

The most consequential GDPR change for data-driven marketing sits in Article 4(1), the definition of personal data. The Council keeps the Commission's added sentences: "Information relating to a natural person is not necessarily personal data for every other person or entity, merely because another entity can identify that natural person. Information shall not be personal for a given entity where that entity cannot identify the natural person to whom the information relates, taking into account the means reasonably likely to be used by that entity. Such information does not become personal for that entity merely because a potential subsequent recipient has means reasonably likely to be used to identify the natural person to whom the information relates."

Recital 27 grounds this in the case law of the Court of Justice, which in September 2025 ruled in EDPS v SRB that pseudonymised data may not be personal for a recipient who cannot reasonably identify the people concerned. The recital adds that a means of identification is not reasonably likely to be used where "the identification of that data subject is prohibited by law or impossible in practice, for example because it would involve a disproportionate effort in terms of time, cost and labour."

A new Article 25a on pseudonymisation would let the Commission adopt implementing acts specifying "means and criteria" for when pseudonymised data no longer constitute personal data for certain entities. The cover note says this article "has been further adjusted, with an explicit reference to security measures." The European Data Protection Board would have eight weeks to give an opinion on each draft implementing act. Recital 27b insists that for "a controller applying pseudonymisation or a processor processing on behalf of the controller, the data subject remains identifiable."

For ad tech, the distinction is between the party holding the key and the party receiving hashed or tokenised records. A measurement vendor or clean room operator receiving pseudonymised event data without any means to re-identify users could argue that, for it, the data are not personal. The Board and the EDPS urged lawmakers in February 2026 not to adopt the definitional change. The Council has adopted it anyway.

AI training and legitimate interest

The proposed Article 88c - renumbered "Article 88 bis" in the Presidency drafts - allows processing "in the context of the development and operation of an AI system" to rely on legitimate interest under Article 6(1)(f), "except where other Union or national laws explicitly require consent, and where such interests are overridden by the interests, or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child."

In the September 3 text, the Presidency had removed the Commission's example safeguards, including an unconditional right to object. The October 2 text, according to the cover note, "has been further complemented with an explicit reference to the right to object." The operative paragraph now reads that processing "shall be subject to appropriate technical and organisational measures and safeguards to protect the rights and freedoms of the data subject in accordance with this Regulation, including the right to object under Article 21."

The reference is to the general right to object in Article 21 of the GDPR. Outside direct marketing, that right allows a controller to continue processing if it demonstrates compelling legitimate grounds. It is therefore narrower than the unconditional opt-out the Commission had proposed, a point the cover note does not address.

Recital 33a adds a limit: "the development and operation of an AI system or AI model does not in itself constitute a legitimate interest, and the applicability of Article 6(1)(f) to processing in the context of AI is to be assessed on a case-by-case basis, taking into account the underlying purpose of that processing." It also says public authorities may rely on the public interest ground in Article 6(1)(e) when they develop or operate AI.

A new point (k) in Article 9(2) would permit "incidental processing of residual data, where not intended by the controller," in AI development and operation. Controllers would have to filter sensitive data out where they can, remove it once identified, and, where removal "proves to be technically impossible or requires manifestly disproportionate effort," protect it from being "used to produce outputs" or disclosed. Recital 33 states that the derogation does not cover sensitive data "directly acquired by or provided to the AI system or AI model in the course of the deployment."

Research, access requests and breaches

Several other GDPR amendments touch commercial operations.

Scientific research. A new definition in Article 4(38) describes research that contributes to "society's general knowledge and wellbeing" following "a methodological and systematic approach," and adds: "This does not exclude that the research may also aim to further a commercial interest." The cover note confirms the Council moved this clarification into the operative text. Combined with the amended Article 5(1)(b), which treats further processing for research as compatible with the original purpose, this widens the room for companies to reuse data for product research.

Access requests. Article 12(5) would let controllers refuse or charge for requests they can show are abusive, where a data subject "abuses the rights conferred by this regulation for purposes other than the protection of their data." Recital 35 offers examples, including requests made to provoke a refusal "in order to subsequently demand the payment of compensation," and requests offered for withdrawal "in return for some form of benefit from the controller." Supervisory authorities would gain a matching power under Article 57(4) for complaints.

Information duties. Article 13 would no longer require a full privacy notice where data are collected "in the context of a clear and circumscribed relationship" with a controller whose activity "is not data-intensive," and where the processing is not high risk. Recital 36 gives "the relationship between a craftsman and their clients" as an example and excludes employment, large-scale processing and sensitive data. The cover note says this exemption "has been further streamlined and simplified."

Automated decisions. The rewritten Article 22 permits solely automated decisions with legal or similarly significant effects where necessary for a contract "regardless of whether the decision could be taken otherwise than by solely automated means."

Breaches. Under Article 33, only breaches "likely to result in a high risk" would have to be notified to the supervisory authority, and the deadline would extend from 72 hours to "not later than 96 hours after having become aware of it." Notification would eventually run through a single-entry point maintained by ENISA, the EU cybersecurity agency. Germany had asked in October 2025 for three working days.

Impact assessments. The Board would prepare EU-wide lists of processing that does and does not require a data protection impact assessment, plus a common template and methodology, for adoption by the Commission through implementing acts. National lists would stay valid until then. A new review clause in Article 97 asks the Commission to examine whether Chapter IV obligations should be "further adapted taking into account the level of risk for data subjects and the impact of such obligations on smaller organisations." Agence Europe reported that the compromise omits a German proposal for a category of "low-risk controllers" and offers this review instead.

Recital 40b and the FATCA dispute

Lehagre's interest in the text is narrower, and it is not about advertising. A business development director at HomeServe France, he founded the Association des Americains Accidentels in 2017 and has led it since. The group represents French citizens who hold US citizenship by birth and whose bank data flows to US tax authorities under FATCA. His LinkedIn profile lists 12,362 followers.

His target is recital 40b, on page 40 of the annex. "Page 40 of the Annex (page 46 of the PDF): the recital 'recalls' that Article 49 GDPR allows 'international data exchange between tax administrations, even where those transfers are repetitive'," he wrote. "No article is amended. The question it answers is pending before the Court of Justice in the FATCA case (C-804/25)."

Article 49 of the GDPR lists derogations that permit transfers to countries without an adequacy decision, including where a transfer is necessary "for important reasons of public interest." Data protection authorities have long read those derogations as suited to occasional transfers. The recital, as it stands in the October 2 text, says transfers under several Article 49(1) derogations "are not required to be non-repetitive," and that the public interest derogation allows transfers "including international data exchange between tax administrations, even where those transfers are repetitive or systematic, if that is necessary to achieve the public interest at issue."

The cover note says the compromise "further clarifies the interpretative recital in relation to the transfers of data to third countries under the derogations for specific situations, including in the context of international data exchange between tax administrations." Lehagre wrote that "the Council Legal Service has noted that it interprets no new provision; the Commission agreed. France and Poland have asked for deletion." Those positions are not recorded in the document itself, which lists no delegation positions.

His objection is procedural. A recital has no binding force on its own, but courts read the operative text in its light. A recital that pre-empts a question the Court of Justice has not yet answered could shape that answer. "Deleting it, or adding 'without prejudice to the interpretation of the Court of Justice', would take one line. Sunday will tell whether anyone writes it," Lehagre wrote.

The issue matters beyond tax. Ad tech firms transferring data to countries without adequacy decisions sometimes rely on Article 49 derogations as a fallback. A recital endorsing repetitive and systematic transfers under the public interest derogation is limited to public-interest cases, and advertising is not one, but it would change the interpretive baseline that authorities apply to Article 49 generally.

The Data Act and the rest of the package

The cover note puts the Data Act first in its list of last-minute changes, and Lehagre attributes the failed Wednesday vote to it. The October 2 text strengthens what the Council calls a "handbrake" on trade secrets. According to the cover note, under Article 4(6) and Article 5(9) of the Data Act, "trade secrets do not have to be disclosed unless the data holder and the user have taken all necessary measures to preserve their confidentiality, in particular regarding third parties." The risk threshold in Articles 4(8) and 5(11) was lowered, and Commission guidelines would cover data in critical sectors and how to assess control of companies by third-country entities.

Other Data Act changes narrow business-to-government data sharing from "exceptional need" to "public emergencies," delete the smart contract requirements in Article 36, and exempt custom-made cloud services under contracts concluded on or before September 12, 2025 from most switching rules, though not from the phase-out of switching and egress charges.

The package would fold the Data Governance Act and the Open Data Directive into the Data Act, and make registration as a data intermediation service voluntary. Public sector bodies could charge higher fees for data reuse to "very large enterprises," including DMA gatekeepers.

The Platform-to-Business Regulation would be largely repealed on the grounds that the Digital Services Act and Digital Markets Act cover its objectives. The annex keeps certain provisions - including selected definitions, Article 4 on restrictions and suspensions, Article 11 on internal complaint handling and Article 15 on enforcement - in application until December 31, 2032. The Netherlands had opposed eliminating the regulation in its November 2025 analysis.

What the text does not settle

Several open points remain even if ambassadors agree on Sunday.

The European Parliament has not adopted its position. PPC Land reported in September that the Council text marked a further step away from the Commission's AI safeguards, and the Parliament committees handling the file have not yet voted. Trilogue negotiations cannot start until both sides have mandates, and any provision can change in those talks.

The browser signal is the clearest point of conflict. The Board and the EDPS supported it in February, the 19-organisation coalition asked for its return in September, and the Council text does not include it. Google commissioned a study from Implement Consulting Group estimating that such a mechanism would cost EU businesses EUR 40-50 billion a year, a figure noyb disputed. If Parliament restores the mechanism, it would become a central trade-off in trilogue.

The interaction between the new cookie rules and existing consent infrastructure is also unaddressed. The text says nothing about the IAB Transparency and Consent Framework or the role of a consent management platform in recording a refusal for four months. Recital 44b notes that a media service provider may "mandate a third party processor, such as a market research company" to carry out exempt processing, but does not discuss how vendors embedded in a page demonstrate that they fall within one of the six purposes.

Finally, the application dates are placeholders. The regulation would enter into force three days after publication, but many of its GDPR provisions rely on implementing acts and Board proposals due nine months after entry into application, and the ePrivacy changes face the six-month and 24-month dates set out above.

Why it matters for marketers

For the advertising market, the October 2 text sets the opening position of 27 governments on three questions that have shaped European digital advertising since 2018: when a cookie needs consent, what counts as personal data, and what legal basis covers AI training.

The answers lean toward measurement over targeting. Contextual ad measurement, frequency caps tied to context, first-party analytics and joint-industry audience measurement would no longer require a banner. Behavioural targeting, cross-site tracking and programmatic use of the data would still need consent, and the consent request could be repeated every four months after a refusal. The shifting state of cookie consent in Europe has already pushed advertisers toward consent mode, modelled conversions and server-side tagging; the Council text would add a legal route for some measurement that currently depends on a yes.

The relative definition of personal data may prove more significant than any cookie rule. If it survives trilogue, the legal status of pseudonymised data shared with measurement partners, clean rooms and AI model trainers would depend on what each recipient can do with it, not on what anyone could do with it.

Ambassadors meet on Sunday.

Timeline

Summary

Who: The Council of the European Union, through its General Secretariat and the Irish Presidency, which prepared the mandate text for the Permanent Representatives Committee; EU member state ambassadors, who are expected to vote on it; and Fabien Lehagre, president of the Association des Americains Accidentels, who flagged a recital on tax data transfers.

What: A 163-page negotiating mandate on the Digital Omnibus that keeps cookie rules in the ePrivacy Directive with six exemptions from consent, including contextual advertising measurement and frequency capping, cuts the wait before a new consent request after a refusal to four months, adopts a relative definition of personal data, allows legitimate interest for AI development with a reference to the Article 21 right to object, raises the breach notification threshold and deadline to 96 hours, and retains recital 40b on repetitive tax data transfers under Article 49 GDPR.

When: The document is dated October 2, 2026. A Coreper meeting on October 7 ended without a vote, and ambassadors are expected to decide on Sunday, October 11, 2026, according to Lehagre.

Where: Brussels, at the Council of the European Union. The rules would apply across the EU, with the ePrivacy changes transposed by each member state.

Why: The European Council asked for all pending omnibus packages to be agreed before the end of 2026. For advertisers and publishers, the text sets the Council's starting position for trilogue negotiations with Parliament on when cookies need consent, how pseudonymised data are treated and how AI training can be justified under the GDPR.