
August 21, 2026
Subscribe to Vretta Buzz
Why Are the Proposals Being Debated
Why Should Assessment Organizations and EdTech Providers Care
Since its adoption, the General Data Protection Regulation (GDPR) has become one of the world's most influential data protection frameworks, shaping how organizations process personal data.
The European Commission's proposed GDPR Omnibus (Omnibus) seeks to simplify certain compliance obligations while maintaining the GDPR's core principles. The proposals have nevertheless generated considerable debate, with supporters viewing them as a necessary modernization of the framework and critics warning that they may weaken existing privacy safeguards.
Although the proposals concern EU legislation, their impact extends beyond Europe. Organizations providing services to EU institutions or processing personal data of individuals located in the EU should closely follow these developments.
In this article, I provide an overview of the proposed Omnibus changes, explain why they became controversial, and consider their practical implementation for assessment organizations and EdTech providers.
The Omnibus proposal contains numerous amendments to the GDPR. While many are technical in nature, some could have broader implications for companies. Below I touch upon three of them, perhaps, the most significant ones.
Clarification of What Constitutes Personal Data
One proposal revisits the interpretation of personal data. Under the current GDPR, information is considered personal data where an individual can be identified directly or indirectly using means reasonably likely to be used for identification.
The proposed amendment clarifies that identifiability should be assessed from the perspective of the specific organization processing the information. Consequently, data would not automatically qualify as personal data for one organization simply because another organization is able to identify the individual. This could narrow the circumstances in which information is regarded as personal data and influence how organizations determine their GDPR obligations and allocate responsibilities between parties involved in processing.
Limitation of the Right to Access and the Right to Information
The proposal amends Articles 12 and 15 GDPR by allowing controllers to refuse or limit data subjects’ requests that are manifestly unfounded or where there are reasonable grounds to consider them excessive. At the same time, controllers would bear the burden of demonstrating that these conditions are met.
It also introduces an explicit possibility to limit access where disclosure would adversely affect trade secrets, intellectual property, public security, or the rights and freedoms of others.
AI and Sensitive Data
The proposal introduces a new legal basis permitting the processing of special categories of personal data where strictly necessary for the development, testing, validation, or maintenance of AI systems serving an important public interest, subject to appropriate safeguards.
The amendment is intended to provide greater legal certainty for AI development, but it also broadens the circumstances in which sensitive personal data may be processed.
The proposals have attracted differing views from regulators, industry, and civil society.
Supporters argue that assessing identifiability from the controller's perspective provides greater legal certainty and reduces unnecessary compliance obligations. Critics, however, argue that it fundamentally changes the established concept of personal data and departs from years of Court of Justice of the European Union (CJEU) case law.
The proposed limitations to the rights of access and information are supported as a means of preventing abusive requests and protecting confidential information. Opponents respond that these rights are fundamental to the GDPR and should not be restricted beyond what is strictly necessary. The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) have therefore called for the proposed limitations to be narrowed and clarified.
The AI amendment has proven particularly controversial. Supporters consider it necessary to enable responsible AI innovation, while critics argue that it creates an unjustified exception allowing broader use of sensitive personal data without sufficient safeguards. One of the notable privacy advocacy organizations has described the proposal as creating an "AI privilege" that is neither necessary nor accompanied by sufficient safeguards for affected individuals. The EDPB and EDPS similarly questioned whether a new AI-specific exception is needed at all, noting that the GDPR already provides legal bases that may apply in appropriate circumstances.
In my view, the objective behind the Omnibus proposals is both legitimate and timely. As technology evolves and organizations increasingly rely on data-driven services and artificial intelligence, it is reasonable to consider whether certain GDPR provisions can be modernized to better support innovation and reduce unnecessary administrative burden.
However, simplification should not come at the expense of legal certainty or individuals' rights. In my opinion, some of the proposed amendments would benefit from clearer safeguards and more narrowly defined conditions for their application. If these elements are refined during the legislative process, I believe the Omnibus has the potential to achieve its intended objective: supporting innovation and reducing unnecessary regulatory burden while preserving the high level of privacy protection that has become a hallmark of the GDPR.
For assessment organizations and EdTech providers, the practical impact of the Omnibus proposals will depend on the final wording adopted. However, several areas deserve attention.
If the definition of personal data changes, organizations may need to revisit how they classify information shared between partners. For example, a technology provider receiving assessment data without access to student identity information may need to reassess whether that data should be treated in the same way as directly identifiable student records.
Changes to the right of access and the use of sensitive data in AI systems may also require organizations to review their internal processes. Organizations using AI-supported features will need to understand what data is used, under what conditions, and what safeguards apply. These practices remain important not only for GDPR compliance, but also for ensuring trust in systems that handle student information.
The proposed Omnibus seeks to simplify parts of the GDPR, however sparking significant debate. Among others, the proposed clarification of the definition of personal data, limitations to certain individual rights, and new rules on the use of sensitive data for AI development all have the potential to reshape how key GDPR concepts are interpreted and applied.
While supporters see these changes as a way to reduce regulatory burden and promote innovation, critics argue that they risk weakening established privacy safeguards and departing from principles developed through years of GDPR enforcement and CJEU case law.
For assessment organizations and EdTech providers, these developments are worth monitoring closely. If adopted, they could influence how personal data is classified, how requests from individuals are handled, and how AI systems are designed and deployed. Understanding these changes early will help organizations adapt while continuing to protect the personal data entrusted to them.

Jana Begun is an EU-based legal professional specializing in data protection and privacy, with a focus on regulatory compliance. She holds an LL.M. from Stockholm University and is a Certified Information Privacy Professional/Europe (CIPP/E). At Vretta, she supports GDPR compliance and integrates privacy and security principles into the company’s day-to-day operations and digital learning platforms.
Her work centers on making complex legal requirements practical. She enjoys transforming privacy and security into actionable frameworks, helping build a culture where these topics are not just policies, but integral parts of everyday decision-making.
If you are interested in discussing data protection developments and explore how to strengthen security practices, please feel free to get in touch with Jana Begun at: dpo@vretta.com | LinkedIn