Faultline Faultline Kommando 161

Germany · de.indymedia · · 34m

Agreement foreseeable: EU states decide on cookie banners, AI training, etc.

Deutsch (original) · Auto-translated to English

The negotiations surrounding the data omnibus in the Council are in a heated phase. It currently looks as if the “blanket permission” for AI training, which NGOs have criticized, will be approved. While the member states are close to an agreement, the camps in the European Parliament are still far apart.


https://cdn.netzpolitik.org/wp-upload/2026/10/huzeyfe-turan-D62arqnPgGE-...class="attachment-landscape-860 size-landscape-860 wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://cdn.netzpolitik.org/wp-upload/2026/10/huzeyfe-turan-D62arqnPgGE-...2556w,https://cdn.netzpolitik.org/wp-upload/2026/10/huzeyfe-turan-D62arqnPgGE-...860w,https://cdn.netzpolitik.org/wp-upload/2026/10/huzeyfe-turan-D62arqnPgGE-...1200w,https://cdn.netzpolitik.org/wp-upload/2026/10/huzeyfe-turan-D62arqnPgGE-...380w,https://cdn.netzpolitik.org/wp-upload/2026/10/huzeyfe-turan-D62arqnPgGE-...1536w,https://cdn.netzpolitik.org/wp-upload/2026/10/huzeyfe-turan-D62arqnPgGE-...2048w" sizes="auto, (max-width: 2556px) 100vw, 2556px" />
The EU wants to make it easier for companies to train AI with our data. – Public domain-like released by unsplash.com:https://unsplash.com/de/@huzeyfet">Huzeyfe Turan

Tomorrow, Wednesday, could be an important day for the General Data Protection Regulation (GDPR). Then the ambassadors from the 27 EU member states discuss the data omnibus, the law that, among other things, is intended to change the GDPR and ePrivacy Regulation. The aim is to find an agreement tomorrow in order to move on to the next phase, the trilogue with Parliament. This comes from, among other things, thehttps://www.consilium.europa.eu/de/documents/public-register/public-regi...of the meetingout.


Since the data omnibus was presented in November last year, the EU Commission's proposals have been heavily debated. The heavily criticized change to the definition of personal data is off the table in the Council. It would have led to the exclusion of pseudonymized data from the scope of the General Data Protection Regulation. According to the current draft from the Irish Presidency of October 2nd, pseudonymized data can still be considered non-personal data for certain recipients. For this purpose, security measures for pseudonymization have been added.


“Blanket permission” for AI training


Instead, the focus of criticism is now on a clarification of the legal basis for the use of personal data for AI training. The draft states that companies should not need consent for this, but can rely on their legitimate interest, provided they comply with certain standards.


This solution, which has been criticized as a blanket permit, has been criticizedhttps://netzpolitik.org/2026/digitale-enteignung-datenschuetzer-warnen-v...like noyband the European onehttps://edri.org/our-work/simplification-for-whom-open-letter-uphold-gdp...Digital Rights (Edri)pronounced.


There are also member states in the Council that disagree with this point. Spain, for example, demands that companies continue to have to justify if they want to use real data, according to the local digital ministry. These would then have to be anonymized. Bulgaria, Latvia and Estonia also oppose the change as it would violate the technology-neutral principle of the GDPR. This means that the GDPR has not yet regulated individual, specific technologies because otherwise it would have to be adapted for every technical innovation. Noyb also emphasizes that this would change with permission for AI training. In the last compromise text, a right to object was added under Article 21 of the GDPR for AI training, which some countries had promoted.


On the other hand, there are some countries, including Poland, the Czech Republic, Sweden and Denmark, that are continually committed to further changes. But the greatest pressure comes from Germany. As Politico reported, Germany stopped a vote on the omnibus in Brussels about a week ago and put forward its own proposal: to exclude certain companies, non-profit organizations and individuals from the scope of the GDPR.

–––

The hut is on fire! We're going in.
We oppose fascisation. We fight for a free, open and solidarity-based society. We defend basic rights for everyone.https://netzpolitik.org/spenden/?via=rss">Thisonly possible with your support.

–––


The federal government introduced this idea in Julyhttps://netzpolitik.org/2026/reformpaket-schwarz-rot-will-99-prozent-der...Reform packagebefore. Accordingly, a new category of “low-risk processors” is to be introduced. However, observers classify this heavily criticized proposal as unrealistic and some of Germany's supporters in the Council do not support it.


S&D negotiator: “No compromises on data protection”


Nevertheless, Germany wanted to introduce the proposal and blocked a common position by the member states, said the Social Democratic MEP Marina Kaljurand at an event organized by the consumer organization BEUC last Wednesday. “I really hope that the Council will agree, will not support the German proposal and will adopt a common position at its meeting in October,” Kaljurand reiterated. In the European Parliament, she is responsible for work on the omnibus together with Aura Salla (EPP). The two are currently going through the more than 1,500 amendments they received from other MPs to their first draft, she said. The parliamentary position is due to be finalized in February. Only then can the trialogue begin.


Kaljurand is clearly against some of the planned changes and said at the BEUC event: "For me, there are no compromises on data protection. It won't be easy, but I can't imagine that we can gain competitiveness by undermining fundamental rights and data protection."


Her colleague Salla, however, takes a completely different position: “We need a real deregulation agenda,” she emphasized at a Financial Times event in Brussels on Thursday. She believes that Europe will never have “leading tech companies” without allowing data use, which is why she is explicitly supporting this point in Parliament. She accused the Social Democratic group and other MPs of not wanting to change the GDPR at all.


At the same time, she advocates including European data in trade negotiations with the USA, so that US companies cannot use the data without paying for it. But it would be better if the data remained in Europe and was used by European companies, said Salla, who worked as a lobbyist for the US company Meta before entering the European Parliament.


A lack of data protection costs consumers billions


With the aim of providing a new perspective on the debate, the European consumer protection organization BEUC recently launched ahttps://www.beuc.eu/reports/economic-costs-weakening-privacy-and-data-pr...which quantifies the value of data protection for consumers. The idea behind this is to show what missing rules and violations actually cost those affected, instead of talking about how much money companies have to spend to comply with rules.


The study was carried out by the British research and analysis company Assembly. The study authors, James Robinson and Bart Smallman, shared a few key figures at the event on Wednesday: Non-compliance with data protection rules costs consumers an estimated 103 billion euros per year. The market for data brokers, where data is collected and added to profiles, is worth an estimated 40.5 billion euros. Calculated down to every EU citizen, that's just under 108 euros per year.

–––

The work of netzpolitik.org is financed by donations from our readers.
Become part of this unique community and support our public interest-oriented, advertising- and tracking-free journalismhttps://netzpolitik.org/spenden/?via=rss">nowwith a donation.

–––


Smallman also pointed out that due to the lack of transparency, consumers fundamentally cannot understand how this market works. One of the study's recommendations is to improve consent. Instead of cookie banners, consumers should be able to automatically set machine-readable preferences in their browser or operating system. This would reduce effort and ensure that their preferences are taken into account more consistently.


Germany against abolition of cookie banners


The EU Commission had also anchored this idea of ​​so-called privacy signals in the data omnibus, but here there were issueshttps://netzpolitik.org/2026/online-tracking-deutschland-und-google-woll...Others like Germany on the other hand, so the change was deleted in the Council. A coalition of civil society then formed under the namehttps://netzpolitik.org/2026/digitaler-omnibus-neues-buendnis-will-das-e...“Kill the Cookie Banner”Pressure put on. However, the Council's latest draft only states that the rejection of cookies should be respected for four (instead of the previous six) months, although it is unclear how this will be technically implemented without a mandatory standard. There is also an addition that when measuring reach, the activity of users outside of the service should not be tracked (tracking).


"I'm a little disappointed that this wasn't taken up by the council. I thought it was all a no-brainer," said Renate Nikolay at the BEUC event. She is the deputy director general of the EU Commission's Connect directorate and developed the omnibus with her team.


Should there ever be a “real” review of the GDPR, Nikolay would like to empower consumers. In addition, she would like to change the rules for international data transfers and improve the implementation structures: more coordination between authorities and faster procedures. The Deputy Director-General would also be open to seeing how a risk-based data protection regime could be applied in practice.


–––

The work of netzpolitik.org is financed by donations from our readers.
Become part of this unique community and support our public interest-oriented, advertising- and tracking-free journalismhttps://netzpolitik.org/spenden/?via=rss">nowwith a donation.

web address: https://netzpolitik.org/2026/einigung-abbaren-eu-staats-entscheiden-ueber-cookie-banner-ki-training-und-co/author/group: Anna Ströbele RomeroTopics: Netactivismfeed-date: Tuesday, October 6, 2026 - 5:13 p.m

Read the full story at the source

Source: de.indymedia