Regulatory Updates

Could your tracking IDs stop being personal data? The Council thinks maybe

Published
Read time3 min read
Regulatory Updates

A Council of the European Union compromise text on the Digital Omnibus would insert a new Article 25a into the GDPR, providing that pseudonymised data is not personal data for a party unable to identify the individual behind it. On 24 September 2026, as EU ambassadors resumed technical discussions, European Digital Rights and more than 127 civil society organisations published an open letter opposing it. Nothing is settled, and that is precisely why it is worth understanding now.

What is being proposed

According to the IAPP and reporting by ppc.land, the Council's text moves the pseudonymisation question into a new Article 25a stating that pseudonymised data shall not be considered personal data for a person who is unable to identify the individual to whom it relates. A further paragraph provides that a natural person is not identifiable where the likelihood of identification is insignificant in practice.

Notably, the Council text strikes the Commission's proposed additions to the definition of personal data in Article 4(1), addressing the same issue through Article 25a instead.

The practical consequence concerns identifiers — cookie IDs, advertising IDs, device identifiers. Today, pseudonymised data remains personal data regardless of which party holds the key to re-identification. Under the proposal, a company further down an advertising chain that cannot itself re-identify a person could treat the same identifier as non-personal.

Key points
Status
A Council compromise text, not law. Trilogue and a final text still lie ahead.
The mechanism
A new Article 25a rather than a redefinition of personal data in Article 4(1).
Opposition
EDRi and 127+ organisations; formal objections from Latvia, Poland and the Netherlands.

The objection, fairly stated

Critics argue the proposal creates a perverse incentive. EDRi's position is that it redistributes responsibility away from the entities doing the most tracking: a downstream adtech participant could disclaim personal data status precisely because it holds no key, even while processing identifiers that trace a real person across the web. Max Schrems of noyb has characterised the direction as "a digital expropriation of Europeans".

The EDPB and EDPS, in their joint opinion of February 2026, warned more broadly that the Digital Omnibus changes could adversely affect the level of protection individuals enjoy, create legal uncertainty and make data protection law harder to apply — while supporting the objective of simplification and welcoming some elements, notably proposals to harmonise breach notification under Articles 33 and 34.

What it would mean in practice — if it survives

Two cautions before anyone reorganises a compliance programme around this. First, it is a compromise text in a process that still has to produce a final agreed law. Second, several member states have formally objected, which is not how settled questions behave.

That said, if something like Article 25a becomes law, the practical effects are worth anticipating:

  • Your position depends on your place in the chain. A publisher or advertiser holding first-party data and the ability to re-identify remains squarely in scope. The relief, such as it is, would fall to parties who cannot.
  • Re-identification capability becomes a compliance fact you must evidence. "We cannot identify anyone" would become a claim requiring proof, revisited whenever a new data source is joined. Combining two datasets you could not individually re-identify can change the answer.
  • ePrivacy does not go away. Rules on storing and accessing information on a user's device rest on separate law. A change to what counts as personal data would not, by itself, remove the consent requirement for cookies and similar technologies.

What to do now

Nothing dramatic — but this is a good moment to be able to answer a question that surprisingly few organisations can: which identifiers do we hold, where did each come from, who else receives it, and could we re-identify the person behind it if we tried?

That map is useful whichever way the legislation lands. It is what a consent record has to attach to, what a data subject access request has to be answered from, and what any future argument about identifiability would have to rest on. Organisations that already hold a consolidated view of what they know about a person, and through which platform, will find this a reporting question. Everyone else will find it a project.

Build one view of what you hold about each person, and which consents cover it.

Explore Consents Manager

Common questions

No. This is a Council of the European Union compromise text within the Digital Omnibus process, not adopted law. It still has to go through negotiation and a final agreed text, and several member states have formally objected to this element.

It would provide that pseudonymised data is not personal data for a party unable to identify the individual it relates to, and that a person is not identifiable where the likelihood of identification is insignificant in practice. In effect, the same identifier could be personal data for one party and not for another.

No. Consent for storing or accessing information on a user's device comes from separate ePrivacy rules, not from whether the resulting data is personal data. A change to the GDPR's treatment of pseudonymised data would not by itself remove that requirement.

Sources

  1. EU member states' leaked Digital Omnibus compromise proposal eliminates revised GDPR definition of 'personal data' — IAPP, 22 September 2026
  2. Simplification for whom? Open letter to EU Member States to uphold GDPR protections in Digital Omnibus on Data — European Digital Rights (EDRi), 24 September 2026
  3. Digital Omnibus: EDPB and EDPS support simplification and competitiveness while raising key concerns — European Data Protection Board, 1 February 2026