Data omnibus: privacy advocates warn against blanket permission for AI training
The privacy group noyb is warning against handing European data over for AI training. A new compromise proposal in the Council of the EU would widen the legitimate interest ground.

Europe's planned deregulation of its data economy is taking concrete shape. netzpolitik.org reported on 21 September 2026 on a compromise proposal from the Irish Council presidency dated 3 September, which the outlet says it has obtained. The proposal would let companies lean more heavily on legitimate interest when they use personal data to train AI models.
"Digital expropriation"
The lawyer Max Schrems and his organisation noyb criticise the plan sharply. In a guest article on netzpolitik.org, they call it a "complete release of European data to global corporations" and "digital expropriation". Put bluntly, the charge is that the GDPR is being hollowed out at a central point, and that citizens get nothing out of it.
The proposal is part of the so-called Digital Omnibus, which the European Commission says will cut red tape. netzpolitik.org counts among its contents the trimming of environmental reporting obligations and a weakening of AI rules. Critics also point out that the negotiations over the text are largely opaque.
The background
The European Data Protection Board established months ago that a balancing of interests can justify the use of data for AI training. The issue is not whether it is possible in justified cases, but whether it becomes a blanket permission.
In a copyright dispute, OpenAI had to concede that it had committed copyright infringements. It trained models on publicly accessible internet content, Reddit comments and YouTube videos, among other sources. Data sets of exactly this kind are also covered by the official order to make LinkedIn data available under the federal government's AI accelerator. The application-training side of the debate is therefore not an abstract case but lived practice.
What is at stake
Critics point to the consequences of a soft purpose limitation: if reuse for "AI training" counts as a legitimate interest, a data base once collected could hardly be limited later. According to the privacy campaigners, those affected would include profile data that reveals health, whereabouts or relationships.
The debate also mentions that the federal government in Berlin campaigned for liberalisation shortly before the European elections. At the same time the trilogue negotiations continue. So far the only certainty is this: the Digital Omnibus bundles so many individual changes that only the final text will show what room for manoeuvre actually remains.
Whether a balancing of interests is permissible in an individual case was never the contested question. What is contested is whether it becomes the rule.
Sources
2- 01netzpolitik.org: Digitale Enteignung – Datenschützer warnen vor Pauschalerlaubnis für KI-TrainingDE
- 02heise online: Big Brother Awards 2026 (Abschnitt Digital Omnibus, KI-Training, berechtigtes Interesse)DE
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.