Policy

EU ambassadors set to vote on Digital Omnibus mandate that shortens cookie re-ask wait

Coreper is expected to decide on October 11, 2026 whether to hand the Irish Presidency a mandate for talks on a 163 page text that also exempts contextual advertising measurement from consent.

T
By TechQuire Daily Staff TechQuire Daily Staff
October 10, 2026 / 7 min read

The European Union's long running effort to simplify its digital rulebook is approaching a decisive procedural step, as national ambassadors prepare to decide whether the Council of the European Union can open negotiations with the European Parliament on the Digital Omnibus. The vote in the Permanent Representatives Committee, widely known as Coreper, is expected on Sunday, October 11, 2026, after an earlier attempt on Wednesday, October 7 ended without a decision.

At the centre of the debate is a 163 page draft, Council document 13886/26, dated October 2, 2026 and prepared by the General Secretariat of the Council for Coreper. Among many other changes, it would shorten to four months the period a website must wait before asking a visitor again for cookie consent after that visitor has refused. The current waiting period under the ePrivacy rules is six months, so the proposal would cut it by a third.

The package is unusually broad. Its subject line covers amendments to eight existing laws, among them the General Data Protection Regulation (Regulation 2016/679), the ePrivacy Directive (2002/58/EC), the Data Act (Regulation 2023/2854) and the NIS2 Directive, plus the repeal of four related instruments: the Platform-to-Business rules, the Free Flow of Non-Personal Data framework, the Data Governance Act and the Open Data rules. The interinstitutional file number is 2025/0360 (COD).

The document is classified LIMITE, so it is not public, and much of what is known about it comes from specialist reporting and from material published by advocacy groups. The European Commission tabled the underlying proposal in November 2025, and the file has been moving through the Council ever since.

Key Facts

PPC Land reported on October 9, 2026 that EU member states are expected to decide on Sunday, October 11, 2026 whether to adopt the Council negotiating mandate on the Digital Omnibus. The same report described the four month cookie consent re-ask period, an exemption from consent for the measurement of contextual advertising, and a contested clause on tax data transfers that the French campaigner Fabien Lehagre says the Council could remove in a single line.

The timing has already slipped once. Agence Europe reported on October 5, 2026 that the Irish Presidency of the EU Council aimed to secure a negotiating mandate at the ambassadors meeting on Wednesday, October 7. That did not happen. Agence Europe reported on October 7, 2026 that Coreper was due to decide that day on the Council position, but that under joint pressure from Germany and France consideration of the text was limited to a discussion and the vote was postponed to October 11.

Trade secrets are central to the reservations of the two capitals. Both Germany and France consider the Data Act provisions on the protection of trade secrets insufficient. Berlin is calling for the sharing of data protected by a trade secret to require an explicit agreement between the data holder and the user seeking access. The compromise put forward by the Irish Presidency instead provides for a mechanism allowing data holders to refuse to share data if they can demonstrate a significant risk of unlawful use or disclosure, particularly to entities in third countries that offer weaker protection. Germany has a further demand: in a working document seen by Agence Europe, Berlin proposed creating a category of low-risk data controllers, under which micro-enterprises, small and medium sized enterprises, and individuals or organisations acting on a non-profit basis could be exempted from many GDPR obligations.

MLex reported on October 5, 2026 that the revised draft dated October 2 would add a review of data protection obligations, shorten the waiting period before providers can make a repeat request for cookie consent, strengthen the protection of trade secrets and clarify that the development or operation of artificial intelligence does not automatically justify personal data processing. MLex also reported on September 25, 2026 that member state review of the digital simplification package would move to a meeting of national ambassadors after a meeting of experts, and noted that governments remained divided on proposed GDPR relief for low-risk data controllers, on the renewal of cookie consent and on the Data Act rules for trade secrets.

One structural choice stands out in the Council text. The Commission had proposed moving consent rules out of the ePrivacy Directive and into the GDPR as a new Article 88a, with a companion Article 88b obliging websites to honour machine-readable consent signals set in browsers. The Council dismantled that structure over the summer: the October 2 text keeps the rules inside the ePrivacy Directive and contains no obligation to honour browser level signals. Under the rewritten Article 5(3), device access without consent is allowed only for a closed list of six purposes.

Analysis

The postponement from October 7 to October 11 is not a technical scheduling matter. It is a signal that the Council still does not have the qualified majority it needs, and that the price of that majority is being negotiated in two different currencies: trade secret protection for Germany and France, and GDPR relief for smaller organisations. The bigger picture here is that the Digital Omnibus has stopped being a pure simplification exercise and has become a bargaining round in which each capital trades its consent for changes to the parts of the package it cares about most.

The cookie change is the most visible consumer facing element, and it is worth being precise about what it does. Cutting the re-ask interval from six months to four does not remove consent, and it does not legalise tracking without permission. It changes how often a website may interrupt a visitor who has already said no. For publishers and advertisers, the difference is measurable: a refusal that lasts four months instead of six means more frequent opportunities to convert a refusal into an acceptance, and therefore more frequent prompts for the same users.

The removal of the browser signal obligation is arguably the more consequential decision, though it receives less attention. The Commission wanted websites to honour machine-readable signals set in browsers, which would have shifted the practical enforcement of consent from thousands of individual banners to the software layer. The Council text drops that obligation. What this really means is that the burden of consent remains on the user, one dialog at a time, even as the interval between those dialogs becomes shorter.

On artificial intelligence, the leaked documents show a recital stating that processing personal data to develop and deploy AI systems may be regarded as carried out for a legitimate interest, while preserving the override where the rights of the data subject prevail. GDPR Local reported on September 22, 2026 that the privacy organisation noyb published leaked Council documents on September 21, 2026, covering Council document 12535/26, a Presidency revised compromise text dated September 3, 2026. noyb reads the recital as a general permission, while the text itself retains the balancing language, and nothing has changed in law.

Why It Matters

For anyone running a website that serves visitors in the European Union, the practical question is when a four month rule could take effect. It cannot take effect on October 11. A Council mandate only authorises the Presidency to negotiate with the European Parliament, which is the co-legislator, and the file number 2025/0360 (COD) shows that the ordinary legislative procedure applies. Nothing has changed in law yet.

The political stakes are larger than the cookie interval. The Digital Omnibus amends eight laws and repeals four instruments, which means a single negotiation now bundles data protection, data sharing, cybersecurity and open data into one package. If the Council adopts its mandate on October 11, the Parliament becomes the next venue, and roughly 1,840 amendments were already tabled there in August 2026. The European Data Protection Board and the European Data Protection Supervisor issued a joint opinion on the Commission proposal in February 2026, so the supervisory authorities have already placed their concerns on the record.

Privacy groups are watching closely. noyb chair Max Schrems said that under these proposals the profits of AI companies would trump the fundamental right to privacy of Europeans, and he described the approach as a digital expropriation of Europeans. Whatever the final text says, the argument about the definition of personal data, which the draft narrows for entities that lack means reasonably likely to be used to identify a person, will follow the file into the trilogue stage.

Next Up

If Coreper reaches agreement on Sunday, October 11, 2026, the Council Presidency will have a negotiating mandate and talks with the European Parliament can begin. If the vote is postponed again, the file remains stuck in the Council while the Parliament continues to process its amendments.

Two other moving parts will shape what happens next: the German push for a low-risk data controller category and the Franco-German demand for stronger trade secret protection in the Data Act provisions. Both will need to be settled before any mandate is signed off.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.