EU digital legislation: ‘Omnibus’ in turbo mode
On 13 November 2025, the 49th Data Protection Conference (DAFTA) of the Society for Data Protection and Data Security (GDD) e.V., Bonn, began in Cologne under the theme ‘From data protection to data usage rights – how operational data protection proves its worth’.
Moderated by Prof. Dr Rolf Schwartmann (Head of the Cologne Research Centre for Media Law, TH Co-logne and Chairman of the Board of the GDD e.V., Bonn), the morning session of the event was devoted in particular to the tension between data use and innovation on the one hand and the protection of personal data on the other. Other key topics included the EU Commission's planned ‘digital omnibus’ and government oversight with regard to the AI Reg-ulation and the Data Act.
Christina Rost (State Commissioner for Data Protection of Saxony-Anhalt) made it clear that, in her opinion, data protection and data use are not at odds with each other, but rather must form a partnership. She emphasised that the Data Act facilitates the use of data, but should not remove the barriers of data protection law. Data protection creates security and trust and is therefore a driver of innovation, according to Rost. According to the BfDI's ‘Data Barometer’, data protection is important to citizens.
Andrea Sanders-Winter (Head of the Digital Department at the Federal Network Agency) made it clear that the AI Regulation is intended to promote innovation while minimising risks. As the central market surveillance authority for monitoring and enforcing the requirements of the AI Regulation, the BNetzA will create legal certainty through guidelines and efficient procedures. With regard to the numerous existing interfaces with data protection, effective cooperation with the Federal Commissioner for Data Protection and Freedom of Information (BfDI) and the state authorities is essen-tial to ensure consistent decisions. Only coordinated action will enable a coherent legal framework that both facilitates innovation and ensures the protection of fundamental rights.
Joerg Heidrich (legal advisor at heise medien, Hanover) explained that the use of generative AI in companies poses many challenges in terms of data protection law. He warned against shadow AI, lack of transparency and risks in the processing of personal data. Technical and organisational measures (TOMs) and clear AI guidelines are crucial to ensure data protection and compliance. Heidrich emphasised that AI should not be used in every area, sensitive data must be given special protection, and system outputs should never be used without being checked.
Sophie Sohm (Privacy Policy Manager, Meta) emphasised that AI only becomes powerful with data. For training pur-poses, Meta uses only data from public profiles of adult users and, in this respect, grants not only users but also affected third parties a right of objection. From Meta's perspective, the AI model resulting from the training no longer allows conclusions to be drawn about individuals and therefore has no personal reference. With regard to the ruling of the Higher Regional Court of Cologne on AI training by Meta, Sohm expressed the view that the court had created legal certainty in a pragmatic manner.
The participants in the discussion agreed that coordinated and cooperative supervision was imperative in view of the new EU data protection legislation and the GDPR. Prof. Dr Rolf Schwartmann spoke of ‘har-monious interface arithmetic’ in supervision, while Christina Rost emphasised the importance of involving the state data protection supervisory authorities and warned against centralising data protection supervision.
There was broad consensus on the ‘Omnibus Package’. According to Andreas Jaspers, Managing Director of the GDD, this does not shake the foundations of the GDPR, but could contribute to greater legal certainty, including with regard to information and reporting obligations and the abuse objection when asserting data subject rights.
About the GDD: The GDD was founded in Bonn in 1977 and has since been supporting companies, in particular their data protection officers, in solving the diverse technical, legal and organisational issues associated with data protection and data security. As a registered non-profit association, it advocates for sensible, reasonable and technically feasi-ble data protection. Together with DATAKONTEXT, the GDD organises the DAFTA data protection conference, which takes place annually in November in Cologne in a hybrid format.