/
The EU Digital Omnibus: What Proposed Cookie and GDPR Changes Could Mean for Influencer Tracking
Guide
Tracking & ROI
Brands
The Digital Omnibus is a November 2025 EU proposal that would move cookie and tracking-consent rules out of the ePrivacy Directive and into the GDPR itself, as two new articles, 88a and 88b. Nothing has been adopted yet. The Council's latest compromise text, from around 18 June 2026, keeps Article 88a — the requirement for a refusal option as easy as accepting, and a six-month cooling-off period between consent requests — but has dropped Article 88b, the browser-level consent-signal mechanism, entirely.
The Digital Omnibus is a November 2025 EU proposal that would move cookie and tracking-consent rules out of the ePrivacy Directive and into the GDPR itself, as two new articles, 88a and 88b. Nothing has been adopted yet. The Council's latest compromise text, from around 18 June 2026, keeps Article 88a — the requirement for a refusal option as easy as accepting, and a six-month cooling-off period between consent requests — but has dropped Article 88b, the browser-level consent-signal mechanism, entirely.
The Digital Omnibus is a bundled EU legislative package the European Commission published on 19 November 2025, with the stated aim of simplifying and modernizing several digital rulebooks at once — including the GDPR, parts of the ePrivacy framework, the Data Act, NIS2 and DORA. The package is really two separate legislative files moving at different speeds through the EU's process, and they shouldn't be confused:
This article covers only the second track. It also shouldn't be confused with other current EU initiatives that separately affect influencer marketing — such as the EU DSA's ad transparency rules, which are already in force, unlike the Digital Omnibus.
The proposal would retire the current model, where cookie consent is governed by the ePrivacy Directive — implemented in Denmark as the cookie regulation ("cookiebekendtgørelsen"), see Consent Mode and influencer tracking in the EU for how that works today — and instead write the rules directly into the GDPR as two new articles:
| Article | What it does, per the proposal | Status in the Council's latest compromise text |
|---|---|---|
| Article 88a | Moves the consent requirement for storing or accessing data on a user's device (cookies etc.) into the GDPR. Keeps consent as the default, but narrows the exception list to an exhaustive set (transmission of a communication, a service the user explicitly requested, a provider's own audience measurement, security). Requires a mechanism to refuse that's as simple as accepting — typically one click — and bars re-asking for consent for the same purpose within six months of a refusal. Moves enforcement from national ePrivacy regulators to data protection authorities (in Denmark, already Datatilsynet for both today). | Retained in the 5th compromise text (around 18 June 2026) |
| Article 88b | Would have required providers to recognize and honour a machine-readable consent signal set once at browser or device level — a form of persistent "no," which in practice could have replaced the individual site's cookie banner. | Removed entirely from the Council's text, per Austrian privacy group noyb's press release of 23 June 2026, citing the Council's own document. Germany, France and Poland reportedly pushed for its removal, per the same source. |
In other words: the part of the proposal that would have done the most for the end user — one consent, set once, honoured everywhere — is currently out of the negotiating text. The part that makes it easier to say no on any individual site is still in the text.
No part of this proposal is adopted law. The process is still moving on both sides of the table:
The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) adopted a joint opinion (Joint Opinion 2/2026) on the proposal on 11 February 2026. Both bodies broadly back the simplification and competitiveness goal, but raise specific concerns — including whether the changes genuinely create more legal certainty, and whether they affect individuals' fundamental rights.
No date for final adoption or entry into force has been set. If the proposal is adopted, the current plan is that Article 88a would apply six months after entry into force, while Article 88b — if it returns to the text at all — would apply 24 months after entry into force.
It's easy to confuse two separate EU files, since both concern replacing the current ePrivacy model. The Digital Omnibus is one. The separate ePrivacy Regulation — a 2017 proposal that would have replaced the entire current ePrivacy Directive with a new regulation — is something else, and it was withdrawn entirely by the Commission: announced in the Commission's work programme in February 2025, formally approved by the Commission on 16 July 2025, and published in the Official Journal on 6 October 2025. The current 2002 ePrivacy Directive — which the Danish cookie regulation implements — therefore remains fully in force, unaffected by that withdrawal, until (and unless) the Digital Omnibus is adopted and replaces parts of it.
As Consent Mode and influencer tracking in the EU already covers, a tracking link's function today depends entirely on whether a visitor actively consents to marketing cookies in the individual brand's own cookie banner — if the customer declines, the cookie never gets set, and the sale disappears from tracking with no modeled substitute. Article 88a doesn't change that underlying mechanic. What it changes is how easy it becomes to say no:
The practical consequence, if Article 88a is adopted as currently drafted: the structural tracking gap already described in the Consent Mode article doesn't shrink — it likely grows, because it becomes easier for more visitors to decline, and because a decline sticks around longer. Article 88b would have changed the mechanics more fundamentally, but it's currently out of the Council's text, so it isn't something to plan around today.
Nothing has changed yet. The rules in force today — the Danish cookie regulation, the ePrivacy Directive and the GDPR operating side by side, as covered in Consent Mode and influencer tracking in the EU and in Influencer marketing and GDPR: what brands need to know — apply in full, unchanged, until (and if) the Digital Omnibus is adopted and enters into force. There's no transition rule to plan around, because there's no adopted law yet to transition from.
IF your cookie banner already meets Datatilsynet's and the Danish Agency for Digitalisation's joint May 2025 guidance (reject as visible as accept, withdrawing consent as easy as giving it) → you already meet the substance of what Article 88a would require. There's nothing to prepare yet.
IF your influencer tracking today has no discount code as a backup for visitors who decline cookies → that's worth prioritizing now, independent of the Digital Omnibus, because the gap is already real today — see Consent Mode and influencer tracking in the EU.
IF you're waiting for a specific entry-into-force date before acting → there isn't one to wait for yet. The most robust approach is to check the proposal's progress periodically rather than building an implementation plan around a date that can still move.
No. As of this article's most recent update, 24 August 2026, the GDPR/ePrivacy/cookie part of the proposal is still under negotiation in the Council, and the European Parliament hasn't yet adopted its own position on this track. Formal trilogue negotiations between the Commission, Council and Parliament haven't started on this track yet.
Article 88a is about making it simpler to refuse cookies on any individual site — one click, and six months of quiet afterward. Article 88b would have gone further and required companies to recognize a consent signal set once at browser level, so a visitor wouldn't have to decide on every individual site. Article 88b has been removed from the Council's latest known text.
No, they're two different tracks inside the same overall package. The AI track is already adopted (Council, 29 June 2026). The GDPR/ePrivacy/cookie track this article covers is not.
There are two separate files that often get confused. The separate ePrivacy Regulation (a 2017 proposal) was withdrawn by the Commission in 2025 — not 2026, as some secondary sources have implied. The current 2002 ePrivacy Directive, which the Danish cookie regulation implements, remains in force and unaffected by that withdrawal. The Digital Omnibus is a third, separate proposal that's now attempting to move parts of the Directive's content into the GDPR.
There's no fixed date. If the proposal is adopted, the current plan has Article 88a applying six months after entry into force — but the entry-into-force date itself depends on when the Council and Parliament reach agreement, which hasn't happened yet.
In our experience, the most common mistake is preparing for a specific version of an EU rule long before it's final — and then having to redo that work once negotiations land somewhere else, exactly as Article 88b's exit from the Council's text shows can happen within a few months. Our recommendation is to spend the time until the proposal is adopted on what's already certain today: a cookie banner that meets Datatilsynet's current requirements, and a tracking setup that isn't solely dependent on the cookie — as covered in how influencer tracking actually works. That work is useful regardless of how Article 88a and 88b end up looking.
Make Influence
Find creators with real audience data, run collaborations in one place, and see clicks and sales per creator while the campaign is live.
Book a demoCreate accountMake Influence
Apply to campaigns from brands that are actively looking, follow your own clicks and sales, and get paid without chasing invoices.
Create creator profileMore creator guidesMake Influence
Briefs, agreed terms, tracking links and results sit together — so brands and creators see the same numbers.
See how it worksBrowse the Academy