I would like to thank the Deputy for the question. The Government strongly supports the EU’s competitiveness agenda. Simplification is a key enabler of this. Both the Letta and Draghi reports underlined the need to reduce the regulatory and administrative burden on EU companies, particularly SMEs.
The European Commission put forward ten simplification Omnibus packages in 2025. Each package usually contains several legislative proposals relevant to multiple Government Departments. My Department has been coordinating Ireland’s approach across Government to these packages.
The digital simplification Omnibus package was published by the European Commission on 19 November last year. It contains two legislative proposals – the digital Omnibus on AI and the digital Omnibus.
In the lead up its publication, Ireland strongly encouraged an ambitious digital simplification package that can support the EU’s strategic positioning as the location of choice for trustworthy digital innovation, while maintaining a central focus on protecting data privacy and fundamental rights of citizens.
The Government recognises the importance of regulation to ensure markets operate efficiently and fairly, and to protect consumers. In this context, it is important that regulations are targeted and proportionate to the policy objective, whether it is to protect consumers and citizens, or to promote competition and innovation. We have therefore advocated for a dynamic, ambitious and risk-based approach, focused on removing regulatory overlaps, reducing administrative burdens, and supporting compliance
The Commission’s proposals are a first step, and an important element of the overall approach to improving competitiveness at an EU level.
In terms of substance, the first legislative proposal – the digital Omnibus on AI - aims to simplify and streamline the EU’s AI Act. This includes linking the implementation timeline of high-risk rules to the availability of standards; extending SME regulatory simplifications to small mid-caps; requiring the Commission and the Member States to foster AI literacy while retaining training obligations for high-risk deployers; increasing flexibility in post-market monitoring by removing the mandatory harmonised plan; reducing the registration requirements for AI systems in high-risk areas when used only for narrow or procedural tasks; centralising the oversight of many General Purpose AI-based and platform-embedded systems within the EU AI Office; expanding the regulatory sandboxes and real-world testing, including an EU-level sandbox, and clarifying the interactions between the AI Act and other EU laws.
The proposed changes respond to practical implementation challenges highlighted by stakeholders and are aimed at increasing certainty for regulators, businesses and citizens, reducing compliance costs and administrative burdens, and supporting innovation whilst maintaining protections. By reducing barriers to investment and innovation, balanced with clear and predictable protections for citizens, we can unlock growth opportunities from the rapid acceleration of technological developments.
A key challenge faced by Member States and businesses included the delay in the availability of technical standards and other support tools, such as guidance and codes of practice, that are necessary for the provision, use and regulation of compliant AI systems.
Discussions on this proposal remain at an early stage and further scrutiny of and consultation on the proposal is ongoing.
The second proposal – the digital Omnibus - aims to simplify and streamline the EU’s data rulebook and cybersecurity incident reporting.
As regards the proposed changes to the EU data rulebook, the proposal merges four existing data-related acts into a single, consolidated instrument for Europe’s data economy. It incorporates elements of the Free Flow of Data Regulation, the Data Governance Act, and the Open Data Directive, into the Data Act, while simultaneously repealing those three instruments. This initiative aligns with the broader Data Union Strategy, which seeks to simplify and streamline the EU’s legislative framework. Among its aims, the proposal extends rules that facilitate compliance with EU data legislation for small and medium sized enterprises to also cover small mid-cap companies. It seeks to balance reduced administrative burdens with enhanced legal certainty and strengthened competitiveness, while also reinforcing safeguards against the risk of severe data leaks to third countries. In addition, it clarifies the scope of the business to government framework and reaffirms that the key provisions of the Data Act remain central to fostering a more open and competitive cloud environment.
The proposal also includes targeted amendments to the General Data Protection Regulation (GDPR) to harmonise, clarify and simplify certain rules to boost innovation and support compliance by organisations, while keeping intact the core of the GDPR, maintaining the highest level of personal data protection. It aims to clarify certain key definitions, for instance the notions of personal data; facilitate compliance, for instance by supporting controllers with respect to the criteria and means to determine whether data resulting from pseudonymisation does not constitute personal data; clarify certain aspects as to the processing of data for AI training and development; and address the lack of clarity about the conditions for scientific research by providing a definition of scientific research and clarifying that scientific research constitutes a “legitimate interest”.
The proposal further includes changes to the rules on “cookies” (e-privacy Directive). It seeks to simplify the interplay of the applicable rules whereby processing of personal data on and from terminal equipment should be governed only by GDPR. The proposal also paves the way for automated and machine-readable indications of individual choices and respect of those indications by website and mobile application providers and providers of mobile phone applications once standards are available. Where controllers ensure that their websites or mobile phone applications comply with such standards, they should benefit from a presumption of compliance.
The Government welcomes the proposed amalgamation of the Open Data Directive, the Free Flow of Non-Personal Data Regulation, the Data Governance and the Data Act into a single consolidated Data Act as it will streamline the data framework and provide greater clarity and alignment of the data rulebook. The Government further believes that strong safeguards regarding the use of personal data should remain in place in alignment with core objectives of the GDPR. Essential principles of public trust, transparency, data protection and improved public outcomes and public good are central to any simplification package.
As regards the proposed changes to cybersecurity incident reporting, the proposal seeks to introduce a single-entry point through which entities can simultaneously fulfil their incident reporting obligations under multiple legal acts and to require ENISA, the EU agency for cybersecurity, to develop the single entry-point. It seeks to mandate the use of the single-entry point for a series of closely interconnected incident reporting obligations set in the NIS2 Directive, GDPR, the Digital Operational Resilience Act (DORA), eIDAS Regulation, and the CER Directive. Other sectoral reporting obligations, such as those set out in the framework of the network code on cybersecurity aspects of cross-border electricity flows (NCCS) and the relevant instruments for the aviation sector, would also be brought under the single-entry point through amendments to the respective delegated and implementing acts that establish the reporting obligations under those frameworks. The proposal also aims at streamlining the contents of reported information by introducing empowerments for several legal acts, where such do not exist - and the Commission is supposed to take due account of the experience gained and the common templates developed under DORA.
The Government welcomes the efforts to simplify the reporting of incidents as the complexity of incident reporting has been repeatedly highlighted by stakeholders as a major issue, particularly for SMEs. However, we have concerns on the proposal to develop a single-entry point (SEP) for incident reporting across a number of legislative files including non cyber security ones such as GDPR. One key concern is the interoperability of a SEP with existing incident reporting mechanisms in Member States and concerns it may encroach upon national security, causing delays and fragmentation in relation to critical information flows.
Discussions in the Council on this proposal also remain at an early stage, and we will continue to engage constructively in these discussions.
It is important to note also that the proposals under the digital simplification Omnibus package must now proceed through the EU’s ordinary legislative procedure, requiring review and approval by both the European Parliament and the Council.
Going forward, it will also be important to future-proof our EU digital regulatory framework, with the overall aim of increasing the coherence and effectiveness of the EU Digital rulebook. This means ensuring that forthcoming digital regulations are developed with the same objectives around simplification, harmonisation and coherence strongly to the fore. In this context, the Government is also very supportive of the broader review of the digital rulebook through the Fitness Check of the Digital Acquis, announced by the Commission as part of this package.