Article 88c would not create a blanket right to train AI on personal data without consent. The proposal’s debated safeguards include data minimization, transparency, machine readable ways to exercise objections, and an unconditional right to object; proposed handling of sensitive data has been framed as lim...
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What is the EU’s revived Digital Omnibus proposal to let companies train AI models on personal data without obtaining explicit user consent—. Article summary: The premise combines two different files. The **Digital Omnibus on AI** has already been adopted as Regulation (EU) 2026/1744; it deferred the main Annex III high-risk-AI obligations to **2 December 2027**. The separate . Topic tags: general, government, documentation, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text,
The EU’s Digital Omnibus debate is often described as a plan to let companies train AI models on personal data without consent. That description is too broad.
The relevant provision, proposed GDPR Article 88c, would explicitly recognize legitimate interest under Article 6(1)(f) GDPR as a possible legal basis when processing personal data is functionally necessary to lawfully design, develop or use an AI system or model. It would not eliminate the GDPR, automatically validate web scraping, or make consent irrelevant where another rule requires it.1
3
Most importantly, this is part of the Digital Omnibus data proposal, not the already-adopted Digital Omnibus on AI. The data proposal remains in the EU legislative process, meaning its text and outcome are not settled.
Under the proposed wording, a controller or third party could potentially rely on legitimate interest for personal-data processing across an AI system’s lifecycle where that processing is functionally necessary for its lawful design, development or use.3
That would make a route that can already exist under the GDPR more explicit in the AI context. The European Data Protection Board (EDPB) had previously concluded that legitimate interest may, in some cases, be an appropriate legal basis for developing and deploying AI models or systems.4
5
But “may” is doing substantial work. A company could not simply declare that its interest in building an AI model wins. It would still need to satisfy the ordinary legitimate-interest framework, including:
Other EU and national rules that require consent would continue to apply. Article 88c therefore would not be a general permission to collect any public or private personal data for model training.1
The debate around Article 88c has focused less on whether legitimate interest can ever apply and more on what protections must accompany it.
Safeguards discussed around the provision include data minimization in source selection and training, technical and organizational protections, meaningful transparency, and mechanisms that recognize machine-readable objections or opt-outs. The proposed approach also includes an unconditional right to object to the relevant AI-related processing.13
In practice, those guardrails would matter because they determine whether a purported legitimate-interest assessment is meaningful. Data minimization limits the argument that a developer may collect everything merely because it might be useful later. Transparency gives people a way to understand the processing. And a real right to object requires more than a hard-to-find preference setting.
Council discussion of a related sensitive-data derogation has emphasized a narrower scenario: incidental and residual processing of special-category data. In other words, the controller did not intend to process sensitive data, but some is unavoidably present within the main processing operation. That is different from deliberately collecting sensitive personal data as training material.2
The EDPB and European Data Protection Supervisor (EDPS) did not dispute that legitimate interest can sometimes support AI-related processing. Their central objection was that a bespoke Article 88c was unnecessary because existing GDPR analysis already permits that conclusion in appropriate cases.4
5
Their concern is practical as well as legal: a new AI-specific provision could be read as going beyond clarification, potentially creating uncertainty around established GDPR protections. The regulators’ position is consultative rather than binding, but it is significant in the legislative debate.5
Available legislative material shows that the Council’s work has been contested. A planned COREPER vote on a Council negotiating mandate was cancelled after agreement could not be reached on open issues, and work then continued under the Irish Council Presidency.
Ireland’s presidency programme states an aim of reaching agreement with the European Parliament on the Digital Omnibus package by the end of 2026. However, the provided official material does not independently establish that Article 88c has been definitively restored in a final Council position.
The safest description is therefore: Article 88c remains politically contested and negotiable. It cannot yet be treated as a binding legal basis that companies may rely on in place of the GDPR’s existing requirements.
Confusion partly arises because a different measure—the Digital Omnibus on AI—has already been adopted as Regulation (EU) 2026/1744.
That AI measure changes the implementation timetable for parts of the AI Act. In particular, obligations for standalone high-risk systems listed in Annex III apply from 2 December 2027; high-risk systems embedded in regulated products have a later timetable.19
20
When those Annex III requirements apply, they include risk assessment and mitigation, high-quality datasets designed to reduce discriminatory outcomes, logging and traceability, documentation, information for deployers, human oversight, robustness and cybersecurity measures.20
Those AI Act obligations are separate from the GDPR question of whether personal data can be processed for AI training. Delaying high-risk-AI obligations does not enact Article 88c.
For developers, Article 88c would offer greater textual clarity but not a compliance shortcut. A defensible approach would still require a documented necessity and balancing assessment, data minimization, transparent information practices, and operational processes for objections.
For people whose data may be used, the key issue is whether the eventual law preserves meaningful limits: whether data use is genuinely necessary, whether sensitive data remains narrowly constrained, and whether objections are technically effective rather than symbolic.
The broader direction is not that Europe has abandoned preventive AI regulation. The adopted AI Omnibus postpones some high-risk obligations, while the separate data proposal explores a clearer route for certain AI-related data processing. The final balance will depend on the Council–Parliament negotiations and on how any adopted text is interpreted and enforced.19
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Article 88c would not create a blanket right to train AI on personal data without consent.
Article 88c would not create a blanket right to train AI on personal data without consent. The proposal’s debated safeguards include data minimization, transparency, machine readable ways to exercise objections, and an unconditional right to object; proposed handling of sensitive data has been framed as lim...
The separate Digital Omnibus on AI is already law and moves Annex III high risk AI obligations to 2 December 2027.