# derouet-rgpd-revision-discrete-digital-omnibus-2025-11-13

## Veille

GDPR revision via Digital Omnibus: redefinition of sensitive data, broadened legitimate interest, weakened individual rights. Data governance and AI implications. IT for Business, European regulatory investigation.

## Titre Article

Enquête : la révision discrète du RGPD – qui y gagne, qui y perd ?

## Date

2025-11-13

## URL

https://www.itforbusiness.fr/enquete-la-revision-discrete-du-rgpd-qui-y-gagne-qui-y-perd-96974

## Keywords

GDPR, sensitive data, data protection, artificial intelligence, Digital Omnibus, digital governance, legitimate interest, behavioral profiling

## Authors

Thierry Derouet

## Ton

**Profile:** Investigative journalism | Analytical third person | Critical and engaged register | Intermediate level (legal/regulatory)

Investigative article from specialized IT press, structured around a "who wins, who loses" grid. The tone is critical and alerting: the Digital Omnibus project is presented as a "quiet revision" with major consequences, drawing on analysis of the amended GDPR articles and expert quotes (Max Schrems). Legal vocabulary made accessible for an audience of IT decision-makers, DPOs, and compliance officers. The author takes a political reading of the stakes (European sovereignty, tech lobbying) while remaining factual about the text's content.

## Pense-betes

- **Redefinition of sensitive data (Art. 9)**: "directly reveals" excludes weak signals (sleep, stress, mobility) from enhanced protection → strategic downgrade for AI
- **Broadened legitimate interest (Art. 6)**: optimization, anomaly detection, model improvement now permitted without explicit consent
- **Restricted individual rights**: "manifestly excessive" criterion expands grounds to refuse access/rectification/erasure without clear definition
- **ENISA centralization**: transfer of powers from national authorities to a technical cybersecurity agency
- **Winners**: major platforms, AI players, pro-industry states
- **Losers**: citizens, SMEs, DPOs, national protection authorities
- **Max Schrems**: "death by a thousand cuts" – cumulative erosion without media noise
- **Context**: US pressure and tech lobbying, abandonment of European fundamental-rights distinctiveness
- **156-page project**: Digital Omnibus presented as "simplification" but rewrites GDPR foundations
- **Critical weak signals**: mobility, heart rate, behavioral patterns feed predictive AI profiling

## RésuméDe400mots

Presented as a "simplification," the 156-page Digital Omnibus project rewrites the foundations of the GDPR with major implications for data governance and AI. Its most decisive amendment concerns Article 9 on sensitive data: by restricting protection to data that "directly reveals" a pathology, the text downgrades all indirect indicators (mobility, heart rate, sleep patterns, behavioral stress) to the less protective general regime.

This reclassification is strategic because these weak signals precisely feed predictive health profiling and AI model training without consent. The document also extends legitimate interest (Article 6) to optimization, anomaly detection, and AI model improvement, making consent less central for many uses.

Fundamental individual rights (access, rectification, erasure) would be restricted by a "manifestly excessive" criterion with no clear definition, giving companies more latitude to refuse citizen requests. On governance, ENISA (the cybersecurity agency) would inherit powers previously exercised by national data protection authorities, centralizing legal interpretation toward a technical institution and reducing local nuance.

This project responds contextually to American criticism and pressure from tech giants. It symbolizes a quiet abandonment of the European distinctiveness that placed fundamental rights at the center of digital regulation, in favor of competitive alignment. The winners are clearly identified: major tech platforms, generative AI players, and industrial states seeking to lighten regulatory constraints.

The losers are numerous: citizens whose rights become contestable, SMEs facing an unclear legal framework, DPOs (data protection officers) with weakened mandates, and national authorities stripped of their powers.

According to Max Schrems and other data protection experts, this revision represents "death by a thousand cuts": each isolated amendment appears technical and minor, but cumulatively they erode the protective spirit of the GDPR without media noise or public debate.

The political question extends beyond the text itself: does Europe choose to maintain its position as protector of fundamental digital rights, or align with the American model of maximal data exploitation? For AI4Data and AI governance, these changes are critical: they weaken the European framework that was precisely the differentiator and the trust-based competitive advantage.

## GrapheDeConnaissance

- Digital Omnibus —remplace→ RGPD (CONCEPT, 0.95)
- Digital Omnibus —affine→ données sensibles (Art. 9) (CONCEPT, 0.95)
- Digital Omnibus —affine→ intérêt légitime (Art. 6) (CONCEPT, 0.92)
- Digital Omnibus —réduit→ droits individuels (CONCEPT, 0.9)
- ENISA —remplace→ autorités nationales de protection des données (ORGANISATION, 0.88)
- Max Schrems —s_oppose_à→ révision RGPD (EVENEMENT, 0.92)
- Max Schrems —affirme_que→ « mort par mille coupes » (CITATION, 0.9)
- révision RGPD —améliore→ position des grandes plateformes tech (CONCEPT, 0.88)
- Thierry Derouet —publie→ enquête révision RGPD (EVENEMENT, 0.95)
- signaux faibles —permet→ profilage prédictif IA (CONCEPT, 0.88)
- révision RGPD —réduit→ protection données européenne (CONCEPT, 0.9)

---
Canonical: https://www.thekb.eu/en/fiches/derouet-rgpd-revision-discrete-digital-omnibus-2025-11-13/
