KontorBund
The Library

The EU Digital Omnibus: the Single Entry Point, the 96-hour question and where the Council stands

Last checked7 October 2026
KeeperOpen — keeper wanted
StatusProposal — not law

The short version

Nothing in this package applies to you yet. The data-and-digital half of the Digital Omnibus — COM(2025) 837 — would route incident reports through a single channel run by ENISA ("single-entry point" in the Commission's text) and would give a controller 96 hours instead of 72 to notify a personal data breach. The AI half of the same package is already law: Regulation (EU) 2026/1744. On 7 October 2026 the talks on the rest were reported to have stalled in the Council over trade-secret provisions, with further talks scheduled for Sunday 11 October 2026. Until an amending act is adopted and in force, each instrument keeps its own deadline and its own recipient — the GDPR's 72 hours included.

What the package is — and what of it is already law

The "Digital Omnibus" is not one act. It is two Commission proposals of 19 November 2025, plus a separate revision of the Cybersecurity Act for ENISA's budget and mandate. One of the two is finished, the other is not.

The proposal this note is about
COM(2025) 837 final of 19 November 2025, procedure 2025/0360(COD): a Regulation amending Regulation (EU) 2016/679 (GDPR), Regulation (EU) 2018/1724, Regulation (EU) 2018/1725 (EUDPR), Regulation (EU) 2023/2854 (Data Act), Directive 2002/58/EC (ePrivacy), Directive (EU) 2022/2555 (NIS2) and Directive (EU) 2022/2557 (CER), and repealing four acts including the Data Governance Act and the Open Data Directive. Article 3 of the proposal is the GDPR part; that is where the 96 hours sit.
The half that is already law
The companion proposal, the Digital Omnibus on AI, became Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July 2026. It amends the AI Act, the civil aviation Regulation and the machinery Regulation. It sets up no single-entry point: where it changes the incident route, it inserts a new Article 75(1a) into the AI Act, so that providers of high-risk systems under the AI Office's exclusive competence report serious incidents to the AI Office instead of the national market surveillance authority, by way of derogation from Article 73. That recipient is the AI Office, not ENISA. We track it in the AI Act note.
The number the Commission attaches to it
The explanatory memorandum puts possible savings at at least €1 billion a year from the moment of entry into force, plus €1 billion in one-off costs saved — at least €5 billion in total over three years, by 2029. These are the Commission's own initial estimates, not an outcome.
Not the Environmental Omnibus
A different package with the same nickname. The Environmental Omnibus (COM(2025) 982 and 983) is about packaging, batteries and EPR, and is tracked separately in this note. Nothing on this page changes anything there.
Two Omnibuses, two statuses — and the difference is the whole point. "The Digital Omnibus is coming" is true of the AI half (it arrived on 27 July 2026) and false of the half with the notification rules, which is still a proposal with no agreed text. Headlines that mix the two will make you plan around a rule that does not exist.

The Single Entry Point: one channel, run by ENISA

The proposal inserts a new Article 23a into the NIS2 Directive, under which ENISA — the EU's cybersecurity agency — develops and maintains a single-entry point for incident reporting, and then rewrites the notification articles of five other acts so that the report is filed through it. The idea is the once-only principle: you inform one place, and that place passes the information to the authorities that need it.

What gets routed through it
Per the Commission's own mapping: GDPR Article 33; NIS2 Article 23(4); eIDAS Regulation (EU) 910/2014 Articles 19a(1a), 24(2a) and 45a(3a); DORA Regulation (EU) 2022/2554 Article 19(1) for major ICT-related incidents and Article 19(2) for voluntary notifications of significant cyber threats; and CER Directive (EU) 2022/2557 Article 15(1).
Once only, including against the CRA
The proposal adds Article 23(12) to NIS2 so that a severe incident is reported once — either under NIS2 or under the Cyber Resilience Act (Regulation (EU) 2024/2847) — and not twice. It also amends NIS2 Article 30(1) so that entities outside a mandatory duty may use the same channel voluntarily.
When it would start
Not on entry into force. The obligation to use the single-entry point starts 18 months after entry into force, or 24 months if the Commission finds that the point does not ensure proper functioning, reliability, integrity or confidentiality. Until it exists, the new Article 33(1a) GDPR says the controller keeps notifying its supervisory authority directly.
Who pays, and one extra promise
The budgetary consequences for ENISA are not in this proposal; they sit in the separate revision of the Cybersecurity Act, Regulation (EU) 2019/881, which the Commission says will also update ENISA's mandate. Where relevant, the point must also be interoperable with the European Business Wallets (Article 23a(3), point (d)).

What the CiTiP analysis says about it

The one analysis we found that works through the mechanism — a CiTiP blog post of 6 October 2026 by Javier López-Guzmán, at KU Leuven's Centre for IT & IP Law — is broadly in favour and adds three points worth keeping:

Pre-emption, or the reform repeats itself
The author's main criticism is that the proposal does not pre-empt member states from adding new notification duties and new authorities of their own; without that, he argues, the tangle is rebuilt within a few years.
The EU institutions should be inside it too
He links the mechanism to the EDPB–EDPS joint opinion 2/2026 on the Digital Omnibus, which proposes extending the use of the single-entry point to the EU institutions themselves by amending the EUDPR.
Support he cites
83% of privacy professionals backed the measure in a survey by CEDPO (the Confederation of European Data Protection Organisations), and the association SMEunited commended it. He also notes under-reporting of incidents as the harder problem the point does not by itself solve.
One list we are not copying across. The analysis names, among the overlapping duties, Article 73 of the AI Act and Articles 23 and 35 of NIS2, and says all of these acts would be amended for the single-entry point. The Commission's proposal text does not do that: it amends the acts listed above, and the AI Act amendments travelled in the separate AI Omnibus, whose published text contains no single-entry point. We record the list as the author's, not as the state of the text — see what we could not establish.

The 96-hour question

Two changes to the GDPR breach notification sit in the same paragraph. The first is the deadline. The second is who has to be told.

Today: 72 hours
Article 33(1) GDPR as it stands requires notification to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. That is the rule in force as you read this.
Proposed: 96 hours, via the Single Entry Point
The replacement paragraph 1 in the proposal reads: "the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 to the supervisory authority competent in accordance with Article 55 and Article 56. Where the notification to the supervisory authority is not made within 96 hours, it shall be accompanied by reasons for the delay." The same move is made for EU bodies and the EDPS: Article 34(1) of the EUDPR, today 72 hours, becomes 96.
The threshold also changes
Recital 39 of the proposal says the notification threshold is aligned with Article 34 GDPR — communication to the data subject — so that where a breach is not likely to result in a high risk, the controller should not have to notify the supervisory authority at all. "High risk" is a higher bar than the "risk" in Article 33 today. Recital 39 is explicit that the documentation duty in Article 33(5) and the accountability duty in Article 5(2) are untouched, and the EDPB is to prepare a common notification template and a common list of circumstances that count as high risk, reviewed at least every three years.
What the analysis questions
López-Guzmán welcomes the alignment between authority and data-subject notifications but argues the 96-hour extension should not be general: it should be conditional on the size and capabilities of the entity, or at least on the number of data subjects affected. He also says the new wording keeps the open term "high risk" and so does not solve the interpretation problem that already exists.

The one thing to take away

Read a headline saying "the EU has moved data-breach reporting to 96 hours" and you would not know that it is 96 hours minus the days spent finding out who you are. In the text as proposed the clock still runs from awareness and the report still goes through one channel — and no adopted act says 96 hours anywhere yet.

Where the Council stands: reported stalled, over trade secrets

MLex reported on 7 October 2026 that the member states' deal on the Digital Omnibus "stalls over trade secrets", with more talks on Sunday 11 October 2026; a second piece the same day describes the deal as threatened by Germany's trade-secrets objection. A third piece, of 6 October 2026, says the latest draft "aims to tighten trade secrets sharing".

We are recording that as a press report, and not more than that. The articles sit behind a subscription, so we have headlines and ledes only: we could not establish which provisions the objection turns on, which draft it refers to, who raised it, or on what document it rests. We found no Council act or published position saying any of this, and when we tried the Council's own website on 7 October 2026 it returned a browser check rather than results. Nothing changes for you either way.

What "trade secrets" means in this file, as far as the text shows. The proposal does carry real trade-secret material, and it is about the Data Act, not about breach reporting: it would let a data holder refuse to disclose a trade secret where there is a high risk of unlawful acquisition, use or disclosure to third countries or to entities under their control in jurisdictions with weaker protection, and it narrows the business-to-government access route to public emergencies. That is the kind of provision a government can object to without touching the notification rules at all — but whether it is what the reported objection is about, we do not know.
Adopted so far
Regulation (EU) 2026/1744 — the AI half. Dated 8 July 2026, in the Official Journal on 24 July 2026, in force since 27 July 2026.
Not adopted
The proposal on the GDPR, the Data Act, NIS2, DORA, eIDAS, CER and the ePrivacy Directive (COM(2025) 837), and the Cybersecurity Act revision that would fund ENISA's side of it. A Council negotiating position is not a law: even after agreement there is Parliament, trilogue and publication before anything bites.
What the analysis says about the timing
Written on 6 October 2026, the day before the reported stall, it describes the situation simply: the AI Omnibus is already approved, "the rest of the EU Digital Omnibus is under debate". That is still where we are.

Who this would matter to

Nothing here is about the size of your business: the notification duties in Article 33 GDPR and in NIS2 attach to what you hold and what you do, not to how many people you employ. Three situations are worth watching.

You hold customer data
If a breach hits you, you file with your supervisory authority — and, if you are also caught by NIS2, you file separately with the CSIRT or competent authority, on a different clock (24 hours for the early warning, 72 hours for the notification, a final report within a month, Article 23(4) NIS2). The proposal's whole point is to make that one filing instead of several.
You are a small seller with a DPA and a host
The value of the change, if it comes, is administrative: one form, one recipient, one set of facts, instead of the same facts typed into different portals with different deadlines. For a one-person business that is the difference between an afternoon and a week.
You have already had an incident
Nothing in the proposal is retroactive, and the 96 hours would not apply to an incident that happened before the new rules are in force. If you have filed a breach notification, the sequence you followed — which authorities, which forms, how long it really took — is exactly the kind of experience worth sending us.

What applies today

GDPR — 72 hours, to your supervisory authority
Unchanged. Article 33 GDPR as it stands, with the Article 55/56 one-stop-shop for cross-border processing, and the documentation duty in Article 33(5).
NIS2 — 24 hours, 72 hours, one month
Unchanged. Article 23(4) of Directive (EU) 2022/2555: early warning within 24 hours, incident notification within 72 hours, final report within one month of the notification. Where NIS2 applies to you, it applies alongside the GDPR duty, not instead of it.
CRA — reporting has been live since 11 September 2026
That one is real, and it already goes to a single ENISA channel — the Single Reporting Platform — under Article 14 of Regulation (EU) 2024/2847. It is not the single-entry point: the proposal only says that ENISA may build the future point on that platform, so the two may end up as one system one day, but today the channel that exists is the CRA's. It is worth knowing which of the two you are being told about. Details in CRA reporting clock.
Everything else — still a draft
The single-entry point, the 96 hours, the lower notification threshold, the alignment of the data-subject and authority notices: all of it sits in a proposal whose Council stage was reported on 7 October 2026 to be stuck.

Three reasons not to plan around this

One: it is a proposal, so there is no text you can rely on and no date. Two: the Council had not agreed a position as of 7 October 2026 — the reports say talks stalled. Three: the obligation to use the point only starts 18 months after entry into force, and entry into force has not happened. A one-person business that needs protection this year is protected by the rules that exist this year.

What we could not establish

The substance of the trade-secrets dispute
Established only at headline and lede level, because MLex is paywalled. We do not know which provisions, which draft, or which member states other than Germany are involved, and we have not treated the three headlines as three confirmations of the substance. The further talks reported for Sunday 11 October 2026 had not happened when this page was last checked.
How far "lower" or "higher" the threshold really goes
The Commission's recital 39 calls the change a higher threshold for notifying the supervisory authority. The CiTiP analysis says the rewording could lower the threshold for notifications to authorities and data subjects. Both readings describe the same sentence, so we print both and resolve neither. The compromise text, if there is one, is what will settle it.
The AI Act and NIS2 Article 35 in the analysis's list
The analysis presents the single-entry point as covering incident duties including Article 73 of the AI Act and Articles 23 and 35 of NIS2. The Commission's proposal text amends NIS2 Article 23(4) and inserts Article 23a and Article 23(12); it does not amend Article 35 of NIS2, and it does not amend the AI Act at all. The AI Act's own incident-reporting route was reworked in the separate AI Omnibus, and it now points some reports at the AI Office (Article 75(1a)) rather than at an ENISA channel. We could not reconcile the list with the text, so we rely on the text.
Where the other institutions are
We found no published European Parliament position on the data-and-digital proposal that we could verify, and no Council document. That is a gap in our reading, not evidence that none exists.
Whether the single-entry point would actually reduce SME work
No adopted text, no implementing act and no ENISA design document yet. The Commission's €5 billion figure is an estimate attached to the proposal; nobody has run this channel in production.

None of this is legal advice

This page tells you what the Commission proposed, what is law and what is not. It does not tell you whether a given incident is notifiable by you, to whom, or by when. That depends on facts about your business.

Sources

Listed with what each one supports, so you can weigh them yourself. Primary acts first.

  1. European Commission — Proposal for a Regulation … (Digital Omnibus), COM(2025) 837 final, 19 November 2025 Read in full (the English text; the German version for the term "zentrale Anlaufstelle"). Source for the date, the procedure number 2025/0360(COD), the list of acts amended and repealed, the exact wording of the new Article 33(1) and (1a) GDPR, the 72-to-96-hour change and the parallel change to Article 34(1) of the EUDPR, recital 39 on the high-risk threshold, the new NIS2 Article 23a and Article 23(12), the eIDAS, DORA and CER articles routed through the point, the 18-month and 24-month application dates, the ENISA budget reference to the Cybersecurity Act revision, the savings estimate, and the Data Act trade-secret provisions
  2. EUR-Lex — Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI) Read in full. Source for the adoption of the AI half: the date of 8 July 2026, the Official Journal of 24 July 2026, the acts amended, the new Article 75(1a) sending serious-incident reports of certain providers to the AI Office by way of derogation from Article 73, and the fact that the published text contains no single-entry point — our basis for saying the AI Act is not part of the ENISA notification route
  3. Directive (EU) 2022/2555 (NIS2) — Article 23 Read at Article 23. Source for the notification deadlines in force today: early warning within 24 hours, incident notification within 72 hours, final report within one month; and for Article 23 being the article the proposal amends and adds to
  4. Regulation (EU) 2018/1725 (EUDPR) — Article 34 Read at Article 34. Source for the 72-hour deadline to the EDPS that the proposal would raise to 96 hours
  5. KU Leuven CiTiP blog — "Simplification done right: the Single Entry Point in the EU Digital Omnibus", 6 October 2026, Javier López-Guzmán Read in full. Authored commentary, not an official record, and the author says it does not represent CiTiP's or KU Leuven's position. Source for the pre-emption argument, the link to EDPB–EDPS joint opinion 2/2026 and the EU-institutions extension, the CEDPO survey figure of 83%, SMEunited's support, the under-reporting point, the criticism of the 96-hour change and of the "high risk" wording, and the list naming Article 73 of the AI Act and Articles 23 and 35 of NIS2 — which we could not reconcile with the proposal text
  6. MLex — Digital Omnibus coverage, 6 and 7 October 2026 Paywalled: we have headlines and ledes only. Source for the reported stall in the Council talks, the further talks on Sunday 11 October 2026, Germany's trade-secrets objection, and the 6 October headline that the latest draft aims to tighten trade-secrets sharing. We could not read the articles' substance and have not treated them as confirmed

Tell us if this moves

This file will change fast: a Council general approach, a Parliament report or a new compromise text can all land within days. If you see a document we have missed, or a German-language version of a term used here that we have got wrong, say so and we'll write the follow-up.