A committee vote most people missed
On June 22, 2026, the European Parliament's Industry (ITRE) and Civil Liberties (LIBE) committees published a joint draft report on the European Commission's Digital Omnibus — the package that rewrites parts of the GDPR, ePrivacy rules, the Data Act, and the incident-reporting regime that eIDAS, NIS2, and DORA all feed into. The two committees discussed the draft on July 13, and by the July 15 amendment deadline, MEPs had tabled more than 1,750 changes to it, according to the European Parliament's own Legislative Train tracker. That volume is not noise. It is the clearest signal yet that Parliament intends to fight the Commission's simplification agenda line by line, not wave it through.
The co-rapporteurs steering that fight are Aura Salla (EPP, Finland) for ITRE and Marina Kaljurand (S&D, Estonia) for LIBE. Kaljurand's presence on this file matters beyond her nationality: Estonia has more infrastructure riding on the outcome than almost any other member state.
What the Omnibus actually touches
Strip away the "simplification" branding and the Digital Omnibus does three concrete things relevant to digital identity. First, it would extend the GDPR Article 33 breach-notification deadline from 72 to 96 hours. Second, it proposes a single-entry-point reporting channel run by ENISA, covering GDPR, NIS2, eIDAS, and DORA incidents under one "report once" mechanism. Third — the part Kaljurand has pushed back on hardest — it loosens the rules on processing sensitive personal data, including a provision letting AI systems process special-category data to detect and correct bias. At a LIBE hearing, Kaljurand argued that carve-out undermines GDPR's technology-neutral design by implying AI processing needs weaker safeguards than everything else, a concern IAPP reported directly from the hearing floor.
None of this is happening in isolation from digital identity. eIDAS 2.0's implementing acts entered into force on December 24, 2024, starting a 24-month clock that requires every member state to offer at least one European Digital Identity (EUDI) Wallet by roughly the end of 2026 — a deadline Estonia's Information System Authority (RIA) confirms it is racing against, having only reached the procurement stage with an international tender issued May 18, 2026. The GDPR provisions the Omnibus is rewriting are the same ones that govern how personal data moves through that wallet, and through the qualified certificates e-Residency already issues.
Why Estonia has more at stake than most
e-Residency is not a symbolic program. As of this year it counts 142,332 e-residents from more than 170 countries, who have founded over 43,000 companies, according to the program's own figures published on e-resident.gov.ee. Every one of those digital identities authenticates through eIDAS-recognized qualified electronic signatures — the exact legal category the Digital Omnibus, the EUDI Wallet rollout, and the GDPR rewrite all intersect on. If Brussels changes how sensitive data can be processed for identity verification, or how breach reporting works across the ENISA single entry point, Estonia doesn't get to opt out and keep its current system running on the side. It has to re-architect the plumbing under 142,000 existing accounts.
The steelman: caution has a real case here
Kaljurand's skepticism is not obstructionism. The joint draft report deliberately restored provisions the Commission wanted gone — it kept the GDPR Article 22 right against purely automated decisions, and reinstated the Platform-to-Business Regulation rather than repealing it as proposed. Bundling AI-training carve-outs, breach-timeline extensions, and identity-framework alignment into a single fast-track "omnibus" procedure makes it genuinely harder for any single provision to get the scrutiny it would receive as standalone legislation. A regime that 142,000 e-residents and every EU citizen's future digital wallet depends on deserves exactly the line-by-line amendment fight it is currently getting, not a rubber stamp.
Where the caution overshoots
The risk to Estonia isn't that Parliament moves too fast — it's that the process stalls entirely while two hard deadlines keep running. The Council already failed to agree a negotiating mandate on June 26, 2026, pushing the file to the Irish Presidency with no fixed date for trilogues. Meanwhile the EUDI Wallet deadline doesn't move, and RIA's own procurement timeline needs about a year to close a contract that started in May. A GDPR framework stuck in amendment limbo for another year, while the digital-identity deadline it's supposed to align with arrives on schedule, is a worse outcome for e-Residency than a faster, narrower fix would be. The 96-hour breach window and the ENISA single entry point are genuinely proportionate — they reduce duplicate reporting without touching a single individual right. Those should move now, separately from the AI-processing fight that legitimately needs more time.
What to watch
The next marker is whether the Irish Council Presidency can revive a negotiating mandate before the EUDI Wallet's end-2026 deadline arrives. If it can't, Estonia's digital-identity infrastructure will be operating under a rulebook still being rewritten underneath it — the worst version of the outcome everyone in Brussels claims to want to avoid.