The EU Digital Omnibus and Monaco
Compliance·6 min read·22 August 2026

The EU Digital Omnibus and Monaco

Brussels is rewriting the GDPR, cookie rules and the AI Act. Monaco is not in the EU — but Monaco businesses will feel it. What to prepare for.

Brussels Is Rewriting Rules You Already Follow

Most Monaco businesses do not read EU legislative files, and they are right not to. Monaco is not an EU member state, and EU regulations do not apply here by default.

But the tools you run your company on were built for EU rules. Your cookie banner, your consent management platform, your CRM's data processing agreement, the deletion workflow your email provider ships — all of it was designed around the GDPR. When the GDPR moves, those products move with it, and they move on your website whether or not you were consulted.

That is what is happening now. A package known as the Digital Omnibus is working its way through the European legislative process, and it proposes the most significant rewrite of the EU's digital rulebook since the GDPR itself took effect. This is forward-looking: much of it is not law yet. But the direction is already shaping vendor roadmaps, and that reaches Monaco well before any text is final.

What the Digital Omnibus Actually Is

On 19 November 2025 the European Commission presented a simplification package touching several major digital laws at once. It has since effectively split into two tracks.

The first is the AI-focused half, which makes targeted amendments to the AI Act — mainly around timelines, governance, and how compliance obligations for high-risk systems are sequenced against the availability of technical standards. This half has moved through the process considerably faster.

The second is the data half, covering the GDPR, ePrivacy and cookie rules, the Data Act, and incident reporting under frameworks such as NIS2. This half remains under negotiation, and its content has already shifted from the Commission's original draft. Nothing in it should be treated as settled.

If you need certainty on a specific obligation and a date, take legal advice rather than a blog post — including this one. What follows is about direction of travel, not a compliance checklist.

The Changes That Would Reach Monaco Desks

Several proposed changes matter commercially rather than just legally.

Cookie and consent handling. The package would widen the categories of activity that do not require consent — things like aggregated audience measurement and security maintenance — and push towards standardised, machine-readable consent signals expressed through browsers rather than a banner on every site. If that lands, the consent layer on your website becomes less of a design problem and more of a technical one. It is worth knowing where your current setup sits before your vendor changes it for you.

AI and personal data. Proposals would clarify when legitimate interest can support AI development and testing, and create a narrow basis for processing sensitive data specifically to detect and correct bias. For any Monaco business exploring AI automation, this is the part of the file to watch: it addresses the question everyone asks and nobody can currently answer cleanly.

Breach notification timing. The Commission proposed extending the EU deadline from 72 hours to 96. Read that carefully, because it is exactly where Monaco businesses will get caught out.

Incident reporting plumbing. A single entry point for notifications across several EU regimes — report once, share many. Useful if you have EU establishments; irrelevant if you do not.

Monaco Is Not Downstream of Brussels — Except Where It Is

Monaco's own framework is Law No. 1.565 of 3 December 2024, supervised by the Autorité de Protection des Données Personnelles (APDP). It is a modern, European-standard regime, but it is Monegasque law. Nothing in the Digital Omnibus amends it, and no EU vote changes a single obligation you have under Monaco law.

There are three routes by which it still reaches you.

The first is scope. If you market to, or monitor, people in the EU, the GDPR can apply to you directly regardless of where you are established. Plenty of Monaco businesses — e-commerce operations, agencies, funds, hospitality groups — are in that position without having thought about it.

The second is your supply chain. Your processors are overwhelmingly EU or US companies building to EU requirements. Their defaults become your defaults.

The third is the longer conversation about how Monegasque and EU frameworks relate to each other, including the question of an EU adequacy finding for Monaco. Law 1.565 was deliberately built to European standards. If the European standard itself moves, that alignment becomes a moving target. Where that leads is genuinely uncertain and worth verifying with counsel rather than assuming.

The Divergence Trap

Here is the practical risk, and it is not theoretical.

Over the next year, a large amount of content, tooling and vendor advice will describe the new EU position — 96 hours for breach notification, relaxed transparency in low-risk cases, wider consent exemptions. Someone in your business will read it, assume it applies, and adjust a process accordingly.

It does not apply. Your obligations sit under Monaco law and are set by Law 1.565 and the APDP, on Monegasque timelines. If the EU moves to 96 hours and you quietly adopt that as your internal incident deadline, you have not simplified anything — you have introduced a gap between what you do and what Monaco requires.

The same logic applies to consent. If a platform update loosens your cookie banner because EU rules changed, that change was not assessed against Monaco law. Someone has to check it. Practically, that means treating data protection compliance as a Monaco question first and an EU question second — not the other way round, which is how most teams currently do it.

What to Do Between Now and Adoption

Three things, none of them expensive.

Know your exposure: write down, in one page, whether you fall under Monaco law only or under both Monaco and EU rules, and why. Most businesses have never done this and guess wrong in both directions.

Know your defaults: list the tools that make compliance decisions on your behalf — consent platform, analytics, CRM, email, hosting — and note who controls their configuration. When a vendor pushes a change, you want to find out from your own list, not from a client.

Change nothing yet on the basis of a proposal. Draft text is not law, and the data half in particular has already been rewritten in negotiation.

If your consent setup, analytics configuration or data flows have not been reviewed since Law 1.565 came into force, that review is worth doing now — independently of Brussels. It is also the natural moment to align it with your wider digital strategy, rather than treating compliance as a separate chore.

We help Monaco businesses build websites and digital operations that hold up under Monegasque rules, not borrowed EU assumptions. If you would like a clear view of where you stand before the next wave of vendor updates arrives, get in touch.

digital omnibusdata protectionlaw 1.565AI actmonaco
BSS Digital Agency

BSS Digital Agency

Digital agency based in Monaco. Web, apps, AI, marketing.

Get in touch