As AI becomes more deeply woven into how our teams work, learn, and collaborate, our responsibility as employers only grows. At Bloomreach, the way we use data is grounded in a belief that innovation is only meaningful when it is built on trust.
The EU’s proposed updates to the GDPR and AI Act highlight the need for technology and regulation to evolve together. These changes aim to ensure AI can continue to advance while safeguarding individual rights. That balance is critical for organizations like ours, because people need to feel confident that the tools designed to help them are also respecting their privacy.
Recent discussion around the draft of the GDPR “Omnibus” Regulation has understandably drawn attention. While still in an early and uncertain phase, the proposal signals that the EU may be considering adjustments to how certain GDPR provisions are interpreted or applied. For businesses and regulators, that could eventually bring clarifications in areas of privacy and business that have proven complex in practice.
When GDPR was introduced, its purpose was clear. It was designed to strengthen data protection, harmonize rules across the EU, and give individuals more control over their personal data. Over time, both regulators and organizations have gained experience applying the law in real-world environments. The emerging Omnibus discussion reflects that ongoing evolution.
We see a similar dynamic with AI. The EU AI Act has been adopted, and organizations like Bloomreach are actively implementing its requirements today. As with any major regulation, further guidance and supporting standards will continue to develop, helping refine how the rules are applied in context. This ongoing evolution is expected and will help ensure that compliance keeps pace with technological progress and emerging risks.

Because the Omnibus is still only a draft, it is too early to know what the final outcome will be. Changes may take years and will require extensive debate, consultation, and refinement. At Bloomreach, we continue to closely monitor these developments to ensure we are prepared for any potential updates that could influence future compliance expectations.
Bloomreach is committed to compliance with GDPR. Learn more about Bloomreach’s privacy program and how it shapes our business practices.
