What the Digital Omnibus proposal changes — and what it doesn't
The European Commission presented the Digital Omnibus package (COM(2025) 837) on November 19, 2025. One of its components moves cookie rules from the ePrivacy Directive into the GDPR itself, under a new Article 88a. The stated objective is to simplify the consent regime for uses that present no real risk to visitor privacy.
Article 88a(3) creates a consent exemption for audience cookies when three cumulative conditions are met: data is processed solely for statistical purposes on the data controller's own site, no individual profiles are created, and data is not shared with third parties. The proposal is currently under review by the European Parliament and the Council of the EU. Final adoption is expected in late 2026 or early 2027; the new cookie rules would apply approximately six months after entry into force.
What Article 88a does not change: advertising pixels, retargeting, SaaS A/B testing tools that send data to third parties, remarketing cookies — all these categories continue to require explicit consent. The exemption is strictly bounded to first-party analytics only, with no ambiguity about its scope.
The three cumulative conditions of the Art. 88a exemption
- Exclusive statistical purpose — data is used only to understand the audience of the controller's own site, not for marketing or advertising purposes.
- No individual profiles — data is aggregated; no visitor is tracked across sessions with a persistent identifier.
- No transfer to a third party — data stays with the data controller and any technical provider acting on their behalf; it is not shared with other parties.
Why GA4 and SaaS analytics remain outside the exemption
Google Analytics 4 does not meet the conditions of Article 88a for a structural reason: measurement data leaves the data controller's server and lands on Google's infrastructure. Google accesses it for its own purposes — product improvement, advertising signal enrichment — and this data is cross-referenced with information from other sites and Google services.
Even if an operator configures GA4 in minimal mode, the transfer to a third party remains inherent to the model: it cannot be eliminated without ceasing to use GA4. The same logic applies to Hotjar, Mixpanel hosted as SaaS, or any tool whose processing relies on servers belonging to a third party.
The distinction is therefore not whether the tool is GDPR-compliant — GA4 can be in certain configurations — but whether the data stays with the data controller. That is the condition that Article 88a(3)(c) makes constitutive of the exemption.
The technical condition: data on your own server
The exemption is based on architecture, not configuration. For an analytics tool to fall under Article 88a, the data controller — in the case of an agency, this may be the agency itself or the end client — must control the infrastructure on which data is stored and processed.
In practice, this means deploying the analytics tool on a server you administer: a VPS with root access, a dedicated HTTPS subdomain, a local database. Measurement data never crosses the boundary of your own infrastructure during each visit. No requests to a third-party CDN, no automatic export, no integration that transfers events to an external platform.
For an agency managing a portfolio of client sites, two architecture models exist:
- Agency-centralized instance — a single analytics VPS hosts dashboards for all client sites. The agency is the data controller for the whole; each client has access to their own dashboard. This model is economical and simplifies maintenance.
- Dedicated instance per client — each client hosts their own analytics on their own VPS. The client is the data controller; the agency configures and maintains. This model is appropriate when the client has data segregation requirements or wants direct control.
SaaS analytics vs self-hosted analytics — what Art. 88a looks at
Scroll the table
| Criterion | GA4 / SaaS Analytics | Plausible CE / Umami (self-hosted) |
|---|---|---|
| Data leaves the data controller's server | Yes — transfer to Google / third party | No — local storage on your VPS |
| Persistent identifier per visitor | Yes (cookie _ga, _gid…) | No — no identifying cookie by default |
| Individual profile across sessions | Yes | No — aggregation only |
| Cross-referencing with other sources | Yes (Google Ads, Search Console enrichment…) | No — isolated data |
| Art. 88a exemption met | No | Yes, subject to configuration without cross-referencing |
| Consent banner required for this use | Required | Not required if conditions are met |
Plausible CE and Umami: what places them within the exemption
Plausible Community Edition (stable version: v3.2.1, May 2026) does not use cookies. Unique visitor measurement relies on a random string reset daily: no persistent identifier is created between sessions. Data stays entirely on the server where the instance is deployed. Plausible collects essential metrics — page views, sources, countries, devices — without personally identifiable information.
Umami operates on the same principle: no cross-site cookies, no automatic collection of personal data, full storage on the operator's infrastructure. For self-hosted deployments, data never leaves the server.
Both tools meet the three conditions of Article 88a(3) by their default architecture:
- Exclusive statistical purpose (no native advertising integration)
- No individual profiles (no persistent identifier)
- Data with the data controller (local storage on your VPS)
Important caveat: this analysis applies to the default configuration of these tools. Adding an integration that sends events to a third-party platform, or enabling automatic export to an external data warehouse, exits the scope of the exemption. Compliance is not a property of the tool alone — it is a property of the deployed architecture.
What the agency gains in practice
For an agency managing client sites with self-hosted first-party analytics, Article 88a produces three measurable effects.
Complete audience measurement. Current consent banners mechanically reduce the volume of data collected: visitors who refuse or ignore the banner are not counted in GA4. With self-hosted analytics compliant with Article 88a, no consent is required for this use case, so no data is lost to refusal. Measurement regains its representativeness.
A documented client argument. When a client asks how you handle cookie compliance on their site, you can answer precisely: analytics is hosted on their own server, data does not leave their infrastructure, the Digital Omnibus proposal creates an explicit exemption for this type of use. This is an opposable argument, anchored in a legislative text in the process of adoption, not in a jurisprudential interpretation.
Reduced operational cost. A CMP (Consent Management Platform) for GA4 involves configuration costs, regular updates, and CNIL/CNDP monitoring. Eliminating this need for analytics — while keeping the CMP for uses that still require it (advertising pixels, remarketing) — simplifies the compliance infrastructure of each site.
How to migrate: from GA4 to self-hosted analytics in four steps
Choose the tool and hosting model
Plausible CE and Umami are the two references for self-hosted analytics compliant with Article 88a. To choose between them — server resources, interface, features — see the article Plausible vs Umami: which self-hosted analytics to choose. Then decide on the model: centralized instance for the whole client portfolio, or dedicated instance per client.
Deploy the instance on a VPS
Both tools install via Docker Compose on a VPS with root access. Plan for 1 vCPU and 512 MB RAM for Plausible CE on a portfolio of a few dozen sites, more if event volume is high. Detailed technical guides are available in the dedicated articles: Plausible CE on VPS and Umami on VPS.
Add the tracking snippet to each site
Each tool generates a JavaScript snippet to insert on the pages to be measured. It points to your own domain (e.g.
stats.youragency.com), not to an external CDN. No data leaves the perimeter of your infrastructure during each visit.
The exemption is an architecture, not a setting
The value of Article 88a does not rest on a configuration in a dashboard: it rests on where data lands. A self-hosted analytics tool that exports its events to a SaaS data warehouse, or sends webhooks to a third-party marketing platform, exits the scope of the exemption — even if the main server is your own. Document the complete data flow architecture for each client site: this document is the basis of your compliance, not just the hosting invoice.
What remains outside the exemption: do not oversell its scope
Article 88a is targeted. Quickly adopting this interpretation without knowing its limits would expose an agency to compliance gaps.
Still subject to consent, regardless of the vote outcome:
- Advertising tracking pixels (Meta Pixel, LinkedIn Insight Tag, TikTok Pixel) — these are third parties by definition, their purpose is advertising, not statistical.
- SaaS-hosted A/B testing tools — test data goes to an external server.
- Remarketing and retargeting — individual identification and cross-site tracking are the core principle of these technologies.
- SaaS session recording tools (journey recording, heatmaps) — they collect individual behavioral data and send it to a third party.
The proposal does not eliminate CMPs — it lightens them on one specific point. An agency that deploys self-hosted analytics can remove this tool from its consent list, but retains its CMP for other categories.
Finally, the proposal is in the process of adoption at the time this article is published (October 2026). It is not yet in force. Migrating to self-hosted analytics is a technically neutral decision regardless of the vote outcome.
Regulatory context: Digital Omnibus, NIS2, DORA
Article 88a is part of a broader movement to clarify European digital law. Other recent texts directly affect agencies that host for their clients.
The NIS2 regulation, in force since 2023 and progressively transposed in Member States, imposes security and incident notification obligations on essential service operators and their digital providers. Hosting falls within this scope for the entities concerned.
The DORA regulation (EU 2022/2554), applicable since January 17, 2025 to financial entities, requires precise clauses in all ICT contracts, including hosting contracts — a point covered in detail in the article DORA: what the regulation requires of your ICT contracts.
These texts share a common logic: they make the choice of a hosting provider measurable and opposable. Article 88a adds a new dimension to this evaluation grid — the location of audience measurement data becomes a compliance criterion, not just a performance choice.