Digital package on simplification: the Digital Omnibus
On 19 November 2025, following the European Commission’s commitment to simplify the EU’s digital rulebook, the Commission published a Digital Package on Simplification, that includes a Digital Omnibus. The Digital Omnibus included a proposed Regulation with targeted amendments to the General Data Protection Regulation (GDPR), ePrivacy rules, the Data Act, and cyber incident reporting rules across EU laws (including the Digital Operational Resilience Act (DORA)), and a proposed Regulation amending the AI Act.
Most of the above-mentioned EU texts apply to intermediaries. Overall BIPAR welcomes the digital package and the Digital Omnibus as it aims at simplifying some EU texts.
(Last updated in June 2026)
Artificial Intelligence (AI)
The development of the use of AI systems by more and more sectors prompted the European Commission to propose several pieces of legislation aimed at regulating its use, such as the Artificial Intelligence Act. Insurance and financial intermediaries using AI systems are affected by the framework.
(Last updated in June 2026)
Digital Operational Resilience Act (DORA)
The Digital Operational Resilience Act (DORA) is part of the European Commission’s Digital Finance Strategy that was published in September 2020. DORA’s primary objective is to enhance the IT security of financial entities. It aims to establish a comprehensive digital operational resilience framework across the European banking, insurance and investment sectors, requiring financial entities in its scope to comply with digital security and reporting requirements to mitigate their Information Communication Technology (ICT) risks.
DORA started to apply, together with its level 2 measures, on 17 January 2025. Insurance intermediaries who are SMEs and microenterprises are exempted from the scope of DORA and its level 2 measures. Opt-out investment firms under MiFID II are exempted as well. Larger insurance intermediaries are within the scope of DORA (more than 250 persons, an annual turnover of more than €50 million and/or an annual balance sheet of more than €43 million). In some cases, intermediaries, if considered by insurers as ICT Third Party Providers or in the context of delegations of authorities under Solvency II, may have to comply with some DORA requirements.
DORA has assigned new tasks and roles to the European Supervisory Authorities (EIOPA, ESMA and EBA – the ESAs), as well as the development of Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS) on certain provisions of the DORA Regulation. RTS and ITS of the ESAs aim to clarify the provisions of a European legislative text and to ensure a coherent harmonisation of the defined areas.
(Last updated in June 2026)
Open insurance: Financial Data Access Act (FIDA)
Data and technology are increasingly driving changes in the insurance sector, producing new business models, insurance products and ways for firms, and in particular insurance intermediaries, to engage with their clients.
(Last updated in June 2026)