Products Intelligence Pricing Methodology Contact
Cresthaven Analytics Intelligence Brief

EDPB Data Protection Brief

July 8, 2026 · European Data Protection Board · EU

EDPB adopts draft guidelines on anonymisation and AI web scraping, finalises blockchain guidance, with comment period to 30 October 2026

The European Data Protection Board adopted two sets of draft guidelines on July 8, 2026: one clarifying the legal standard for anonymous data and one addressing GDPR compliance for web scraping used in generative AI training. A finalised version of the Board's blockchain data-processing guidelines was also adopted following public consultation.

The three outputs together close a significant interpretive gap in EU data protection law for AI development. Organisations building or operating generative AI systems that rely on web-scraped training data now face a structured GDPR compliance framework with no safe-harbour carve-outs for incidental special category data collection. The anonymisation guidelines redefine the threshold at which GDPR obligations cease to apply, directly affecting data-sharing arrangements, synthetic data strategies, and AI training pipelines that have relied on informal anonymisation assessments. The blockchain guidelines, now final, carry immediate interpretive authority for any GDPR-governed entity processing personal data on-chain.

  • Anonymisation Standard Tightened Around a Three-Part Test: Organisations seeking to rely on anonymous data must now assess three criteria: no record isolation, no linkage, and no inference. Controllers may apply either a contextual approach, which accounts for differences in re-identification capability across entities, or a simplified approach that treats data as non-anonymous unless all three criteria are met for every relevant party. The choice of approach carries direct consequences for whether GDPR obligations attach.
  • Web Scraping for AI Training Carries Full GDPR Exposure: The Board confirms that GDPR applies to web scraping wherever personal data is collected, stored, organised, or retrieved. AI developers and data pipeline operators relying on web scraping for generative AI training must document a lawful basis under Article 6, observe purpose limitation and transparency obligations, and apply data minimisation measures. Scraping from unreliable sources without timestamp recording and data validation creates an accuracy-principle compliance gap.
  • Special Category Data in Scraped Datasets Requires a Dual Legal Gateway: Where web scraping incidentally captures special category data, controllers must satisfy both a lawful basis and an Article 9(2) exception. The Board references the Court of Justice ruling in GC & Others as potentially applicable to incidental collection, but states explicitly that no general exemption from Article 9 exists and that each case requires individual assessment.
  • Legitimate Interest Basis for AI Training Receives Structured Guidance: Building on the Board's 2024 opinion on AI models, the web scraping guidelines provide additional examples of when legitimate interest may serve as the legal basis for scraping personal data for AI training. This does not constitute a blanket authorisation; controllers must conduct a balancing test and implement appropriate safeguards.
  • Blockchain Guidelines Now Final and Binding in Interpretation: The blockchain guidelines, previously in consultation, are now adopted in final form. Organisations using blockchain architectures to process personal data must assess their specific architecture against the GDPR compliance framework the Board has established. The Board published a track-changes version and a consultation outcome report alongside the final text.

- The anonymisation guidelines incorporate the September 2025 Court of Justice ruling in EDPS v SRB (C-413/23 P). This makes them the first EDPB guidance to formally integrate that judgment into the operational anonymisation standard.

- The web scraping guidelines extend the Board's 2024 AI models opinion into a concrete operational framework, moving from principle-level analysis to specific compliance steps for data pipeline design.

- Both draft guideline sets are open for public comment until October 30, 2026. That window runs concurrently with the EU AI Act's phased application schedule, creating overlapping compliance planning obligations for AI developers operating under both regimes.

HIGH — Three sets of EDPB guidelines with sector-wide application alter the operational anonymisation standard, establish a GDPR compliance framework for AI training data pipelines, and finalise binding interpretive authority for blockchain data processing, requiring compliance posture review across all EU-regulated data controllers using these technologies.

comment_close — 2026-10-30

Monitor the EDPB for the consultation outcome reports and final adopted versions of the anonymisation and web scraping guidelines following the October 30, 2026 comment-period close.

EDPB Guidelines 02/2026 on Anonymisation; EDPB Guidelines 06/2026 on Web Scraping in the Context of Generative AI; EDPB Guidelines 02/2025 on Blockchain Technologies (final version); Regulation (EU) 2016/679 (GDPR), Article 6; Regulation (EU) 2016/679 (GDPR), Article 9(2); CJEU Case C-413/23 P, EDPS v SRB, judgment of 4 September 2025; CJEU Case C-136/17, GC & Others, judgment of 24 September 2019; EDPB Opinion 28/2024 on certain data protection aspects related to AI models

www.edpb.europa.eu — Source ↗

This is a sample intelligence brief from Cresthaven Analytics. Live subscribers receive briefs like this on a daily or weekly cadence depending on tier.