On July 8, 2026, the European Data Protection Board (“EDPB”) adopted draft guidelines on anonymization and draft guidelines on web scraping in the context of generative artificial intelligence (“AI”), and finalized its guidelines on the processing of personal data through blockchain technologies. Together, these measures further clarify how the EU General Data Protection Regulation (“GDPR”) applies in several fast-developing technical areas.
Anonymization
The draft anonymization guidelines aim to clarify when data may be treated as anonymous under EU data protection law. The EDPB reiterates that, under the GDPR, data is anonymous only if it does not relate to an identified or identifiable natural person. The guidelines also note that information may relate to a person by its content, purpose or effect, even where that connection is not immediately obvious.
The guidelines further explain that a person is identifiable if they can be distinguished from others using means reasonably likely to be used. Those means should be interpreted broadly and may include information or capabilities available through a third party. Whether such means are reasonably likely to be used should be assessed based on objective factors and from the perspective of the relevant entity. The guidelines also reflect recent Court of Justice of the European Union (“CJEU”) case law, including the September 4, 2025 judgment in C-413/23 P EDPS v SRB, which clarified the scope of personal data in the context of a transfer of pseudonymized data to third parties.
To help organizations assess whether anonymization is effective, the draft anonymization guidelines set out a practical framework based on two possible approaches: (1) a “contextual approach,” which considers the capabilities of parties that might identify individuals; and (2) a more conservative “simplified approach,” which does not. It also introduces three key criteria for testing anonymity: “no record isolation,” “no linkage” and “no inference.” If all three criteria are met, the data may be regarded as anonymous; if not, additional assessment is required. Finally, Annex 1 of the draft anonymization guidelines includes a flow chart as a support tool to help organizations decide whether a simplified or contextual approach should be taken, and to determine whether data may be considered anonymous or personal.
Web Scraping in the Context of Generative AI
The draft guidelines on web scraping for generative AI confirm that the GDPR applies where scraping involves personal data and highlights the importance of compliance with core GDPR principles. The guidance recommends steps such as scraping from reliable sources, recording collection dates and validating data before using it for AI training. The draft guidelines also address legal basis and note that private entities commonly rely on legitimate interests in this context but must satisfy the balancing test of Article 6.1(f) of the GDPR and implement safeguards as part of this balancing test. The guidance includes practical examples to help organizations assess the balancing test under the legitimate interests basis. In addition, with regard to special categories, controllers must identify both a lawful basis under Article 6 of the GDPR and an applicable condition under Article 9(2) of the GDPR. The EDPB notes that existing CJEU case law may be relevant in limited cases involving incidental and residual collection but stresses that there is no general exemption and that each case must be assessed individually.
Processing of Personal Data Through Blockchain Technologies
The blockchain guidance is intended to help organizations using blockchain technologies evaluate GDPR compliance issues, including how different blockchain architectures may affect the processing of personal data and create risks for data subjects. The guidelines stress the importance of implementing data protection by default and by design measures to give effect to GDPR principles, facilitate the effective exercise of data subjects’ rights and ensure that appropriate technical and organizational measures are in place. They also make clear that storing personal data on a blockchain should be avoided where doing so would conflict with data protection principles. Where such storage cannot be avoided, organizations should consider advanced techniques, appropriate organizational measures and robust data protection policies. The guidelines also examine how the technical aspects of blockchain interact with core GDPR principles. In particular, the guidelines highlight the importance of carrying out a data protection impact assessment before implementing any processing activity involving blockchain technology.
Public Consultation Period
The draft guidelines on anonymization and the draft guidelines on web scraping for generative AI are both open for public consultation until October 30, 2026.
Read the EDPB press release here. See the draft anonymization guidelines here. See the draft web scraping guidelines here. See the blockchain guidelines here.
Search
Recent Posts
Categories
- Behavioral Advertising
- Centre for Information Policy Leadership
- Children’s Privacy
- Cyber Insurance
- Cybersecurity
- Enforcement
- European Union
- Events
- FCRA
- Financial Privacy
- General
- Health Privacy
- Identity Theft
- Information Security
- International
- Marketing
- Multimedia Resources
- Online Privacy
- Security Breach
- U.S. Federal Law
- U.S. State Law
- Workplace Privacy
Tags
- Aaron P. Simpson
- Accountability
- Adequacy
- Advertisement
- Advertising
- Age Appropriate Design Code
- Age Verification
- Alabama
- American Privacy Rights Act
- Anna Pateraki
- Anonymization
- Anti-terrorism
- APEC
- Apple Inc.
- Argentina
- Arkansas
- Article 29 Working Party
- Artificial Intelligence (AI)
- Attorney General
- Audit
- Australia
- Austria
- Automated Decisionmaking
- Baltimore
- Bankruptcy
- Belgium
- Biden Administration
- Big Data
- Binding Corporate Rules
- Biometric Data
- Blockchain
- Bojana Bellamy
- Brazil
- Brexit
- British Columbia
- Brittany Bacon
- Brussels
- Business Associate Agreement
- BYOD
- California
- CalPrivacy
- CAN-SPAM
- Canada
- Cayman Islands
- CCPA
- CCTV
- Centre for Information Policy Leadership (CIPL)
- Chatbot
- Children’s Online Privacy Protection Act (COPPA)
- Chile
- China
- Chinese Taipei
- Christopher Graham
- CIPA
- Class Action
- Clinical Trial
- Cloud
- Cloud Computing
- CNIL
- Colombia
- Colorado
- Committee on Foreign Investment in the United States
- Commodity Futures Trading Commission
- Compliance
- Computer Fraud and Abuse Act
- Congress
- Connecticut
- Consent
- Consent Order
- Consumer Protection
- Consumer Rights
- Cookies
- COPPA
- Coronavirus/COVID-19
- Council of Europe
- Council of the European Union
- Court of Justice of the European Union
- CPPA
- CPRA
- Credit Monitoring
- Credit Report
- Criminal Law
- Critical Infrastructure
- Croatia
- Cross-Border Data Flow
- Cross-Border Data Transfer
- Cyber Attack
- Cybersecurity
- Cybersecurity and Infrastructure Security Agency
- Data Breach
- Data Brokers
- Data Controller
- Data Localization
- Data Minimization
- Data Privacy Framework
- Data Processor
- Data Protection Act
- Data Protection Authority
- Data Protection Impact Assessment
- Data Protection Officer
- Data Security
- Data Transfer
- David Dumont
- David Vladeck
- Deceptive Trade Practices
- Delaware
- Denmark
- Department of Commerce
- Department of Defense
- Department of Health and Human Services
- Department of Homeland Security (DHS)
- Department of Justice
- Department of the Treasury
- Design
- Digital Markets Act
- District of Columbia
- Do Not Call
- Do Not Track
- Dobbs
- Dodd-Frank Act
- DORA
- DPIA
- E-Privacy
- E-Privacy Directive
- Ecuador
- Ed Tech
- Edith Ramirez
- Electronic Communications Privacy Act
- Electronic Privacy Information Center
- Electronic Protected Health Information
- Elizabeth Denham
- Employee Monitoring
- Encryption
- ENISA
- EU Data Protection Directive
- EU General Data Protection Regulation (GDPR)
- EU Member States
- European Commission
- European Data Protection Board
- European Data Protection Supervisor
- European Parliament
- European Union
- Facial Recognition Technology
- FACTA
- Fair Credit Reporting Act
- Fair Information Practice Principles
- Federal Aviation Administration
- Federal Bureau of Investigation
- Federal Communications Commission
- Federal Data Protection Act
- Federal Trade Commission
- FERC
- Financial Data
- FinTech
- Florida
- Food and Drug Administration
- Foreign Intelligence Surveillance Act
- France
- Franchise
- Fred Cate
- Freedom of Information Act
- Freedom of Speech
- Fundamental Rights
- GDPR
- Genetic Data
- Geofencing
- Geolocation
- Geolocation Data
- Georgia
- Germany
- Global Privacy Assembly
- Global Privacy Enforcement Network
- Gramm Leach Bliley Act
- Grok
- Hacker
- Hawaii
- Health Data
- HIPAA
- HITECH Act
- Hong Kong
- House of Representatives
- Hungary
- Illinois
- India
- Indiana
- Indonesia
- Information Commissioners Office
- Information Sharing
- Insurance Provider
- Internal Revenue Service
- International Association of Privacy Professionals
- International Commissioners Office
- Internet
- Internet of Things
- Iowa
- IP Address
- Ireland
- Israel
- Italy
- Jacob Kohnstamm
- Japan
- Jason Beach
- Jay Rockefeller
- Jenna Rode
- Jennifer Stoddart
- Jersey
- Jessica Rich
- John Delionado
- John Edwards
- Kentucky
- Korea
- Large Language Model
- Latin America
- Laura Leonard
- Law Enforcement
- Lawrence Strickling
- Legislation
- Liability
- Lisa Sotto
- Litigation
- Location-Based Services
- London
- Louisiana
- Madrid Resolution
- Maine
- Malaysia
- Maryland
- Massachusetts
- Meta
- Mexico
- Michigan
- Microsoft
- Minnesota
- Missouri
- Mobile
- Mobile App
- Mobile Device
- Montana
- Morocco
- MySpace
- Natascha Gerlach
- National Institute of Standards and Technology
- National Labor Relations Board
- National Science and Technology Council
- National Security
- National Security Agency
- National Telecommunications and Information Administration
- Nebraska
- NEDPA
- Netherlands
- Nevada
- New Hampshire
- New Jersey
- New Mexico
- New York
- New Zealand
- Nigeria
- Ninth Circuit
- North Carolina
- North Dakota
- North Korea
- Norway
- Obama Administration
- OCPA
- OECD
- Office for Civil Rights (OCR)
- Office of Foreign Assets Control
- Ohio
- Oklahoma
- Online Behavioral Advertising
- Online Privacy
- Opt-In Consent
- Opt-Out
- Oregon
- Outsourcing
- Pakistan
- Parental Consent
- Payment Card
- PCI DSS
- Penalty
- Pennsylvania
- Personal Data
- Personal Health Information
- Personal Information
- Personally Identifiable Information
- Peru
- Philippines
- Poland
- PRISM
- Privacy
- Privacy and Information Security Law
- Privacy By Design
- Privacy Notice
- Privacy Policy
- Privacy Rights
- Privacy Rule
- Privacy Shield
- Profiling
- Protected Health Information
- Purpose Limitation
- Ransomware
- Record Retention
- Red Flags Rule
- Rhode Island
- Richard Thomas
- Right to Be Forgotten
- Right to Privacy
- Risk Assessment
- Risk-Based Approach
- ROSCA
- Rosemary Jay
- Russia
- Safe Harbor
- Salesforce
- Sanctions
- Schrems
- Scott Kimpel
- SECURE Data Act
- Securities and Exchange Commission
- Security Rule
- Senate
- Sensitive Data
- Serbia
- Service Provider
- Singapore
- Smart Grid
- Smart Metering
- Social Media
- Social Security Number
- South Africa
- South Carolina
- South Dakota
- South Korea
- Spain
- Spyware
- Standard Contractual Clauses
- State Attorneys General
- Steven Haas
- Stick With Security Series
- Stored Communications Act
- Student Data
- Supreme Court
- Surveillance
- Surveillance Pricing
- Sweden
- Switzerland
- Taiwan
- Targeted Advertising
- Telecommunications
- Telemarketing
- Telephone Consumer Protection Act
- Tennessee
- Terry McAuliffe
- Texas
- Text Message
- Thailand
- Transparency
- Transportation Security Administration
- Trump Administration
- United Arab Emirates
- United Kingdom
- United States
- Unmanned Aircraft Systems
- Uruguay
- Utah
- Vermont
- Video Privacy Protection Act
- Video Surveillance
- Virginia
- Viviane Reding
- Washington
- Whistleblowing
- Wireless Network
- Wiretap
- ZIP Code