Data protection digest 3 – 17 Jul 2026: blockchain latest, ‘humanless’ resources & AI-repellent fashion
Summary
The European Data Protection Board (EDPB) issued significant guidelines in July 2026 on anonymisation, web scraping for generative AI, and blockchain technologies, providing a GDPR compliance framework for organizations. Concurrently, the Court of Justice of the European Union (CJEU) ruled that placing criminal conviction data online for payment does not constitute "journalistic purposes," enabling data subject remedies. In the US, 26 current and former Meta Platforms employees filed a lawsuit alleging AI-assisted systems, including "Metamate," disproportionately selected employees on protected leave for a May 2026 layoff affecting 10% of its workforce. French CNIL investigations highlighted risks of mobile app geolocation data re-identification, even when "anonymous." Further guidance from German BSI on AI trustworthiness and French CNIL on employer supervision and connected vehicle data use was released. Italian and Polish authorities issued fines totaling over €1.8 million to Wind Tre Spa, a hospital, and Character.AI for various GDPR violations, including security deficiencies and age verification failures. Privacy International also exposed transparency and fairness issues in AI recruitment platforms.
Key takeaway
For legal professionals advising on data protection, the recent EDPB guidelines and CJEU rulings underscore the critical need to review and update compliance frameworks for AI, blockchain, and web scraping. You must ensure internal systems, especially those involving automated decision-making like AI-assisted layoffs or recruitment, adhere strictly to GDPR principles of fairness, transparency, and non-discrimination. Proactively audit third-party data processors and address geolocation data re-identification risks to mitigate significant regulatory fines and legal challenges.
Key insights
Regulatory bodies are actively defining GDPR compliance for emerging technologies like AI and blockchain, while enforcement actions highlight persistent data protection challenges.
Principles
- GDPR compliance requires explicit frameworks for new tech.
- Automated systems must not penalize protected leaves.
- Geolocation data, even "anonymous," poses re-identification risks.
Method
The EDPB's blockchain guidelines provide a framework covering lawfulness, roles, Data Protection by Design, international transfers, retention, security, and data subject rights for planned processing activities.
In practice
- Organizations using blockchain must align processing with EDPB guidelines.
- Implement robust security for login credentials and digital certificates.
- Ensure AI recruitment systems comply with GDPR Art. 22 on automated decisions.
Topics
- GDPR Compliance
- EDPB Guidelines
- Artificial Intelligence
- Blockchain Technology
- Data Protection Fines
- Automated Decision-Making
Best for: CTO, VP of Engineering/Data, Director of AI/ML, Legal Professional, AI Ethicist, Policy Maker
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by TechGDPR.