The EDPS highlights anonymization and harvesting for generative AI and adopts the final version of the guidelines on blockchain.
Summary
On July 7, 2026, the European Data Protection Board (EDPB) adopted new guidelines clarifying anonymisation and web scraping for generative AI, alongside finalizing its guidelines on blockchain technologies. The anonymisation guidelines define anonymous data, considering CJEU judgments like C-413/23 P, EDPB/CRU, of September 4, 2025. They offer a practical framework with "contextual" and "simplified" approaches, using three criteria: no individualisation, no correlation, and no inference, for successful anonymisation. Separately, the scraping guidelines address GDPR compliance for large-scale data extraction in AI development, detailing legal bases, conditions for processing special categories of data under Article 6 and Article 9(2), and principles like purpose limitation, transparency, accuracy, and data minimisation. Both the anonymisation and scraping guidelines are open for public consultation until October 30, 2026. The finalized blockchain guidelines assist organizations in GDPR compliance for data processing using distributed ledger technologies.
Key takeaway
For legal professionals and AI developers navigating data privacy, these EDPB guidelines are crucial. If you are involved in generative AI development or data processing, you must review the new anonymisation framework and web scraping rules to ensure GDPR compliance. Pay close attention to legal bases for scraping and strict conditions for handling special categories of data. Additionally, organizations using blockchain should consult the finalized guidelines to align their data processing architectures with GDPR requirements, mitigating potential legal risks.
Key insights
EDPB guidelines clarify GDPR compliance for anonymisation, web scraping in AI, and blockchain data processing.
Principles
- Anonymous data must not relate to an identifiable person.
- Scraping for AI must adhere to GDPR principles.
- Processing special categories of data is generally prohibited.
Method
The anonymisation framework assesses differences in identification capabilities ("contextual approach") or simplifies by ignoring them ("simplified approach"), then applies 3 criteria.
In practice
- Apply the 3 anonymisation criteria for data safety.
- Extract data only from reliable sources for AI training.
- Implement technical measures to prevent special data collection.
Topics
- GDPR Compliance
- Data Anonymisation
- Web Scraping
- Generative AI
- Blockchain Technology
- European Data Protection Board
Best for: CTO, VP of Engineering/Data, Director of AI/ML, Legal Professional, Policy Maker, AI Ethicist
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by RSS - Actualités CNIL.