Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

EDPB consults on draft anonymization and AI web scraping guidelines

Consultation closes 30 Oct

The European Data Protection Board (EDPB) is consulting on draft guidelines for anonymization and AI web scraping, aiming to clarify identifiable data under the EU General Data Protection Regulation (GDPR) and address modern technology impacts. These guidelines are open for public consultation through 30 Oct. The EDPB Secretariat Deputy Head Gwendal Le Grand discussed these drafts, which follow a joint opinion from the EDPB and the European Data Protection Supervisor on GDPR reforms.

Today's question

A data protection officer is reviewing their organization's AI development practices, specifically concerning the collection of public data for training models. Given recent regulatory discussions, which of the following best describes the primary challenge related to web scraping under GDPR?

  1. Ensuring that all scraped data is immediately deleted after model training is complete.
  2. Determining whether data obtained through web scraping constitutes 'identifiable data' and thus falls under GDPR's scope.
  3. Obtaining explicit consent from all individuals whose data is scraped from public websites.
  4. Implementing robust encryption for all scraped data, regardless of its sensitivity or identifiability.

Answer this question on the site

Worth knowing

  1. European Commission issues EU AI Act transparency guidelines

    The European Commission issued guidelines on July 20, 2026, to help providers and deployers of artificial intelligence (AI) systems comply with the transparency requirements of the EU Artificial Intelligence Act (AI Act). These guidelines clarify disclosure and labelling requirements for directly interactive AI systems, synthetic content, and deepfakes. They also specify that providers of AI systems intended to interact directly with individuals must design systems to inform users they are interacting with AI.

  2. ICO upholds FOI request against Home Office for failing to respond within statutory timeframe

    The ICO upheld a Freedom of Information (FOI) request against the Secretary of State for the Home Department (Home Office) on July 23, 2026, for failing to respond within 20 working days as specified under FOIA. The Home Office must now provide a substantive response within 30 calendar days of the decision notice. Failure to comply may result in the Commissioner making written certification to the High Court, potentially leading to contempt of court.

  3. California Legislature advances bill to curb CIPA pen register lawsuits

    On July 1, 2026, a California legislative committee advanced amendments to SB 690, aiming to eliminate private lawsuits asserting website-based "pen register" claims under the California Invasion of Privacy Act (CIPA). The bill seeks to shift enforcement exclusively to the California Attorney General, addressing a surge of lawsuits challenging website technologies. The committee described these lawsuits as a "poster child for abusive lawsuits" due to the staggering potential liability for businesses.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.