Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

30 October 2026: EDPB draft guidelines on AI web scraping close for consultation

30 October 2026

On 30 October 2026, the consultation period closes for the EDPB Guidelines 03/2026 on web scraping in the context of generative AI. These guidelines will bind developers and deployers training models on scraped web data, and publishers whose sites are scraped. Organisations must analyse their data processing operations against the draft guidelines and submit feedback before the deadline.

The EDPB Guidelines 03/2026 address the application of the GDPR to web scraping activities, particularly when data is used for training generative AI models. Developers and deployers of AI models must establish a lawful basis for processing personal data obtained through web scraping, considering the principles of purpose limitation and data minimisation. This includes conducting thorough DPIAs where high risk processing is identified, and ensuring transparency towards data subjects regarding the collection and use of their data.

Publishers of websites, as data controllers, need to understand their rights and obligations when their sites are scraped. The guidelines will clarify how to assess the legality of scraping activities and what measures can be taken to protect personal data. Both parties should review the draft guidelines to understand the EDPB's position on legitimate interests, consent, and the responsibilities of controllers and processors in the web scraping ecosystem. Evidence of this preparatory work, such as internal legal analyses, updated records of processing activities, and impact assessments, would be expected by supervisory authorities.

Dates like this one are missed far more often than obligations are misread, because the work that has to precede them is owned by teams who never see the deadline.

EDPB Guidelines 03/2026 on web scraping in the context of generative AI

Who this binds
Developers and deployers training models on scraped web data, and publishers whose sites are scraped
What changed
Nothing changed today. What is fixed is the date: 30 October 2026, when the consultation window on the EDPB draft covering scraping for AI training closes
What to check
If you scrape or license scraped data, map your lawful basis and transparency position against the draft and respond before it closes
What this does not mean
This is a date in the diary, not a new obligation published today. Nothing in force changed this morning.

Send this to your team

The EDPB's draft guidelines on web scraping for generative AI close for consultation on 30 October 2026, impacting developers, deployers, and publishers of web data.

Today's question

A US based credit repair company is found to be making unsubstantiated claims about its ability to remove negative items from consumer credit reports, leading to significant financial losses for its customers. Which US authority is most likely to take enforcement action against this company for these deceptive practices?

  1. The Federal Communications Commission (FCC)
  2. The Securities and Exchange Commission (SEC)
  3. The Federal Trade Commission (FTC)
  4. The Consumer Financial Protection Bureau (CFPB)

Answer this question on the site

Worth knowing

  1. Autoriteit Persoonsgegevens consults on DPIA exceptions list

    The Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) has prepared a list of processing activities for which a Data Protection Impact Assessment (DPIA) is not required and is seeking public input. This consultation aims to refine the list to better align with practical application, particularly for SMEs and independent entrepreneurs.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.