Hello,
the Digital Policy Alert added new events. Please find a brief overview below.
Best regards,
the DPA Team
July 8, 2026
| Outline Consultation Opened | Data Governance
On 8 July 2026, the European Data Protection Board (EDPB) opened the consultation on the draft guidelines on anonymisation until 30 October 2026. The draft guidelines apply to any entity anonymising personal data under the General Data Protection Regulation (GDPR), including anonymising controllers, recipients of anonymised data, and third parties who might access such data. The draft guidelines state that anonymity requires a negligible likelihood of identifying individuals using means reasonably likely to be used and introduce a technical assessment based on three criteria, no record isolation, no linkage and no inference. They clarify that the assessment depends on the perspective and capabilities of the relevant entity and address datasets containing both personal and anonymous data, which must generally be treated as personal data where the two cannot be separated. The draft guidelines also outline GDPR obligations for anonymisation processes, including the need for a lawful basis, transparency, documentation of the anonymisation approach and regular reassessment of re-identification risks over time.
July 7, 2026
| Outline Drafting | Data Governance
On 7 July 2026, the European Data Protection Board (EDPB) released the draft guidelines on anonymisation. The draft guidelines apply to any entity anonymising personal data under the General Data Protection Regulation (GDPR), including anonymising controllers, recipients of anonymised data, and third parties who might access such data. The draft guidelines state that anonymity requires a negligible likelihood of identifying individuals using means reasonably likely to be used and introduce a technical assessment based on three criteria, no record isolation, no linkage and no inference. They clarify that the assessment depends on the perspective and capabilities of the relevant entity and address datasets containing both personal and anonymous data, which must generally be treated as personal data where the two cannot be separated. The draft guidelines also outline GDPR obligations for anonymisation processes, including the need for a lawful basis, transparency, documentation of the anonymisation approach and regular reassessment of re-identification risks over time.
July 7, 2026
| Outline Drafting | Data Governance
On 7 July 2026, the European Data Protection Board (EDPB) released the draft guidelines 03/2026 on web scraping in the context of generative AI, clarifying the legal and technical implications under the General Data Protection Regulation (GDPR) of scraping personal data from the internet to train or fine-tune generative AI models. The draft guidelines clarify controller and processor roles depending on whether data is scraped directly, through a contracted party, or reused from an existing dataset. They state that consent is generally unlikely to be suitable for large-scale web scraping and provide guidance on transparency, data minimisation, legitimate interest assessments, and safeguards for processing personal data, including special categories of data. The guidelines emphasise the need for measures such as filtering unnecessary data, limiting collection, improving transparency, facilitating data subject rights, and preventing memorisation or extraction of personal data from AI models. They also address the residual collection of sensitive data during scraping, noting that such processing may only be permitted under strict conditions and with appropriate technical and organisational safeguards.