EDPB adopts final guidelines on anonymisation, web scraping for generative AI, and blockchain personal data processing
At its July 2026 plenary, the EDPB adopted three sets of guidelines: on anonymisation, on web scraping in the context of generative AI, and the final version of guidelines on blockchain. The anonymisation guidelines clarify the legal notion of anonymous data under GDPR, incorporating the CJEU ruling in C-413/23 P EDPS v SRB (4 September 2025), and establish that whether data is anonymous may differ across entities depending on content, purpose, or effect. Compliance teams must reassess anonymisation practices against the new standards and review any web scraping or generative AI workflows for alignment with the dedicated guidelines.
What changed
- New EDPB guidelines on anonymisation adopted, clarifying when data qualifies as anonymous under GDPR and integrating CJEU case law (C-413/23 P EDPS v SRB, 4 September 2025).
- Anonymisation assessment is entity-specific: the same dataset may be anonymous for one controller but not for another, depending on means reasonably available.
- Data 'relates' to an individual if there is a link through content, purpose, or effect — even where that link is not immediately obvious.
- New EDPB guidelines on web scraping in the context of generative AI adopted, addressing GDPR obligations when scraping publicly available personal data for AI training.
- Final version of EDPB guidelines on processing personal data through blockchain technologies adopted (v2, superseding earlier draft).
Who is affected
All EU/EEA controllers and processors subject to GDPR, particularly those building or deploying generative AI systems, conducting web scraping, publishing or anonymising datasets, or using blockchain for personal data processing. No sector or size restriction stated in the source.
- Effective
- 2026-07-08
- Action
- Action required
- Language
- EN