
We are here to share clear and practical insights on the latest developments in data protection, AI, and tech regulation, helping you stay informed and compliant in this ever-changing digital landscape.
Whether you manage compliance or simply want to stay safer and better informed online, this newsletter is for you.
As always, our Data Protection Team is here to help. If you would like tailored advice or to discuss a specific issue, please contact us using the details at the end of this page.
Anonymous? It's Complicated. What the EDPB's New Guidelines Really Say
On 7 July 2026 the European Data Protection Board (EDPB) has published their Guidelines 02/2026 on Anonymisation, marking the first major update to EU anonymisation guidance in more than a decade. Currently open for public consultation until 30 October 2026, the Guidelines appear to be a landmark in the field of data anonymization.
🧩Key takeaway
- Deleting names is not enough.
This is probably the biggest wake-up call in the guidelines: removing direct identifiers like names, emails, or ID numbers doesn't make the privacy risk disappear. People can still be re-identified through combinations of seemingly harmless details, publicly available information, or, increasingly, AI-driven inference techniques that are getting better at connecting dots humans would never spot.
- Anonymity isn't a fixed label.
It depends on who's holding the data. The EDPB confirms that whether a dataset counts as "anonymous" hinges on who is processing it, and whether they have realistic means to re-identify people. This follows recent CJEU case law, and it has a surprising consequence: the exact same dataset could be genuinely anonymous in one organization’s hands, and still personal data in another's.
- There's now a clear three-part test.
In order for an anonymised record not to be considered personal data, it must pass three clear steps: individuals cannot be identified within it, the records cannot be linked to other datasets that allow identification, and no meaningful information can be inferred about a person from the record under assessment. Miss even one of these, and you cannot simply assume you are in safe, anonymous territory.
❔Why is it important?
The new guidelines significantly raise the bar for organisations relying on anonymised data. For businesses a robust, documented assessment is now essential and misclassifying personal data as anonymous risks real regulatory scrutiny. At the same time, data that genuinely meets the EDPB's criteria falls outside the GDPR entirely, opening the door to broader data sharing, innovation and AI development with far fewer compliance obligations. With the public consultation open until 30 October 2026, now is the time to revisit anonymisation practices, document assessments, and make sure existing processes align with the EDPB's new expectations.
EDPB Issues New Guidelines on Web Scraping for AI Development
On 7 July 2026, the European Data Protection Board (EDPB) adopted their Guidelines 03/2026 on Web Scraping in the Context of Generative AI, introducing the first comprehensive GDPR compliance framework specifically addressing the large-scale collection of internet data used to train generative AI models (“data scraping”). Currently open for public consultation until 30 October 2026, the guidelines apply to organisations that collect web data for AI development, as well as those that purchase or reuse datasets created through web scraping.
🧩Key takeaway
- Public doesn't mean fair game.
The moment scraped data includes anything that identifies a person, a name, a photo, a contact detail, even indirectly, the GDPR applies from the moment you collect it right through to cleaning, structuring and storing it. The fact that data sits openly on the internet does not mean it's freely reusable. A valid legal basis and compliance with GDPR principles is still needed.
- Know exactly what role you're playing.
Scraper, AI developer, data broker and everyone in the pipeline needs to work out whether they're a processor, a joint controller, or a separate controller, depending on who actually decides what gets collected and how. And here's the catch: buying a pre-scraped dataset doesn't let you off the hook. If you're using someone else's scraped data, you inherit responsibility for making sure it was collected properly in the first place.
- You still owe people transparency… one way or another.
Individually notifying every scraped person is often impossible at scale, and the guidelines acknowledge that. But relying on this exception isn't a free pass: organisations need a genuinely justified reason, plus a clear public privacy notice covering what data was collected, where from, when, and how people can exercise their rights.
- Sensitive data is a red line, with one narrow exception.
As a general rule, Article 9 GDPR prohibits the processing of special categories of personal data, such as information revealing racial or ethnic origin, health, political opinions, or sexual orientation. Scraping this type of data is only lawful if you can rely on both a valid legal basis under Article 6 and an applicable exception under Article 9. There's a narrow door for “genuinely incidental collection” (special categories of personal data that the controller did not intend to collect and that bypassed the existing organisational and technical controls), but it's not a blanket safe harbour, every case stands on its own.
❔Why is it important?
Generative AI relies on massive web-scraped datasets, and the EDPB's new guidelines set clear, enforceable rules on how that collection must happen under EU law. For AI developers, compliance now has to based on Legitimate interest assessments and data source documentation must exist before scraping begins, with privacy built into the technical architecture itself, since personal data is notoriously hard to remove once a model is trained.
For individuals, the guidelines strengthen rights over publicly posted content and push back against AI scraping's "chilling effect" on free expression, requiring genuine transparency and opt-out options. The public consultation remains open until 30 October 2026.
EU AI Act: Transparency Obligations Take Effect on 2 August, Is Your Organisation Ready?
From 2 August 2026, providers and deployers of AI systems will need to comply with transparency obligations under Article 50 of the AI Act. These obligations apply instantly to all AI systems within scope, regardless of when the system was placed on the market or put into service, meaning existing AI systems must comply from day one.
On 20 July, the European Commission adopted the final version of its “Guidelines on transparency obligations for providers and deployers of certain AI systems”. With the clock ticking, here's what organisations need to know.
🧩Key takeaway
- It's not just about high-risk AI, it's about specific use cases.
Article 50 obligations apply to all AI systems used in four specific situations, not just to high-risk systems. These cover direct interaction with individuals, AI-generated content, emotion recognition, biometric categorisation, and deep fakes or AI-generated text on public-interest matters. Any organisation deploying a chatbot, generating synthetic media, or publishing AI-written content touching EU users needs to check whether it falls within scope, regardless of how "risky" the system seems.
- Chatbots and synthetic content both carry disclosure duties.
Providers of AI systems intended to interact directly with people, chatbots, voice assistants, conversational agents, must design them to inform users of the relevant information while dealing with AI, no later than the first interaction, unless this is obvious from the point of view of a natural person who is reasonably well-informed. Separately, providers of systems generating synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as AI-generated, with technical marking standards still being finalised through the Code of Practice.
- Open-source and non-EU providers are not off the hook.
Two common assumptions don't hold up: AI systems released under free and open-source licences are not exempted, providers and deployers of open-source systems within scope of Article 50 must still comply. And geography offers no shelter either, since the duties reach businesses wherever they are established, so a provider or deployer serving EU users is caught regardless of location.
❔Why is it important?
The financial exposure here is significant and immediate. Non-compliance with Article 50 can lead to fines of up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. Because the obligations apply from day one with no phase-in period for existing systems, there's no grace period to rely on. Organisations that haven't yet mapped their AI systems against the four Article 50 categories are running out of runway. With enforcement powers activating alongside the obligations themselves, August 2 is the day.
Contact
Need advice on Data Protection, AI, or Whistleblowing compliance?
Our Data Protection team is here to support you. Contact us today to discuss your needs and explore how we can assist you: Dara Kelly, Head of Advisory, or Pasquale Esposito, Data Protection Officer.