惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 三生石上(FineUI控件)
月光博客
月光博客
S
SegmentFault 最新的问题
有赞技术团队
有赞技术团队
Stack Overflow Blog
Stack Overflow Blog
Engineering at Meta
Engineering at Meta
T
The Blog of Author Tim Ferriss
The GitHub Blog
The GitHub Blog
小众软件
小众软件
Hugging Face - Blog
Hugging Face - Blog
IT之家
IT之家
宝玉的分享
宝玉的分享
A
About on SuperTechFans
Vercel News
Vercel News
P
Proofpoint News Feed
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 【当耐特】
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
Visual Studio Blog
Jina AI
Jina AI
Y
Y Combinator Blog
T
Tailwind CSS Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Last Week in AI
Last Week in AI

Privacy & Cybersecurity Law Blog

EU Cyber Resilience Act Reporting Obligations Take Effect for Manufacturers Delaware Expands State Privacy Law Dutch DPA Fines Uber Over Automated Decisions Affecting Drivers European Commission Designates ChatGPT, Reddit, and Roblox Under the Digital Services Act China Issues New Rules on Cyberspace Security Inspection Court Approves Meta Settlement With 29 States Over Alleged Harms to Children and Teens FTC Proposes Enforcement Policy Statement on Personalized Pricing New Jersey Enacts the Kids Code Act with Privacy-by-Default and Safety-by-Design Obligations White House Memorandum Establishes Framework for Government-Directed Private-Sector Cyber Operations FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices CalPrivacy Settles with Two Data Brokers over Registration Failures and Privacy Violations New York Attorney General Releases Final Rules for SAFE for Kids Act China Publishes Official Q&A on Administrative Policies for Cross-Border Data Transfers Hawaii Enacts AI Companion Disclosure and Safety Law EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence CNIL Issues FAQs on Recommendation for Tracking Pixels in Emails European Commission Issues Guidance on the Cyber Resilience Act European Commission Issues EU AI Act Transparency Guidelines EU Digital Omnibus on AI Enters Into Force Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays EDPB Opens Public Consultation on New Personal Data Breach Notification Template European Commission Advances New Proposal to Expand Cloud Capacity and AI Infrastructure
EDPB Adopts Guidelines on Anonymous Data, Web Scraping, a...
2026-08-17 · via Privacy & Cybersecurity Law Blog

On July 8, 2026, the European Data Protection Board (“EDPB”) adopted draft guidelines on anonymization and draft guidelines on web scraping in the context of generative artificial intelligence (“AI”), and finalized its guidelines on the processing of personal data through blockchain technologies. Together, these measures further clarify how the EU General Data Protection Regulation (“GDPR”) applies in several fast-developing technical areas.

Anonymization

The draft anonymization guidelines aim to clarify when data may be treated as anonymous under EU data protection law. The EDPB reiterates that, under the GDPR, data is anonymous only if it does not relate to an identified or identifiable natural person. The guidelines also note that information may relate to a person by its content, purpose or effect, even where that connection is not immediately obvious.

The guidelines further explain that a person is identifiable if they can be distinguished from others using means reasonably likely to be used. Those means should be interpreted broadly and may include information or capabilities available through a third party. Whether such means are reasonably likely to be used should be assessed based on objective factors and from the perspective of the relevant entity. The guidelines also reflect recent Court of Justice of the European Union (“CJEU”) case law, including the September 4, 2025 judgment in C-413/23 P EDPS v SRB, which clarified the scope of personal data in the context of a transfer of pseudonymized data to third parties.

To help organizations assess whether anonymization is effective, the draft anonymization guidelines set out a practical framework based on two possible approaches: (1) a “contextual approach,” which considers the capabilities of parties that might identify individuals; and (2) a more conservative “simplified approach,” which does not. It also introduces three key criteria for testing anonymity: “no record isolation” (i.e., the data does not contain a unique combination of attribute values relating to a single individual), “no linkage” (i.e., the data does not contain an individual’s record that could be linked to another record, using means reasonably likely to be used, relating to that same individual in a different dataset), “no linkage” (i.e., the data does not contain an individual’s record that could be linked to another record, using means reasonably likely to be used, relating to that same individual in a different dataset), and “no inference” (i.e., no specific and meaningful inference can be drawn from the data). If all three criteria are met, the data may be regarded as anonymous; if not, additional assessment is required. Finally, Annex 1 of the draft anonymization guidelines includes a flow chart as a support tool to help organizations decide whether a simplified or contextual approach should be taken, and to determine whether data may be considered anonymous or personal.

Web Scraping in the Context of Generative AI

The draft guidelines on web scraping for generative AI confirm that the GDPR applies where scraping involves personal data and highlights the importance of compliance with core GDPR principles. The guidance recommends steps such as scraping from reliable sources, recording collection dates and validating data before using it for AI training. The draft guidelines also address legal basis and note that private entities commonly rely on legitimate interests in this context but must satisfy the balancing test of Article 6.1(f) of the GDPR and implement safeguards as part of this balancing test. The guidance includes practical examples to help organizations assess the balancing test under the legitimate interests basis. In addition, with regard to special categories, controllers must identify both a lawful basis under Article 6 of the GDPR and an applicable condition under Article 9(2) of the GDPR. The EDPB notes that existing CJEU case law may be relevant in limited cases involving incidental and residual collection but stresses that there is no general exemption and that each case must be assessed individually.

Processing of Personal Data Through Blockchain Technologies

The blockchain guidance is intended to help organizations using blockchain technologies evaluate GDPR compliance issues, including how different blockchain architectures may affect the processing of personal data and create risks for data subjects. The guidelines stress the importance of implementing data protection by default and by design measures to give effect to GDPR principles, facilitate the effective exercise of data subjects’ rights and ensure that appropriate technical and organizational measures are in place. They also make clear that storing personal data on a blockchain should be avoided where doing so would conflict with data protection principles. Where such storage cannot be avoided, organizations should consider advanced techniques, appropriate organizational measures and robust data protection policies. The guidelines also examine how the technical aspects of blockchain interact with core GDPR principles. In particular, the guidelines highlight the importance of carrying out a data protection impact assessment before implementing any processing activity involving blockchain technology.

Public Consultation Period

The draft guidelines on anonymization and the draft guidelines on web scraping for generative AI are both open for public consultation until October 30, 2026.

Read the EDPB press release here. See the draft anonymization guidelines here. See the draft web scraping guidelines here. See the blockchain guidelines here.