惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hugging Face - Blog
Hugging Face - Blog
WordPress大学
WordPress大学
Microsoft Azure Blog
Microsoft Azure Blog
F
Fortinet All Blogs
B
Blog RSS Feed
Last Week in AI
Last Week in AI
The Cloudflare Blog
大猫的无限游戏
大猫的无限游戏
人人都是产品经理
人人都是产品经理
P
Proofpoint News Feed
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Microsoft Security Blog
Microsoft Security Blog
博客园 - 三生石上(FineUI控件)
Y
Y Combinator Blog
GbyAI
GbyAI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
小众软件
小众软件
雷峰网
雷峰网
C
Check Point Blog
阮一峰的网络日志
阮一峰的网络日志
博客园 - 叶小钗
博客园 - 司徒正美
U
Unit 42
量子位

EDPB News

Failure to respect the rights of individuals: The CNIL fined EXTIA 300 000 EUR Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE) Stakeholder event on guidelines on the interplay between data protection and competition law: overview of topics available Stakeholder event on guidelines on the interplay between data protection and competition law: save the date EDPB calls for legal basis for cross-regulatory information sharing EDPB requires Belgian DPA to handle the merits of NOYB cookie banner complaint EDPB and AMLA to develop Joint Guidelines on partnerships for information sharing One-Stop-Shop case digest on right to object and right to erasure updated Supporting GDPR consistency: EDPB launches dedicated form EDPB gets a new look: discover the new website and brand identity Coordinated Supervision Committee extends scope to include Eurodac Coordinated Supervision Committee extends scope to include Eurodac EDPB meets with EU Commissioner McGrath and adopts common data breach notification template EDPB meets with EU Commissioner McGrath and adopts common data breach notification template The Italian SA imposed a 40 000 EUR fine on a company for violating the confidentiality of a employee's email account after the end of his employment The Italian SA fined Poste Vita for data breach Imposition of fine on a telecommunications company for violations of data subject’s rights The Italian Supervisory Authority fined a company 120 000 EUR for tracking five employees who drove company cars Italian SA fines a company for post-sick leave questionnaires The Italian Supervisory Authority has fined Verisure Italia for unlawful processing of personal data for direct marketing purposes EDPB and EDPS support strengthening EU’s cybersecurity and easing compliance while protecting individuals’ personal data Europe Day 2026: let’s celebrate together Marking 10 years of the GDPR: the evolution of the European data protection landscape Stakeholder event on competition and data protection: save the date Stakeholder event on competition and data protection EDPB brings clarity to data processing for scientific research, speeds up the finalisation of the anonymisation guidelines and approves first European data protection seal as a tool for transfers Enhancing compliance and consistency: EDPB adopts DPIA template EDPB annual report 2025: supporting stakeholders through guidance and dialogue EDPB conference on cross-regulatory cooperation: what we learned
EDPB sheds light on anonymisation and web scraping for ge...
EDPB · 2026-07-08 · via EDPB News

Brussels, 8 July– During its latest plenary, the EDPB has adopted guidelines on anonymisation and guidelines on web scraping in the context of generative AI. In addition, the Board has adopted the final version of its guidelines on the processing of personal data through blockchain technologies.

Understanding anonymous data

The new EDPB guidelines bring clarity to the notion of anonymous data, taking also into account the ruling of the Court of Justice of the EU in the case C-413/23 P EDPS v SRB of 4 September 2025 and other CJEU jurisprudence.

The guidelines mark a significant milestone in clarifying the notion of anonymous data, establishing clear standards that facilitate the use of data while protecting individuals' fundamental rights.

In developing these guidelines, we incorporated valuable input from our stakeholder event, showing, once more, our strong commitment to collaborative dialogue as outlined in the EDPB Helsinki statement.

EDPB Chair, Anu Talus

Data is anonymous if it does not relate to an identified or identifiable natural person. Whether this is the case may vary from one entity to another.

Information can relate to an individual because of its content, purpose, or effect. The existence of such a link may not be immediately obvious and could require further analysis.

An individual is considered 'identified or identifiable' if they can be distinguished from others in a specific context using means reasonably likely to be used in a way that makes it possible to treat them differently. Whether the means are reasonably likely to be used will depend on the relevant entity’s perspective and should be assessed in light of all objective factors.

The guidelines also provide a practical framework for organisations to determine if anonymisation is successful. The framework can be applied in two ways: either by assessing differences in capabilities between those who might identify the individual (‘contextual approach’) or for simplicity’s sake by not taking such differences into account (‘simplified approach’), if a controller chooses to do so. The contextual approach reflects the full nuances of the legal standard for anonymisation. The simplified approach can go beyond the legal standard and may lead an anonymising controller to treat data as though it is not anonymous even if it would actually be so for some relevant entities, but this approach can be more convenient, and provide greater confidence that data is actually anonymous.

The framework uses 3 criteria to test if data is anonymous: 1) no record isolation, 2) no linkage, and 3) no inference. If all 3 criteria are met, the data can be safely considered anonymous. If any of these criteria are not satisfied, further analysis should be done to determine if the data may be considered anonymous.

The guidelines will be subject to public consultation until 30 October 2026, providing stakeholders with the opportunity to comment and provide feedback.

Clarifying data protection implications of web scraping for AI development

Web scraping is a large-scale automated data extraction process that often operates without individuals being aware, and which may pose significant risks to the protection of their personal data. In its guidelines on web scraping in the context of generative AI*, the Board clarifies various aspects of the GDPR compliance of web scraping, including the legal basis for such activities and the conditions under which special categories of data can be processed in this context.

The GDPR applies to web scraping when it includes personal data processing operations, such as collection, storage, organisation and retrieval.

When relying on web scraping, particular attention needs to be paid to the purpose limitation principle, and to the transparency principle. However, depending on how the data processing is precisely designed, the controller might not have to inform individuals personally if this proves to be impossible or require excessive effort.

The EDPB recommends scraping data only from reliable sources, recording the timestamp, and validating the data before using them in AI training to ensure compliance with the accuracy principle. The guidelines also advise on measures the controller should implement to comply with the data minimisation principle.

Building on the EDPB Opinion on AI models, the guidelines provide further clarifications and examples on the use of the legitimate interest legal basis in the specific context of web scraping for AI training.

Finally, the EDPB recalls that processing special categories of personal data is in principle prohibited. If web scraping involves such data, both a lawful basis under Art. 6 of GDPR and an exception under Art. 9(2) of the GDPR are required. The EDPB suggests that the Court ruling in GC & Others (C-136/17) may be relevant for incidental or residual collection of special categories of personal data, provided the controller acts within the ”framework of their responsibilities, powers, and capabilities” and implements appropriate technical and organisational measures to prevent the collection and dissemination of such data. The Board emphasises that there is no general exemption from the requirements of Art. 9 GDPR and each case must be assessed individually to determine whether the Court’s reasoning applies.

The guidelines will be subject to public consultation until 30 October 2026, providing stakeholders with the opportunity to comment and provide feedback

Blockchains guidelines finalised after public consultation

Following public consultation, the EDPB has adopted the final version of its guidelines on blockchain technologies. The guidelines help organisations using blockchain technologies to comply with the GDPR. The EDPB explains how blockchains work, assessing the different possible architectures and their implications for the processing of personal data.

In line with the Helsinki statement’s objective to strengthen the dialogue with stakeholders, the Board has also released a report on the outcome of the dedicated public consultation, as well as a track changes version of the guidelines.

Note to editors: 
*Generative AI is a technology aiming to create new content by learning patterns from existing data. It uses specialised machine learning models designed to produce a wide and general variety of outputs such as text, image or audio.