PrivacySignal
GDPR / Intl

EDPB discusses focuses in draft anonymization, AI web scraping guidelines

IAPP · · International · GDPR & International

The European Data Protection Board is developing draft guidelines that address both anonymization standards and the use of AI web scraping, signaling a move to clarify how these practices align with EU data protection rules. The guidelines are still in draft form and reflect the EDPB's current enforcement and policy priorities.

Why this matters: Two issues in one set of guidelines, and both matter a lot. Anonymization rules determine whether companies can use your data freely or not — get the standard wrong and 'anonymous' data is just personal data with a fig leaf. Web scraping for AI training is how most large models were built, often without asking anyone. If the EDPB sets real limits here, it affects every AI company pulling data from the open web. These are not abstract rules. They decide whose data gets used, for what, and whether anyone is accountable for it.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

GDPR / Intl
I Inside Privacy · · International

State Comprehensive Privacy Law Round-Up: Several States Amend Their Privacy Statutes

Several U.S. states have recently moved to amend their existing comprehensive privacy statutes, signaling continued legislative activity at the state level as jurisdictions refine and update rules governing how personal data is collected and used.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#state-privacy#privacy Read original →
GDPR / Intl
S StateScoop · · International

Experts warn AI-driven data inferencing is outpacing state privacy protections

Privacy experts are warning that AI systems can now infer sensitive personal information from seemingly innocuous data at a speed and scale that existing state privacy laws were not designed to address. The gap between what AI can deduce and what regulations currently protect is widening.

Who should care: Lawyers · Privacy officers · Compliance · General readers · AI governance · Policy

#state-privacy#ai#privacy Read original →
GDPR / Intl
EDPB · · EU

EDPB calls for legal basis for cross-regulatory information sharing

At a July 2026 meeting in Dublin, the European Data Protection Board called for an explicit legal foundation governing how data protection authorities share information with regulators outside their jurisdiction. The EDPB also discussed deepening cooperation among DPAs to strengthen consistent GDPR enforcement across the EU.

Who should care: Lawyers · Privacy officers · AI governance · Compliance · General readers · Policy

#gdpr#regulation#privacy Read original →
GDPR / Intl
Just Security · · US Federal

To Audition for the Role of Attorney General, Blanche Is Prosecuting to Please

Legal analysts at Just Security argue that Todd Blanche, Trump's nominee for Attorney General, has pursued prosecutions of figures like James Comey in ways that appear designed to satisfy political preferences rather than independent legal judgment. Critics describe the pattern as prosecutorial sycophancy aimed at securing the top law enforcement post.

Who should care: Lawyers · Privacy officers · Compliance

#state-privacy Read original →
GDPR / Intl
IAPP · · International

Thought for the week: Web scraping for generative AI is subject to the GDPR

A commentary from the IAPP argues that web scraping used to build generative AI training datasets falls within the scope of GDPR, meaning the collection and processing of personal data found online is not exempt simply because it occurs at scale or at the infrastructure level.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy