PrivacySignal
GDPR / Intl

EDPB sheds light on anonymisation and web scraping for generative AI and adopts final version of guidelines on blockchain

EDPB · · EU · GDPR & International

The European Data Protection Board has adopted new guidelines on anonymisation, web scraping for generative AI, and blockchain data processing. The anonymisation guidance incorporates recent Court of Justice of the EU case law to clarify when data can genuinely be considered anonymous under European privacy law.

Why this matters: These guidelines matter because 'anonymous data' is the escape hatch that lets companies avoid GDPR entirely. If data is truly anonymous, almost none of the rules apply. The EDPB is now tightening what that actually means, which will affect every AI company scraping the web and claiming the data is clean to use. The web scraping guidelines are just as consequential. Generative AI runs on scraped data. Whether that data contains personal information, and who is responsible for it, is a live fight between regulators and the AI industry. Clearer rules put companies on notice.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Deep Signal · Part I of III

The Algorithm Said So

Federal rulemakers are deciding what to do when artificial intelligence produces the kind of conclusion that once required an expert. They disagree about how to regulate it. They also disagree about whether the problem has arrived.

· 10 min read Read →

Related stories

GDPR / Intl
EPIC · · US Federal

EPIC Offers Comments on Vermont Age-Appropriate Design Code Rulemaking

EPIC submitted formal comments to the Vermont Attorney General on two proposed rules designed to implement Vermont's Age-Appropriate Design Code, which sets design and data protection standards for online products likely to be accessed by children.

Who should care: Lawyers · Privacy officers · Compliance

#state-privacy#regulation Read original →
GDPR / Intl
W WIS News 10 · · International

SC Attorney General Alan Wilson presses Flock Safety for answers on AI use, data privacy

South Carolina Attorney General Alan Wilson has contacted Flock Safety, a license plate reader and surveillance technology company, seeking information about how the company uses AI and handles personal data collected through its systems.

Who should care: Lawyers · Privacy officers · Compliance · General readers · AI governance · Policy

#state-privacy#ai#privacy Read original →
GDPR / Intl
Information Commissioner's Office · · UK

ICO welcomes transition to new Information Commission and marks new chapter with Manchester head office opening

The UK's Information Commissioner's Office is transitioning to a newly structured Information Commission and has opened a head office in Manchester, marking an institutional shift in how the country's data protection authority is organized.

Who should care: Lawyers · Privacy officers · AI governance

GDPR / Intl
ICO · · UK

ICO head office address change

The UK's Information Commissioner's Office has announced a change to its head office address.

Who should care: Lawyers · Privacy officers · AI governance

GDPR / Intl
O Ogletree · · International

Deployment of AI Recruitment Tools in the EU: Employer Obligations Under GDPR and EU AI Act

Employers in the EU using AI-powered recruitment tools face obligations under both GDPR and the EU AI Act, which together impose rules on how candidate data is collected, processed, and used in automated hiring decisions.

Who should care: Lawyers · Privacy officers · AI governance · Administrators · General readers · Policy

#gdpr#ai-governance#ai Read original →