PrivacySignal
GDPR / Intl

EDPB sheds light on anonymisation and web scraping for generative AI and adopts final version of guidelines on blockchain

EDPB · · EU · GDPR & International

The European Data Protection Board has adopted new guidelines on anonymisation, web scraping for generative AI, and blockchain data processing. The anonymisation guidance incorporates recent Court of Justice of the EU case law to clarify when data can genuinely be considered anonymous under European privacy law.

Why this matters: These guidelines matter because 'anonymous data' is the escape hatch that lets companies avoid GDPR entirely. If data is truly anonymous, almost none of the rules apply. The EDPB is now tightening what that actually means, which will affect every AI company scraping the web and claiming the data is clean to use. The web scraping guidelines are just as consequential. Generative AI runs on scraped data. Whether that data contains personal information, and who is responsible for it, is a live fight between regulators and the AI industry. Clearer rules put companies on notice.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

GDPR / Intl
C Computing UK · · International

ICO: Police facial recognition needs stronger oversight

The UK's Information Commissioner's Office has called for stronger oversight of how police use facial recognition technology, signaling concern that current controls are insufficient to govern the practice.

Who should care: Lawyers · Privacy officers · AI governance · Cybersecurity · General readers · Policy

#gdpr#surveillance#privacy Read original →
GDPR / Intl
C Computer Weekly · · International

ICO police facial recognition audits reveal ‘mixed’ bag

The UK's Information Commissioner's Office conducted audits of police use of facial recognition technology and found inconsistent results across the forces reviewed. The findings suggest compliance and practice vary significantly, with no uniform standard being met.

Who should care: Lawyers · Privacy officers · AI governance · Cybersecurity · General readers · Policy

#gdpr#surveillance#privacy Read original →
GDPR / Intl
B Biometric Update · · International

UK ICO finds police facial recognition use mostly compliant with data regulations

The UK's Information Commissioner's Office reviewed police use of facial recognition technology and found it to be largely compliant with data protection law. The assessment stops short of a full endorsement but does not identify systemic violations.

Who should care: Lawyers · Privacy officers · AI governance · Compliance · Cybersecurity · General readers · Policy

#gdpr#regulation#surveillance#privacy Read original →
GDPR / Intl
I Infosecurity Magazine · · International

ICO Urges Police to Improve Data Governance in Facial Recognition Roll

The UK's Information Commissioner's Office has called on police forces to strengthen how they manage data as facial recognition technology is deployed more widely. The ICO's intervention signals concerns about compliance and oversight during the rollout.

Who should care: Lawyers · Privacy officers · AI governance · Cybersecurity · General readers · Policy

#gdpr#surveillance#privacy Read original →
GDPR / Intl
K keyt.com · · International

State Privacy Regulator Issues Second Decision Penalizing Out-of-State Data Broker

A state privacy regulator has issued its second enforcement decision against an out-of-state data broker, signaling continued regulatory action beyond its own borders. The decision adds to a pattern of state-level agencies asserting jurisdiction over companies that collect and sell resident data regardless of where those companies are based.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#state-privacy#regulation#privacy Read original →