Low New document eu

EDPB adopts guidelines on anonymisation, web scraping for generative AI, and blockchain data processing

Original title: EDPB Guidelines on Anonymisation and Web Scraping for Generative AI; Final Version of Guidelines on Blockchain

The European Data Protection Board has adopted three sets of guidelines: on anonymisation (with clarity on what constitutes anonymous data following CJEU ruling C-413/23 P), on web scraping in generative AI contexts, and the final version on blockchain technology. The anonymisation guidelines establish that data is anonymous if it does not relate to an identified or identifiable person, and provide a practical framework for organisations to assess anonymisation success using contextual or simplified approaches. These guidelines help organisations navigate complex privacy issues while maintaining compliance with GDPR and protecting individuals' fundamental rights in emerging technology contexts.

What changed

  • EDPB publishes new guidelines on anonymisation that clarify the notion of anonymous data, incorporating CJEU jurisprudence including case C-413/23 P EDPS v SRB (4 September 2025), establishing that an individual is 'identified or identifiable' if they can be distinguished from others using means reasonably likely to be used in a way that enables differential treatment
  • Guidelines provide a practical two-part framework for assessing whether anonymisation is successful: a contextual approach evaluating differences in capabilities between potential identifiers, or a simplified approach that disregards such differences
  • EDPB adopts guidelines on web scraping specifically in the context of generative AI applications
  • EDPB adopts final version of guidelines on processing personal data through blockchain technologies
  • Guidelines emphasise that whether information relates to an individual depends on content, purpose, or effect, and such links may require further analysis and assessment from the relevant entity's perspective

Who is affected

Organisations processing personal data across the EU, particularly those developing or using generative AI systems, conducting web scraping activities, or implementing blockchain technologies for data processing. Data controllers and processors in all sectors subject to GDPR.

Language
EN

Frameworks

GDPR

Open the original source