Skip to content
EDPB Draft Guidelines on AI Web Scraping & Anonymization
Nemko DigitalAug 19, 2026, 10:30:01 AM3 min read

EDPB Draft Guidelines: Navigating AI Web Scraping and Data Anonymization

The new guidelines, open for public consultation through October 30, respond to the growing intersection of privacy and artificial intelligence. They follow a joint opinion from the EDPB and the European Data Protection Supervisor regarding potential GDPR reforms under the European Commission's Digital Omnibus, emphasizing the critical need for organizations to understand and adapt to evolving definitions of personal data.

 

Assessing Anonymization in a Modern Context

The EDPB’s draft anonymization guidelines mark a significant update from its 2014 guidance, addressing over a decade of advancements in data use and privacy-enhancing technologies. A central focus of the updated framework is the concept of reidentification within specific contexts.

Rather than viewing anonymity in absolute terms, the EDPB draft guidelines emphasize evaluating the likelihood of an individual being identified by a specific entity. This means anonymity must be assessed from the perspective of any party for whom the data is intended.

To facilitate this, the EDPB outlines both contextual and simplified approaches for organizations. The simplified approach allows data controllers to voluntarily shift the risk by treating anonymous data as personal data if they overestimate the likelihood of reidentification. While this may lead to unnecessary classification of information as personal data, it provides greater confidence in compliance efforts, which can be further refined using the contextualized approach. Organizations should also distinguish anonymization from pseudonymization, as pseudonymized information may still fall within GDPR provisions.

For companies managing complex data ecosystems, aligning these practices with broader global AI regulations is essential for maintaining robust data governance.

 

AI Web Scraping and Data Minimization

In parallel with its anonymization efforts, the EDPB has issued guidance on AI web scraping, complementing its joint work with the European AI Office on compliance with the GDPR and the EU AI Act.

 

The guidelines stress that organizations should only collect data strictly necessary for AI training and other specific purposes. Data controllers must adhere to the GDPR's principles of data minimization and purpose limitation when gathering and storing consumer information. Transparency is also a critical requirement, particularly when personal data is sourced from publicly available platforms. Organizations should document their legal bases for such processing activities and consider the implications of the Digital Services Act and Article 5 Digital Markets Act where applicable.

Given the complexities of web scraping, the EDPB acknowledges the difficulty of ensuring that special categories of data are not inadvertently collected. Drawing on reasoning from the CJEU's Case C-136/17 judgment, the incidental collection of sensitive data for AI training may not be considered unlawful if controllers implement stringent measures to prevent its dissemination. This is especially important for data covered by Article 9, including information about patients, health data, and data used for clinical trials or scientific research purposes.

To mitigate risks associated with personal data processing, the EDPB recommends that organizations consider alternative methods, such as utilizing synthetic data for training AI models. Other suggested strategies include applying syntax-based filtering and replacing real data with synthetic alternatives where feasible. These safeguards can support appropriate conditions for processing and help reduce GDPR implications, including risks related to automated decision-making and cross-border transfers to third countries.

 

Strategic Compliance for Tech Professionals

As regulatory frameworks continue to evolve, proactive engagement with these guidelines is crucial. The EDPB’s commitment to stakeholder consultation highlights the importance of industry feedback in shaping final regulations and future enforcement by data protection supervisory authorities.

For organizations navigating these changes, understanding the nuances of the EDPB draft guidelines is a vital step in ensuring compliant and ethical AI development. Companies must continuously reassess their data processing capabilities and compliance strategies, particularly concerning the obligations for handling sensitive data under the general data protection regulation. They should also monitor new rules, joint guidelines, and specific provisions that may emerge from the European Data Protection Board, the European Commission, and the EDPB-EC cooperation.

Tech professionals seeking to build resilient systems should explore comprehensive ethics and guidelines for trustworthy AI to align their practices with emerging European standards. Additionally, maintaining strong data governance structures, as outlined in the Data Governance Act EU framework, will be instrumental in adapting to these regulatory shifts. Organizations operating across the EEA should ensure their conduct reflects the applicable GDPR provisions, while also tracking developments such as the CIPL response, ANPD consultation, DMA Taskforce Unit guidance, Article 89 GDPR requirements, and the four DMA provisions that may affect data use.

avatar
Nemko Digital
Nemko Digital is formed by a team of experts dedicated to guiding businesses through the complexities of AI governance, risk, and compliance. With extensive experience in capacity building, strategic advisory, and comprehensive assessments, we help our clients navigate regulations and build trust in their AI solutions. Backed by Nemko Group’s 90+ years of technological expertise, our team is committed to providing you with the latest insights to nurture your knowledge and ensure your success.

RELATED ARTICLES