This article accompanies Hour 1: Global Privacy Law Updates in our full-day CPD programme on XpertAcademy. Completion of the full one-hour session, including the related learning materials, contributes to the one-hour CPD certificate issued for that session. Access CPD Event A: Full-Day Regulatory Privacy Training.
The annual reports from the Data Protection Commission, European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) gave privacy leaders a useful view of regulatory direction. Our EDPS Annual Report 2025 analysis completes that annual-report picture. The developments that followed in July 2026 show the direction moving into more concrete implementation.
The EDPB adopted draft guidance on anonymisation and web scraping for generative AI, finalised its blockchain guidance and called for a clearer legal basis for information sharing between regulators. At the same time, the AI Omnibus entered into force and the Commission published practical guidance on AI Act transparency obligations.
Individually, these are different developments. Together, they point to a more connected European governance environment in which data protection, AI, platforms, competition, cybersecurity and fundamental rights are increasingly likely to meet around the same facts.
Our European data protection and AI governance map explains how the principal institutions and regulatory responsibilities fit together.
Anonymisation is being given a more operational test
On 8 July, the EDPB adopted draft Guidelines on anonymisation. The guidance takes account of the CJEU's September 2025 judgment in EDPS v SRB and distinguishes between a contextual and a simplified approach to assessing whether information is anonymous.
The contextual approach considers the capabilities and means reasonably likely to be used by the relevant entity or entities. The simplified approach can apply a more conservative assumption without distinguishing between those capabilities. It may therefore treat information as personal data even where the full contextual analysis could produce a narrower result.
The EDPB's practical framework asks whether three outcomes have been prevented:
- record isolation;
- linkage; and
- inference.
Passing those tests is not simply a matter of removing direct identifiers. The organisation needs to understand the data, the surrounding information, the likely actors and the decisions or effects that could follow.
Anonymisation is not a formatting technique. It is a supported conclusion about whether people remain identifiable in the relevant context.
For privacy and AI teams, the immediate action is to revisit any control or product claim that depends on data being outside the GDPR. Evidence should include the transformation performed, the plausible attack or inference routes, auxiliary data, recipients, access conditions and the reason the conclusion remains valid over time. Our earlier guide to anonymisation risk testing for AI datasets provides a practical starting point.
Both the anonymisation and web-scraping guidelines are open for consultation until 30 October 2026. Organisations materially affected should consider whether operational evidence from their sector would improve the final guidance.
GenAI web scraping is now squarely on the governance agenda
The EDPB also adopted draft Guidelines 03/2026 on web scraping in the context of generative AI. The guidance addresses legal basis, purpose limitation, transparency, special-category data, accuracy and data minimisation.
The fact that information is publicly accessible does not remove GDPR responsibilities. Scraping can involve collection, storage, organisation, retrieval and subsequent model use at a scale and for purposes that individuals may not reasonably understand from the original publication context.
Where legitimate interests is considered, organisations need a real purpose assessment, necessity analysis and balancing exercise tied to the actual model and processing design. They also need to consider whether Article 9 special-category data is likely to be collected and, if so, whether an exception is available. A broad statement that the data came from the open web will not answer either question.
The EDPB recommends attention to source reliability, collection timestamps and validation, as well as measures supporting minimisation and transparency. That creates implications for dataset provenance, refresh decisions, model documentation and downstream supplier assurance.
A web-scraping assessment should be able to explain not only what could be collected, but why this data, from these sources, for this model and this purpose was necessary.
Organisations procuring rather than developing models should not assume the issue belongs only to the supplier. They should establish what evidence the provider can supply, what the organisation itself does with prompts, retrieval sources and outputs, and whether its intended use changes the rights or risk position.
The blockchain guidance is final
At the same July plenary, the EDPB adopted the final version of its guidelines on personal-data processing through blockchain technologies. The guidance considers architecture, allocation of responsibility, data protection by design, storage choices and the difficulty of giving practical effect to rights where data is designed to be persistent.
The operational lesson is not that blockchain is prohibited. It is that architectural decisions made early can determine whether later compliance is realistic. Where personal data, or data that can be linked back to a person, is written directly to an immutable ledger, rectification and erasure problems cannot be solved by policy wording.
Teams assessing a distributed-ledger proposal should establish whether a blockchain is necessary, what information is written on-chain, whether off-chain storage or cryptographic references can reduce exposure, who determines purposes and means, and how rights and security events will be handled across participants.
The EDPB wants stronger cross-regulator information sharing
On 17 July, the EDPB called for a clear legal basis for cross-regulatory information sharing, including confidential information relevant to authorities enforcing adjacent EU regimes.
This is a policy call rather than a new obligation for organisations. It is still significant. AI and digital-platform investigations can involve facts relevant to data protection, competition, consumer protection, online safety, equality and market surveillance. Regulators may need to coordinate without exceeding the confidentiality and purpose constraints governing the information they hold.
For organisations, the practical implication is that regulator engagement should be managed as a connected evidence problem. A statement made to one authority may be relevant elsewhere, even where powers and legal tests differ. Legal privilege, confidentiality, consistency and ownership need to be considered from the start, not after parallel correspondence has developed.
This is also a strong reason to maintain one verified chronology and evidence index while preserving the separate submissions and legal positions required by each regulator.
The AI Omnibus has changed the implementation timetable
Regulation (EU) 2026/1744, the AI Omnibus, entered into force on 27 July 2026. It amends the AI Act rather than replacing it.
The changes include later dates for high-risk requirements: 2 December 2027 for Annex III use cases and 2 August 2028 for Annex I product-related systems. They also extend some proportionate measures to small mid-cap companies, adjust AI-literacy wording, simplify aspects of registration and post-market monitoring, expand sandbox arrangements and introduce additional prohibited practices that apply from 2 December 2026.
The delay to high-risk requirements should not be treated as a pause in AI governance. Prohibitions and AI literacy already apply. General-purpose AI obligations began applying in August 2025. Transparency duties under Article 50 apply from 2 August 2026. GDPR, employment, equality, consumer, security and sectoral duties continue regardless of AI Act phasing.
Our separate practical EU AI Act timeline sets out the dates and actions in one place.
AI transparency is now a live implementation issue
On 20 July, the Commission published guidelines on Article 50 transparency obligations. The obligations apply from 2 August 2026 and cover several different situations.
Providers may need to ensure that people know when they are interacting directly with an AI system. Providers of systems generating synthetic audio, image, video or text must support machine-readable marking and detection. Deployers have duties concerning emotion-recognition and biometric-categorisation systems, deepfakes and certain AI-generated or manipulated text published to inform the public on matters of public interest.
There are exceptions and role-specific conditions. There is also a limited transition until 2 December 2026 for the Article 50(2) marking and detection obligation where relevant systems were placed on the market before 2 August 2026. It is not a general grace period for Article 50.
For most organisations, the practical review should cover chatbots and assistants, generated marketing and public communications, synthetic images and video, voice tools, emotion or biometric capabilities, and the supplier evidence supporting technical marking.
AI transparency should be matched to the system, output and organisational role. A generic "made with AI" statement will not satisfy every Article 50 duty.
What should senior privacy and AI teams do now?
The immediate work is reasonably contained.
- Review any anonymisation claims supporting data sharing, analytics or AI development.
- Identify whether web-scraped data enters models or datasets directly or through suppliers.
- Test blockchain proposals at architecture stage, before personal data is committed to a ledger.
- Update the AI Act implementation plan for the enacted Omnibus dates.
- Complete an Article 50 transparency review across systems and public-facing content.
- Establish one regulator-engagement evidence record with separate legal sign-off routes.
- Track consultation and guidance status so draft interpretations are not presented as final law.
This is a governance exercise, not merely a legal-update exercise. Each development needs an owner, an affected system or process, an evidence requirement and a decision about whether action is required.
The XpertDPO view
The strongest theme in this round of European activity is operational verifiability. The EDPB wants anonymisation conclusions that withstand realistic analysis, scraping decisions tied to purpose and necessity, and better regulator cooperation. The AI Act is moving from broad preparation into live transparency and enforcement duties.
That favours organisations with connected evidence and clear accountability. It creates difficulty for those whose privacy, AI, security, procurement and legal records tell different versions of the same system.
XpertDPO's AI governance and DPIA lifecycle support helps in-house teams interpret these developments, review affected systems and turn regulatory change into proportionate actions with a defensible evidence trail.
What This Means for CPD
For Event A Hour 1, the practical learning is to distinguish enacted law, draft guidance, final guidance and regulatory commentary, then translate each development into an owner, affected process, evidence need and review date. Not every update requires immediate change, but each needs an accurate status.
This article is intended to support the learning covered in Hour 1 of our XpertAcademy CPD programme. The relevant CPD certificate is issued for completion of the full one-hour session on XpertAcademy, rather than for reading this article on its own. Return to CPD Event A: Full-Day Regulatory Privacy Training.
Sources
- EDPB, Anonymisation, GenAI web scraping and final blockchain guidelines
- EDPB, Guidelines 03/2026 on web scraping in the context of generative AI
- EDPB, Cross-regulatory information sharing
- EUR-Lex, Regulation (EU) 2026/1744
- European Commission, AI Omnibus enters into force
- European Commission, Article 50 transparency guidelines