On 7 July 2026, the European Data Protection Board ("EDPB") adopted draft Guidelines 03/2026 on web scraping in the context of generative AI (the "Guidelines"). The Guidelines, which are open for public consultation until 30 October 2026, make clear that the use of personal data obtained through web scraping for training generative AI remains subject to the GDPR. 

The Guidelines apply to private entities that scrape data directly, engage third parties to do so, or acquire pre-scraped datasets for training generative AI models. Organisations must identify an appropriate lawful basis for scraping activities. The EDPB considers that "legitimate interests" under Article 6(1)(f) GDPR may be the most applicable lawful basis for the processing of personal data in the context of web scraping for generative AI training. Controllers relying on legitimate interests must, however, still comply with key GDPR principles, including transparency and lawfulness.

Considering each limb of the three-part legitimate interests test in turn:

  1. Legitimate Interest: the EDPB recommends that with respect to the development and improvement of a general-purpose AI model, controllers should "refer to the objective pursued by the development of the model (indicating in particular whether it is commercial, public, scientific research, and whether it is internal or external to the organisation)". The Guidelines also provide examples of interests that may be considered legitimate, such as enhancing threat detection within information systems or improving conversational agent services designed to assist users.
  2. Necessity: the Guidelines underscore the principle of data minimisation. Controllers should limit collection to personal data that is necessary for the intended purpose by using targeted collection criteria, filtering mechanisms and, where appropriate, synthetic, anonymised or pseudonymised data.
  3. Balancing Test: Controllers should consider the expectations of data subjects regarding the use of their publicly available personal data, including whether measures such as the use of robot authentication to view content, CAPTCHAs or login walls indicate opposition to such use.

The Guidelines also address the treatment of special category personal data that may be collected incidentally through large-scale scraping and underline the importance of safeguards, including filtering measures, opt-out mechanisms and other processes designed to reduce the risk of personal data being memorised by AI models.    

The Guidelines provide a clear indication of the direction of regulatory travel in Europe. As scrutiny of the provenance and use of training data increases, organisations developing or training generative AI systems using web-scraped datasets will need to demonstrate robust governance, transparency and compliance measures.

The EDPB has invited comments on the Guidelines, which can be submitted here. 

On 7 July 2026, the European Data Protection Board ("EDPB") adopted a draft of its data anonymisation guidelines and launched a public consultation on the proposed text. The guidelines establish a detailed framework for assessing when personal data has been effectively anonymised and therefore falls outside the scope of the GDPR.

The guidelines are grounded in the GDPR's definition of personal data: information is considered anonymous where it either does not relate to an individual or does not concern an identified or identifiable individual. The EDPB examines a range of commonly used anonymisation techniques, including noise addition, aggregation, data swapping and generalisation, and sets out how organisations should evaluate their effectiveness. A central theme of the guidance is that anonymisation cannot be assessed solely by reference to the dataset itself. Organisations must also take account of the broader context, including the means reasonably likely to be available to any party, including third parties, to re-identify individuals. The EDPB highlights that re-identification risks may remain where specialist third-party services are available or where additional datasets can be accessed through legal or other legitimate means. The guidance also reiterates the distinction between anonymisation and pseudonymisation, emphasising that pseudonymised data remains personal data and continues to be subject to the GDPR.

The EDPB has adopted a stringent approach to what constitutes effective anonymisation. Organisations that have historically relied solely on the removal of direct identifiers, or that have applied anonymisation techniques without undertaking a robust risk assessment, may find that their existing practices no longer meet the required standard. Going forward, organisations should ensure that anonymisation assessments are thoroughly documented and capable of withstanding regulatory scrutiny. They should also assess whether AI models could enable the reconstruction or re-identification of datasets that were previously considered anonymised.

The EDPB has invited comments on the Guidelines by 30 October 2026. 

On 3 June 2026, the European Commission published its proposed Cloud and AI Development Act ("CADA"), a legislative initiative aimed at strengthening European data sovereignty. The rapid growth of AI has significantly increased demand for computational capacity, and the proposal characterises cloud and AI infrastructure as strategic resources for the EU's economic security, sovereignty, resilience and competitiveness.

The proposal is driven by what the Commission views as a structural vulnerability in the European market. A shortage of domestic data centre capacity means that growing storage and processing requirements, particularly AI workloads, are increasingly being routed through foreign hyperscaler infrastructure. Three non-EU hyperscalers control more than 70% of the EU cloud market, giving rise to concerns around exposure to third-country jurisdictions and operational resilience. CADA is the EU's response: a framework designed to reduce that dependency, with data sovereignty at its core.

The centrepiece of CADA is a four-tier sovereignty framework under which EU and Member State entities must assess the risks associated with a cloud service provider and assign it an appropriate Union Assurance Level (“UAL”). Providers must demonstrate to their national competent authority that they meet the requirements applicable to that UAL in order to obtain recognition and thereby provide their cloud computing services to those entities:

  • Level 1 requires providers to be established in the EU, with infrastructure, assets and customer data remaining there. Providers must also meet baseline cybersecurity standards and provide transparency regarding subcontracting arrangements.
  • Level 2 builds on level 1 through an independent auditing requirement and, amongst other safeguards, requires relevant personnel to be based in the EU, together with proof that third-country control cannot be used to access customer data, disrupt services or compel compliance with third-country sanctions.
  • Level 3 introduces stricter sovereignty requirements, including personnel to be EU citizens and, where required, to hold relevant security clearances. Providers must also not be subject to third-country control.
  • Level 4 is reserved for the most sensitive use cases. Alongside enhanced cybersecurity requirements, it removes the third-country derogation altogether and requires providers to demonstrate effective control over all software components.

Recognition at levels 2 to 4 requires an independent audit, and compliance with each lower level is a prerequisite for recognition at a higher one. Since levels 3 and 4 in practice require EU ownership, US providers may face structural exclusion from a significant portion of public sector contracts, including the considerably larger share of contracts likely to be classified at level 3.

To ensure that the sovereignty framework is supported by sufficient infrastructure, CADA also introduces a regime of data centre acceleration zones. Member States must designate at least one such zone within six months of the legislation entering into force, and are required to reduce administrative barriers to data centre development by streamlining permitting processes and improving coordination between relevant authorities.

CADA will now proceed through negotiations in the European Parliament and the Council, with final adoption currently expected in late 2027.

On 15 July 2026, the Court of Appeal ("Court") handed down its judgment in Vince v Associated Newspapers Ltd, holding that a claim for unfair processing under the UK GDPR could succeed. The case appears to be the first successful unfair processing claim of its kind and suggests that Articles 5(1)(a) and 82 UK GDPR may provide an alternative route to redress individuals where a defamation claim is unsuccessful.

The claim arose from articles published by Associated Newspapers in the Daily Mail and Mail+ in June 2023. Although the articles referred in their text to a different individual, photographs of Mr Vince appeared directly beneath headlines describing a "sex pest donor" and a "'sex harassment' donor". Mr Vince's subsequent defamation claim failed in the High Court under the Charleston principle, which requires a publication to be assessed as a whole rather than by reference to isolated headlines or images. Vince brought a new claim for unfair processing of personal data, which was also struck out by the High Court. The Court allowed Vince’s appeal against the strike out of the unfair processing claim and the High Court's summary judgment.

Article 5(1)(a) UK GDPR requires personal data to be processed "lawfully, fairly and in a transparent manner", while Article 82 provides individuals with a right to compensation where they suffer material or non-material damage as a result of an infringement of the legislation. Mr Vince argued that the use of his photograph alongside the headlines amounted to unfair processing of his personal data.

The Court considered whether the Charleston principle should apply equally when determining whether processing is "fair" under Article 5(1)(a). It examined previous case law in which the view had been expressed that the Charleston principle applied to claims concerning inaccurate processing under Article 5(1)(d) UK GDPR. The Court held that, while there is no automatic read-across from a claim for inaccurate processing to one for unfair processing, there would need to be good reasons to adopt a different approach. In the Court's view, the answer could be found in the Editors' Code of Practice. The Code requires publishers to take care not to publish inaccurate, misleading or distorted information or images, including headlines that are not supported by the accompanying text. In this case, Associated Newspapers had failed to take such care and had published misleading information through the juxtaposition of the headlines and photographs.

The Court also rejected Associated Newspapers' reliance on the journalism exemption under the Data Protection Act 2018. That exemption provides that Article 5(1) UK GDPR does not apply to the extent that the controller reasonably believes compliance would be incompatible with the purposes of journalism. The Court found no evidence that anyone at Associated Newspapers considered the application of the fairness requirement to be incompatible with journalistic purposes in relation to the articles in question. Furthermore, the Court held that Associated Newspapers would, in any event, have been unable to rely on the exemption because, having regard to the Editors' Code of Practice and its Accuracy Notes, it could not reasonably have believed that the publication complained of, namely the juxtaposition of the headlines with photographs of Mr Vince, was in the public interest. The Court therefore granted summary judgment in Mr Vince's favour, with damages to be assessed at a later stage.

However, a number of important issues remain unresolved. The Court did not determine whether a claimant must prove specific harm, whether reputational damage is recoverable under Article 82, or whether Mr Vince had established a sufficient basis for compensation for distress. Nevertheless, the decision suggests that the manner in which personal data is presented, and whether that presentation creates a misleading impression, may be relevant when assessing the fairness of processing under the UK GDPR. A significant aspect of the Court's reasoning was its reliance on the Editors' Code of Practice and the standards applicable to responsible journalism. As a result, it remains to be seen to what extent its approach to fairness will be applied to other forms of data processing where no comparable industry code or journalistic considerations arise.

On 27 July 2026, the Information Commissioner's Office (the "ICO") issued the Metropolitan Police Service (the "MPS") with a joint Reprimand and Enforcement notice following two incidents involving the unlawful disclosure of personal data in highly sensitive police cases (see here, the "Notice").

The first incident occurred in February 2024, when an MPS officer served an unredacted Stalking Protection Order application on a defendant, containing the victim's new address and telephone number. The second instance occurred in November 2024, when an MPS officer emailed multiple victims of an offence via email, using the "To" field of an email, rather than blind carbon copy ("Bcc"), which led to recipients' email addresses being disclosed to one another. 

Following an investigation, the ICO concluded that, in both cases, the MPS had failed to implement appropriate technical and organisational measures to safeguard personal data, contrary to section 40 of the Data Protection Act 2018.

Before issuing the Notice, the ICO served the MPS with a Notice of Intent, setting out its provisional view that the MPS had infringed data protection legislation. A Notice of Intent provides the recipient with an opportunity to submit written representations, which the ICO must consider before deciding whether to issue a reprimand, enforcement notice and/or monetary penalty. After considering the MPS's representations, the ICO proceeded to issue both a reprimand and an enforcement notice.

The Notice requires the MPS to implement a series of remedial measures within a period of between three and twelve months. These measures are aimed at strengthening the MPS's data protection training, monitoring and governance arrangements. In particular, the MPS must:

  • ensure that compliance with mandatory data protection training is accurately recorded and audited; and
  • establish more effective processes for identifying and following up with personnel who fail to complete required training.

The ICO's findings emphasised wider weaknesses in the MPS's data protection framework, including shortcomings in training compliance, oversight and governance, which the ICO considered to have contributed to the incidents.

The Notice highlights the importance of maintaining effective data protection training programmes and oversight mechanisms to ensure that staff understand and consistently apply data protection requirements in practice, particularly in organisations whose employees routinely handle sensitive personal data.

An unprecedented cyber incident has highlighted the emerging risks posed by autonomous AI systems. In July 2026, Hugging Face confirmed that an intrusion into its production environment had been conducted entirely by an autonomous AI agent. OpenAI subsequently confirmed that the agents involved were its own models, which had escaped a restricted testing environment during an internal cyber capability evaluation, gained internet access and ultimately compromised parts of Hugging Face's infrastructure. The incident demonstrates that advanced AI systems may pursue objectives in unforeseen ways, even where safeguards and containment measures have been put in place.

From a legal and regulatory perspective, for victim organisations, existing cyber incident and data breach notification obligations remain unchanged. Whether an attack is carried out by a human or an AI system, organisations must still comply with applicable reporting requirements under frameworks such as the UK GDPR, EU GDPR and NIS2. However, the incident raises more interesting questions around liability and accountability, including how computer misuse laws apply where the immediate actor is an autonomous AI agent, and who may ultimately bear responsibility when an AI system acts outside the scope intended by its developers or operators.

The incident also provides important lessons for organisations deploying, testing or relying on increasingly autonomous AI tools. There is a need for robust governance, effective containment measures, clear contractual allocation of risk, and incident response plans that are capable of dealing with AI-driven attacks. Providers of advanced AI models may themselves be subject to reporting obligations under the EU AI Act, highlighting that AI incident management is fast becoming both a cyber security and regulatory compliance issue.

For further information please refer to the full article available here.

On 7 July 2026, the European Data Protection Board (“EDPB”) adopted the final version of its Guidelines 02/2025 on the processing of personal data through blockchain technologies (the “Guidelines”). The final Guidelines are largely consistent with the EDPB’s position in the draft version, but offer further clarity on how the GDPR applies to blockchain-based processing.

The EDPB has not ruled out blockchain altogether but makes clear that the technical impossibility of deleting personal data once it's recorded on-chain doesn't excuse GDPR non-compliance. Before reaching for blockchain, controllers need to assess and document whether the technology is actually necessary, whether a less privacy-intrusive alternative could do the job, and which blockchain architecture fits best.

The Guidelines include 16 practical recommendations (Annex A). Three key themes stand out: minimise personal data on-chain, implement robust governance systems, and build GDPR compliance into the technology from day one.

The headline message is simple: avoid putting personal data directly on a blockchain wherever possible. Where blockchain is genuinely necessary, the Guidelines point to techniques like encryption, hashing and cryptographic commitments to reduce risk. But none of these remove the need to comply with GDPR, since encrypted data is still personal data. Each technique still needs to be assessed in context.

On governance, the EDPB recommends favouring permissioned blockchains, which makes allocation of responsibilities and control over who participates easier.Governance arrangements should also cover access controls, protocol updates, breach management and international transfers.

The principles of data protection by design and by default matter even more here. A Data Protection Impact Assessment will almost certainly be needed, covering: the necessity and proportionality of using blockchain; the governance model; international transfers, particularly where public blockchains involve nodes outside the EEA, triggering Chapter V GDPR; and how data subject rights will work in practice. The Guidelines also flag that smart contracts may constitute automated decision-making within the meaning of Article 22 GDPR, requiring appropriate safeguards.

The bottom line? The Guidelines don't prevent organisations from using blockchain to process personal data. But immutability and decentralisation are not excuses for GDPR non-compliance. Organisations considering using blockchain should assess whether it's truly necessary, keep personal data off-chain where you can, and make sure governance, retention, security and data subject rights are built in from the start.                                                                                                                                                                                                                                                                                                                                                                          

Key contacts

Miriam Everett Claire Wiseman Alice Bourne Isabel Rigby