AI Policy Wiki
Dashboard

European Data Protection Board (EDPB)

medium confidence · updated 2026-07-26

EU body of national data-protection authorities ensuring consistent GDPR application; issuer of AI-relevant guidance including Opinion 28/2024 on AI models and the July 2026 guidelines on anonymisation and web scraping for generative AI.

The European Data Protection Board (EDPB) is the European Union body responsible for the consistent application of the General Data Protection Regulation across the EU and EEA. Established by Article 68 of the GDPR when the regulation took effect in May 2018, it comprises the heads of the national data-protection supervisory authorities of each member state and the European Data Protection Supervisor (EDPS). Since 2023 it has been chaired by Anu Talus, head of Finland's data-protection authority (Source: edpb.europa.eu).

Role and powers

The EDPB issues guidelines, recommendations, and best practices on the interpretation of the GDPR; adopts binding decisions in cross-border consistency disputes between national authorities under the GDPR's one-stop-shop mechanism; and issues opinions under Article 64 on matters of general application. Its guidance is not itself legislation, but national data-protection authorities apply it in enforcement, making it a primary reference point for how EU data-protection law reaches AI systems trained on or processing personal data.

The board's most-cited AI intervention is Opinion 28/2024, adopted in December 2024, on data-protection aspects of processing personal data in the context of AI models — addressing when a trained model is itself personal data, the use of the legitimate-interest legal basis for AI training, and the consequences of unlawfully processed training data (Source: edpb.europa.eu).

At its plenary on July 8, 2026, the board adopted two AI-relevant guidelines and opened both for public consultation until October 30, 2026 (Source: edpb.europa.eu; mlex.com):

  • Guidelines on anonymisation — clarifying when data is anonymous (and so outside the GDPR), incorporating the Court of Justice ruling in C-413/23 P EDPS v SRB (September 4, 2025). The guidelines set a three-criterion test — no record isolation, no linkage, no inference — and offer a "contextual approach" reflecting the full legal standard alongside a stricter-but-simpler "simplified approach" (EDPB Guidelines 02/2026 on Anonymisation). The framework treats anonymity as relative rather than absolute — "anonymity should be assessed from each relevant entity's perspective" — and defines identifiability as the ability to distinguish a person "in a way that makes it possible to treat them differently." The board is explicit that the simplified approach "can go beyond the legal standard," potentially treating data as personal even where it would be anonymous for some entities.
  • Guidelines 03/2026 on web scraping in the context of generative AI — clarifying the GDPR compliance of large-scale scraping for AI training, including the legitimate-interest legal basis (building on Opinion 28/2024), purpose limitation and transparency, accuracy measures (scraping from reliable sources, timestamping, validation before training), data minimisation, and the treatment of special-category data, where the board points to GC & Others (C-136/17) as potentially relevant for incidental or residual collection while emphasizing there is no general exemption from Article 9 (EDPB Guidelines 03/2026 on web scraping in the context of generative AI).

Two positions in the web-scraping guidelines bear directly on current industry practice. On consent, publishing data online "does not mean that the data subjects gave their consent to the scraping of their personal data for a specific purpose," and "the absence or non-applicability of a robots.txt file on a web site does not amount to consent within the meaning of the GDPR." On transparency, the Article 14(5)(b) disproportionate-effort exemption from informing data subjects is framed around archiving and research purposes, and "should not be routinely relied upon by controllers" outside them. The necessity limb of the legitimate-interest test is also read against indiscriminate collection: "narrowing the collection criteria to exclude unnecessary collection of personal data, rather than scraping a wide part of the internet may be crucial to ensure the necessity condition is met." The board further treats deployment-stage safeguards as relevant to the training-stage balance, naming "measures to limit the risks of memorisation, regurgitation or attack of AI models or systems" (EDPB Guidelines 03/2026 on web scraping in the context of generative AI).

The same plenary adopted the final version of the board's guidelines on processing personal data through blockchain technologies, following public consultation (Source: edpb.europa.eu).

Coverage of the web-scraping guidelines characterized them as the board's first EU-level position precluding AI firms from relying on consent as a legal basis to justify large-scale scraping for generative-AI training (Source: ppc.land).

At a Dublin meeting on July 16–17, 2026, the board called on the European Commission to propose a legal basis for cross-regulatory information sharing among EU digital regulators, citing rising complaint volumes driven in part by increased AI use (Source: edpb.europa.eu).

Relation to national authorities

The EDPB coordinates rather than replaces national enforcement: authorities such as France's CNIL and Ireland's Data Protection Commission investigate and fine controllers, while the board resolves consistency disputes and sets shared interpretive positions. In the AI context this division has produced national enforcement actions against model providers running alongside board-level guidance on training-data lawfulness.

Both texts are tracked as legislative instruments: EDPB Guidelines 03/2026 on web scraping in the context of generative AI and EDPB Guidelines 02/2026 on Anonymisation.

Relationships