From the journal

EDPB Issues Draft Guidelines on Web Scraping for Generative AI Training, EU, July 2026

On 7 July 2026, the European Data Protection Board adopted Guidelines 03/2026 on web scraping in the context of generative AI. The draft, open for consultation until 30 October 2026, confirms that publicly accessible personal data retains full GDPR protection. Consent is identified as an impracticable legal basis at scale; legitimate interest under Article 6(1)(f) is available but requires a full three-part balancing test, with robots.txt and ai.txt signals treated as relevant indicators of data subject expectations.

3 min read

The European Data Protection Board (EDPB) adopted Guidelines 03/2026 on web scraping in the context of generative AI (Version 1.0) on 7 July 2026 and opened them for public consultation through 30 October 2026. The guidelines address large-scale automated extraction of personal data from publicly accessible web sources for the purpose of training generative AI models, applicable to any entity engaged in that activity where GDPR jurisdiction is triggered.

The EDPB confirms in the guidelines that public accessibility does not remove personal data from GDPR protection. Consent under Article 6(1)(a) is identified as generally unavailable as a legal basis for web scraping at scale because the requirements of Article 7, including free, specific, and informed consent with a genuine right to withdraw, cannot realistically be met in the context of large-scale automated collection from public websites. Legitimate interest under Article 6(1)(f) is the primary available legal basis but requires satisfaction of a three-part test: identification of the specific legitimate interest pursued by the controller, necessity of the processing for that interest, and a balancing of that interest against data subjects' rights and reasonable expectations. The EDPB states the balancing outcome is not automatic and depends on the specific context.

The guidelines directly affect AI developers, large language model providers, academic institutions and research bodies building training corpora, and cloud platforms supplying training data pipelines. Controllers relying on web scraping as a data source must publish detailed public privacy notices accessible at the point of collection where feasible, and must implement mechanisms for data subjects to exercise rights, including pre-collection opt-out. Robots.txt files, ai.txt files, CAPTCHAs, and login walls are characterised as relevant indicators of data subjects' reasonable expectations; controllers that technically override such signals face heightened scrutiny in the legitimate interest balancing assessment.

The guidelines are in draft form and subject to revision following the consultation period closing 30 October 2026. Member state supervisory authorities may take divergent interim positions pending final adoption. The guidelines do not resolve the application of Article 28 to data supply chain arrangements between scraping contractors and AI model developers, nor do they address Chapter V transfer obligations where scraped data is processed outside the EU by non-EEA entities.

Licentium advises AI developers, data processors, and technology companies on GDPR compliance for AI training pipelines and data acquisition strategies. Contact us at www.licentium.io if this development is relevant to your operations. Work we undertake includes legal basis assessments for training data collection, web scraping compliance reviews, data subject rights framework design, privacy notice drafting, and regulatory consultation responses.

Source: EDPB, Guidelines 03/2026 on web scraping in the context of generative AI (v1.0), 7 July 2026

AI Regulatory

More from the journal

See all
Illia Prokopiev

Crypto Vaults and Lending Strategies Under U.S. Federal Securities Law

Commissioner Hester M. Peirce’s July 22, 2026 statement does not establish binding law, but it identifies the principal federal securities-law questions raised by crypto vaults and onchain lending strategies. This analysis examines when vault interests, lending claims, receipt tokens, and related service-provider activities may trigger the Securities Act, Exchange Act, Investment Company Act, and Investment Advisers Act.

MiCAR Transitional Regime for CASPs Expires Across the EU, July 2026

On 1 July 2026, the MiCAR transitional period under Article 143(3) of Regulation (EU) 2023/1114 expired across the EU. Former virtual asset service providers operating under national registrations must now hold a MiCAR crypto-asset service provider authorisation or cease providing crypto-asset services. In Luxembourg, the CSSF confirmed that VASP registration under the 2004 AML Law no longer provides a sufficient legal basis for market activity.

EDPB Adopts Final GDPR Guidelines on Blockchain Data Processing, EU, 8 July 2026

On 8 July 2026, the European Data Protection Board adopted the final version of Guidelines 02/2025 on the processing of personal data through blockchain technologies. The guidelines confirm that encrypted and hashed on-chain data remains personal data under the GDPR and that blockchain immutability does not override data subjects' right to erasure under Article 17. Controllers must address architecture choices and data minimisation before any on-chain recording of personal data.