From the journal

EDPB Issues Draft Guidelines on Web Scraping for Generative AI Training, EU, July 2026

On 7 July 2026, the European Data Protection Board adopted Guidelines 03/2026 on web scraping in the context of generative AI. The draft, open for consultation until 30 October 2026, confirms that publicly accessible personal data retains full GDPR protection. Consent is identified as an impracticable legal basis at scale; legitimate interest under Article 6(1)(f) is available but requires a full three-part balancing test, with robots.txt and ai.txt signals treated as relevant indicators of data subject expectations.

3 min read

The European Data Protection Board (EDPB) adopted Guidelines 03/2026 on web scraping in the context of generative AI (Version 1.0) on 7 July 2026 and opened them for public consultation through 30 October 2026. The guidelines address large-scale automated extraction of personal data from publicly accessible web sources for the purpose of training generative AI models, applicable to any entity engaged in that activity where GDPR jurisdiction is triggered.

The EDPB confirms in the guidelines that public accessibility does not remove personal data from GDPR protection. Consent under Article 6(1)(a) is identified as generally unavailable as a legal basis for web scraping at scale because the requirements of Article 7, including free, specific, and informed consent with a genuine right to withdraw, cannot realistically be met in the context of large-scale automated collection from public websites. Legitimate interest under Article 6(1)(f) is the primary available legal basis but requires satisfaction of a three-part test: identification of the specific legitimate interest pursued by the controller, necessity of the processing for that interest, and a balancing of that interest against data subjects' rights and reasonable expectations. The EDPB states the balancing outcome is not automatic and depends on the specific context.

The guidelines directly affect AI developers, large language model providers, academic institutions and research bodies building training corpora, and cloud platforms supplying training data pipelines. Controllers relying on web scraping as a data source must publish detailed public privacy notices accessible at the point of collection where feasible, and must implement mechanisms for data subjects to exercise rights, including pre-collection opt-out. Robots.txt files, ai.txt files, CAPTCHAs, and login walls are characterised as relevant indicators of data subjects' reasonable expectations; controllers that technically override such signals face heightened scrutiny in the legitimate interest balancing assessment.

The guidelines are in draft form and subject to revision following the consultation period closing 30 October 2026. Member state supervisory authorities may take divergent interim positions pending final adoption. The guidelines do not resolve the application of Article 28 to data supply chain arrangements between scraping contractors and AI model developers, nor do they address Chapter V transfer obligations where scraped data is processed outside the EU by non-EEA entities.

Licentium advises AI developers, data processors, and technology companies on GDPR compliance for AI training pipelines and data acquisition strategies. Contact us at www.licentium.io if this development is relevant to your operations. Work we undertake includes legal basis assessments for training data collection, web scraping compliance reviews, data subject rights framework design, privacy notice drafting, and regulatory consultation responses.

Source: EDPB, Guidelines 03/2026 on web scraping in the context of generative AI (v1.0), 7 July 2026

AI Regulatory

More from the journal

See all

Hong Kong SFC and FSTB Conclude Consultation on Virtual Asset Advisory and Management Regimes, 26 May 2026

On 26 May 2026, Hong Kong's Securities and Futures Commission and Financial Services and the Treasury Bureau published consultation conclusions on proposed licensing regimes for virtual asset advisory and management service providers. The regimes apply the same business, same risks, same rules principle and align SFC licensing requirements with those for securities advisory and management businesses. A bill implementing the regimes is planned for introduction into the Legislative Council in 2026.

OCC Grants Circle Final Charter for First National Digital Currency Bank N.A., 9 July 2026

The Office of the Comptroller of the Currency granted final approval on 9 July 2026 for Circle Internet Group to establish First National Digital Currency Bank, N.A., operating as Circle National Trust. The bank opened 24 July 2026 under direct OCC oversight and will manage USDC reserves on a directed basis, act as collateral trustee for USDC holders, and provide digital asset custody services to Circle affiliates.

Manitoba Enacts Public Sector AI and Cybersecurity Governance Act June 2026

On 1 June 2026, Bill 51, The Public Sector Artificial Intelligence and Cybersecurity Governance Act (S.M. 2026, c. 43), received Royal Assent in Manitoba, Canada. The Act mandates transparency, accountability structures, and cybersecurity incident reporting for public sector entities using AI systems. Substantive obligations take effect only through regulations yet to be made.