From the journal

EDPB Adopts Guidelines 03/2026 on Web Scraping for Generative AI Training Data

At its July 2026 plenary, the European Data Protection Board adopted Guidelines 03/2026 on web scraping in the context of generative AI, clarifying when GDPR applies to large-scale automated data collection used to train AI models. The guidelines are open for public consultation until 30 October 2026.

2 min read

At its July 2026 plenary, the European Data Protection Board adopted Guidelines 03/2026 on web scraping in the context of generative AI (Version 1.0). The guidelines address when and how GDPR requirements apply to large-scale automated extraction of publicly available personal data used to train generative AI systems. A public consultation runs until 30 October 2026, after which the EDPB may revise the text before issuing a final version.

The EDPB concluded that GDPR applies whenever a web scraping operation collects or processes personal data, regardless of whether the source was publicly accessible online. Article 5(1)(b) of GDPR governs purpose limitation: data originally published for a different purpose may not be re-used to train AI models without an independently valid legal basis. Processing of special categories of data under Article 9, including health, racial origin, and political opinion data incidentally scraped, requires explicit consent or another enumerated Article 9(2) ground.

Companies building or operating generative AI systems in the EU face the most direct impact. Foundation model providers, fine-tuning operators, and data aggregators supplying training sets must assess each scraping operation against the legal basis, purpose compatibility, and transparency requirements set out in the guidelines. Organisations relying on legitimate interest under Article 6(1)(f) must conduct a balancing test that accounts for the scale of the scraping and the absence of individual notice to data subjects.

The guidelines are in consultation phase and the EDPB may revise specific positions before finalisation. Separately, the EDPB adopted guidelines on anonymisation at the same plenary. Web scraping that produces genuinely anonymised outputs before those outputs enter training pipelines would fall outside GDPR scope, but the anonymisation guidelines set a high threshold for what qualifies as sufficiently anonymised.

We advise on GDPR compliance for AI training data programmes and maintain a partner network for multi-jurisdictional data protection engagements. Contact us to discuss your specific training data practices. Work we undertake includes AI training data audits, web scraping compliance reviews, data protection impact assessments for generative AI systems, and legitimate interest balancing documentation.

Source: European Data Protection Board, Guidelines 03/2026 on Web Scraping in the Context of Generative AI, Version 1.0, July 2026

AI Regulatory

More from the journal

See all

EU AI Act Article 50 Transparency: 2026 Implementation and Compliance Guide

Article 50 of the EU AI Act assigns disclosure duties to providers and deployers of certain AI systems. The question is which duties apply on August 2, 2026, what the official guidance and Code add, and what remains unsettled. This analysis assumes nonpersonal use with an EU territorial connection. It excludes exclusively military, defence, or national-security uses. It assumes no authorized law-enforcement exception. It states the law as of July 31, 2026.

Illia Prokopiev

Dubai VASP Licensing: Fresh Authorizations Signal Continued Regulatory Momentum

Dubai’s Virtual Assets Regulatory Authority records permissions for specified virtual-asset activities in Dubai outside the Dubai International Financial Centre. The question is whether “Dubai VASP licensing continues to show fresh authorization activity” is supported as at 31 July 2026, and what those records legally permit. This analysis treats VARA’s English register and entity pages as the current factual record. It distinguishes active full licences from non-operational in-principle approvals.

Illia Prokopiev

UK Crypto Authorisation: From Future Watching to Application Preparation

The United Kingdom has made legislation and principal FCA rules for a new authorisation regime covering specified cryptoasset activities. The question is whether firms should now prioritise application work, given the published dates and FCA pre-application warning. This analysis tests that proposition as at 31 July 2026. It assumes no firm-specific facts and addresses commercial cryptoasset services provided in or to the United Kingdom.