From the journal

EDPB Adopts Guidelines 03/2026 on Web Scraping for Generative AI Training, July 2026

The European Data Protection Board adopted Guidelines 03/2026 at its 122nd Plenary on 8 July 2026, confirming that the GDPR governs web scraping for generative AI training wherever personal data is collected. The guidelines impose purpose-limitation, transparency, and legal-basis obligations on scrapers and reject a blanket AI-training exemption. Public consultation closes 30 October 2026.

3 min read

The EDPB adopted Guidelines 03/2026 at its 122nd Plenary session on 8 July 2026, establishing the Board's formal position on GDPR compliance for web scraping operations conducted by private entities for generative AI training. The guidelines are issued under Article 70(1)(e) GDPR and carry adopted status subject to public consultation until 30 October 2026, after which the Board will issue a final version.

The guidelines apply whenever a scraping operation involves the collection, storage, organisation, or retrieval of personal data, regardless of whether the data subject made that data publicly accessible. Legitimate interest under Article 6(1)(f) GDPR is identified as the primary candidate legal basis, requiring a three-part balancing test: a legitimate aim, necessity, and the absence of overriding data subject interests. Processing of special-category data under Article 9 GDPR collected incidentally during scraping — including health information, religious beliefs, biometric data, and sexual-orientation data — requires either explicit consent or a demonstrable Article 9(2) exemption. Purpose limitation under Article 5(1)(b) and transparency under Article 5(1)(a) are treated as threshold compliance conditions that must be satisfied before legal-basis analysis.

Generative AI developers, data pipeline operators, and research institutions scraping EU-resident personal data must document the lawful basis for each scraping operation, provide data subjects with a mechanism to object, and delete or anonymise incidentally collected special-category data where no narrow Article 9(2) basis applies. Platform operators that make data publicly accessible are not relieved of their own GDPR obligations, but primary responsibility rests on the entity conducting the scraping. AI deployers that procure scraped training data from third parties must conduct due diligence on their supplier's GDPR compliance chain.

The guidelines reject a blanket exemption for generative AI training purposes and reject the argument that model training constitutes a compatible secondary purpose under Article 5(1)(b). Whether national scientific-research derogations under Article 89 GDPR can apply to commercial AI training remains an open question on which the EDPB invites stakeholder input during the consultation period. National supervisory authorities retain jurisdiction to enforce against infringements on their territory, and divergence in national interpretations of Article 89 is possible pending the EDPB's final position.

Licentium may advise on GDPR compliance for AI training data pipelines and has a partner network to assist companies operating in the EU digital market. Organisations reviewing scraping practices or training-data provenance in light of Guidelines 03/2026 are welcome to contact us. Work we undertake includes legal-basis analysis for AI training data, legitimate-interest assessments, data protection impact assessments, transparency notice drafting, and supervisory authority engagement.

Source: EDPB, Guidelines 03/2026 on web scraping in the context of generative AI, Version 1.0, 8 July 2026

AI Regulatory

More from the journal

See all

Hong Kong SFC and FSTB Conclude Consultation on Virtual Asset Advisory and Management Regimes, 26 May 2026

On 26 May 2026, Hong Kong's Securities and Futures Commission and Financial Services and the Treasury Bureau published consultation conclusions on proposed licensing regimes for virtual asset advisory and management service providers. The regimes apply the same business, same risks, same rules principle and align SFC licensing requirements with those for securities advisory and management businesses. A bill implementing the regimes is planned for introduction into the Legislative Council in 2026.

OCC Grants Circle Final Charter for First National Digital Currency Bank N.A., 9 July 2026

The Office of the Comptroller of the Currency granted final approval on 9 July 2026 for Circle Internet Group to establish First National Digital Currency Bank, N.A., operating as Circle National Trust. The bank opened 24 July 2026 under direct OCC oversight and will manage USDC reserves on a directed basis, act as collateral trustee for USDC holders, and provide digital asset custody services to Circle affiliates.

Manitoba Enacts Public Sector AI and Cybersecurity Governance Act June 2026

On 1 June 2026, Bill 51, The Public Sector Artificial Intelligence and Cybersecurity Governance Act (S.M. 2026, c. 43), received Royal Assent in Manitoba, Canada. The Act mandates transparency, accountability structures, and cybersecurity incident reporting for public sector entities using AI systems. Substantive obligations take effect only through regulations yet to be made.