EDPB Draft Guidance on Anonymisation and AI Web Scraping: What Data Protection Professionals Need to Know.

6–9 minutes

By Kieran Harte

The European Data Protection Board (EDPB) has launched two important public consultations that are likely to shape the future of European data governance: Guidelines 02/2026 on Anonymisation and draft guidance on web scraping for generative AI systems. Both consultations remain open until 30 October 2026.

For privacy professionals, the anonymisation guidance is arguably the more significant development. It reflects an emerging line of European jurisprudence recognising that whether information constitutes personal data is not always an absolute question. Instead, identifiability must be assessed in context, taking into account the position, capabilities and realistic means available to the specific recipient of the information. This approach, developed most notably by the Court of Justice of the European Union (CJEU) in EDPS v Single Resolution Board (Case C-413/23 P), may provide organisations with greater legal certainty when assessing whether data can genuinely fall outside the scope of the GDPR.

A Turning Point in the Definition of Personal Data

For much of the GDPR era, regulators and courts have tended to interpret the concept of personal data broadly. If information could potentially be linked to an individual, directly or indirectly, it was often treated as personal data, even where the possibility of identification was remote in practice. This expansive interpretation created significant challenges for data sharing, research, analytics, AI development and emerging technologies.

The CJEU’s judgment in EDPS v SRB marks an important refinement of that approach. The Court expressly confirmed what many commentators describe as a “relative” or contextual approach to personal data. Whether information is personal data may depend on the perspective of the particular entity receiving the data and whether that entity has access to means reasonably likely to be used for identification.

As the Court recognised, pseudonymised data do not automatically remain personal data for every person, in every context and for every purpose. While data may continue to constitute personal data for the original controller that retains re-identification information, the same dataset may potentially be anonymous from the perspective of an independent recipient that lacks realistic legal or practical means of identifying individuals.

The EDPB’s draft anonymisation guidance builds directly on this evolving jurisprudence and represents a significant step towards a more operationally realistic framework for assessing identifiability.

Anonymisation Requires More Than Removing Direct Identifiers

One of the clearest messages from the draft guidance is that anonymisation is not achieved simply by removing names, customer numbers or other direct identifiers. The EDPB emphasises that organisations must assess whether individuals can still be:

· singled out within a dataset;

· linked across datasets; or

· identified through inference using additional information.

This reflects long-standing European thinking on anonymisation but places renewed emphasis on demonstrable risk assessment. In particular, organisations cannot assume that pseudonymisation alone removes information from the scope of the GDPR. Instead, they must evaluate the practical risk of re-identification in the specific context in which the data will be used.

For data protection teams, this means anonymisation projects increasingly require documented evidence regarding:

· the identity of relevant recipients and actors;

· the information already available to them;

· the availability of supplementary datasets;

· the feasibility, cost and effort required for re-identification; and

· the reasons why any residual risk can properly be regarded as insignificant.

The Recipient’s Perspective Matters

Perhaps the most important practical implication of the guidance is its recognition that anonymity is not assessed in the abstract.

The critical question is no longer simply whether someone could theoretically identify an individual. Instead, the relevant question becomes anonymous for whom?

The EDPB acknowledges that the same information may constitute personal data for one organisation while being anonymous for another. In assessing identifiability, organisations should consider objective factors including:

· the characteristics, granularity and sensitivity of the data;

· the availability of additional information;

· the time, effort and cost of identification;

· current and reasonably foreseeable technological capabilities;

· contractual, technical and organisational restrictions on access; and

· legal prohibitions on re-identification.

This recipient-focused approach has potentially significant implications for research collaborations, data-sharing initiatives, AI development and analytics activities. It offers greater flexibility than a purely theoretical standard while simultaneously imposing stronger accountability obligations. Organisations will need to document and justify the conclusions they reach.

The Three Core Tests for Anonymisation The draft guidance places three established anonymisation criteria at the centre of the EDPB’s analytical framework. Before information can be regarded as anonymous, organisations must demonstrate the absence of:

1. Record Isolation

Individuals should not be capable of being singled out through unique combinations of attributes or identifiers.

2. Linkability

Records should not be capable of being linked to other information relating to the same individual using means reasonably likely to be employed.

3. Inference

The data should not permit specific and meaningful conclusions to be drawn about an individual where that information could not otherwise be obtained.

While these principles are not new, the EDPB now treats them as the central pillars of its anonymisation framework. Organisations seeking to rely on anonymisation must be able to demonstrate that all three risks have been adequately addressed.

The Important Processor Limitation

The draft guidance maintains a firm position regarding processors.

The EDPB makes clear that a controller cannot transform personal data into anonymous data simply by disclosing them to a processor that lacks the means to identify individuals. Where a processor acts on behalf of a controller, the assessment remains tied to the controller’s ability to identify the data subjects.

This reflects the broader principle confirmed in commentary on EDPS v SRB that the contextual approach principally applies to independent recipients acting in their own capacity, rather than processors operating within the controller’s processing environment.

For outsourcing arrangements, cloud services and managed service providers, the consequence is straightforward: the personal data status of the information generally remains unchanged.

Implications for AI, Analytics and Data Sharing

The guidance is particularly relevant for organisations developing AI systems, machine learning models, analytics platforms and data-sharing frameworks.

For several years, uncertainty surrounding the scope of personal data has complicated AI governance discussions. The recipient-focused approach emerging from EDPS v SRB, reinforced by the EDPB’s draft guidance, may provide a more workable framework for assessing whether data supplied to independent recipients remain subject to data protection law.

However, organisations should not view this as a relaxation of regulatory standards.

The EDPB repeatedly stresses that advances in artificial intelligence, automated analysis and large-scale data aggregation continue to reduce the cost and effort associated with re-identification. A dataset regarded as anonymous today may not remain so as analytical capabilities improve and additional datasets become available.

The EDPB’s relative approach may create greater scope for contextual assessments of identifiability, but increasingly sophisticated AI tools may simultaneously narrow the circumstances in which anonymisation can safely be relied upon.

Consequently, anonymisation should be viewed as an ongoing governance activity rather than a one-off technical exercise.

Practical Actions for Data Protection Professionals

While consultation remains open, organisations should consider reviewing:

· existing anonymisation methodologies;

· data-sharing arrangements involving pseudonymised information;

· AI training, testing and evaluation datasets;

· re-identification risk assessment processes;

· governance and documentation frameworks;

· processor and controller classifications; and

· contractual, legal and technical measures that limit re-identification.

The accompanying EDPB draft guidance on web scraping for generative AI provides a complementary reminder that publicly available information does not fall outside the GDPR simply because it can be accessed online. Scraping, storing, organising and retrieving personal data remain processing operations that require a lawful basis and compliance with core GDPR principles. Organisations should therefore take a closer look at the provenance of datasets used to train, fine-tune and evaluate AI systems.

Looking Ahead

The EDPB’s draft anonymisation guidance represents one of the most significant developments in European data protection law since the introduction of the GDPR. It acknowledges a growing body of case law recognising that identifiability must be assessed contextually and from the perspective of the relevant recipient rather than through purely theoretical possibilities.

The guidance stops short of creating a broad safe harbour for anonymised data. Instead, it seeks to strike a balance between legal realism and robust protection of individuals’ rights. Organisations may benefit from greater flexibility where recipients genuinely lack realistic means of identification, but they will need to support those conclusions with evidence, risk assessments and documented accountability measures.

For privacy professionals, the message is clear: anonymisation remains achievable, but only where organisations can demonstrate, through objective evidence, that individuals cannot realistically be singled out, linked to other information or identified through inference in the hands of the relevant recipient. The final version of the guidance, together with its interaction with wider reforms such as the proposed Digital Omnibus package, will be watched closely across the privacy, technology and AI sectors.

Discover more from Irish Computer Society

Subscribe now to keep reading and get access to the full archive.

Continue reading