EDPB clarifies anonymization and web scraping for generative artificial intelligence and adopts final version of blockchain guidelines

The new EDPB guidelines clarify the concept of anonymized data, including in light of the EU Court of Justice ruling in case C-413/23 P EIOÚ. In developing these guidelines, we incorporated valuable input from our stakeholder engagement and reaffirmed our strong commitment to a cooperative dialogue, as stated in the Helsinki Declaration of the EDPB. Data are considered anonymous if they do not relate to an identified or identifiable natural person. Simplified approaches may go beyond legal standards and could lead anonymizing controllers to treat data as if they were not anonymous, even if they are for certain relevant subjects, but this approach may be more convenient and provide greater assurance that data are truly anonymous. The guidelines also clarify the implications of web scraping for AI development from a data protection perspective. Web scraping is an extensive automated data extraction process that often operates without individuals' knowledge and can pose significant risks to their personal data. The guidelines on web scraping in relation to generative AI explain various aspects of internet search compliance with GDPR, including the legal basis for such activities and conditions under which processing of special categories of data may occur. The EDPB notes that the Court of Justice ruling in case GC & others (C-136/17) may be relevant for incidental or residual collection of special categories of personal data, provided the controller acts within their duties, powers, and capabilities and implements appropriate technical and organizational measures to prevent the collection and dissemination of such data.

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source