< Back to all clusters
[TECHNOLOGY] · 3 sources

European Data Protection Board sets new GDPR rules for blockchain and AI web scraping

The European Data Protection Board (EDPB) adopted new guidelines on 8 July 2026 that clarify how the EU General Data Protection Regulation (GDPR) applies to blockchain technologies. The guidance distinguishes public permissionless networks, private permissioned blockchains and consortium chains, stating that personal data stored on‑chain remains subject to GDPR obligations, including the right to erasure. Organisations are urged to keep personal data off‑chain where possible, using cryptographic references, and to consider future re‑identification risks from encryption or hashing.

The same plenary also released guidelines on anonymisation and on web‑scraping for generative AI. The anonymisation framework defines data as anonymous only when it cannot be isolated, linked or inferred to identify a natural person, and offers a contextual and a simplified assessment approach. The web‑scraping guidance outlines GDPR compliance requirements for large‑scale data extraction, including lawful bases, purpose limitation and transparency obligations. The guidelines will remain open for public comment until 30 October 2026.