Diritto al Digitale

EDPB Anonymisation Guidelines: What They Mean for AI Systems & GDPR

DLA Piper Law Firm

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 7:35

The EDPB has issued its new Guidelines on Anonymisation, and they could have major implications for AI systems, AI training data and GDPR compliance.

In this episode of the Legal Break, Giulio Coraggio, partner and location head of the Intellectual Property & Technology department at the law firm DLA Piper, discusses the new EDPB Guidelines with journalist Antonio Ravenna and explains what they mean in practice for organisations developing or deploying AI.

Among the key issues discussed:

• When can data really be considered anonymous under the GDPR?
• Why anonymisation is relative and context-dependent
• The EDPB's three criteria: No Record Isolation, No Linkage and No Inference
• Why AI models and synthetic data create new re-identification risks
• How AI can make inference and re-identification easier
• Why simply removing names and identifiers may not be enough
• What the Guidelines mean for AI developers and businesses using personal data
• Why organisations should periodically reassess whether data remains anonymous
• The relationship between the EDPB's anonymisation guidance and its approach to AI and web scraping

The EDPB Guidelines 02/2026 were adopted in July 2026 and are currently open for public consultation until 30 October 2026.

The key message: anonymisation is no longer something organisations can assume; it needs to be demonstrated, tested and reassessed.

📌 Read the full analysis:
https://www.gamingtechlaw.com/2026/07/edpb-anonymisation-guidelines-ai/

Send us Fan Mail

📌 You can find our contacts 👉 www.dlapiper.com

People on this episode