Diritto al Digitale is the must-listen podcast on innovation law, brought to you by Giulio Coraggio, data and technology lawyer at the global law firm DLA Piper. Each episode explores the cutting-edge legal challenges shaping our digital world—from data privacy and artificial intelligence to the Internet of Things, outsourcing, e-commerce, and intellectual property.
Join us as we illuminate the legal frameworks behind today’s breakthroughs and provide insider insights on how innovation is transforming the future of business and society.
You can contact us at the details available on dlapiper.com
EDPB Anonymisation Guidelines: What They Mean for AI Systems & GDPR
•DLA Piper Law Firm
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
0:00
|
7:35
The EDPB has issued its new Guidelines on Anonymisation, and they could have major implications for AI systems, AI training data and GDPR compliance.
In this episode of the Legal Break, Giulio Coraggio, partner and location head of the Intellectual Property & Technology department at the law firm DLA Piper, discusses the new EDPB Guidelines with journalist Antonio Ravenna and explains what they mean in practice for organisations developing or deploying AI.
Among the key issues discussed:
• When can data really be considered anonymous under the GDPR? • Why anonymisation is relative and context-dependent • The EDPB's three criteria: No Record Isolation, No Linkage and No Inference • Why AI models and synthetic data create new re-identification risks • How AI can make inference and re-identification easier • Why simply removing names and identifiers may not be enough • What the Guidelines mean for AI developers and businesses using personal data • Why organisations should periodically reassess whether data remains anonymous • The relationship between the EDPB's anonymisation guidance and its approach to AI and web scraping
The EDPB Guidelines 02/2026 were adopted in July 2026 and are currently open for public consultation until 30 October 2026.
The key message: anonymisation is no longer something organisations can assume; it needs to be demonstrated, tested and reassessed.
Hello everyone, I'm Giulio Coraggio, the location head of the Italian Intellectual Property and Technology Department at the Law Firm DLA Parter.
SPEAKER_00
And I'm Antonio Ravenna, a journalist.
SPEAKER_01
Today we're gonna talk about the new guidelines by the European Data Protection Board on Anonymization that have a massive impact on artificial intelligence.
SPEAKER_00
And we're gonna make it during the time of a coffee break. So, Julio, on July 7, 2026, the ADPB adopted the draft guidance on anonymization. It's the first real update since 2014. So, what's actually new?
SPEAKER_01
It was um an update that was highly expected because um technology has changed. It is true that what was personal data over 10 years ago is um still personal data, but wasn't personal data at that time, maybe is personal data now because of uh the technology that is uh more powerful. At the same time, the case law has uh substantially evolved. The milestone that is more relevant for these guidelines is uh not only the development of artificial intelligence, but the what was normally called as the Deloitte uh decision of the European Court of Justice that introduced a concept of um subjective assessment of what is personal data.
SPEAKER_00
And so, Julio, what is the subjective analysis of personal data?
SPEAKER_01
Well, so far the position of European data protection authorities was um you need to make sure that uh directly or indirectly, no one can link that information to an individual. When uh we were referring to no one, was really no one, no one in the world that was definitely too broad, there was a concept of uh reasonableness, but it was very blurred. For a company like Google, some could argue basically any information is personal data because of the massive amount of data that they uh have about us. Uh but after the Deloitte decision of the European Court of Justice, it was validated that you need to have a look at uh the position of the entity processing that data, not the rest of the world, and whether that entity has reasonably in its hands the information able to link the information received to the relevant individual. If that information cannot be linked, then we're not processing personal data anymore. Obviously, that needs to be reassessed with the evolution of the technology. It's um a burden of proof that is on the entity processing data. But this is really important because um until now, basically you had to look at the perspective of whoever could have in its hands that information, which definitely was too broad to be assessed.
SPEAKER_00
And the ADPB relies on three criteria singling out, linkability, and inference. Uh, which of these is the hardest for AI systems to satisfy and why does AI change the equation here?
SPEAKER_01
Well, the inference is the most tricky element because um directly or indirectly, I don't have to be able to link that information to the relevant um individual. We know that uh artificial intelligence is so powerful because it can process a massive amount of personal data. But then uh if uh, for example, we refer to the identification code of a client of a bank, that information is in the ends of the bank, but for the rest of the world, it's not the information of an individual. Or uh uh same thing for the IBAN number. That information is for my bank, linked to my bank account, but probably the rest of the world doesn't know much uh about that number is not able to link that to an individual. But this has massive um implications, for instance, when it comes to medical trials. In that case, patients are identified through an identification code that uh is unique, that's true, but the uh table able to link that patient to the relevant um code is just in the hands of the hospital. Then you need to understand whether through the other information in the hands of the third party the inference is still possible, it's uh still possible to link that information to the relevant individual. But you know, uh while in the past uh the test was quite uh simple, straightforward, if add a code that directly and indirectly potentially could have been linked to an individual, then that information was a personal data, now it's uh a completely different perspective.
SPEAKER_00
The ADPB also says that anonymization isn't a one-time check. It has to be reassessed periodically as ray-identification techniques improve. Um, what should companies building or deploying AI systems actually change starting now?
SPEAKER_01
Antonio, this is the trickiest element. It is true that uh technology evolves, especially in the last years. Uh, we have had a look how AI systems have been quickly evolving. We're doing now something that uh was uh totally uh unforeseeable two years ago. Having uh your database is information that now is not personal data and might become personal data makes uh the burden for companies processing that information very hard to manage because um then I should run a sort of audit on that uh information periodically, and uh, what is the time span that uh is relevant? It might be a year, but it really depends because in a year at the age of AI the perspective could be completely changed. So definitely companies need to put in place a procedure to reassess anonymization. How long the assessment has to be performed should be analyzed periodically based on the evolution of the technologies.
SPEAKER_00
The public consultation stays open until October 30, 2026. If an organization has time for just one concrete action before then, what should it be?
SPEAKER_01
What I do believe is more relevant is to have uh the concept of anonymization more precise, more straightforward, because I need to be certain that I'm not processing personal data. It is true that um rules around privacy are principle-based, so there will be uh no case where there is a situation of black or white, but companies in order to run the business need rules that are more precise. So there should be a sort of shift from a purely principle based methodology to something that uh companies can more easily implement in their operations so that once the test is completed, then they can move forward more easily.