Entries by Francesca Blythe

EDPB Publishes Draft Guidelines on Anonymisation

On 7 July 2026, the European Data Protection Board published its long-awaited draft Guidelines 02/2026 on Anonymisation. The draft Guidelines – which are intended, once finalised, to replace the former Article 29 Working Party’s Opinion 05/2014 on Anonymisation Techniques – adopt a “relative” approach to identifiability, as endorsed by the EU Court of Justice in the EDPS v SRB case. The practical consequence is that the same dataset can be considered personal data for one party and anonymous for another (i.e., anonymity is not an intrinsic property of the data itself but depends on who holds it and what they can realistically do with it). Organisations that work with data they regard as anonymised (e.g., training AI models or sharing research datasets) may find the draft Guidelines a helpful reference point for reviewing and strengthening existing practices.

EU Lawmakers Reach Provisional Agreement to Delay Key EU AI Act Obligations

On 7 May 2026, following extensive negotiations, the European Council and European Parliament reached a provisional agreement on the EU Digital Omnibus on AI (AI Omnibus) which proposes targeted amendments to the EU Artificial Intelligence Act (AI Act). On 16 June 2026, the European Parliament voted to adopt the provisional agreement — although, formal adoption remains subject to European Council approval.

Preparing for the UK’s New Data Protection Complaints Regime: Key Steps Before June 2026

The Data (Use and Access) Act 2025 (“DUAA”) has made a number of changes to the UK’s data protection regime, many of which have already come into force. From 19 June 2026, organisations will need to implement or update their data protection complaints procedure to align with the new DUAA requirements which provide a mechanism for complaints made directly to a controller. This new requirement is supported by recent guidance from the UK Information Commissioner’s Office (“ICO”). This marks a shift towards a more formalised, controller-led complaints-handling framework, requiring organisations to treat certain expressions of dissatisfaction as regulated complaints with defined procedural obligations.