EDPB Publishes Draft Guidelines on Anonymisation
On 7 July 2026, the European Data Protection Board published its long-awaited draft Guidelines 02/2026 on Anonymisation. The draft Guidelines – which are intended, once finalised, to replace the former Article 29 Working Party’s Opinion 05/2014 on Anonymisation Techniques – adopt a “relative” approach to identifiability, as endorsed by the EU Court of Justice in the EDPS v SRB case. The practical consequence is that the same dataset can be considered personal data for one party and anonymous for another (i.e., anonymity is not an intrinsic property of the data itself but depends on who holds it and what they can realistically do with it). Organisations that work with data they regard as anonymised (e.g., training AI models or sharing research datasets) may find the draft Guidelines a helpful reference point for reviewing and strengthening existing practices.

What Do the European Data Protection Board’s Web Scraping Guidelines Mean for AI Training Datasets?
On July 7, 2026, the European Data Protection Board (EDPB) published draft guidelines on web scraping for generative AI (Guidelines). The Guidelines are intended to provide practical GDPR guidance in one of the more complex areas of AI development and will be of direct relevance to any organization building or procuring generative AI systems trained on internet-sourced data.

EU AI Act Transparency Obligations: Preparing for Compliance by 2 August 2026
From 2 August 2026, organisations will become subject to the transparency obligations set out in Article 50 of the EU AI Act (Regulation (EU) 2024/1689).
Article 50 introduces transparency requirements for providers and deployers in relation to certain AI system functionalities and use cases that may create transparency risks for individuals. Whilst much of the EU AI Act focusses on obligations on high-risk AI systems, Article 50 obligations may also apply to certain limited-risk systems. As a result, many organisations will need to implement governance, disclosure and content-labelling measures to ensure users are appropriately informed about the use of certain AI systems and AI-generated content.
EU Lawmakers Reach Provisional Agreement to Delay Key EU AI Act Obligations
On 7 May 2026, following extensive negotiations, the European Council and European Parliament reached a provisional agreement on the EU Digital Omnibus on AI (AI Omnibus) which proposes targeted amendments to the EU Artificial Intelligence Act (AI Act). On 16 June 2026, the European Parliament voted to adopt the provisional agreement — although, formal adoption remains subject to European Council approval.

Scientific Research and the GDPR: EDPB Issues Long-Awaited Guidelines
On 15 April 2026, the European Data Protection Board (“EDPB”) published its long-awaited draft Guidelines 1/2026 on the processing of personal data for scientific research purposes (the “Guidelines”), marking the most comprehensive regulatory statement to date on how the GDPR applies to scientific research activities.
European Biotech Act I: Navigating the EDPB/EDPS Vision for the Future of Clinical Trials
On 12 March 2026, the European Data Protection Board (“EDPB”) and the European Data Protection Supervisor (“EDPS”) issued a Joint Opinion (the “Joint Opinion”) on the proposed European Biotech Act I (the “Biotech Act”). The Joint Opinion broadly supports the EU’s ambition to strengthen its biotechnology sector. However, it emphasises that data protection safeguards must be tightened, particularly where health data is involved. The recommendations signal forthcoming scrutiny during the legislative process and highlight key compliance considerations for organisations involved in clinical trials.
UK Operational Incident and Third-Party Reporting Rules: What Firms Should Do Now
The Financial Conduct Authority (FCA) has published Policy Statement PS26/2 together with final guidance in FG26/3 and FG26/4. The Prudential Regulation Authority (PRA) has also published PS7/26 alongside Supervisory Statement SS1/26 and an update to SS2/21. PS26/2 and PS7/26 introduce a new UK framework for reporting serious operational incidents and material third-party arrangements. The framework was developed by the FCA, PRA, and the Bank of England and is intended to give the regulators better visibility of operational disruption and third-party dependencies and to support a more data-driven supervisory approach.

Geopolitics and Cybersecurity: Japan and the UK Announce Strategic Cyber Partnership Among Growing Global Focus on Privacy and Cyber Risks Posed by Foreign Actors
On January 31, 2026, the governments of Japan and the United Kingdom announced they were strengthening their cybersecurity collaboration through a bilateral Strategic Cyber Partnership (Partnership).
UK Data Privacy and Cybersecurity Outlook for 2026: What Financial Services Firms Need To Know
Last year saw many developments across the international data privacy and cybersecurity landscape, and this momentum shows no sign of slowing.
EU Court of Justice Issues Landmark Judgment on Concept of “Personal Data”
On 4 September 2025, the EU Court of Justice (the “CJEU”) issued a landmark ruling in SRB v. EDPS confirming that pseudonymous data is not automatically personal data in all cases (the “SRB Case”). Instead, the key question is whether the controller can realistically re-identify the individual. This judgment is expected to have a significant impact on instances where effective technical and/or organisational measures prevent re-identification by the controller. Importantly, although the ruling arose under EU Regulation 2019/1725 – i.e., the EU data protection law applicable to EU Institutions (such as the Commission) – the CJEU confirmed that the same interpretation applies under the General Data Protection Regulation (the “GDPR”).

