Artificial intelligence models at the crossroads of new European rules and the GDPR.
On July 11, the European Data Protection Board adopted—in a version for public consultation—new Guidelines (02/2026) on anonymization.
The timing appears far from coincidental: the document arrives just as European institutions—having approved certain amendments to the AI Act—are set to revisit the “Digital Omnibus.” This initiative proposes simplifying measures regarding specific aspects of the GDPR that are particularly relevant to the AI industry, specifically the boundary between personal data and anonymous data.
This distinction determines whether a dataset used to train an AI model remains subject to the GDPR—entailing compliance with obligations such as the legal basis for processing, transparency notices, and data subject rights—or falls outside its scope.
The guidelines aim to update Opinion 5/2014 of the former Article 29 Working Party—which served as the primary reference point for over a decade—in light of the Court of Justice’s increasingly nuanced case law. This evolution culminated in the recent *EDPS v SRB* judgment, which reaffirmed that the assessment of anonymity must be based on the perspective of the party regarding whom the data subject’s identifiability is being evaluated, rather than on an absolute or abstract judgment. This is the first point the EDPB highlights in the document: anonymity is not an intrinsic property of the data itself but describes a relationship between the data and the entity holding or potentially accessing it.
Consequently, the same dataset may be considered personal data by one party and anonymous by another, depending on the means "reasonably likely to be used" by each. For companies developing artificial intelligence systems—which frequently share datasets with partners and other entities—this means that mapping out these relevant perspectives becomes an essential step in ensuring compliance.
At the heart of the guidelines lies the three-criterion paradigm (no record isolation, no linkage, no inference), which reformulates and refines three tests already established (singling out, linkability, and inference) in the 2014 opinion. A significant development for the artificial intelligence sector is the extensive treatment of inference: the Committee acknowledges that de-aggregation techniques and model attacks can extract personal information not only from raw data but also from synthetic datasets or statistical correlations. This serves as a signal to those who believe that using synthetic data—or models with opaque internal workings—places them outside the scope of the GDPR. The Digital Omnibus builds upon these foundations. To be continued.
Marco Bassini, Professor of AI and Fundamental Rights, Tilburg University; Oreste Pollicino, Professor of Constitutional Law and AI Regulation, Bocconi University.
Translation performed by an AI assistant.
Leggi anche:

