Daily Briefing
2026-07-10

July 10, 2026

28 signals · generated 08:01 UTC

European regulatory output on AI and data processing reached a significant threshold this week. The EDPB adopted final guidelines on anonymisation standards, web scraping practices for generative AI training, and blockchain data processing — establishing the most concrete GDPR-grounded compliance framework to date for organisations building or deploying AI systems on EU-sourced data. Simultaneously, the European Parliament voted on July 9 to reinstate the interim ePrivacy derogation allowing voluntary scanning of private communications for child sexual abuse material, restoring a legal basis that had lapsed. Together, these two actions materially reshape the operating environment for technology firms with EU data exposure and signal that EU institutions are moving on multiple fronts — hardening AI data standards while reviving contested surveillance permissions.

The EDPB's anonymisation and web scraping guidelines carry immediate compliance weight. Controllers and processors training generative AI models on scraped EU data must now assess their pipelines against the Board's updated positions on when anonymisation thresholds are met and when scraping constitutes lawful processing. The concurrent finalisation of blockchain guidelines closes a further gap in GDPR interpretation for distributed ledger applications. Organizations that have operated under informal assumptions in these areas should treat the adoption date as the start of a remediation window.

Watch level: PREPARE (AI developers and deployers with EU data pipelines, blockchain application operators, DPOs)

The European Parliament's revival of Chat Control 1.0 — reinstating voluntary, indiscriminate scanning of private communications — warrants close attention from compliance and policy teams. The derogation, restored without the legislative scrutiny critics argue the measure requires, extends an interim regime that was always contested on proportionality grounds. The broader Chat Control 2.0 proposal, which would mandate scanning, remains deadlocked in Council. The gap between a lapsed derogation and a mandatory regime is now refilled by this vote, creating continued legal uncertainty for encrypted messaging and communications service providers operating under the ePrivacy Directive.

Watch level: MONITOR (encrypted communications providers, EU policy counsel, civil liberties practitioners)

The US House passed the KIDS Act by a 267–117 margin, sending consolidating internet regulation legislation to a Senate where opposition is already organised. The bill bundles age-verification and age-gating mandates across online platforms; critics including the EFF contend the age-determination mechanisms required will necessitate collection of government IDs or biometrics, creating structural privacy risks that undercut the bill's child-safety rationale. The Senate path remains genuinely uncertain. Compliance teams at platform operators should begin assessing the bill's technical requirements now, given the compressed implementation timelines that age-verification mandates have historically imposed once enacted.

Watch level: PREPARE (online platform operators, app stores, child safety compliance teams, platform policy counsel)

Three EU enforcement and institutional developments warrant tracking by legal and compliance teams. The CJEU ruled in Case C-199/24 that commercial publication of criminal conviction records for payment does not qualify as journalistic processing under GDPR Article 85, narrowing the exemption and elevating commercial motive as a disqualifying factor — operators of legal data or court records services across the EU must assess their publication models against this standard. Separately, the European Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice for NIS2 transposition failures, now more than 20 months past the implementation deadline, exposing those states to financial penalties and sustaining regulatory fragmentation for cross-border critical infrastructure operators. The EDPB and the Anti-Money Laundering Authority also announced joint guidelines on information-sharing partnerships, directly addressing the longstanding tension between AML data-sharing obligations and GDPR requirements — a development financial institutions should monitor closely.

Watch level: PREPARE (legal data publishers, court records services — CJEU ruling); MONITOR (critical infrastructure operators in IE/ES/FR/NL — NIS2 referrals; AML compliance teams, financial institution DPOs — EDPB/AMLA initiative)

Two US enforcement actions signal continued federal scrutiny of consumer-facing data practices. The FTC settled with RentGrow, a tenant screening agency, for $2.25 million over FCRA violations including duplicate records and inadequate data accuracy procedures — reinforcing the agency's focus on housing-sector consumer reporting at a moment when its broader enforcement posture is under scrutiny. A bipartisan coalition of state attorneys general separately reached a $45 million settlement with Block, Inc. over allegations that Cash App misrepresented its security protections to users, signalling coordinated multistate enforcement pressure on non-bank fintech platforms that imply bank-equivalent consumer safeguards without delivering them. Both actions provide concrete reference points for compliance reviews in their respective sectors.

Watch level: PREPARE (tenant screening firms, background check providers — RentGrow/FCRA; fintech platforms, neobanks, peer-to-peer payment services — Block/Cash App)

Top Signals

🇪🇺standards
EDPB Finalises AI Web Scraping and Anonymisation Guidelines Under GDPR
🇪🇺legislation
European Parliament Reinstates Voluntary CSAM Scanning Derogation Under ePrivacy Directive
🇺🇸legislation
US House Passes KIDS Act; Senate Opposition Signals Contested Path
🇪🇺litigation
CJEU Narrows GDPR Journalism Exemption for Commercial Criminal Records Publication
← Older
July 9, 2026
Newer →
July 13, 2026
← Briefing ArchiveLive Dashboard →

Policy Signal · policysignalhq.com · Major privacy + AI governance moves, distilled.