Legislative and regulatory pressure on AI data practices converged on both sides of the Atlantic on July 14, with the US House passing sweeping age-verification mandates and the EDPB publishing long-awaited guidance that directly constrains how AI developers may source and classify training data under GDPR. The alignment is not coincidental: both moves reflect intensifying institutional concern about children's exposure to digital systems and about the data pipelines sustaining generative AI — concerns that now carry real compliance deadlines.
The EDPB's new guidance on anonymisation and web scraping for generative AI is the more immediately actionable development for international technology operators. The Board's positions on anonymisation determine whether GDPR applies at all to training datasets — a threshold question for every AI developer processing data from EU residents. Its web scraping clarifications will shape what data sourcing practices remain defensible. Blockchain guidelines adopted alongside this output add a further layer of certainty to an area that has been technically contested. Organizations should begin gap assessments against these positions now, before supervisory authorities apply them in enforcement.
Watch level: PREPARE (generative AI developers, data governance counsel, DPOs with EU exposure)
The House passage of the KIDS Online Safety Act package (H.R. 7757) by 267–117 advances age-verification obligations into the Senate, where the bill's trajectory remains genuinely uncertain. The core compliance tension the Electronic Frontier Foundation and others have articulated is structural: any technically functional age-gating system requires collection of sensitive identity data from all users, not only minors. That tradeoff creates potential conflicts with existing state privacy frameworks in California, Colorado, and Virginia, as well as COPPA. Senators should expect intensive opposition advocacy in the coming weeks.
Watch level: MONITOR (platform operators, ad-tech, children's privacy counsel, US state privacy teams)
The FTC's $2.25 million settlement with tenant screening firm RentGrow reinforces a pattern of FCRA enforcement targeting accuracy failures in consumer reporting. The agency found RentGrow reported duplicate records and omitted required source disclosures — both longstanding obligations that the settlement makes clear remain live enforcement priorities. This action follows the FTC and state AG parallel enforcement noted in the prior briefing and confirms that housing-sector consumer reporting agencies are under active scrutiny. Background screening vendors and their legal teams should treat accuracy procedure audits as an immediate operational matter.
Watch level: PREPARE (tenant screening CRAs, proptech compliance teams, housing-sector counsel)
The announced EDPB–AMLA joint guidelines on information-sharing partnerships represent a structural development for compliance teams operating across privacy and financial crime regimes simultaneously. Formal coordination between EU data protection and anti-money laundering supervisors has been absent despite years of tension between GDPR's data minimisation principles and AML's information-sharing imperatives. The guidelines are not yet published, but the signal is clear: future information-sharing architectures will need to satisfy both supervisory frameworks, and firms building or revising those arrangements should track the drafting process closely. Financial institutions, fintechs, and their technology partners with cross-border EU operations are the primary audience.
Watch level: MONITOR (EU financial institutions, fintech compliance, AML and DPO functions)
Policy Signal · policysignalhq.com · Major privacy + AI governance moves, distilled.