General

The Guidelines 03/2026 on web scraping in the context of generative AI, adopted by the European Data Protection Board “EDPB” for public consultation on 7 July 2026, are notable not only for what they require but for what they acknowledge. The document is unusually candid about three limitations: an epistemic one (the controller may not always know what it has collected), a technical one (what a model has learned cannot, today, be easily unlearned), and an institutional one (some of the assessments woven into the GDPR analysis sit, at least in part, with other authorities and courts). These acknowledgements are welcome, and they distinguish the text from more declaratory guidance. The tension is that the requirements built on top of them are not always adjusted accordingly, and that gap, between what the EDPB admits and what it nonetheless requires, is where the most interesting questions of the consultation lie.

Briefly, the Guidelines cover scraping performed by private entities, whether carried out in-house, commissioned from a third party or effected through the acquisition of pre-scraped datasets. They work through the familiar sequence: allocation of controller and processor roles, the core principles of Article 5 GDPR (purpose limitation, transparency, minimization, accuracy), the choice of legal basis, with legitimate interest under Article 6(1)(f) GDPR treated as the realistic candidate and consent all but discarded, and the treatment of special categories of data incidentally swept up in the collection, for which the EDPB adapts the CJEU’s GC & Others framework. Little of this structure will surprise anyone who has followed the Board’s recent work on AI. What rewards attention is how each of these familiar steps is made to function once the three limitations above enter the analysis.

Continue Reading Regulating the Irreversible: The EDPB’S Web Scraping Guidelines and the Limits of GDPR Orthodoxy

We are proud to celebrate the recognition of 10 attorneys in Lawdragon’s 2026 500 Leading Global Cyber Lawyers Guide, a prestigious listing that honors lawyers at the forefront of privacy, cybersecurity, data protection, incident response, and related regulatory and litigation matters. Lawdragon’s guide recognizes leaders who help organizations navigate an increasingly complex digital landscape and

Recently, we hosted an intimate dinner in Los Angeles with a group of general counsels and senior executive leaders to discuss the evolving challenges posed by artificial intelligence (AI), data privacy and cybersecurity, particularly as they relate to HR and production environments. The roundtable discussion was dynamic and insightful, reflecting the real-world risks and strategic

The UK’s data protection framework continues to evolve following the enactment of the Data (Use and Access) Act 2025 (DUAA). One of the more operationally significant developments for organisations is the introduction of a new statutory right for individuals to complain to controllers regarding infringements of the UK General Data Protection Regulation (GDPR), as well as a framework governing how controllers must handle those complaints.

The relevant provisions will apply from 19 June 2026, pursuant to the Data (Use and Access) Act 2025 (Commencement No. 6) Regulations 2026. On or before that date, organisations subject to the UK GDPR will need to update their privacy notices, and introduce formal data protection complaint handling processes that meet specific legal requirements.

Continue Reading The Data (Use and Access) Act 2025 and the new right for individuals to complain to controllers: What organisations need to do before 19 June 2026

SPB’s Alan Friel has previously explained here and here how consumer privacy law and online teen safety laws can go too far and be constitutionally suspect.  This issue has heated up in the courts as states rush to regulate. 

In a recent Network Advertising Initiative panel Alan moderates a speaker from Netchoice, an industry advocacy

Join the Los Angeles County Bar Association’s (“LACBA”) Privacy & Cybersecurity Section on May 21, 2026 (6:30–8:00 PM) at the Jonathan Club in Downtown Los Angeles for “Protecting Consumers & Promoting Innovation in a Data-Driven Economy.” The program features FTC Bureau of Consumer Protection Director, Chris Mufarrige, who will discuss evolving consumer protection enforcement priorities