Assistant lawyers Paulina Patašiūtė and Erlandas Prakapavičius compiled the material.
Data protection / data & tech
EDPB adopts guidelines on anonymisation and web scraping for generative AI and processing personal data through blockchain technologies
Adopted: 8 July 2026
The European Data Protection Board (EDPB) adopted new guidelines clarifying the concept of anonymous data under the GDPR, taking into account recent CJEU case law. The guidelines introduce a practical framework for assessing whether data can be considered anonymous, based on three criteria: no record isolation, no linkage and no inference.
The EDPB also adopted guidelines on web scraping in the context of generative AI, providing guidance on GDPR-compliant data collection for AI training, including legal bases for processing, transparency obligations, data minimisation requirements and the treatment of special categories of personal data. The Board emphasised that web scraping involving personal data remains fully subject to GDPR requirements and that special category data may only be processed where both Articles 6 and 9 GDPR are satisfied.
In addition, the EDPB finalised its guidelines on the processing of personal data through blockchain technologies following public consultation. The guidelines provide practical guidance on GDPR compliance when deploying blockchain-based solutions and assess the data protection implications of different blockchain architectures.
See also press release
Court of Justice rules that placing criminal conviction decisions online for payment does not in principle constitute processing for journalistic purposes under GDPR
Ruled: 9 July 2026
The Court of Justice of the European Union held that the publication of criminal conviction decisions online in return for payment does not, in principle, constitute processing of personal data for “journalistic purposes” under the GDPR. As a result, operators of such databases cannot automatically benefit from GDPR exemptions and derogations available to journalistic activities.
The Court further ruled that Member States cannot exclude the application of the GDPR and leave affected individuals solely with remedies based on defamation law. Individuals must retain access to the rights and remedies guaranteed under the GDPR, including the right to lodge complaints with supervisory authorities, seek judicial remedies and claim compensation for unlawful processing of personal data.
According to the Court, processing may qualify as being carried out for journalistic purposes only where its objective is to inform the public, the content is prepared in accordance with journalistic standards or editorial policies, and the underlying information has been subject to verification. The mere commercial publication of criminal conviction decisions does not appear to satisfy these conditions.
See also press release
DMA: Apple’s actions challenging its designation as gatekeeper for App Store and iOS, dismissed by General Court
Ruled: 8 July 2026
The General Court dismissed Apple’s challenge against the European Commission’s decision designating Apple as a gatekeeper under the Digital Markets Act (DMA) in relation to the App Store and the iOS operating system. The Court confirmed the Commission’s assessment that the various App Store versions across Apple devices constitute a single core platform service and therefore meet the DMA thresholds applicable to gatekeepers.
The Court also ruled that Apple’s challenges concerning the iMessage service were inadmissible. While iMessage was classified as a core platform service, it was not ultimately designated as an important gateway and therefore was not subject to DMA obligations. As a result, the classification alone did not produce legal effects capable of being challenged before the Court.
The judgment represents one of the most significant judicial endorsements of the European Commission’s DMA enforcement framework to date and strengthens the legal basis for imposing obligations on large digital platform operators designated as gatekeepers.
See also press release
Court of Justice upholds Commission’s fine of approximately €4.1 billion imposed on Google Search for abuse of dominant position
Ruled: 2 July 2026
The Court of Justice of the European Union dismissed Google and Alphabet’s appeal and upheld the €4.125 billion fine imposed for abuse of a dominant position in relation to the Android operating system. The Court confirmed that Google’s contractual arrangements requiring the pre-installation of Google Search and Chrome, as well as restrictions on competing Android versions, unlawfully strengthened Google’s dominance in the online search market.
The Court also confirmed that the General Court correctly found the practices to be capable of restricting competition without requiring proof that equally efficient competitors would necessarily have been excluded. In addition, it upheld the finding that Google’s anti-fragmentation agreements limited the development of alternative Android ecosystems and reinforced barriers to entry for competitors.
The judgment represents one of the most significant EU competition law rulings in the digital sector and provides further judicial support for the European Commission’s enforcement strategy against dominant technology platforms.
See also press release
Commission preliminarily finds the addictive design of Instagram and Facebook in breach of the Digital Services Act
Announced: 10 July 2026
The European Commission preliminarily found that Meta may be in breach of the Digital Services Act (DSA) due to the allegedly addictive design of Instagram and Facebook. The investigation focuses on features such as infinite scroll, autoplay, push notifications and highly personalised recommender systems, which the Commission believes may encourage compulsive use, particularly among minors and vulnerable users.
According to the Commission, Meta failed to adequately assess and mitigate the risks that these design features pose to users’ physical and mental wellbeing. The Commission also considers that existing mitigation measures, including screen-time management tools and parental controls, are insufficient to effectively address those risks. As part of its preliminary findings, the Commission suggested that Meta may need to implement design changes, including disabling autoplay and infinite scroll by default, introducing effective screen-time breaks and reducing the engagement-driven nature of its recommender systems.
If the preliminary findings are confirmed, the Commission may adopt a non-compliance decision and impose fines of up to 6% of Meta’s worldwide annual turnover.
See also press release