GDPR & AI Act News: key takeaways from July
July saw no slowdown in regulation: the CNIL ruled on email tracking (consent is mandatory unless strictly necessary for technical purposes), the AI Act entered a key phase with new transparency obligations for General Purpose AI (GPAI) models, the EDPB set strict criteria for defining anonymized data in AI training, and transfers to the US remain under legal scrutiny. This recap details the key points and concrete actions to integrate for the new season.

July is often seen as a month for vacations and operational slowdowns. However, on the front of data protection and emerging technology regulation, the summer offers no pause. Between the definitive clarification of rules on email tracking, the progressive entry into force of AI Act obligations for general-purpose models, and renewed tensions over training data governance, this July requires DPOs, CISOs, and legal departments to stay the course.
Here is the essential regulatory, privacy, and AI news you shouldn't have missed this month, decoded to guide your priorities for the return.
Email tracking: The CNIL ends the gray area
Key takeaways
The CNIL has published a long-awaited clarification on the use of invisible pixels and tracking markers inserted into HTML emails. By linking this practice to the requirements of Article 82 of the French Data Protection Act and the guidelines on cookies and other trackers, the authority reiterates that individual measurement of opens and clicks for behavioral or marketing analysis purposes does not benefit from any exemption. It requires prior, free, specific, and informed consent from the recipient.
Only trackers strictly necessary for providing the service (such as technical verification of deliverability or management of bounce-backs) are exempt from this obligation.
This clarification marks the end of a certain operational ambiguity in digital marketing. For organizations, the challenge goes beyond simple regulatory compliance: it is about initiating a transition toward data sobriety. Rather than accumulating intrusive individual indicators, the trend is shifting toward aggregated measurement and contextualized evaluation.
Our advice: take advantage of back-to-school campaign planning to audit your mailing tools (CRM, newsletters) and evaluate the relevance of your engagement metrics in light of the data minimization principle (Article 5.1.c of the GDPR)
AI Act: The starting gun for General Purpose AI (GPAI) and transparency
Key takeaways
The implementation timeline for the European Artificial Intelligence Act (AI Act) has reached a pivotal stage. The European Commission and the AI Office have finalized the publication of guidelines and orientations regarding the transparency of AI systems and General Purpose AI (GPAI) models.
These provisions now require providers of general-purpose models to:
- Provide detailed technical documentation on the model's operation and architecture
- Draft and publish a substantial summary of the training data used
- Demonstrate the implementation of a copyright compliance policy
For companies that are clients or integrators of generative AI solutions, this deadline serves as a powerful governance tool. The AI Act should not be viewed as a hurdle, but as a quality assurance framework. The transparency required of developers directly facilitates your Data Protection Impact Assessments (DPIAs) and your algorithmic risk mapping.
Our advice: Do not treat AI and GDPR as two separate silos. Demand transparency sheets and technical documentation from your service providers as early as the procurement or software renewal phase.
Web scraping and anonymization: the EDPB sets guidelines for training data governance
In response to the rise of mass data scraping practices used to feed algorithms, the European Data Protection Board (EDPB) has provided firm clarifications regarding the concepts of anonymization and the reuse of public data.
The EDPB reiterates a fundamental rule: the mere fact that data is publicly available on the internet does not strip it of its status as personal data. Furthermore, for a dataset to be classified as anonymous—and thus fall outside the scope of the GDPR—it must irreversibly meet three cumulative criteria: the impossibility of singling out, linking, and inferring.
At a time when the demand for data volume for machine learning is exploding, reliance on raw web scraping carries major legal and reputational risks for AI developers. The emergence of synthetic data and federated learning architectures is shaping the future of responsible, privacy-by-design AI.
Our advice: if your organization is developing or fine-tuning internal models, ensure the traceability and lawfulness of your initial dataset collection before beginning the training phase.
Cross-border transfers: ongoing vigilance regarding the Data Privacy Framework
The governance of data transfers to the United States continues to fuel legal debate. Although the Data Privacy Framework (DPF) remains fully in effect, recent discussions within European institutions and challenges brought by civil society highlight the structural fragility of adequacy mechanisms based on U.S. executive orders.
Beyond legal uncertainty, this issue reaffirms the strategic importance of digital sovereignty. Securing your data flows requires reducing reliance on extraterritorial hosting for your most critical processing activities.
Our recommendation: maintain an accurate map of your processors and cross-border flows in your record of processing activities. Prioritizing sovereign solutions ensures your organization's operational continuity, regardless of shifts in international case law.
Key takeaways for the new season: managing compliance in 3 areas
FAQ - July GDPR & AI Act updates
What does the CNIL's clarification on email tracking change?
Individual tracking of opens and clicks for marketing purposes now requires prior, free, specific, and informed consent, except for trackers strictly necessary for the service (deliverability, bounce management).
What obligations does the AI Act impose on General Purpose AI (GPAI) models?
Providers must publish detailed technical documentation, a substantial summary of training data, and demonstrate a policy for copyright compliance.
Can public data from the internet be considered anonymous?
No, according to the EDPB: public availability does not remove the status of personal data. To be classified as anonymous, data must irreversibly meet three cumulative criteria: no possibility of singling out, correlation, or inference.
Is the Data Privacy Framework still valid for transfers to the United States?
Yes, the DPF remains in effect, but legal challenges and institutional debates highlight the structural fragility of mechanisms based on U.S. executive orders.
How does DPO software help better manage these regulatory changes?
A platform like Adequacy centralizes the record of processing activities, automates DPIAs, and tracks AI Act requirements to manage compliance as regulations evolve.
Learn more
Looking to structure your record of processing activities, automate your DPIA management, or get ahead of the AI Act requirements? Discover how the Adequacy platform helps you manage your compliance with ease.
%20RGPD%20efficace%20.png)
