CNIL clears AI web scraping under strict GDPR conditions

On 19 June 2025, the CNIL confirmed that scraping publicly accessible data for AI development is not inherently prohibited. The legal basis is legitimate interest, subject to rigorous necessity and proportionality checks. The guidance is soft law, not binding regulation, but it carries authoritative weight.
The CNIL builds explicitly on EDPB Opinion 28/2024, which had already recognized the same legal basis with strict conditions. Clifford Chance notes the CNIL goes further by providing more detailed operational instructions and placing less emphasis on consent. That shift matters: it moves the compliance burden from obtaining permission to documenting justification.
For Dutch AI developers and operators scraping European web data, this guidance sets a practical floor. Expect Dutch regulators to reference both the EDPB opinion and CNIL guidance when assessing training pipelines. The question is no longer whether scraping is permitted. The question is whether your necessity assessment holds up under review.