Guidelines 02/2025 on processing of personal data through blockchain technologies

For the purposes of the following analysis, the EDPB considers the following blockchain components: the block data structure describing the data fields retained in blocks and any other data on-chain storage (accounts, smart contract storage, receipt logs, etc); the consensus algorithm describing the conditions to append and verify blocks; communication networks for an exchange of information among users; ecosystem to interact with the blockchain, like user access tools (e.g. The GDPR defines the data controller as the entity “which, alone or jointly with others, determines the purposes and means of the processing of personal data”16, while the processor is defined as “a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller”17. The governance framework often defines a set of policies, technologically-enforced or not, as well as technical requirements (such as formats, protocols, algorithms, implementations, updates, etc.) and organisational and legal requirements (such as the accountability requirements, contractual obligations among participants, management of inconsistencies and violations, data protection by design approaches, among others). Controllers are reminded that, according to Article 25(2) GDPR, technical and organisational measures shall ensure “(…) that by default personal data are not made accessible without [the data subject’s] intervention to an indefinite number of natural persons.” This requirement applies to the storing of personal data on both public and non-public blockchains. Measures and safeguards implementing the principle of fairness also support the rights and freedoms of data subjects, specifically the right to information (transparency), the right to intervene (access, erasure, data portability, rectify) and the right to limit the processing (right not to be subject to automated individual decision-making and non-discrimination of data subjects in such processes). A blockchain might also be used where the processing operation is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject to whom the personal data refer in line with Article 6(1)(f) GDPR36 37 38.

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source