GuidelinesFinal · v2.0Adopted 2026-07-07

EDPB 02/2025

Guidelines 02/2025 on processing of personal data through blockchain technologies

What it covers

This document examines how GDPR principles apply to the processing of personal data through blockchain technologies, describing blockchain architecture, the identification of controllers and processors in decentralised governance, and how data protection principles, lawfulness, international transfers, retention, security and data subject rights can be addressed when data is recorded on a distributed ledger.

Why it matters

It addresses the tension between blockchains' immutable, append-only design and GDPR requirements such as erasure and storage limitation, giving organisations deploying blockchain technology practical mitigation measures.

Refer to it when

  • assessing GDPR compliance of a proposed blockchain application
  • identifying controllers and processors among blockchain participants
  • designing on-chain/off-chain data architecture to limit personal data exposure
  • handling erasure or rectification requests for blockchain-recorded data

Questions this document addresses

  • Who is the controller in a permissioned or permissionless blockchain?
  • How can personal data minimisation be achieved on an append-only ledger?
  • What technical measures can substitute for erasure on a blockchain?
  • What legal basis can support processing personal data via smart contracts?

Topics

  • Blockchain
  • Data protection by design
  • Controller & processor
  • International transfers
  • DPIA & high-risk processing

Official EDPB page for this document

Addresses data protection in blockchain systems: identifying controllers, storage choices, data minimisation, legal bases, transfers, security and how to give effect to erasure and rectification on immutable ledgers.

Inline PDF preview is not supported in this browser. Open the PDF instead.

Mapped GDPR Articles

Reproduced from official EDPB publications for reference. Not legal advice.