EDPB 02/2025
Guidelines 02/2025 on processing of personal data through blockchain technologies
What it covers
This document examines how GDPR principles apply to the processing of personal data through blockchain technologies, describing blockchain architecture, the identification of controllers and processors in decentralised governance, and how data protection principles, lawfulness, international transfers, retention, security and data subject rights can be addressed when data is recorded on a distributed ledger.
Why it matters
It addresses the tension between blockchains' immutable, append-only design and GDPR requirements such as erasure and storage limitation, giving organisations deploying blockchain technology practical mitigation measures.
Refer to it when
- assessing GDPR compliance of a proposed blockchain application
- identifying controllers and processors among blockchain participants
- designing on-chain/off-chain data architecture to limit personal data exposure
- handling erasure or rectification requests for blockchain-recorded data
Questions this document addresses
- Who is the controller in a permissioned or permissionless blockchain?
- How can personal data minimisation be achieved on an append-only ledger?
- What technical measures can substitute for erasure on a blockchain?
- What legal basis can support processing personal data via smart contracts?
Topics
- Blockchain
- Data protection by design
- Controller & processor
- International transfers
- DPIA & high-risk processing
Addresses data protection in blockchain systems: identifying controllers, storage choices, data minimisation, legal bases, transfers, security and how to give effect to erasure and rectification on immutable ledgers.
Mapped GDPR Articles
Reproduced from official EDPB publications for reference. Not legal advice.