Watch · Blockchain & GDPR

Videos

Short, practical explainers on how blockchain and the GDPR fit together. Privacy-friendly: nothing is loaded from YouTube until you click play — the preview below is a local image served from this site.

New EDPB anonymisation guidelines — and how they read EDPS v SRB

The new EDPB draft Guidelines on Anonymisation heavily discuss EDPS v SRB, and the EDPB moves closer to the law as the CJEU reads it. The EDPB recognises a risk-based definition of personal data and that a possible, but prohibited, identification can render data non-personal.

Summary & sources

The EDPB’s new draft anonymisation guidelines cite the CJEU judgment in EDPS v SRB 14 times – in the blockchain guidelines, revised the very same day, they don’t cite it once.

This development says a lot: the CJEU’s judgment has finally made an impact at the EDPB.

What changed, and where does the EDPB still not follow the Court:

  • From absolute to relative: the EDPB now frames identifiability as a question of likelihood, assessed per entity, and it’s the risk-based reading that gives the relative definition its bite.
  • The circular processor argument it shares with the Danish DPA: data is personal because the entity is a processor, and it’s a processor because the data is personal. A genuine catch-22.
  • Breyer’s “prohibited identification” limb: after ten years the EDPB finally takes it up, only to downgrade a statutory ban to a merely rebuttable presumption.
  • It softens the Court’s wording: the CJEU said pseudonymised data “must not be regarded as constituting, in all cases and for every person, personal data.” The guidelines only concede that data can be anonymous “for some entities, but not for others.” Same direction, weaker message.

The trench between Europe’s top court and its data protection authorities has narrowed — good news for privacy-friendly decentralised technology. But the two are still far from aligned.

EDPS v SRB — Part 1: Why it is relevant for blockchains

Pseudonymised data, the relative concept of personal data, and hashes on-chain.

Summary & sources

Are pseudonymised data always "personal data"? In EDPS v SRB the CJEU's reasoning says: not always and not for everyone. For a recipient who genuinely cannot re-identify — because the data are traceable only via the original data held elsewhere — pseudonymised data can fall outside the GDPR. The same logic fits a hash on a blockchain: used only for verification, it can be linked to a person only by someone who already holds the full original data — so it adds no new identifiability, as long as the input has enough entropy.

EDPS v SRB — Part 2: How regulators react to it

How Bavaria, Denmark and France read the ruling — and what it means in practice.

Summary & sources

Supervisory authorities are hesitant to apply the EDPS v SRB ruling. In Bavaria, the BayLfD tends to apply the old test; in Denmark, the Datatilsynet argues — potentially circular — with the processor/controller situation; and in France, the CNIL and the Conseil d'État do not apply it where identification is still possible.

Is a hash personal data? Verification artefacts under the GDPR

eIDAS certificates, hashes, commitments and zero-knowledge proofs — and why the EDPB’s draft blockchain guidelines get decentralised verification backwards.

Summary & sources

Is an artefact that only lets you verify a document containing personal data itself “personal data”? Under eIDAS, a qualified certificate makes a document verifiable without adding information about anyone — and data protection authorities agree it is not personal data. For decentralised artefacts (a hash, a commitment, a zero-knowledge proof) the EDPB’s draft blockchain guidelines take the opposite view. Yet the structure is the same, and decentralised verification is the more privacy-friendly design: it does not phone home to a central authority the way certificate-revocation checks (OCSP/CRL) can. In EDPS v SRB the CJEU made clear that such an expansive reading of personal data is not supported by the GDPR — the CJEU interprets the law, the EDPB’s guidance does not.

Do public blockchains transfer data to third countries?

Lindqvist (CJEU, C-101/01): why publishing on the internet is not a Chapter V transfer.

Summary & sources

Public blockchains replicate to nodes worldwide — so does putting data on-chain trigger the GDPR's Chapter V transfer rules? Following the CJEU's Lindqvist ruling: no. Publishing or making data accessible online is not, by itself, a transfer to a third country — and it does not matter where the server is located. Otherwise, every web publication would be a transfer to every country on earth. You still need a legal basis to publish personal data, but global replication alone does not trigger Chapter V.