Short, practical explainers on how blockchain and the GDPR fit together. Privacy-friendly: nothing is loaded from YouTube until you click play — the preview below is a local image served from this site.
The new EDPB draft Guidelines on Anonymisation heavily discuss EDPS v SRB, and the EDPB moves closer to the law as the CJEU reads it. The EDPB recognises a risk-based definition of personal data and that a possible, but prohibited, identification can render data non-personal.
The EDPB’s new draft anonymisation guidelines cite the CJEU judgment in EDPS v SRB 14 times – in the blockchain guidelines, revised the very same day, they don’t cite it once.
This development says a lot: the CJEU’s judgment has finally made an impact at the EDPB.
What changed, and where does the EDPB still not follow the Court:
The trench between Europe’s top court and its data protection authorities has narrowed — good news for privacy-friendly decentralised technology. But the two are still far from aligned.
Pseudonymised data, the relative concept of personal data, and hashes on-chain.
Are pseudonymised data always "personal data"? In EDPS v SRB the CJEU's reasoning says: not always and not for everyone. For a recipient who genuinely cannot re-identify — because the data are traceable only via the original data held elsewhere — pseudonymised data can fall outside the GDPR. The same logic fits a hash on a blockchain: used only for verification, it can be linked to a person only by someone who already holds the full original data — so it adds no new identifiability, as long as the input has enough entropy.
How Bavaria, Denmark and France read the ruling — and what it means in practice.
Supervisory authorities are hesitant to apply the EDPS v SRB ruling. In Bavaria, the BayLfD tends to apply the old test; in Denmark, the Datatilsynet argues — potentially circular — with the processor/controller situation; and in France, the CNIL and the Conseil d'État do not apply it where identification is still possible.
eIDAS certificates, hashes, commitments and zero-knowledge proofs — and why the EDPB’s draft blockchain guidelines get decentralised verification backwards.
Is an artefact that only lets you verify a document containing personal data itself “personal data”? Under eIDAS, a qualified certificate makes a document verifiable without adding information about anyone — and data protection authorities agree it is not personal data. For decentralised artefacts (a hash, a commitment, a zero-knowledge proof) the EDPB’s draft blockchain guidelines take the opposite view. Yet the structure is the same, and decentralised verification is the more privacy-friendly design: it does not phone home to a central authority the way certificate-revocation checks (OCSP/CRL) can. In EDPS v SRB the CJEU made clear that such an expansive reading of personal data is not supported by the GDPR — the CJEU interprets the law, the EDPB’s guidance does not.
Lindqvist (CJEU, C-101/01): why publishing on the internet is not a Chapter V transfer.
Public blockchains replicate to nodes worldwide — so does putting data on-chain trigger the GDPR's Chapter V transfer rules? Following the CJEU's Lindqvist ruling: no. Publishing or making data accessible online is not, by itself, a transfer to a third country — and it does not matter where the server is located. Otherwise, every web publication would be a transfer to every country on earth. You still need a legal basis to publish personal data, but global replication alone does not trigger Chapter V.