The EDPB’s final guidance explains how blockchain projects can handle personal data without undermining the technology’s core benefits

Before artificial intelligence becam e the non-stop hot topic we know today, tech news was flooded with brand-new investment opportunities that you had supposedly already missed unless you had bought the latest meme coin or celebrity-endorsed NFT. Beyond the hype-train and the occasional Ponzi scheme laid a somewhat grey regulatory area regarding the underlying technology supporting a myriad of applications. The legislative gap was finally addressed by the adoption of the MiCA EU Regulation, in 2023. Nonetheless, such a complex issue as the blockchain technology was raising multiple concerns, one of which was addressed in July of this year by the European Data Protection Board (“EDPB“) in the finalised version of Guidelines 02/2025 on processing of personal data through blockchain technologies (“Guidelines“). 

Briefly, a blockchain is a distributed database in which transactions are recorded in linked blocks and replicated across multiple participants. The network uses agreed rules and a consensus mechanism to validate entries. Participation may be open or restricted. This architecture can deliver resilience, transparency and strong protection against undetected changes. Those same features, however, become challenging when information relates to an identifiable person.

GDPR-centric design

The EDPB does not say that blockchain and the GDPR are incompatible, but it does say that privacy cannot be treated as a patch added after launch. Before choosing blockchain, a project team should establish:

  • whether personal data will be processed;
  • why blockchain is needed instead of a conventional database;
  • which architecture offers the right level of control; and
  • what technical and organisational safeguards will apply.

Public, permissionless networks may make it harder to control access, identify responsible parties and manage data replicated outside the EU. Where personal data is involved, the EDPB therefore favours permissioned blockchains, which generally provide clearer governance and tighter access controls.

Off-chain data storage

Practically, the EDPB suggests avoiding storing personal data directly on-chain. Instead, the underlying information should be stored in a separate system and the only evidence on the blockchain should be records such as a pointer, keyed hash or cryptographic commitment. 

This does not make privacy obligations disappear. Encrypted data and hashes may still qualify as personal data, depending on whether they can be linked back to an individual. However, off-chain storage gives organisations more realistic options for correcting or deleting the underlying information and applying retention periods.

Consequences for implementation

GDPR evaluation by implementation teams should be a priority, due to the inherent issues. Additionally, where the processing is likely to create high risks, a data protection impact assessment may be required. More broadly, governance should cover participant roles, protocol changes, vulnerabilities, security incidents and users’ requests concerning their data. 

Blockchain can still support privacy-conscious products, with careful design of the underlying architecture. If a conventional database can achieve the same goal with less complexity and lower privacy risk, the simpler tool might be preferable. If not, the suggestions highlighted above should be considered before deployment.

In conclusion, it is important to keep in mind that using blockchain technology is not a processing activity in itself, but rather it represents the backbone of numerous applications that shape up the current technological landscape. As a result, given the technology neutral nature of the GDPR, personal data should be one of the main concerns for teams assessing the compliance of their blockchain dependent solutions.

Cluj IT will not be liable for any false, inaccurate, inappropriate or incomplete information presented, as the authors are free to choose their approach and relevant topics, within the general guidelines of the newsletter. The opinions expressed by the authors and those providing comments are theirs alone, and do not reflect the opinions of Cluj IT.
Certain links in the articles or comments may lead to external websites. Cluj IT accepts no liability in respect of materials, products or services available on any external website which is not under the control of Cluj IT.