From the journal

EDPB Adopts Final GDPR Guidelines on Blockchain Data Processing, EU, 8 July 2026

On 8 July 2026, the European Data Protection Board adopted the final version of Guidelines 02/2025 on the processing of personal data through blockchain technologies. The guidelines confirm that encrypted and hashed on-chain data remains personal data under the GDPR and that blockchain immutability does not override data subjects' right to erasure under Article 17. Controllers must address architecture choices and data minimisation before any on-chain recording of personal data.

2 min read

The European Data Protection Board (EDPB) published final Guidelines 02/2025 on the processing of personal data through blockchain technologies on 8 July 2026, following a public consultation in Q2 2025. The guidelines apply to any GDPR-subject controller or processor deploying distributed ledger technology where personal data is at stake.

The guidelines work through the GDPR's foundational concepts across three blockchain architectures: public (permissionless) chains open to any participant, private (permissioned) chains restricted to vetted participants, and consortium chains governed jointly by a named group. The EDPB confirms under Article 4(1) GDPR that encrypted data, hashed data, and pseudonymous on-chain records all qualify as personal data unless absolute anonymity is technically demonstrated. On the right to erasure under Article 17, the EDPB states that blockchain immutability does not exempt controllers from the obligation; controllers must instead design systems capable of implementing erasure before any on-chain deployment. The EDPB recommends against recording clear text, encrypted, or hashed personal data directly on-chain.

The primary effect falls on blockchain developers, protocol operators, financial institutions deploying tokenised assets, exchanges recording trade data on public chains, and any data controller embedding personal identifiers in on-chain transactions. Controllers must conduct a data protection impact assessment under Article 35 GDPR where processing is likely to result in high risk. The EDPB expressly recommends permissioned blockchain architectures over public chains where personal data processing is unavoidable.

The guidelines acknowledge difficulty in identifying controllers and processors in decentralised architectures lacking a single responsible entity. No safe harbour is created for decentralised governance models. Controllers are directed to document their role allocation analysis. The guidelines do not provide transitional guidance for existing deployments already recording personal data on public chains, leaving those operators to address compliance retrospectively.

Licentium advises on GDPR compliance for blockchain and digital asset projects across the EU. If the final Guidelines 02/2025 affect your operations, contact us at www.licentium.io. Work we undertake includes GDPR compliance reviews for blockchain deployments, data protection impact assessments, controller and processor role analysis, privacy architecture review, and regulatory interface on behalf of protocol operators.

Source: EDPB, Guidelines 02/2025 on processing of personal data through blockchain technologies (v2.0), 8 July 2026

Crypto Regulatory

More from the journal

See all
Illia Prokopiev

Crypto Vaults and Lending Strategies Under U.S. Federal Securities Law

Commissioner Hester M. Peirce’s July 22, 2026 statement does not establish binding law, but it identifies the principal federal securities-law questions raised by crypto vaults and onchain lending strategies. This analysis examines when vault interests, lending claims, receipt tokens, and related service-provider activities may trigger the Securities Act, Exchange Act, Investment Company Act, and Investment Advisers Act.

MiCAR Transitional Regime for CASPs Expires Across the EU, July 2026

On 1 July 2026, the MiCAR transitional period under Article 143(3) of Regulation (EU) 2023/1114 expired across the EU. Former virtual asset service providers operating under national registrations must now hold a MiCAR crypto-asset service provider authorisation or cease providing crypto-asset services. In Luxembourg, the CSSF confirmed that VASP registration under the 2004 AML Law no longer provides a sufficient legal basis for market activity.

New York UCC Article 12 on Digital Asset Collateral Takes Effect, June 2026

New York's adoption of the 2022 Uniform Commercial Code amendments became effective on 3 June 2026, introducing Article 12 on controllable electronic records (CERs) and new priority rules for digital asset collateral. A security interest perfected by control of a CER now takes priority over one perfected by UCC-1 filing, regardless of filing date. The amendments affect secured lenders, custodians, and counterparties using digital assets as collateral in New York-governed transactions.