From the journal

EDPB Adopts Final GDPR Guidelines on Blockchain Data Processing, EU, 8 July 2026

On 8 July 2026, the European Data Protection Board adopted the final version of Guidelines 02/2025 on the processing of personal data through blockchain technologies. The guidelines confirm that encrypted and hashed on-chain data remains personal data under the GDPR and that blockchain immutability does not override data subjects' right to erasure under Article 17. Controllers must address architecture choices and data minimisation before any on-chain recording of personal data.

2 min read

The European Data Protection Board (EDPB) published final Guidelines 02/2025 on the processing of personal data through blockchain technologies on 8 July 2026, following a public consultation in Q2 2025. The guidelines apply to any GDPR-subject controller or processor deploying distributed ledger technology where personal data is at stake.

The guidelines work through the GDPR's foundational concepts across three blockchain architectures: public (permissionless) chains open to any participant, private (permissioned) chains restricted to vetted participants, and consortium chains governed jointly by a named group. The EDPB confirms under Article 4(1) GDPR that encrypted data, hashed data, and pseudonymous on-chain records all qualify as personal data unless absolute anonymity is technically demonstrated. On the right to erasure under Article 17, the EDPB states that blockchain immutability does not exempt controllers from the obligation; controllers must instead design systems capable of implementing erasure before any on-chain deployment. The EDPB recommends against recording clear text, encrypted, or hashed personal data directly on-chain.

The primary effect falls on blockchain developers, protocol operators, financial institutions deploying tokenised assets, exchanges recording trade data on public chains, and any data controller embedding personal identifiers in on-chain transactions. Controllers must conduct a data protection impact assessment under Article 35 GDPR where processing is likely to result in high risk. The EDPB expressly recommends permissioned blockchain architectures over public chains where personal data processing is unavoidable.

The guidelines acknowledge difficulty in identifying controllers and processors in decentralised architectures lacking a single responsible entity. No safe harbour is created for decentralised governance models. Controllers are directed to document their role allocation analysis. The guidelines do not provide transitional guidance for existing deployments already recording personal data on public chains, leaving those operators to address compliance retrospectively.

Licentium advises on GDPR compliance for blockchain and digital asset projects across the EU. If the final Guidelines 02/2025 affect your operations, contact us at www.licentium.io. Work we undertake includes GDPR compliance reviews for blockchain deployments, data protection impact assessments, controller and processor role analysis, privacy architecture review, and regulatory interface on behalf of protocol operators.

Source: EDPB, Guidelines 02/2025 on processing of personal data through blockchain technologies (v2.0), 8 July 2026

Crypto Regulatory

More from the journal

See all

Hong Kong SFC and FSTB Conclude Consultation on Virtual Asset Advisory and Management Regimes, 26 May 2026

On 26 May 2026, Hong Kong's Securities and Futures Commission and Financial Services and the Treasury Bureau published consultation conclusions on proposed licensing regimes for virtual asset advisory and management service providers. The regimes apply the same business, same risks, same rules principle and align SFC licensing requirements with those for securities advisory and management businesses. A bill implementing the regimes is planned for introduction into the Legislative Council in 2026.

OCC Grants Circle Final Charter for First National Digital Currency Bank N.A., 9 July 2026

The Office of the Comptroller of the Currency granted final approval on 9 July 2026 for Circle Internet Group to establish First National Digital Currency Bank, N.A., operating as Circle National Trust. The bank opened 24 July 2026 under direct OCC oversight and will manage USDC reserves on a directed basis, act as collateral trustee for USDC holders, and provide digital asset custody services to Circle affiliates.

Manitoba Enacts Public Sector AI and Cybersecurity Governance Act June 2026

On 1 June 2026, Bill 51, The Public Sector Artificial Intelligence and Cybersecurity Governance Act (S.M. 2026, c. 43), received Royal Assent in Manitoba, Canada. The Act mandates transparency, accountability structures, and cybersecurity incident reporting for public sector entities using AI systems. Substantive obligations take effect only through regulations yet to be made.