The European Data Protection Board (EDPB) published final Guidelines 02/2025 on the processing of personal data through blockchain technologies on 8 July 2026, following a public consultation in Q2 2025. The guidelines apply to any GDPR-subject controller or processor deploying distributed ledger technology where personal data is at stake.
The guidelines work through the GDPR's foundational concepts across three blockchain architectures: public (permissionless) chains open to any participant, private (permissioned) chains restricted to vetted participants, and consortium chains governed jointly by a named group. The EDPB confirms under Article 4(1) GDPR that encrypted data, hashed data, and pseudonymous on-chain records all qualify as personal data unless absolute anonymity is technically demonstrated. On the right to erasure under Article 17, the EDPB states that blockchain immutability does not exempt controllers from the obligation; controllers must instead design systems capable of implementing erasure before any on-chain deployment. The EDPB recommends against recording clear text, encrypted, or hashed personal data directly on-chain.
The primary effect falls on blockchain developers, protocol operators, financial institutions deploying tokenised assets, exchanges recording trade data on public chains, and any data controller embedding personal identifiers in on-chain transactions. Controllers must conduct a data protection impact assessment under Article 35 GDPR where processing is likely to result in high risk. The EDPB expressly recommends permissioned blockchain architectures over public chains where personal data processing is unavoidable.
The guidelines acknowledge difficulty in identifying controllers and processors in decentralised architectures lacking a single responsible entity. No safe harbour is created for decentralised governance models. Controllers are directed to document their role allocation analysis. The guidelines do not provide transitional guidance for existing deployments already recording personal data on public chains, leaving those operators to address compliance retrospectively.
Licentium advises on GDPR compliance for blockchain and digital asset projects across the EU. If the final Guidelines 02/2025 affect your operations, contact us at www.licentium.io. Work we undertake includes GDPR compliance reviews for blockchain deployments, data protection impact assessments, controller and processor role analysis, privacy architecture review, and regulatory interface on behalf of protocol operators.