On 7 July 2026, the European Data Protection Board adopted version 2.0 of Guidelines 02/2025 on the processing of personal data through blockchain technologies, incorporating amendments made following the April 2025 public consultation. On the same date, the EDPB adopted Draft Guidelines 02/2026 on anonymisation for public consultation, open until 30 October 2026. The draft anonymisation guidelines are intended to replace Opinion 05/2014 on Anonymisation Techniques issued by the former Article 29 Working Party. The blockchain guidelines are binding on EU member state supervisory authorities in their final form.
Guidelines 02/2025 v2.0 apply GDPR obligations to blockchain processing, with particular emphasis on Articles 5 (data minimisation and storage limitation), 17 (right to erasure), 25 (data protection by design), and 32 (security of processing). The guidelines affirm that both public and permissioned blockchains may constitute personal data processing where content is identifiable, and require controllers to assess before deployment whether blockchain architecture is necessary given the difficulty of exercising data subject rights and the immutability of on-chain records. Draft Guidelines 02/2026 on anonymisation adopt the relative identifiability standard endorsed by the Court of Justice in Case C-582/14 (Breyer), introducing two analytical approaches described as a contextual approach and a simplified approach, and three anonymity-testing criteria: no record isolation, no linkage, and no inference.
Blockchain developers and smart contract operators must treat Guidelines 02/2025 v2.0 as the operative GDPR compliance standard for their processing activities. Developers building on public chains face the most acute compliance challenge: the immutability of on-chain data conflicts directly with the Article 17 right to erasure, and the guidelines do not provide a technical safe harbour; they require a documented necessity assessment before blockchain is selected as an architecture. For AI system operators, the draft anonymisation guidelines are material because they clarify when training data may be processed without a GDPR legal basis on the grounds of anonymisation; the relative standard requires a context-specific assessment of re-identification risk for the likely recipient, not merely a technical de-identification step applied to the dataset in isolation.
The blockchain guidelines leave open how data minimisation obligations under Article 5(1)(c) interact with on-chain governance tokens and transaction metadata, and do not address zero-knowledge proof architectures directly. The public consultation on Draft Guidelines 02/2026 on anonymisation closes on 30 October 2026; organisations wishing to influence the final standard should submit responses before that date. No timeline for adoption of the final anonymisation guidelines has been published by the EDPB.
Licentium advises blockchain developers, AI operators, and data controllers on GDPR compliance for decentralised systems and data processing architectures, drawing on a partner network of EU data protection counsel for cross-jurisdictional matters. Contact us to discuss how the finalised blockchain guidelines or the draft anonymisation standard apply to your systems. Work we undertake includes GDPR compliance audits for blockchain architectures, data protection impact assessments, anonymisation standard gap analyses, and regulatory consultation submissions.