Jump to

Immutable Meets Erasable: The EDPB’s Final Blockchain Guidelines Are Here — What Web3 Builders Must Change

On 7 July 2026, the European Data Protection Board adopted the final version of its Guidelines 02/2025 on processing personal data through blockchain technologies. The draft had gone out for consultation in April 2025 and drew heavy fire from the sector — one sentence in particular, contemplating deletion of an entire chain where compliance cannot otherwise be achieved, was debated for months. The final text softens some edges. The spine survives intact. We read all forty pages; here is what the Board actually says, and what it means in practice for anyone shipping on-chain products.

Timeline of EDPB Guidelines 02/2025 on blockchain: from the April 2025 draft to the final text of 7 July 2026

Start with the mindset

One idea runs through the whole document: blockchain is a technology choice, and choices demand justification. The Board says it in terms — technical impossibility is no excuse for non-compliance. You chose to write data into an immutable structure; the structure’s refusal to forget does not extinguish your duty to erase. The line is not new — the Board used it in its 2024 ChatGPT taskforce report. What is new is watching it applied, clause by clause, to every layer of a blockchain stack.

The second foundational choice deserves equal billing: in the Board’s eyes, permissioned chains are the rule and public chains the exception. A public chain is defensible only where public access is genuinely necessary for at least one purpose of the processing, and anything else requires documented justification. In practice: “we deployed on Ethereum because that’s where the ecosystem is” is no longer an architecture rationale before a supervisory authority. It is a confession.

The “it’s just a hash” defence is formally over

The most-quoted section will be the one working through, form by form, what may be written on-chain:

What goes on-chain The Board’s assessment Our reading
Clear-text personal data Cannot be erased or amended; not advisable in any form A design defect — if it exists in your stack, stop adding to it today
Encrypted data Remains personal data; on an indefinite chain, today’s cipher is tomorrow’s clear text Defensible only where key destruction is engineered as the erasure mechanism
Salted or keyed hash Still personal data; destroying the off-chain salt and key can sever the link Reasonable for integrity proofs — if the off-chain side is genuinely governed
Data off-chain, only a commitment on-chain The architecture the Guidelines point everyone toward The default for anything user-related

Note the quieter point beneath the table: wallet addresses, transaction identifiers, event logs and smart-contract traces — everything besides the payload — are personal data whenever they can identify someone directly or indirectly. The position the crypto industry has rested on for years, “we hold no personal data, only addresses,” finds no support in the final text.

Who answers for a decentralised network?

The Board’s answer is short: someone. Decentralisation cannot produce a world where nobody is accountable. Roles are assigned through a factual assessment anchored in governance: who defines the protocol, who decides upgrades, who sets the rules of participation. In consortium chains this analysis will often yield joint controllership among the governing entities — with the Article 26 arrangement that status requires. On public chains, the practical consequence is blunt: since the network itself is hard to hold responsible, the risk settles on whoever builds a product on top. The status of node operators remains contested; if you are the product owner, that debate will not save you.

Lawful basis — and the overlooked door of Article 23

The Guidelines invent no special legal basis for blockchain; every processing operation must rest on one of the Article 6 grounds. Two nuances matter. First, consent is set at an even higher bar than usual: if you rely on it, withdrawal must actually result in erasure or anonymisation. Building consent-based processing on an unerasable chain means choosing a legal basis engineered to self-destruct — Recommendation 9 says so expressly: if the architecture cannot delete, do not use consent at all. Second, Article 23: where Union or member-state law requires blockchain for defined purposes — the Board’s own examples are anti-money-laundering and asset registries such as land records — data subject rights may be restricted, proportionately and by statute. For public-sector chain projects, that is where the real game will be played.

A borderless chain meets bordered law

Every node on a public chain holds a full copy. With nodes spread across the world — and they are — every byte of personal data written on-chain is simultaneously “transferred” to dozens of jurisdictions, to counterparties you neither chose nor vetted. The Guidelines face this honestly but cannot resolve it satisfyingly: Chapter V applies, transfers must be identified and covered by appropriate mechanisms — standard contractual clauses folded into existing agreements, for instance. Since one cannot sign SCCs with anonymous node operators, the operational message circles back to the same place: keep personal data off public chains altogether.

The security section is more concrete than expected

Three items stand out. Safeguards against collusive misuse by participant groups — the 51% attack — which on permissioned chains should be backed contractually and through administrative oversight privileges. Protections against unauthorised transactions from compromised wallets or rogue employees, which pushes security duties down into each participant’s own systems. And, most striking, cryptographic ageing: the risk that today’s algorithms fail within the chain’s expected lifespan must be assessed, and an emergency plan for swapping algorithms must exist before the vulnerability does. Nobody can warrant that today’s curve holds for twenty years; the Board asks you to plan for the day it does not.

The DPIA: which risks must be on the list

Most personal-data blockchain scenarios will make a DPIA unavoidable. The Guidelines’ real contribution is an inventory of risk sources that reaches well beyond the ledger itself: the gathering and storage of transactions awaiting validation, the handling of blocks in dead-end branches, off-chain storage tied to on-chain identifiers, communication metadata, and the management of cryptographic material — keys, seeds, salts. A DPIA silent on these items is, in the Board’s eyes, incomplete. And one exit door stays open throughout: where risks cannot be mitigated, the controller “always has the option” to use a different blockchain model or a different technology — the politest available phrasing of a regulator may reject your architecture outright.

Data subject rights: erasure, rectification, and who has the last word

For erasure, the accepted route is destroying the off-chain connectors — keys, salts, identifiers — so that what remains on-chain can no longer be linked to anyone. The Board concedes this is hard, and adds: if you do not truly need the chain’s integrity guarantees, use something else. Rectification carries an interesting flexibility: in some cases a subsequent transaction announcing the cancellation of an earlier one satisfies the right, even though the first entry remains visible. And for smart contracts, the critical sentence: execution may constitute automated decision-making under Article 22, in which case human intervention and the right to contest must be honoured even after the contract has already performed. The European answer to “code is law”: code executes, but a human gets the last word.

The view from Türkiye

Three channels make this document relevant to Turkish companies. Direct scope: a single EU-resident user of your CASP-licensed platform brings GDPR and these Guidelines to the table. Regulatory convergence: the Turkish DPA’s practice on anonymisation and pseudonymisation runs on the same substance-over-label logic — what Brussels writes today, Ankara tends to ask tomorrow. And contractual pressure: enterprise customers and investors will convert this document into vendor questionnaires and diligence questions; the architecture memo you write is written for them too.

Two questions we keep hearing

We already have personal data on a public chain. Is the company burnt?

No — but it needs a work plan: inventory it, stop adding to it today, engineer unlinkability by deleting the off-chain elements that connect chain data to people, and document the residual-risk analysis. The Board will distinguish between a company with a demonstrable remediation design and one shrugging “that’s how chains work.”

Are NFTs and token transfers covered too?

Wherever an identifiable person stands behind the transfer, yes — and the link between a wallet address and an identity can be forged by an exchange KYC record, a payment trail or a social-media post. What speaks is not an assumption of anonymity but an analysis of linkability.

Decision path before personal data touches the chain: is it personal data, can it live off-chain, is a public chain truly required?

Where to start

The first recommendation in Annex A reads like a summary of the entire document: will personal data touch the chain; why is a blockchain necessary and proportionate for this processing; which alternatives did you consider and reject — write it down. If you cannot write that memo honestly on one page, the problem is not your drafting but your architecture — and learning that before a DPIA, a redesign or an enforcement file is the cheapest legal advice available.

Source: EDPB Guidelines 02/2025 (v2.0, full text) · Related: RWA tokenization in Türkiye · travel rule · data processor.

Author

  • Erdem Mümtaz Hacıpaşaoğlu

    Mümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals — including crypto-asset infrastructure, fintech and games — bringing a former startup founder's perspective to every engagement.

    View all posts
Considering a similar matter?Talk to counsel that moves at the speed of your round.
Book a call →

If this is on your desk

Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.

Founder AcademyBook an intro call
Published: 14 July 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.