Confidentiality is workable so long as the regulated firm can identify parties and disclose on demand.
What CJEU on identifiability actually says
Whether a blockchain address is personal data is not a settled question, and the two European institutions answering it are drifting apart. The Court's line is contextual. Breyer held in 2016 that data are personal to a party who has means reasonably likely to be used to identify the person, and in September 2025 the Court sharpened this considerably: the same pseudonymised dataset can be personal data for the controller holding the re-identification key and non-personal for a recipient with no realistic path to re-identify. That is the strongest available argument that an address is not personal data to everyone who can see it. The EDPB's blockchain guidelines take a markedly broader view. This gap is the most consequential open question for anyone building on-chain in Europe.
The instruments that matter
- Breyer, C-582/14 (19 October 2016)
- established the relative test, under which data are personal to a party with means reasonably likely to be used to identify the person
- EDPS v SRB, C-413/23 P (4 September 2025)
- pseudonymised data may be personal to the holder of the re-identification key and non-personal to a recipient who cannot reasonably re-identify
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- EDPB blockchain guidelinesEurope · Data protection guidance · Guidelines 02/2025
- EU Data Act, Article 36Europe · Smart contract requirements · Regulation (EU) 2023/2854
- MiCAEurope · Market licensing · Regulation (EU) 2023/1114
- Digital euroEurope · Central bank digital currency · COM(2023) 369
- eIDAS 2 and the EU Digital Identity WalletEurope · Digital identity · Regulation (EU) 2024/1183
- EU AMLR Article 79Europe · Anti-money laundering · Regulation (EU) 2024/1624
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.