# CJEU on identifiability

> CJEU on identifiability (Court of Justice of the European Union): Case law · is a wallet address personal data. Region: Europe. Privacy with disclosure: Confidentiality is workable so long as the regulated firm can identify parties and disclose on demand.

Part of the Soda Labs Privacy Hub regulation map, which reads the instruments
themselves rather than summarising the summaries: https://www.sodalabs.xyz/privacy-hub/regulation

## Key facts

- Entry type: Regulator or standard-setter
- Region: Europe
- Subject: Case law · is a wallet address personal data
- Authority: Court of Justice of the European Union
- Stance on on-chain confidentiality: Privacy with disclosure. Confidentiality is workable so long as the regulated firm can identify parties and disclose on demand.
- Tags: identifiability, pseudonymisation, Breyer, unresolved
- Canonical page: https://www.sodalabs.xyz/privacy-hub/regulation/reg-cjeu-identifiability

## What it actually says

Whether a blockchain address is personal data is not a settled question, and the two European institutions answering it are drifting apart. The Court's line is contextual. Breyer held in 2016 that data are personal to a party who has means reasonably likely to be used to identify the person, and in September 2025 the Court sharpened this considerably: the same pseudonymised dataset can be personal data for the controller holding the re-identification key and non-personal for a recipient with no realistic path to re-identify. That is the strongest available argument that an address is not personal data to everyone who can see it. The EDPB's blockchain guidelines take a markedly broader view. This gap is the most consequential open question for anyone building on-chain in Europe.

## The instruments that matter

- **Breyer, C-582/14 (19 October 2016)**: established the relative test, under which data are personal to a party with means reasonably likely to be used to identify the person
- **EDPS v SRB, C-413/23 P (4 September 2025)**: pseudonymised data may be personal to the holder of the re-identification key and non-personal to a recipient who cannot reasonably re-identify

## Sources

- [C-413/23 P](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0413)
- [Breyer, C-582/14](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0582)

## Related entries

- [EDPB blockchain guidelines](https://www.sodalabs.xyz/privacy-hub/regulation/reg-edpb-blockchain): Data protection guidance · Guidelines 02/2025
- [EU Data Act, Article 36](https://www.sodalabs.xyz/privacy-hub/regulation/reg-eu-data-act): Smart contract requirements · Regulation (EU) 2023/2854
- [MiCA](https://www.sodalabs.xyz/privacy-hub/regulation/reg-mica): Market licensing · Regulation (EU) 2023/1114
- [Digital euro](https://www.sodalabs.xyz/privacy-hub/regulation/reg-digital-euro): Central bank digital currency · COM(2023) 369
- [eIDAS 2 and the EU Digital Identity Wallet](https://www.sodalabs.xyz/privacy-hub/regulation/reg-eidas2): Digital identity · Regulation (EU) 2024/1183
- [EU AMLR Article 79](https://www.sodalabs.xyz/privacy-hub/regulation/reg-eu-amlr): Anti-money laundering · Regulation (EU) 2024/1624
