Confidentiality is workable so long as the regulated firm can identify parties and disclose on demand.
What EDPB blockchain guidelines actually says
The reference text on how European data protection law lands on a ledger, final since 7 July 2026. Its positions are demanding: a public key is personal data whenever it can be associated with an identifiable person, encrypted or hashed on-chain data is not automatically outside GDPR, and unsalted hashes are treated as insufficient on a public chain. On erasure the Board offers architecture rather than a doctrinal exemption. Keep personal data off-chain, delete the off-chain identifiers, or render the on-chain data effectively anonymous, which it concedes is technically demanding. It prefers permissioned designs and treats permissionless ones as needing justification. Zero-knowledge constructions and commitments are acknowledged as mitigations, not exemptions. Guidelines are not binding law, but supervisors follow them.
The instruments that matter
- Adopted 7 July 2026
- version 2.0, following the draft consulted on between 14 April and 9 June 2025
- Public keys as personal data
- a wallet address qualifies whenever it can be associated with an identifiable person; unsalted hashes do not escape GDPR on a public chain
- Off-chain by default
- the Board urges keeping personal data off-chain and expressly prefers permissioned architectures
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- CJEU on identifiabilityEurope · Case law · is a wallet address personal data
- EU Data Act, Article 36Europe · Smart contract requirements · Regulation (EU) 2023/2854
- MiCAEurope · Market licensing · Regulation (EU) 2023/1114
- Digital euroEurope · Central bank digital currency · COM(2023) 369
- eIDAS 2 and the EU Digital Identity WalletEurope · Digital identity · Regulation (EU) 2024/1183
- EU AMLR Article 79Europe · Anti-money laundering · Regulation (EU) 2024/1624
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.