# EDPB blockchain guidelines

> EDPB blockchain guidelines (European Data Protection Board): Data protection guidance · Guidelines 02/2025. Region: Europe. Privacy with disclosure: Confidentiality is workable so long as the regulated firm can identify parties and disclose on demand.

Part of the Soda Labs Privacy Hub regulation map, which reads the instruments
themselves rather than summarising the summaries: https://www.sodalabs.xyz/privacy-hub/regulation

## Key facts

- Entry type: Regulator or standard-setter
- Region: Europe
- Subject: Data protection guidance · Guidelines 02/2025
- Authority: European Data Protection Board
- Stance on on-chain confidentiality: Privacy with disclosure. Confidentiality is workable so long as the regulated firm can identify parties and disclose on demand.
- Tags: EDPB, Guidelines 02/2025, permissioned preference, soft law
- Canonical page: https://www.sodalabs.xyz/privacy-hub/regulation/reg-edpb-blockchain

## What it actually says

The reference text on how European data protection law lands on a ledger, final since 7 July 2026. Its positions are demanding: a public key is personal data whenever it can be associated with an identifiable person, encrypted or hashed on-chain data is not automatically outside GDPR, and unsalted hashes are treated as insufficient on a public chain. On erasure the Board offers architecture rather than a doctrinal exemption. Keep personal data off-chain, delete the off-chain identifiers, or render the on-chain data effectively anonymous, which it concedes is technically demanding. It prefers permissioned designs and treats permissionless ones as needing justification. Zero-knowledge constructions and commitments are acknowledged as mitigations, not exemptions. Guidelines are not binding law, but supervisors follow them.

## The instruments that matter

- **Adopted 7 July 2026**: version 2.0, following the draft consulted on between 14 April and 9 June 2025
- **Public keys as personal data**: a wallet address qualifies whenever it can be associated with an identifiable person; unsalted hashes do not escape GDPR on a public chain
- **Off-chain by default**: the Board urges keeping personal data off-chain and expressly prefers permissioned architectures

## Sources

- [Guidelines 02/2025 (final)](https://www.edpb.europa.eu/system/files/2026-07/edpb_guidelines_202502_blockchain_v2_en.pdf)
- [Consultation page](https://www.edpb.europa.eu/our-work-tools/documents/public-consultations/2025/guidelines-022025-processing-personal-data_en)

## Related entries

- [CJEU on identifiability](https://www.sodalabs.xyz/privacy-hub/regulation/reg-cjeu-identifiability): Case law · is a wallet address personal data
- [EU Data Act, Article 36](https://www.sodalabs.xyz/privacy-hub/regulation/reg-eu-data-act): Smart contract requirements · Regulation (EU) 2023/2854
- [MiCA](https://www.sodalabs.xyz/privacy-hub/regulation/reg-mica): Market licensing · Regulation (EU) 2023/1114
- [Digital euro](https://www.sodalabs.xyz/privacy-hub/regulation/reg-digital-euro): Central bank digital currency · COM(2023) 369
- [eIDAS 2 and the EU Digital Identity Wallet](https://www.sodalabs.xyz/privacy-hub/regulation/reg-eidas2): Digital identity · Regulation (EU) 2024/1183
- [EU AMLR Article 79](https://www.sodalabs.xyz/privacy-hub/regulation/reg-eu-amlr): Anti-money laundering · Regulation (EU) 2024/1624
