Soda Labs

EU Data Act, Article 36

Smart contract requirements · Regulation (EU) 2023/2854

Regulator or standard-setterEuropePrivacy with disclosure

Confidentiality is workable so long as the regulated firm can identify parties and disclose on demand.

What EU Data Act, Article 36 actually says

A useful case of a rule written for one context landing awkwardly on another. Article 36 sets essential requirements for smart contracts used to execute data-sharing agreements, including robustness, access control and, the contested one, safe termination and interruption. Read broadly, a mandatory kill switch cannot coexist with an immutable, non-upgradeable contract. Read as drafted, it addresses enterprise data-sharing rather than permissionless DeFi, and its extension to public-chain contracts was disputed from the start. It has applied since 12 September 2025. The Commission's Digital Omnibus proposal of November 2025 would delete Article 36 outright on legal-certainty grounds, which is a fair signal of how well the drafting landed, but that proposal is still in procedure.

The instruments that matter

Article 36
essential requirements for smart contracts used in data-sharing agreements, namely robustness, access control, safe termination and interruption, archiving, continuity
Applicable since 12 September 2025
Digital Omnibus (November 2025)
would delete Article 36 entirely without replacement, on legal-certainty grounds; still in procedure, so treat Article 36 as in force

What this means for confidential transactions

Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.

Compliant by default.

See how selective disclosure satisfies a supervisor without publishing your book to the world.