EU Data Act, Article 36
Smart contract requirements · Regulation (EU) 2023/2854
Confidentiality is workable so long as the regulated firm can identify parties and disclose on demand.
What EU Data Act, Article 36 actually says
A useful case of a rule written for one context landing awkwardly on another. Article 36 sets essential requirements for smart contracts used to execute data-sharing agreements, including robustness, access control and, the contested one, safe termination and interruption. Read broadly, a mandatory kill switch cannot coexist with an immutable, non-upgradeable contract. Read as drafted, it addresses enterprise data-sharing rather than permissionless DeFi, and its extension to public-chain contracts was disputed from the start. It has applied since 12 September 2025. The Commission's Digital Omnibus proposal of November 2025 would delete Article 36 outright on legal-certainty grounds, which is a fair signal of how well the drafting landed, but that proposal is still in procedure.
The instruments that matter
- Article 36
- essential requirements for smart contracts used in data-sharing agreements, namely robustness, access control, safe termination and interruption, archiving, continuity
- Applicable since 12 September 2025
- Digital Omnibus (November 2025)
- would delete Article 36 entirely without replacement, on legal-certainty grounds; still in procedure, so treat Article 36 as in force
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- CJEU on identifiabilityEurope · Case law · is a wallet address personal data
- EDPB blockchain guidelinesEurope · Data protection guidance · Guidelines 02/2025
- MiCAEurope · Market licensing · Regulation (EU) 2023/1114
- Digital euroEurope · Central bank digital currency · COM(2023) 369
- eIDAS 2 and the EU Digital Identity WalletEurope · Digital identity · Regulation (EU) 2024/1183
- EU AMLR Article 79Europe · Anti-money laundering · Regulation (EU) 2024/1624
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.