EU Data Act, Article 36
Smart contract requirements · Regulation (EU) 2023/2854
Confidentiality is workable so long as the regulated firm can identify the parties and disclose on demand. Encrypted amounts are not the thing being restricted.
What EU Data Act, Article 36 actually says
A useful case of a rule written for one context landing awkwardly on another. Article 36 sets essential requirements for smart contracts used to execute data-sharing agreements, including robustness, access control and, the contested one, safe termination and interruption. Read broadly, a mandatory kill switch cannot coexist with an immutable, non-upgradeable contract. Read as drafted, it addresses enterprise data-sharing rather than permissionless DeFi, and its extension to public-chain contracts was disputed from the start. It has applied since 12 September 2025. The Commission's Digital Omnibus proposal of November 2025 would delete Article 36 outright on legal-certainty grounds, which is a fair signal of how well the drafting landed, but that proposal is still in procedure.
The instruments that matter
- Article 36
- essential requirements for smart contracts used in data-sharing agreements, namely robustness, access control, safe termination and interruption, archiving, continuity
- Applicable since 12 September 2025
- Digital Omnibus (November 2025)
- would delete Article 36 entirely without replacement, on legal-certainty grounds; still in procedure, so treat Article 36 as in force
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- CJEU on identifiabilityEurope · Case law · is a wallet address personal data
- EDPB blockchain guidelinesEurope · Data protection guidance · Guidelines 02/2025
- MiCAEurope · Market licensing · Regulation (EU) 2023/1114
- AustriaEurope · EU baseline, with an early transition close
- BelgiumEurope · EU baseline, with no national layer on confidentiality
- CzechiaEurope · EU baseline, supervised by the central bank
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.