The regime itself mandates, pilots or funds privacy-preserving technology.
What GDPR actually says
The law most often described as a problem for blockchain is also the strongest European argument for building with privacy technology. Article 25 requires data protection by design and by default, and Article 5(1)(c) requires minimisation, which is a legal instruction to publish less, not more. The friction is real in two places: Article 17 erasure against an append-only ledger, and whether a wallet address counts as personal data under Article 4(1). Worth holding onto in the AML debate, GDPR does not authorise blanket collection either. Processing for anti-money laundering still has to clear necessity and proportionality under Article 6 and the Charter. A Commission Digital Omnibus proposal from November 2025 would amend the identifiability test; treat it as pending.
The instruments that matter
- Article 5(1)(c) and Article 25
- data minimisation and data protection by design and by default, the strongest legal basis in Europe for building with privacy technology
- Article 17
- the right to erasure, in direct tension with an append-only ledger
- Article 4(1)
- whether a wallet address is personal data turns on this definition of identifiability
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- Digital euroEurope · Central bank digital currency · COM(2023) 369
- eIDAS 2 and the EU Digital Identity WalletEurope · Digital identity · Regulation (EU) 2024/1183
- CJEU on identifiabilityEurope · Case law · is a wallet address personal data
- EDPB blockchain guidelinesEurope · Data protection guidance · Guidelines 02/2025
- EU AMLR Article 79Europe · Anti-money laundering · Regulation (EU) 2024/1624
- EU Data Act, Article 36Europe · Smart contract requirements · Regulation (EU) 2023/2854
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.