Soda Labs

GDPR

Data protection · Regulation (EU) 2016/679

Regulator or standard-setterEuropeBuilds with privacy tech

The regime itself mandates, pilots or funds privacy-preserving technology.

What GDPR actually says

The law most often described as a problem for blockchain is also the strongest European argument for building with privacy technology. Article 25 requires data protection by design and by default, and Article 5(1)(c) requires minimisation, which is a legal instruction to publish less, not more. The friction is real in two places: Article 17 erasure against an append-only ledger, and whether a wallet address counts as personal data under Article 4(1). Worth holding onto in the AML debate, GDPR does not authorise blanket collection either. Processing for anti-money laundering still has to clear necessity and proportionality under Article 6 and the Charter. A Commission Digital Omnibus proposal from November 2025 would amend the identifiability test; treat it as pending.

The instruments that matter

Article 5(1)(c) and Article 25
data minimisation and data protection by design and by default, the strongest legal basis in Europe for building with privacy technology
Article 17
the right to erasure, in direct tension with an append-only ledger
Article 4(1)
whether a wallet address is personal data turns on this definition of identifiability

What this means for confidential transactions

Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.

Compliant by default.

See how selective disclosure satisfies a supervisor without publishing your book to the world.