The European Data Protection Board published draft guidelines on April 14, 2025 explaining how the EU General Data Protection Regulation applies when blockchain systems process personal data. Guidelines 02/2025 opened for public consultation through June 9, 2025 after the board adopted the draft at its April 8 plenary.

The development mattered because a blockchain’s durable, replicated history can collide with GDPR duties to minimize data, limit retention and enable rights such as rectification and erasure. The EDPB did not ban blockchains or change the GDPR. It set out the board’s event-day interpretation for organizations designing or operating blockchain-based processing, while leaving the text open to public comment.

Personal data can extend beyond the payload

The draft treated the compliance question as broader than whether someone writes a name into a transaction. It said transaction metadata can include user identifiers such as public keys; those identifiers qualify as personal data when a natural person can be identified by means reasonably likely to be used. Transaction payloads, links to documents and data collected around a wallet or decentralized application—including IP addresses—can also fall within the assessment.

That conditional test is important. The draft did not say every alphanumeric address identifies a person in every circumstance. It required controllers to evaluate the actual architecture, the information available on-chain and off-chain, and the realistic possibility of linking an identifier to an individual.

The EDPB also rejected technical design as an excuse for leaving responsibility undefined. Organizations were told to assess who determines the purposes and means of each processing activity and who acts as a processor. Governance, permissioning, node roles and application-layer choices could change that allocation; “decentralized” was not itself an exemption.

Design before deployment

The draft’s practical center was data protection by design and by default. It advised against putting personal data directly into transaction content and recommended storing additional personal data off-chain beyond identifiers already required in transaction metadata. Where a chain is used as proof, the draft favored approaches such as keyed hashes, pointers or cryptographic commitments, with the verifying data kept outside the blockchain under strong confidentiality controls.

Those techniques were not presented as automatic escapes from GDPR. The draft said encrypted personal data remains personal data, warned that indefinite retention can outlast encryption, and treated hashes as personal data where they still relate to an identifiable person. It also said plain-text personal data on-chain could conflict with GDPR principles and strongly discouraged that design.

Controllers were expected to document why a blockchain was necessary instead of a less risky alternative, choose an appropriate public or non-public and permissioned or permissionless architecture, establish a legal basis, define retention periods and build procedures for individual rights. A data protection impact assessment was required before processing where the proposed use was likely to create high risk to people’s rights and freedoms.

Immutability did not settle the legal question

The draft addressed the core tension directly: in most blockchains, modifying or deleting historical data is practically difficult and may undermine the system’s tamper-resistant design. The EDPB’s position was that technical impossibility could not justify noncompliance. If personal data did not need to remain for the life of the chain, it generally should not be written there unless the design could effectively prevent later identification. A lifetime retention period required a documented necessity and proportionality justification.

This was draft interpretive guidance, not a fine, enforcement decision or final legislative rule. No named blockchain, wallet provider, exchange or token was found noncompliant on April 14. The immediate institutional signal was nevertheless clear: European privacy authorities expected blockchain projects to solve controllership, retention and data-subject rights at the architecture stage, not after immutable records had accumulated.

What remained open on April 14

The consultation left stakeholders until June 9, 2025 to challenge the draft’s technical assumptions and proposed compliance approaches. Any later final version, enforcement action or court interpretation was outside the April 14 record and cannot be projected backward. The event-day document established a regulatory position for debate; it did not establish how every decentralized network would ultimately be treated.

Primary sourceEuropean Data Protection Board — April 14 announcement of blockchain guidelines

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.