EDPB finalizes GDPR guidelines for blockchain processing

August 5, 2026

About: GDPR

#version-updates #program-changes

On July 8, 2026, the European Data Protection Board (EDPB) announced that it had adopted the final version of its guidelines on processing personal data through blockchain technologies. The Board published version 2.0 of Guidelines 02/2025 after public consultation (adopted July 7, 2026). Blockchain does not create an exemption from the General Data Protection Regulation (GDPR).

The same plenary also released draft guidelines on anonymisation and on web scraping for generative AI. Those drafts remain open for comment through October 30, 2026, and are not final. This post covers only the finalized blockchain guidance.

What the final guidelines emphasize

The guidelines explain how different blockchain architectures affect GDPR roles and compliance. Practical themes for organizations designing or buying blockchain-backed processing include:

  • Justify necessity: document why blockchain is needed for the purpose, and whether a less privacy-intrusive design would work
  • Prefer designs that keep personal data off-chain where possible, storing hashes or proofs on-chain instead of raw identifiers
  • Favor permissioned models when they give participants clearer control over who processes personal data
  • Map controllers and processors carefully; shared ledger designs can blur accountability
  • Plan for data subject rights (access, rectification, erasure, and objection). Technical immutability does not waive those rights, so erasure and related requests need a workable design from the start
  • Build data protection by design and by default into retention, security, and governance choices before go-live

Public, permissionless chains that put personal data on-chain remain hard to reconcile with GDPR expectations around control and erasure. Teams already live on those designs should reassess scope, legal basis, and remediation options against the final text.

What is not changing

The GDPR itself is unchanged. Adequacy decisions, standard contractual clauses, and other transfer tools are outside this document. The anonymisation and web-scraping drafts from the same plenary are still consultations, not adopted guidance.

What to do now

  1. Inventory products, vendors, and internal systems that put personal data (or strongly identifying metadata such as wallet addresses tied to people) on a blockchain.
  2. Read the final guidelines PDF and update DPIAs, controller/processor maps, and retention designs where the ledger is in scope.
  3. Prefer off-chain personal data with on-chain proofs, and document why any on-chain personal data is necessary.
  4. Confirm you can meet access, rectification, and erasure requests for the chosen architecture, or redesign before scaling.
  5. See the GDPR page for what the regulation requires, and follow GDPR on this site for further EDPB guidance updates.

#version-updates#program-changes

← Back to news