Article content
In briefShow moreShow lessThe EDPB published draft guidelines on personal data processing through blockchains.
- The EDPB published draft guidelines on personal data processing through blockchains.
- Blockchain immutability does not override the GDPR.
- Relevant draft EDPB guidance under the GDPR as applied in Norway through the EEA; not a change in law.
What happened
The EDPB published draft guidelines on personal data processing through blockchains. They emphasised privacy by design, clear roles, minimisation, impact assessment, and effective access, correction and erasure.
Blockchain immutability does not override the GDPR. As a general rule, the EDPB advised avoiding personal data on-chain where principles and rights cannot be upheld, using suitable off-chain architecture instead.
Legal status in Norway
Relevant draft EDPB guidance under the GDPR as applied in Norway through the EEA; not a change in law.
What the sources clarify
The EDPB stressed that roles and responsibilities must be determined when the blockchain is designed. Where processing is likely to create high risk, a DPIA is required before personal data is written. Hashing or encryption does not automatically make data anonymous, while an immutable ledger can conflict with rectification and erasure. A more resilient design keeps personal data off-chain and stores only necessary proofs or references on-chain, with controlled deletion in the external store. Choosing a public, consortium or private architecture changes access, accountability and the practical ability to enforce individual rights.
Before choosing a ledger, the team should ask which property actually requires immutability and whether an ordinary database can meet the goal. If blockchain remains justified, key management, participant roles, node access and error handling should be designed before data is written. Rights requests need to be tested against the architecture rather than described only in policy.
Practical implications
The architecture decision should compare the proposal with an erasable database and explain why blockchain remains necessary. Before production, the team should demonstrate rectification, access control and lost-key handling. If an individual right cannot be exercised in the test, the data flow needs redesign before launch.
Sources
European Data Protection Board: “EDPB adopts blockchain guidelines,” 14 April 2025.
European Data Protection Board: “EDPB Guidelines 02/2025 on blockchain technologies,” 14 April 2025.
For discussion
Which supplier do we need more evidence from?

