Following its public consultation in Q2 2025, the European Data Protection Board (EDPB) has now published its finalised Guidelines on processing of personal data through blockchain technologies. In short, very few changes have been made to the draft guidelines published in April 2025. The amendments are mostly limited to terminological clarifications and minor corrections. We previously published a blog post as well as a full client briefing on the draft guidelines.
Some of the key takeaways from the Guidelines include:
- Blockchain is not an excuse for non-compliance: The EDPB rejects the suggestion that the compliance challenges presented by blockchain technology are somehow an excuse for not complying with the GDPR. Any blockchain solution must enable all participants to comply with their obligations under the GDPR including respecting data subject rights such as the rights to access, rectification and erasure and the right to object to automated decision-making.
- Is blockchain appropriate?: The first question that must be answered is whether blockchain is the most appropriate technology for the processing use case. If a centralised database can achieve the same result with less risk, that solution should be preferred.
- Choose a private, permissioned blockchain: Public, permissionless blockchains (such as Bitcoin or Ethereum) present significant challenges for GDPR compliance. The EDPB strongly recommends using a private, permissioned blockchain, to give participants in the network greater control over the processing of personal data by the network.
- Minimise the processing of personal data: The immutability of blockchain solutions makes deletion or rectification of personal data challenging. Wherever possible personal data should be kept off-chain – instead, only hashes or proofs should be stored on chain.
- Establish clear governance: Clear governance is particularly important when using blockchain solutions as they can lead to a blurring of the lines between controllers and processors and compliance obligations.
- Consider cross-border transfers: Wherever personal data may be transferred outside the EEA to countries not subject to an adequacy decision from the EU, it will be necessary to put in place a compliant solution which will most often include the use of the Standard Contractual Clauses. These will usually therefore need to be incorporated into the contractual arrangements for the solution.
While the final Guidelines provide helpful confirmation of the EDPB’s approach, they miss an opportunity to address several key areas of uncertainty, such as:
- providing concrete examples of GDPR-compliant use cases for public, permissionless blockchains;
- offering further guidance on when encryption or hashing might result in effective anonymisation, particularly following the CJEU’s decision in EDPS v Single Resolution Board (see our recent post here); and
- considering the practical implications of the EDPB’s acknowledgement that the right to rectification may, in some cases, require erasure of personal data rather than correction through subsequent transactions.
You can read our full client briefing on the draft guidelines, which considers the EDPB’s recommendations and these outstanding questions in more detail, here.

/Passle/5badda5844de890788b571ce/SearchServiceImages/2026-07-17-13-59-00-842-6a5a3524fe349fc6afb44812.jpg)
/Passle/5badda5844de890788b571ce/SearchServiceImages/2026-07-16-20-49-26-788-6a5943d68c2e773540fef0a1.jpg)
/Passle/5badda5844de890788b571ce/SearchServiceImages/2026-07-15-14-29-36-561-6a57995077150555cae1ff76.jpg)
/Passle/5badda5844de890788b571ce/SearchServiceImages/2026-07-14-11-09-35-409-6a5618ef3b3a0bc7a472d324.jpg)