EDPB Guidelines 02/2025: Blockchain, Governance, and GDPR Compliance
Article 25 GDPR mandates integrating data protection safeguards (minimisation, encryption, retention) at the system design stage (By Design) and ensuring the most privacy-protective settings by default without requiring user intervention (By Default).
Data Protection by Design (Art. 25.1)
Under EDPB Guidelines 4/2019, the principle of Data Protection by Design requires data controllers to implement appropriate technical and organisational measures both at the time of determining the means for processing and at the time of the processing itself.
This assessment must account for the state of the art, implementation costs, nature, scope, context, and purposes of processing, as well as the risks to the rights and freedoms of data subjects:
- Implementation of pseudonymisation and encryption in transit and at rest;
- Native embedding of retention periods and automated purging of expired data;
- Granular access controls anchored in the principle of least privilege.
Data Protection by Default (Art. 25.2)
The principle of Data Protection by Default requires that, by default, only personal data strictly necessary for each specific purpose of the processing are processed, without necessitating user action.
This applies to the amount of data collected, the extent of their processing, the period of their storage, and their accessibility (ensuring data is not made accessible without individual intervention to an indefinite number of natural persons).
Blockchain: Designing Architecture to Safeguard Data Subject Rights
The final EDPB Guidelines 02/2025 emphasize that blockchain technology is not inherently incompatible with the GDPR, but that governance structures and architectural choices must be deliberately resolved at the design stage.
Personal data should not be stored directly on-chain in plaintext: the EDPB recommends storing personal data off-chain, implementing cryptographic commitments (such as salted hashes or zero-knowledge proofs), and establishing clear contractual governance among participants:
- Identify controllers, processors, or joint controllers according to the network's governance model;
- Prefer permissioned blockchains where this facilitates accountability allocation;
- Assess the necessity of a public ledger before making data globally accessible;
- Evaluate the impact of ledger immutability on erasure and rectification rights, and isolate identifiable personal data outside the immutable state layer.
Verified Official Sources
Traitements de données au moyen de blockchains : nécessité de l'architecture, minimisation, données hors chaîne, gouvernance des rôles, protection dès la conception et effectivité des droits (version finale 2.0 adoptée le 7 juillet 2026).
Consult official source →General Data Protection Regulation — EU Reference Legal Framework
Consult official source →Privacy by Design & by Default, minimisation, sécurité dès la conception
Consult official source →Associated Operational Micro-Tools
Check whether your project triggers mandatory DPIA requirements or meets the EDPB 9 high-risk criteria.
See Also in the Legal Framework
Article 25 GDPR : Data Protection by Design and by Default Principles
Practical implementation of Article 25 GDPR and EDPB Guidelines 4/2019: integrating data protection principles upstream ...
Article 35 GDPR : Criteria and Methodology of the DPIA
Legal framework of the Data Protection Impact Assessment (Art. 35 GDPR): mandatory cases, WP248 high-risk criteria, asse...
Article 32 GDPR : Security of Processing Through Risk-Appropriate Measures
Article 32 GDPR: pseudonymisation and encryption, confidentiality, integrity, availability and resilience, prompt restor...