Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. EDPB Guidelines 02/2025 (Blockchain)
Resources
Français (Belgique / France) English Nederlands (België / Nederland)
EU Legal Reference🇪🇺 EDPB Guidelines🇪🇺 Adopted Doctrine

EDPB Guidelines 02/2025: Blockchain, Governance, and GDPR Compliance

Official EU Regulation (EU) 2016/679 legal analysis · Verified official sources

⚡ In 30 seconds:

Article 25 GDPR mandates integrating data protection safeguards (minimisation, encryption, retention) at the system design stage (By Design) and ensuring the most privacy-protective settings by default without requiring user intervention (By Default).

Data Protection by Design (Art. 25.1)

Under EDPB Guidelines 4/2019, the principle of Data Protection by Design requires data controllers to implement appropriate technical and organisational measures both at the time of determining the means for processing and at the time of the processing itself.

This assessment must account for the state of the art, implementation costs, nature, scope, context, and purposes of processing, as well as the risks to the rights and freedoms of data subjects:

  • Implementation of pseudonymisation and encryption in transit and at rest;
  • Native embedding of retention periods and automated purging of expired data;
  • Granular access controls anchored in the principle of least privilege.

Data Protection by Default (Art. 25.2)

The principle of Data Protection by Default requires that, by default, only personal data strictly necessary for each specific purpose of the processing are processed, without necessitating user action.

This applies to the amount of data collected, the extent of their processing, the period of their storage, and their accessibility (ensuring data is not made accessible without individual intervention to an indefinite number of natural persons).

Blockchain: Designing Architecture to Safeguard Data Subject Rights

The final EDPB Guidelines 02/2025 emphasize that blockchain technology is not inherently incompatible with the GDPR, but that governance structures and architectural choices must be deliberately resolved at the design stage.

Personal data should not be stored directly on-chain in plaintext: the EDPB recommends storing personal data off-chain, implementing cryptographic commitments (such as salted hashes or zero-knowledge proofs), and establishing clear contractual governance among participants:

  • Identify controllers, processors, or joint controllers according to the network's governance model;
  • Prefer permissioned blockchains where this facilitates accountability allocation;
  • Assess the necessity of a public ledger before making data globally accessible;
  • Evaluate the impact of ledger immutability on erasure and rectification rights, and isolate identifiable personal data outside the immutable state layer.

Verified Official Sources

🇪🇺 Adopted EDPB Guidelines
Guidelines 02/2025 on processing of personal data through blockchain technologies · 2026-07-07

Traitements de données au moyen de blockchains : nécessité de l'architecture, minimisation, données hors chaîne, gouvernance des rôles, protection dès la conception et effectivité des droits (version finale 2.0 adoptée le 7 juillet 2026).

Consult official source →
⚖️ Binding Source
Regulation (EU) 2016/679 (GDPR) · CELEX: 32016R0679 · 2016-04-27

General Data Protection Regulation — EU Reference Legal Framework

Consult official source →
🇪🇺 Adopted EDPB Guidelines
Guidelines 4/2019 on Article 25 Data Protection by Design and by Default

Privacy by Design & by Default, minimisation, sécurité dès la conception

Consult official source →

Associated Operational Micro-Tools

🔎
Art. 35 GDPR
DPIA Check (WP248 Criteria)

Check whether your project triggers mandatory DPIA requirements or meets the EDPB 9 high-risk criteria.

Launch interactive tool →

See Also in the Legal Framework

Article 25 GDPR Official Text

Article 25 GDPR : Data Protection by Design and by Default Principles

Practical implementation of Article 25 GDPR and EDPB Guidelines 4/2019: integrating data protection principles upstream ...

View document
Article 35 GDPR Official Text

Article 35 GDPR : Criteria and Methodology of the DPIA

Legal framework of the Data Protection Impact Assessment (Art. 35 GDPR): mandatory cases, WP248 high-risk criteria, asse...

View document
Article 32 GDPR Official Text

Article 32 GDPR : Security of Processing Through Risk-Appropriate Measures

Article 32 GDPR: pseudonymisation and encryption, confidentiality, integrity, availability and resilience, prompt restor...

View document
← Explore this topic in the interactive RGPD.click knowledge base
Reviewed date: 2026-08-28 Last modified: 2026-08-28

Independent legal reference documentation on Regulation (EU) 2016/679 (GDPR).

Home · Resources Index · Privacy Policy · Legal Notice