Live data from Hacker News

Blockchain technology is on a collision course with EU privacy law

iapp.org

1–10 of 46 posts

Re: Blockchain technology is on a collision course with EU privacy law

#2
Some of the comments By interviewees in this article are so backwards it's comical:

> "From a practitioner's perspective, it sounds to me that it was drafted by trying to implement a certain perspective of how the world should be without taking into account how technology actually works," Steiner said. "The way [public decentralized network] architecture works, means there is no such thing as the deletion of personal data. The issue with information is once it's out, it's out."

My answer to this is - don't put personal information in the blockchain then! What's the purpose of technology that doesn't serve human needs?

It's a bizarre worldview that positions technology as the master, not the servant of mankind.

Re: Blockchain technology is on a collision course with EU privacy law

#3
If you put data that's considered personal into a public blockchain, or any decentralized system, who becomes the owner of that data? Was it the company/service that originally published it on the blockchain? or is every node required to treat it as their own GDPR-compliant data?

Re: Blockchain technology is on a collision course with EU privacy law

#4

Some of the comments By interviewees in this article are so backwards it's comical: > "From a practitioner's perspective, it sounds to me that it was drafted by trying to implement a certain perspective of how the world should be without taking into account how technology actually works," Steiner said. "The way [public decentralized network] architecture works, means there is no such thing as the deletion of personal…

> It's a bizarre worldview that positions technology as the master, not the servant of mankind.

Your comment is at odds with this statement. Blockchain and smart contracts appeal to those who want lines of code to have the final say in transactions. Most people want our institutions to make those decisions!

Re: Blockchain technology is on a collision course with EU privacy law

#5
There's a very naive assumption in the article that Blockchain being incompatible with GDPR issue can be resolved by altering GDPR.

I think it is impossible: GDPR is specifically designed to prevent sensitive personal information from leaking and information about one's financial transactions is one of the most sensitive pieces of information there is.

So, if GDPR versus Blockchain case ever reaches any EU court the only possible ruling is to outlaw the Blockchain technology (at least in it's current incarnation).

Re: Blockchain technology is on a collision course with EU privacy law

#6
post #3

If you put data that's considered personal into a public blockchain, or any decentralized system, who becomes the owner of that data? Was it the company/service that originally published it on the blockchain? or is every node required to treat it as their own GDPR-compliant data?

Not just a public blockchain, any blockchain. Say an employee leaves, they should have the right to have records removed. The internal Enterprise Blockchain doesn't allow that.

But because of hype, every big company has to have some sort of blockchain somewhere, for no good reason. The EU will get a lot of bad publicity while actually doing something very reasonable.

Re: Blockchain technology is on a collision course with EU privacy law

#7
post #3

If you put data that's considered personal into a public blockchain, or any decentralized system, who becomes the owner of that data? Was it the company/service that originally published it on the blockchain? or is every node required to treat it as their own GDPR-compliant data?

[deleted]

Re: Blockchain technology is on a collision course with EU privacy law

#8
post #3

If you put data that's considered personal into a public blockchain, or any decentralized system, who becomes the owner of that data? Was it the company/service that originally published it on the blockchain? or is every node required to treat it as their own GDPR-compliant data?

GDPR defines "data controllers" and "data processors," who both have obligations to the "data subject." Who qualifies as the "data controller" may be ambiguous in this situation, but it's a reasonable proposition that every node would be considered a "data processor" for that data.

Re: Blockchain technology is on a collision course with EU privacy law

#9
post #5

There's a very naive assumption in the article that Blockchain being incompatible with GDPR issue can be resolved by altering GDPR. I think it is impossible: GDPR is specifically designed to prevent sensitive personal information from leaking and information about one's financial transactions is one of the most sensitive pieces of information there is. So, if GDPR versus Blockchain case ever reaches any EU court the…

Laws are mutable, in general blockchains aren't. It is the case that the law can be modified.

> I think it is impossible

Unless they create an exemption for technologies which effectively partition transaction details from identity details. Or they could require the use of masking/ambiguation features like Ring signatures, mixer/tumblers, etc.

Re: Blockchain technology is on a collision course with EU privacy law

#10
post #4

Some of the comments By interviewees in this article are so backwards it's comical: > "From a practitioner's perspective, it sounds to me that it was drafted by trying to implement a certain perspective of how the world should be without taking into account how technology actually works," Steiner said. "The way [public decentralized network] architecture works, means there is no such thing as the deletion of personal…

> It's a bizarre worldview that positions technology as the master, not the servant of mankind. Your comment is at odds with this statement. Blockchain and smart contracts appeal to those who want lines of code to have the final say in transactions. Most people want our institutions to make those decisions!

Current technology is great but still sometimes it fails. It's comforting to know that there's an actual human being that you can talk to and ask them to fix the mistake made by software.

That's what makes technologies like Blockchain at odds with human needs: unless you can formally prove that your software does not contain any bugs and therefore does not make mistakes there always has to be the room for manual intervention (like deleting personal data from blockchain).

Post reply on HN