Live data from Hacker News

Blockchain technology is on a collision course with EU privacy law

iapp.org

11–20 of 46 posts

Re: Blockchain technology is on a collision course with EU privacy law

#11
GDPR is not only conflicting with some Blockchain use cases but with old-fashioned ledgers and paper-based accounting as well because the same principles apply here, too (an entry cannot be deleted, its effect can merely be reversed).

If followed to the letter GDPR would've major repercussions on tax regulations because as a company you're legally bound to keep accounting records for at least 10 years whereas according to GDPR you're required to delete any record if asked by a person whose personal data appears in that record.

The solution in that case is that GDPR only applies if it doesn't contradict other, already existing laws.

So, where Blockchain applications facilitate legal requirements or don't manage personal data this should be perfectly fine but yes, other types of Blockchain applications are pretty much ruled out by GDPR.

Re: Blockchain technology is on a collision course with EU privacy law

#12
post #3

If you put data that's considered personal into a public blockchain, or any decentralized system, who becomes the owner of that data? Was it the company/service that originally published it on the blockchain? or is every node required to treat it as their own GDPR-compliant data?

Not just a public blockchain, any blockchain. Say an employee leaves, they should have the right to have records removed. The internal Enterprise Blockchain doesn't allow that. But because of hype, every big company has to have some sort of blockchain somewhere, for no good reason. The EU will get a lot of bad publicity while actually doing something very reasonable.

> because of hype, every big company has to have some sort of blockchain somewhere, for no good reason.

Fortunately that's not actually the case. Amusingly, it's nothing more than hype that every big company is actively using blockchain somewhere. Most of the Fortune 500 could care less from what I've seen of press releases and a couple hundred quarterly reports over the last two years. Blockchain is meaningless to their businesses for now because it's still not being used for anything of consequence to them. There are a few exceptions, most of which are in finance.

Re: Blockchain technology is on a collision course with EU privacy law

#13

GDPR is not only conflicting with some Blockchain use cases but with old-fashioned ledgers and paper-based accounting as well because the same principles apply here, too (an entry cannot be deleted, its effect can merely be reversed). If followed to the letter GDPR would've major repercussions on tax regulations because as a company you're legally bound to keep accounting records for at least 10 years whereas accordi…

> If followed to the letter GDPR would've major repercussions on tax regulations because as a company you're legally bound to keep accounting records for at least 10 years whereas according to GDPR you're required to delete any record if asked by a person whose personal data appears in that record.

http://www.privacy-regulation.eu/en/recital-65-GDPR.htm

False. You're allowed to retain the data where it is necessary to comply with other legal obligations, or to protect yourself legally (e.g. failure to pay invoices), among other reasons.

Re: Blockchain technology is on a collision course with EU privacy law

#14
post #9
post #5

There's a very naive assumption in the article that Blockchain being incompatible with GDPR issue can be resolved by altering GDPR. I think it is impossible: GDPR is specifically designed to prevent sensitive personal information from leaking and information about one's financial transactions is one of the most sensitive pieces of information there is. So, if GDPR versus Blockchain case ever reaches any EU court the…

Laws are mutable, in general blockchains aren't. It is the case that the law can be modified. > I think it is impossible Unless they create an exemption for technologies which effectively partition transaction details from identity details. Or they could require the use of masking/ambiguation features like Ring signatures, mixer/tumblers, etc.

> Laws are mutable, in general blockchains aren't. It is the case that the law can be modified.

Or storing someone else's personal information on the blockchain opens you up to an effectively unlimited liability: Not smart.

It really depends on what is being stored. Is it that there is €30 in account 123 and €50 in account 234? It's unclear if this is personal information if someone can have multiple accounts and access them anonymously.

Re: Blockchain technology is on a collision course with EU privacy law

#15
Clickbaity headline. It's not the "blockchain technology" as a whole, but some specific use of it that can potentially violate the GDPR. You don't need a blockchain to violate the law: you can do it with paper or mysql or usb keys.

Bottom line is: don't put your customers' personal data onto anything that you don't control.

Nothing to see here.

Re: Blockchain technology is on a collision course with EU privacy law

#16
post #3

If you put data that's considered personal into a public blockchain, or any decentralized system, who becomes the owner of that data? Was it the company/service that originally published it on the blockchain? or is every node required to treat it as their own GDPR-compliant data?

Not just a public blockchain, any blockchain. Say an employee leaves, they should have the right to have records removed. The internal Enterprise Blockchain doesn't allow that. But because of hype, every big company has to have some sort of blockchain somewhere, for no good reason. The EU will get a lot of bad publicity while actually doing something very reasonable.

> Say an employee leaves, they should have the right to have records removed.

Not exactly. They have the right to be forgotten which is slightly different, and the company has certain rights to keep those records. Recital 65 is quite broad and allows a company to remember that it hired (or fired) someone because it may need this information to protect against legal claims, or to pay taxes correctly (i.e. another legal obligation). It would seem to permit private blockchains, and (at least in some cases) public blockchains.

http://www.privacy-regulation.eu/en/recital-65-GDPR.htm

Re: Blockchain technology is on a collision course with EU privacy law

#17

Some of the comments By interviewees in this article are so backwards it's comical: > "From a practitioner's perspective, it sounds to me that it was drafted by trying to implement a certain perspective of how the world should be without taking into account how technology actually works," Steiner said. "The way [public decentralized network] architecture works, means there is no such thing as the deletion of personal…

> don't put personal information in the blockchain then!

Someone else may do that for you. Example: revenge porn. Here's a relevant experiment:

https://boobies.surge.sh/

Re: Blockchain technology is on a collision course with EU privacy law

#19
Wouldn't it easy for a blockchain to just reference external data which then get deleted to comply with GDPR? I know, breaks some ideas about storing data in the chain, but if that's the compromise that works. In the end it will all be about the specific implementation of each blockchain, the idea of blockchains in general will never be endangered like u/mamon suggested.

Re: Blockchain technology is on a collision course with EU privacy law

#20
post #13

GDPR is not only conflicting with some Blockchain use cases but with old-fashioned ledgers and paper-based accounting as well because the same principles apply here, too (an entry cannot be deleted, its effect can merely be reversed). If followed to the letter GDPR would've major repercussions on tax regulations because as a company you're legally bound to keep accounting records for at least 10 years whereas accordi…

> If followed to the letter GDPR would've major repercussions on tax regulations because as a company you're legally bound to keep accounting records for at least 10 years whereas according to GDPR you're required to delete any record if asked by a person whose personal data appears in that record. http://www.privacy-regulation.eu/en/recital-65-GDPR.htm False. You're allowed to retain the data where it is necessary t…

That‘s exactly what I said. For instance, you have to retain accounting records such as invoices even if the invoice recipient asks you to delete the personal data on that invoice.

Anything else would open up new avenues for tax fraud.

Post reply on HN