This gets close to something else I've been pondering lately - how to deal with immutable data structures in the realm of GDPR. Recitations in GDPR require systems to be designed with privacy in mind. Immutable structures like the Bitcoin blockchain or Merkle trees in other applications would seem to be fundamentally incompatible with some GDPR privacy requirements. Let's say Google receives a valid right to be forgo…
And against whom would I claim my rights, for example: my right to be forgotten (Article 17: The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay [...])?
In the case of a distributed blockchain, who is the controller as defined by the GDPR?
And even if one could identify a controller (say, in the case of a blockchain under centralized control), there are still exceptions to the rights of data subjects. Privacy is key to the GDPR, but not an absolute.