Skip to content

BLOCKCHAIN LAB BRIEFING · KYB AND IDENTITY

A Public Ledger Is a Poor System of Record for Personal Data. GDPR Makes That Operational.

The General Data Protection Regulation assumes you can limit access, state a purpose, and often delete. A public replicated ledger assumes the opposite. Do not store the person on the chain.

2 October 2026

All briefings

01

What happened

Regulation (EU) 2016/679 requires a lawful basis, purpose limitation, data minimisation, and, in many cases, a way to erase or to stop processing personal data. A public blockchain replicates data to parties the controller does not choose, for as long as the network keeps the history.

That tension is not solved by hashing a name if the name is still recoverable, and it is not solved by saying the chain is decentralised. Decentralisation is not a lawful basis.

02

Why it matters

The Canon’s rule, and the rule on every briefing about verification, is the same: wallet, status, policy, expiry, and a salted hash if you need a link to an off-chain file. Not the file. Not the passport. Not the email.

Product teams under pressure to make KYB on-chain are usually trying to impress a reviewer with transparency. The reviewer who understands GDPR will ask the opposite question: why was this published.

03

The operating layer

Decide the controller before you design the transaction. If you cannot name the controller, you are not ready to write personal data anywhere. Keep documents in a system that can delete. If you need a public commitment, commit to a hash whose inputs stay off-chain, with a salt that is not the person’s identifier.

A privacy policy that says we do not control the chain is an admission, not a control.

04

What is verified

The regulation is public on EUR-Lex. European supervisors have warned for years about personal data in distributed ledgers. This page is not a data-protection impact assessment.

05

What remains unclear

Whether a particular transaction input is personal data in context, including a wallet that has already been linked to a person in your own systems. How long your off-chain store actually retains the document.

06

The catch

Publishing less is the design. Adding a second private chain for the same documents adds cost and still requires a deletion story. The simplest design remains: the chain holds a minimum reference, and the document lives where the law expects a controller to be able to act.

Not legal advice.

WATCH

What builders should watch

  1. 01The fields in each on-chain record, listed, with a reason.
  2. 02Who the controller is for the off-chain file.
  3. 03The erasure path, tested, for that file.

BOTTOM LINE

If you cannot erase it, do not write it. A hash is a reference, not a document.

Sources

Blockchain Lab uses public social posts as reporting leads, not as proof. Every published briefing is assessed against primary sources, available documentation and relevant technical context. Social engagement is not used as evidence of the underlying claim.

Continue