Blockchain and the General Data Protection Regulation: an irreconcilable regulatory approach?
Abstract
A blockchain is a class of technology that allows the creation and management of \ndifferent forms of decentralised and distributed digital ledgers where data are stored, \nchronologically recorded, transferred and finally shared between the ‘nodes’ participating in \na peer-to-peer network. These features prima facie clash with the GDPR that informs the EU \ndata protection legislation and is based on a centralised representation of the reality in which \ndata are processed, collected, and recorded in a database controlled by identified subjects. \nThe underpinning idea of this article is diametrically opposed to the one which considers the \ntechnology not GDPR-compliant by default. First, the author argues that the points of tension \ncan be mitigated by technical and/or governance methods, thus acting at both application and \ninfrastructure level. In essence, a case-by-case analysis is the only feasible option to assess the \ncompliance between the regulation and the technology. Second, a further and closer look at \nblockchain’s underlying concepts reveals how both the GDPR and the blockchain have the \nsame purposes but different approaches. More interestingly, the article suggests that the \nblockchain could be seen as a Privacy Enhancing Technology (PET), which might help data \nsubjects gain more control over their personal data and hence support one of the GDPR’s \npurposes (recital 7).
Community
0 commentsNo discussion yet
Be the first to share a question or observation.