Blockchain has led to a new way of storing data and guaranteeing data integrity and transparency. However, tensions still remain between blockchain and the current legal system, especially data protection law. This paper chooses the General Data Protection Regulation (GDPR) in the European Union to identify how blockchain can be compatible with the principles of modern data protection law and if blockchain can also be a way through which to achieve legal objectives. Finally, this paper proposes standardisation as a way to mitigate blockchain’s drawbacks and to leverage its advantages.
This paper studies three existing technical solutions for a self-sovereign identity on blockchains and analyzes the arising issues related to the General Data Protection Regulation (GDPR) of the European Union (EU). In particular, the paper provides an overview of the existing Sovrin self-sovereign identity on the Hyperledger Indy public permissioned blockchain as well as uPort and Jolocom on the Ethereum public permissionless blockchain. The paper then concludes with a discussion on the GDPR-compliance of the blockchain-based identity concepts.
Dieser Beitrag untersucht die Einwilligung im Kontext der Humanforschung und zeigt auf, welche Gesetzesänderungen notwendig sind, um die Grundlagen für ein elektronisches Einwilligungsverfahren zu schaffen. Anhand der Funktionen der einzelnen Merkmale der Schriftlichkeit wird ein aktuelles prototypisches Verfahren und die Möglichkeiten der Distributed-Ledger-Technologie geprüft.
Die längst überfällige Neugestaltung des europäischen Stromnetzes erfordert eine Aufteilung der Hauptenergiepools in kleinere und regionale Energieerzeuger. Die Vor-Ort-Produktion von erneubaren Energie kann einen positiven Beitrag zur Entlastung der Stromnetze leisten und damit die Netzstabilität erhöhen und die Kosten senken. Darüber hinaus ermutigen blockchainbasierte Smart Contracts Prosumer dazu, sich über das Peer-to-Peer-Netzwerk am direkten Handel zu beteiligen. Die dadurch geschaffene Transparenz eliminiert Intermediäre, erhöht die Entscheidungsfreiheit der User und verringert die Marktmacht der Hauptanbieter. Mit den passenden regulatorischen Maßnahmen kann diese Transformation beschleunigt und vorangetrieben werden. All dies kann eine breitere Beteiligung an der Ökostromerzeugung erleichtern und zu einem nachhaltigeren Stromnetz beitragen.
In den vergangen Jahren haben Corwd-Sensing-Anwendungen immer mehr an Relevanz gewonnen. Mit der Zunahme von mobilen Geräten nahm auch die Verwendung dieser als Sensoren zur Datenerhebung zu. In dieser Arbeit betrachten wir hierbei die Nutzung eines solchen Systems zur Verfolgung mobiler Objekte. Smart-Contracts bieten seit wenigen Jahren die Möglichkeit, dezentral auf einer Blockchain Anwendungen zu implementieren, welche nicht auf einen einzelnen Server angewiesen sind. Smart-Contracts sind transparent und können außerhalb der ersichtlichen, implementierten Möglichkeiten nicht manipuliert werden. Mobile-Target-Tracking-Anwendungen selbst sind keine Neuheit mehr, wohl aber die dezentrale Ausführung dieser auf einer Blockchain. Im Rahmen dieser Arbeit wurde eine Mobile-Target-Tracking-Anwendung implementiert, welche mithilfe von Crowd-Sensing ein Objekt sucht. Die erfassten Daten werden an den Smart-Contract in der Ethereum-Blockchain gesendet, dort gespeichert und nach Erreichen bestimmter Kriterien ausgewertet. Die korrekten Meldungen sollen vom Smart-Contract mit einem Ether-Betrag belohnt werden. Dazu werden in dieser Arbeit verschiedene Algorithmen zum Finden einer konsistenten Menge von Sichtungen diskutiert. Die Herausforderungen der Implementierung und die Evaluation der entstandenen Smart-Contracts werden in dieser Arbeit vorgestellt.
Shares issued on a distributed ledger have already been designated as a future market standard. The potential of these dlt-shares is also acknowledged by the Swiss government, which has published a preliminary draft on the adaptation of federal law to developments in distributed ledger technology earlier this year. This essay focuses on various mainly private law issues related to the issuance…
Whereas Article 22 of the General Data Protection Regulation (‘GDPR’) prohibits solely automated data processing, the precise scope of this qualified prohibition as well as related requirements remain untested and unclear. Examining Article 22 GDPR from the perspective of smart contracts sheds light on the resulting uncertainties and inconsistencies. Smart contracts indeed appear to qualify as a form of solely automated data processing under Article 22(1) GDPR. This implies that they can only be used where they meet the requirements of Article 22(2) and implement the safeguards of Article 22(3) GDPR. Under Article 22(2) GDPR, solely automated data processing can only be used where it (i) is necessary for a contract between the data subject and controller, (ii) authorized by EU or Member State law, or (iii) based on the data subject’s explicit consent. At first sight, these requirements can be met in the smart contract context just as in others. Yet, the research unveils that even where a smart contract is related to a legal contract, that contract may not be between the data subject and controller. Furthermore, consent may have limited value in this context as under EU data protection law, the data subject must be able to revoke consent, which is difficult where the data processing cannot be halted at the request of the data subject. Where the requirements of Article 22(2) GDPR are met, Article 22(3) requires that data controllers implement safeguarding measures including a right to human intervention by the controller. There are ongoing uncertainties and controversies regarding the scope of this obligation that also permeate the smart contract context. Yet, solutions are already being developed to create forms of smart contracts that may be responsive to these legal obligations, confirming the GDPR’s innovation-shaping function. In accordance with Article 22(1) of the General Data Protection Regulation (‘GDPR’) a data subject has the right ‘not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or or or At a where automated data processing is on the of the regarding the scope of this qualified prohibition and for the to subject to to the of the data of the Data Protection already that be as and that the of human intervention in indeed to a of human these the a prohibition of automated processing resulting in This by to in as Article of the Data Protection In the GDPR a and forms of solely automated processing, of they or In of for the data the precise of this remain as it in the prohibition of solely automated data processing has in law, in automated not solely forms of data are or are based on this which in data processing and has to be the as it and that are able to human from the perspective of and Smart which are the of the are form of automated data processing that to and Smart contracts can be as that it is these are in the context of the of automated is also being with in to and has already used in for a of In automated is smart value smart contract is a that on of a and this of the of a this form of automated as automated for the of Article 22(1) GDPR, the data protection be a the to which smart contracts can be used in the smart contracts have from the perspective of contract as the has to Whereas a smart contract only in be to a legal contract, they of automated data processing, the of GDPR In this to light on smart contracts qualify as a form of solely automated data processing under the GDPR. smart contracts as to the of Article 22 as well as to the of smart contracts in the legal with to the Article 22 GDPR and to smart with a of that smart solely automated processing and the GDPR’s qualified prohibition in Smart contracts are of the with have as on that are of on the of In a smart contract is that is of these to they are just with the on and legal Furthermore, smart contracts are in to are to smart contracts the of this to a smart contract as of in including which the on these in a that it difficult for to by the of contracts that be and by and of a the smart contracts are that value and only it are a smart contracts are that can be by a of the of a the have and In the the has and as has on smart contracts are also legal even of contract of smart contracts are to which in including that of to in and in that smart contracts for of they are in with legal to smart contract is that the of a and the of that on the of by the or from the smart contracts can indeed be used as a of that smart contracts are also legal smart contract is not smart a Smart contracts are not as they are to as or to are can be or or that the as a has or have Smart contracts also cannot be qualified as contracts in the legal they are a to for smart contract is a of that a in for they are as of and can that smart contracts are smart contracts that they are the is the At on where the is smart contract and cannot be halted this is the or a or the on automated in of human or and and smart contracts can of is smart value already that the are and of to a at has the intervention of a or the is by the automated Where smart contracts are used to the of obligations, is the the can be used for the of in the of or to are for smart contracts for Smart contracts can be on to to where are In this the smart contract is to and where these a a is to the Smart contracts may to This has not as the has to smart contracts in to Smart contracts the of a of also by smart contracts as a of of not only also Where can be This can be as a legal or to on as by cannot be can also be for as the of including and to for and to the in by on also has as indeed in of as or which cannot be smart contracts have in to smart contracts from the of the that automated smart contract it not cannot be halted the has also a that that smart contracts also be on that smart contracts are a it is that they have a this automated that with a is of a smart Under this smart contracts can be in be as of a smart contract, as well as a and of these and are as the are in in a to human intervention in the the of automated In this is not a the and of smart contracts contracts have for a smart used in a or legal for is that in smart contracts are to the automated of This a of automated data GDPR, a qualified prohibition of solely automated data Article 22(1) GDPR that data have the right not to be subject to decision based solely on automated processing, including profiling, which produces legal effects or or or smart contracts are by this it must be (i) a smart contract as a decision based solely on automated processing, and (ii) that decision produces legal effects for the data subject or or GDPR automated data automated processing a of or a indeed that automated processing not be as a the of the GDPR in the of it the and the on the with in the of the In the for a of the that automated processing of data not to to the scope of Article it that automated a scope and may with or from also a of solely automated as to by human decision is on automated processing where is human in the to and smart automated can be of as of value in which of the is by a human GDPR only solely automated data This the a smart contract can be qualified as a This is of the GDPR that may have it also in of as the precise to be to the at This is by the that Article 22 only to by solely automated data processing, that data have the right not to be subject to a which may a based on solely automated data of in the in the of the GDPR a of which to as the of the GDPR indeed only used the of in Article which only by the these to be be by the of have that a is or with legal a is or with this is indeed the in can be as Article 22 that can have legal effects or In the that that a can also be a that the to be of of the to a of GDPR as data or in to the and protection of data the At where a smart contract to that be a human in the be as a This be the where a smart contract is used in to on the of it is the of a smart contract to a or a appear that the that human is in where is by law, even of have the of under the of related of smart contracts may qualify as measures and be the of EU data protection has of by Article the of on the of as of solely automated human This smart contracts a that is by and by a This even be qualified as a smart contract a of the as or are to qualify as for GDPR it is to that smart contract the of a smart contract as a decision or may also the of may that the to the of the smart contract of a as a decision a or of a In with the of smart is human at the of that Article 22(1) to that the a and is of the that in the smart in be on the and of the smart a human as the the smart contract data to Furthermore, are also to human Where a smart contract is to a legal contract as a smart contract is used to of the be to Whereas this to to the of Article it is to be that Article 22(2) explicit from the Article 22(1) prohibition where a smart contract is used to a human in the of the contract to be for the of the first be for explicit to this in the the of Article 22 GDPR as a the that the for the of Article 22(1) is to be the of the which indeed human may that smart contracts are at in by Article 22(1) GDPR. a the qualified prohibition of automated data processing only where automated processing produces legal or effects on the data subject. This is the of the Article 22(1) that Under Article 22(1) GDPR, data are only not to be to based on automated processing the legal effects or is necessary to smart contracts can (i) legal or (ii) This is to be on a and be as the of where be effects on at smart contracts have for as they is are or for a or is has as a in legal or obligations, legal or under a a smart contract is used to a obligation a in legal and where a is or a or is the of and the of smart contracts have legal effects and as a be by Article where legal effects are a smart may a data subject. Under Article a can be or and where the of automated data processing are or to be of This is to effects on the or of the or a or on the In this to Article scope of as effects of from context and to automated decision to to a on a or may be in in as where a to a Whereas is on the of is to be from or it to that is as is and data protection by effects a is it is to that this be in at is that effects that are from to to legal is is a that Article 22(1) a in a where with legal effects be by the prohibition of automated processing, even where they are a of a from the of automated of or automated human which are in that must be is that of the necessary for forms of solely automated data processing to be by the GDPR. is for solely automated data processing of data is data or is by Article 22 or to be data that as data for this to be the This is not from the of Article 22(1) which of a decision being to data This the of data the a data subject. that is a for data to qualify as be the in of or automated where the data is indeed may can be where data is not data and the decision is that Article 22 GDPR that smart contracts are to at in the scope of the GDPR’s qualified prohibition of automated This prohibition is automated processing can be on the of Article 22(2) GDPR. of Article 22 GDPR in which automated data processing in and the to smart that only with that not as in for processing to Article 22(2) the prohibition of automated processing not the is necessary for or a contract between the data subject and a data is by or Member State to which the is subject and which also measures to the data and and or is based on the data explicit consent. to the prohibition of automated processing under Article 22(1) it that automated is where it is necessary for the or of a contract between the data subject and the controller. that the for smart contracts in the automated of legal Where the smart contract is to a automated processing in the form of can be that the legal contract is between the data subject and the data controller. the of the and the that automated must be of the of a the that that this contract must between the and the data which has in the of the In this not where a a smart contract to automated the is a to the contract, and at the the data in to the Where and that can be and used by are used to the smart contract, the that the contract be between the data subject and the data In a data may be in of the data to the be with the smart contracts may also be to be data for the of Article 22 GDPR where they a decision that is to the data subject where this in data that or to or the on also qualify as Under the GDPR, a data is the that or the and and of data has that a of this to be the in that of a are controllers with regarding of the data that the of a must be to the and protection of data a the of a on be as by of in on and the of and in the of the and of processing the data of the to that where a smart contract is the that is on also a data controller. Yet, and are not by a legal that be as the controller. these are by the of a of including and and as to as the from the perspective of the Data Protection that smart contract can also be data controllers in Whereas the precise of the data has to be in light of a it to that at the as well as at the smart are under the GDPR. is to be that the the to the smart contract also be a these a in to the of Article is is as of on this it to that the of a with at of controllers be to this it is the of as Article that solely automated data processing may where it necessary for or a contract between the data subject and a data the of this at this it be to that solely automated processing only be used where are Yet, is can be on the of the of solely automated data processing in the that of a and automated the of be indeed as and are well in the of the the has that is not where and to the this that to be the by the by the it the in to processing that where of of for a this of may automated necessary as a first in the this is is a to be as the be even it of There regarding the scope of and can that is necessary in the of or Article GDPR Member or the EU to create to the prohibition of automated processing that data subject and are At this has at EU or Member State to solely automated data processing in to smart At the Member to related to may on Article GDPR for these of this in the that the requirements under Article 22(3) GDPR, not Article GDPR automated data processing where it is based on the data subject’s explicit consent. Where is the smart contract this can be in a as explicit consent be on the as the contract is can be in as forms of where is legal contract to the smart at in the it also be to consent in are in this the of consent, which is not in the has by the in on consent as necessary in that data protection that of data is consent a or on of the data subject. Where consent is in of the of data processing, the data subject of which the form of a or the in of form or Data controllers are to of of consent is a Article GDPR requires that the data subject has right to or consent at this may not the of processing based on consent that to this in the of automated data processing this is it may be difficult for a data subject to to the data processing in consent. In and in the of that data processing as data be by the controller, which to the of or data in that data controllers to on consent as a for data processing Article 22(2) a of to smart contracts under EU Where this is the requirements must be on automated processing under Article or safeguarding measures in the form of a right to human intervention Article 22(3) and a right to be and has that where automated processing a a Data Protection may be Article 22(3) that where automated processing is authorized on the of the first or of Article the data implement measures to the data and and at the right to human intervention on the of the controller, to or of and to the EU data protection only automated data processing where it is in is indeed based on a Article 22(1) only where processing solely automated the of human by of Article 22(3) processing can be solely automated Article 22(3) obligation that automated data processing can only under Article or where is of human intervention on of the and the data subject’s and are Whereas the precise of the are subject to the of human intervention is Data are of to not on the of human for solely automated data processing under the GDPR. this to smart is human at must it be and is the data in a to it is to human intervention must to the of the data protection has that human intervention must not just be the form of a by the and to the a of the including by the data that human intervention not just be is has that to by and even where is that it is even where a is as a human as a it may be used as the where the human or the the must the in human intervention There is to this that it is that human intervention the decision has in the of the as a of In the smart contract that the of the smart contract it has a this is as a is for the it to the for of human smart contracts are to with the GDPR to of automated as In to the of human intervention for the of Article 22(3) may be for smart contracts to a smart contract to human intervention in a as in or can be as the smart contract is a by In as to be from human this is for the of a smart contract a even a for human intervention are to as these may be with the to human must be to Article that the data human the of the data in of and and is to be that be a of controllers at and qualify as a controller. of human intervention must be by these or only of the is that Article GDPR and requires that controllers that the of that the data subject can This that controllers are to with the of human it that the is that data controllers have that the of be with to the of the Where solely automated processing the data subject is to this of data Where automated processing the data subject has a right to be this subject to Article GDPR requires that the data with and the processing of this to be in to automated data processing on the between and as well as GDPR. Article GDPR that a data subject is to be the of automated including profiling, to in Article 22(1) and at in the as well as the and the of processing for the data subject. Article GDPR the in where data not from the data is also by Article that of be to the data subject. the (i) of automated (ii) the and (iii) the and the of the to a to the right to as it is with in these that in of solely automated processing, a data subject from including the right of the decision and to the Whereas the can be difficult to as it is not by the of the GDPR and this by the may be as that to of the precise in which a decision is is to be by the data controller, that the of also in this context. There has as to the of the of in the and of in is in the of a is that of a are not are to the of the and can with the that they cannot be used for a of the the GDPR a of for in the have the of the of just they uncertainties have to as to are under the GDPR. may the GDPR a to that may protection to data the a has regarding the of the GDPR’s right to In a first and that the GDPR a to in of a a to of not in the General Data Protection that is only a right to in only as right for be the of right to be automated decision that the between and Article 22 from the that a right to for Article 22 this in the of from the a in with by and that and 22 be that they for Whereas protection may a data subject’s right to they that the of protection be to data protection and a to and that the on the right be a right to by or a right to used in that a data to be and the of right to as a where they have by the have the as to these to be In the the has on these that is of data controllers is that they (i) the data subject that they are in solely automated processing, (ii) the (iii) and the and to these the of data these data are as are the is for the and it is used to a decision the data appear to to in of the that is used is as to the data subject the or the on in the is is ‘not a of the used or of the the to the data subject be to the for the these are a in the is a of the to be that of or of the that in it is not In the to to the data subject the or the on in the This the of which the or measures a for the and the of these requirements in a smart contract context be that these on the data the as the of the obligation be Smart contracts in the form of data and the in processing is a that can be and is the between the right to and the to automated processing explicit consent under Article may of is in to for consent to be Where the of automated processing are not it may be consent cannot be This may in a where is under Article as a of the obligation to the data subject of of data This is of as ongoing as have as to can a of a that may have data and may or There is a regarding and automated can be and which is is the of In data controllers that on smart contracts also be subject to a to a Data Protection In on automated processing obligation to a Data Protection are of the of the processing on data that to be by data controllers where the the context and of processing are of to the and of which can be the in where are Under Article GDPR are in where processing (i) a and of of based on automated (ii) data and data related to and or (iii) where the of a on is Where a that processing in a for data and measures to the can be the is to the At first the that a must the of a smart are where automated processing that Article to not automated as Article this is only the where processing a and of of it cannot be that as a the context and of processing are of to the and of be that in smart contracts are a a that smart contracts as a be of smart contracts has on in as in or automated and where a smart contract is on a of a and are to a as this a that a from a data protection it on a where and is from in to of the of as and of on these be as a for data a is in that a to be to the precise for the data subject as they from the and can also be as in with the data protection by Article GDPR requires the of the data protection of data protection by and data protection by data processing Article GDPR requires that controllers implement and measures to meet the GDPR’s at the of processing as well as the of In this the of the the of and the context and of processing as well as the of and for and of by the to be In the GDPR a for the to implement and measures that the requirements not just to the processing also to the as to that only the data for of the are these requirements is that may be a of to the of it is that to the of the of and it to has in the of the Data Protection that and measures to be in to processing and also is a of by as it is that in are measures that data processing, the of a data subject to data processing and and by the controller. have for smart Article GDPR obligation for to this as well as the they on in a with the GDPR not just Article the requirements of data protection by and data protection by smart contract on a This is are in a that with of the GDPR it is difficult for to meet the data they are a of or to implement data subject as they to and they are to human In light of these on Article GDPR, which the of as to with the data protection by and data protection by requirements have to are the scope of Article GDPR as the has not on the and the is in a with these is as it is a the of for of the has that the GDPR’s prohibition of solely automated processing to smart Whereas on automated smart contracts can be where it is necessary in a is authorized by law, or where the data subject to the processing, and must be in a data protection This the of human the of regarding the of processing in a in smart contract must also be in a that for the data protection by and by with these requirements at in be with as This is in the context. these that they can be in of or this human intervention in the and of the data Smart contracts can be used as a to that Yet, as smart contracts are to to and legal these and they may also GDPR in to by including the a these not in from have and it is that on for and to the smart contracts on these There is ongoing to smart contracts in of with of the that can as a in the or that the automated that smart contracts not be the automated and the of is ongoing of with that the of smart contracts and automated in this are ongoing research and to smart contracts a in to to be used in This may to have effects on GDPR as they of human the of the to the with it can In a is human which is by the data subject and smart contracts of to a a of a the to a that is based on that of the and that of the of the and the and the Where a to the to the Where a that cannot be by the the to as these the requirements of Article 22(3) GDPR which to human Furthermore, are ongoing of to be smart At it of automated with where the smart contract forms of a that be is a of a related contract in the smart contract and the smart contracts or has a the contract, as by to of this smart be used to the smart in the of a or to legal contract be with and the smart contract that to and the and which the smart contract with human of are smart contract that can be used in are on
As a consequence of the blockchain revolution, a key challenge of our times is to identify the legal boundaries of smart contracts and thus to develop conflict rules for divergences between state law and technology-based code. Even if smart contracts are technologically self-executing, they are not necessarily legally enforceable. Rather, they must satisfy a variety of legal and contract law requirements. Two different levels of such rules can be differentiated, namely rules of recognition and substantive restrictions. At both levels, it emerges that either the lawmaker can intervene and introduce new, specific rules, or the judiciary can develop rules on the basis of existing and more general legal standards. For example, at the European level the Unfair Terms Directive and (in future) the Directive on Contracts for the Supply of Digital Content limit the potential scope of smart contracts. At national level, the rules on self-help constitute a crucial legal boundary. At least some applications of blockchain technology will be subject to these rules, strictly limiting their admissibility. Under German law, for instance, a waiver of the relevant provisions is largely excluded. In the case of cross-border situations, the comparative divergence of self-help rules will create legal uncertainty and may hinder the use of smart contracts.
... Recent years have shown a surge of interest from various enforcement agencies to remedy commercial behaviour exploiting the increasing information and power asymmetries between consumers and firms. What is particularly notable about this rise in attention is that enforcement actions demonstrate clear interactions between different legal fields that are traditionally applied and enforced in isolation. The present article will focus in particular on the growing interaction between competition, data protection, and consumer law. The Italian Competition, Communications and Data Protection Authority opened a joint ‘big data’ sector inquiry in May 2017 that not only aims to identify potential competition concerns but also to define ‘a regulatory framework able to foster competition in the markets of the digital economy, to protect privacy and consumers, and to promote pluralism within the digital ecosystem’.1 The Bundeskartellamt (German competition authority) announced its preliminary assessment in the Facebook competition investigation in December 2017, reaching the view that Facebook’s collection and use of data from third-party sources is abusive. According to the Bundeskartellamt, Facebook’s terms of service violate data protection provisions and thereby constitute abuse of dominance under competition law as well.2 On the basis of its new competence in the area of consumer protection,3 the Bundeskartellamt also opened two sector inquiries into online price comparison websites and smart TVs in October and December 2017, respectively. The sector inquiry into comparison websites aims to uncover possible violations of consumer law and to identify possible deficits in the enforcement of consumer rights that so far mainly takes place in individual private court proceedings.4 The sector inquiry into smart TVs investigates how producers of smart TVs handle user data. In particular, the Bundeskartellamt is looking to clarify to what extent smart TV manufacturers collect, use and pass on personal data, and whether individuals are appropriately informed of these practices in the contract terms.5
We propose to use the terms Verfügungsmacht (power to dispose, analogous to possession) and Verfügungsrecht (right to dispose, analogous to ownership) to discern whom a Bitcoin belongs to in case of a bankruptcy. Using the example of Tezos, we demonstrate that the storage location of private keys alone does not suffice to meaningfully answer the question to whom the foundation's assets belong. Instead, the context and the contractual arrangement, from which the right to these assets can be derived, also need to be taken into account. This view provides a legal basis for the storage of Bitcoins on behalf of a client without taking them onto one's balance sheet, ensuring that the client's assets are not included in the bankruptcy estate. Furthermore, we classify the Internet currency Bitcoin as a rival, fictive, intangible asset sui generis and opine that there is a gap in the law regarding Aussonderung (removing an asset from the bankruptcy estate and returning it to the rightful owner) and Admassierung (adding an asset to the bankruptcy estate from a third party) of Bitcoins. Courts and bankruptcy administrators are encouraged to fill this gap in accordance with article 1 of the Swiss Civil Code when faced with Bitcoins in a bankruptcy case.
Die Autoren gehen der Frage nach, ob Kryptowährungen als Sachen im Sinne des ZGB aufgefasst und daran namentlich Eigentumsrechte begründet werden können. Dabei werden zunächst technische Grundlagen der sog. Blockchain-Technologie und der drei nach Markkapitalisierung grössten Kryptowährungen Bitcoin (BTC), Ethereum (Ether, ETH) und Ripple (XRP) dargestellt. Sodann wird untersucht, ob diese Kryptowährungen die Eigenschaften erfüllen, welche für die Qualifikation eines Objektes als Sache im Sinne des ZGB vorliegen müssen, und welches die Folgen einer solchen Qualifikation sind. Im Sinne einer modernen Auslegung des Sachbegriffs schliessen sich die Autoren der Auffassung an, wonach Kryptowährungen grundsätzlich als Sache und damit als Gegenstand des Eigentums zu behandeln sind.
In our research we introduce “the forensic smart contract” as a punishment alternative for tiny law violations. After studied the legislation boundaries and legal power transfer example for out of court applications, we evaluated three Blockchain applications covering three various cases in smart contracting. A smart-Law-script to eliminate illegal cellphone car use, with best punishment an Irrevocable prepayment in digi-money for a car phone kit. Then a “Lawscript” resolving the double taxation problem in international tax conventions. Finally a Court launches a community sentence through a “Rehabilitation Law sentence script”. After mass adoption of our methodologies we faced an unexpected globalization peace factor in Blockchain and much wide adoption of CBDC (Central Bank Digital Currency).
Bitcoin und die zugrunde liegende Technologie der Blockchain sind längst keine Randphänomene mehr. Zwar ist Bitcoin in vielerlei Hinsicht neuartig. Das steht aber einer Einordnung als «Geld im weiteren Sinn» bzw. als «Kryptowährung» nicht im Weg. Bitcoin ient zurzeit primär als Spekulationsobjekt, aber auch zur Wertaufbewahrung und als Zahlungsmittel. Während das Bitcoin-System nur die Übertragung von Bitcoins erlaubt, ist die Blockchain von Ethereum, der zweitgrössten Kryptowährung, frei programmierbar and erlaubt die Emission beliebiger «Tokens». Diese können Währungen, Anleihen, Aktien oder beliebige andere Vermögenswerte mit oder ohne vom Emittenten garantierten Wert darstellen. Kryptowährungen haben das Potenzial, einen Digitalisierungsschub im Finanzbereich auszulösen. Um dieses Potenzial zu realisieren, bedarf es aber noch der Klärung verschiedener Rechtsfragen und der Beseitigung rechtlicher Hürden.
Auf dem bisherigen Höchststand des Bitcoins-Kurses Mitte Dezember 2017 kündigte die Generalstaatsanwaltschaft Frankfurt an, sie wolle 126 beschlagnahmte Bitcoins (damaliger Wert: 1,9 Millionen Euro) veräußern. Die in Gießen angesiedelte Außenstelle der hessischen Zentralstelle zur Bekämpfung der Internet- und Computerkriminalität ZIT hatte 2014 mehrere Online-Marktplätze abgeschaltet, auf denen u.a. mit Drogen gehandelt wurde. Bei einer Razzia beschlagnahmte sie die Server der Betreiber und gelangte so in den Besitz von Bitcoins. Im Folgenden wird erläutert, wie eine die Beschlagnahme bzw. Sicherstellung von Bitcoins strafprozessual und polizeirechtlich umgesetzt wird und warum die erhofften Millionengewinne die Ausnahme bleiben werden.
Die Digitalisierung erfasst alle Lebens- und Rechtsbereiche, auch das Gesellschaftsrecht. Der Beitrag befasst sich mit den Einflüssen der Digitalisierung auf die verschiedenen Formen der Kommunikation im Gesellschaftsrecht, sei es der virtuellen Gesellschafterversammlung oder des Einsatzes digitaler Medien in den Organen, aber auch gegenüber potentiellen Investoren. Dabei werden die jeweiligen rechtlichen Rahmenbedingungen auch jenseits des Gesellschaftsrechts beleuchtet, etwa medien- oder datenschutzrechtliche Fragen. Die Digitalisierung wirkt sich aber auch auf die Haftung der Organe aus, indem mehr verfügbare Daten und verbesserte Algorithmen dazu führen, dass die Organe die verbesserten Informationen zur Entscheidungsfindung nutzen müssen. Umgekehrt ist IT-Sicherheit heute „Chefsache“ geworden, da durch die Digitalisierung der Wertschöpfungsprozesse Unternehmen bei Ausfall ihrer IT-Systeme in ihrer Existenz bedroht werden können. Ferner ermöglicht die neue Technologie der Blockchain die eindeutige Nachvollziehung von Transaktionen, damit auch von Abstimmungen, bis hin zum Einsatz in der Rechnungslegung. Besondere Fragen werfen neue Investitionsformen unter Einsatz der Blockchain-Technologie auf, etwa die DAO Ethereum. Abschließend wird ein Blick auf die Formen der engen vertraglichen Kooperation bei Industrie 4.0 geworfen.
The current legal analysis on the blockchain technology focuses on the financial regulation of the cryptocurrencies and little investigation is done in the area of privacy regulation of this technology.
This research shows that the blockchains are much more nuanced than could be served by a one-size fits all approach from regulatory perspective. The GDPR implications for the types of blockchains differ. It is possible to achieve compliance with the GDPR if the authorities adopt a nuanced approach and make reliable advance assessments on specific features are afforded by this technology. In that regard, innovators ought to be assisted by the European Data Protection Supervisor, Article 29 Working Party and local Data Protection Authorities, in particular, on the question of recognition of the data subject as her own controller by way of implementing specific, electronic identity management techniques on top of blockchains. The utility of the blockchains depend on the GDPR regulators to understand and accept that this technological architecture is best regulated by other technological tools which establish the data subject’s agency on her personal data.