Blockchain Privacy: Payment Data and the GDPR on a Ledger
Blockchain privacy is the question of who can see which data on a ledger. On a public blockchain every transfer and every address history is visible to all participants. For a bank this matters in two ways: payment data is commercially sensitive, and personal data falls under the GDPR. Dated events on the topic are in the calendar below.
Pseudonymous, not anonymous
The Wikipedia article on blockchain privacy describes public chains as providing pseudonymity while making transaction data and histories visible to all participants, which can allow linking and tracing of activity. Once an address is tied to a company, its payments, amounts and counterparties can be read by anyone. The page on Canton Network describes why a confidential bond trade does not fit a chain that writes every transaction to every node.
A 2020 literature review in the journal Sensors names traceability as a privacy risk and notes that "pseudonymisation is not a method of anonymisation". The GDPR takes the same view in recital 26: pseudonymized data that can be linked back to a person is still personal data.
GDPR requirements for blockchain projects
The European Data Protection Board adopted guidelines 02/2025 on processing personal data through blockchain technologies on 14 April 2025 and put them out for public consultation until 9 June 2025. The board asks for technical and organizational measures at the earliest stage of design, a decision on the roles of the different actors during design and a data protection impact assessment before processing starts. It also states that "storing personal data in a blockchain should be avoided if this conflicts with data protection principles", in particular the rights to rectification and erasure.
A&O Shearman summarizes the annex of 16 recommendations and the point that keeping personal data on chain for the lifetime of the blockchain has to be justified as necessary and proportionate. For a bank the practical answer is to keep names and documents off chain and write only hashes or credentials to the ledger, the design described on the page on KYC on blockchains.
Tools that keep payment data private
Jad Wahab's review of privacy in blockchain systems covers secure multi-party computation, ring signatures and zero-knowledge proofs as techniques for building privacy into a ledger, and concludes that "the current state of privacy on blockchains still needs work for it to be reliable". The page on zero knowledge proofs covers how a payment can be shown to be valid without its amount or parties.
The other route is access control. Wikipedia notes that private blockchains can be configured with stronger privacy controls than public ones, which is the model of a permissioned blockchain. Central bank money has its own privacy debate, covered on the page on digital euro privacy.
Upcoming events on data protection and digital assets in Germany
Finance Loop and data protection on chain
Finance Loop covers privacy questions of tokenized finance on its pages on digital euro privacy, KYC on blockchains and zero knowledge proofs. Finance Loop events in Frankfurt bring together data protection and compliance people from banks and payment firms.
Risk & Compliance
Digital Infrastructure & Sovereignty
Is blockchain compatible with the GDPR?
It can be, if the design keeps personal data off the ledger where it would conflict with the rights to rectification and erasure. The EDPB asks for a data protection impact assessment before personal data is processed on a blockchain.
Is a wallet address personal data?
It is pseudonymous data. As soon as an address can be linked to a person, for example through a KYC record, it counts as personal data under recital 26 of the GDPR.
Can data on a blockchain be deleted?
On most ledgers not after validation, which is why the EDPB advises against storing personal data on chain where this conflicts with data protection principles. Data kept off chain, with only a hash on the ledger, can still be deleted.
How do banks keep payment data private on a blockchain?
Through ledgers such as Canton that show each transaction only to its parties, through zero knowledge proofs, and by storing personal data off chain.
Blockchain privacy and Finance Loop
Finance Loop covers blockchain privacy in its Risk & Compliance track, from the confidentiality of payment data to the GDPR duties of banks that use a ledger. Finance Loop brings data protection and compliance teams of banks and payment firms together at events in Frankfurt, Munich, Berlin and Hamburg.
Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, digital payments, cloud and blockchain solutions. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.