Transcription of Blockchain and the General Data Protection Regulation
1 STUDY Panel for the Future of Science and Technology EPRS | European Parliamentary Research Service Scientific Foresight Unit (STOA) PE July 2019 EN Blockchain and the General Data Protection Regulation Can distributed ledgers be squared with European data Protection law? Blockchain and the General Data Protection Regulation Can distributed ledgers be squared with European data Protection law? Blockchain is a much-discussed instrument that, according to some, promises to inaugurate a new era of data storage and code-execution, which could, in turn, stimulate new business models and markets.
2 The precise impact of the technology is, of course, hard to anticipate with certainty, in particular as many remain sceptical of Blockchain 's potential impact. In recent times, there has been much discussion in policy circles, academia and the private sector regarding the tension between Blockchain and the European Union's General Data Protection Regulation (GDPR). Indeed, many of the points of tension between Blockchain and the GDPR are due to two overarching factors.
3 First, the GDPR is based on an underlying assumption that in relation to each personal data point there is at least one natural or legal person the data controller whom data subjects can address to enforce their rights under EU data Protection law. These data controllers must comply with the GDPR's obligations. Blockchains, however, are distributed databases that often seek to achieve decentralisation by replacing a unitary actor with many different players. The lack of consensus as to how (joint-) controllership ought to be defined hampers the allocation of responsibility and accountability.
4 Second, the GDPR is based on the assumption that data can be modified or erased where necessary to comply with legal requirements, such as Articles 16 and 17 GDPR. Blockchains, however, render the unilateral modification of data purposefully onerous in order to ensure data integrity and to increase trust in the network. Furthermore, blockchains underline the challenges of adhering to the requirements of data minimisation and purpose limitation in the current form of the data economy.
5 This study examines the European data Protection framework and applies it to Blockchain technologies so as to document these tensions. It also highlights the fact that Blockchain may help further some of the GDPR's objectives. Concrete policy options are developed on the basis of this analysis. STOA | Panel for the Future of Science and Technology AUTHOR This study was written by Dr Mich le Finck at the request of the Panel for the Future of Science and Technology (STOA) and managed by the Scientific Foresight Unit, within the Directorate- General for Parliamentary Research Services (EPRS) of the Secretariat of the European Parliament.
6 ADMINISTRATOR RESPONSIBLE Mihalis Kritikos, Scientific Foresight Unit (STOA) To contact the publisher, please e-mail LINGUISTIC VERSION Original: EN Manuscript completed in July 2019. DISCLAIMER AND COPYRIGHT This document is prepared for, and addressed to, the Members and staff of the European Parliament as background material to assist them in their parliamentary work. The content of the document is the sole responsibility of its author(s) and any opinions expressed herein should not be taken to represent an official position of the Parliament.
7 Reproduction and translation for non-commercial purposes are authorised, provided the source is acknowledged and the European Parliament is given prior notice and sent a copy. Brussels European Union, 2019. PE ISBN: 978-92-846-5044-6 doi: QA-02-19-516-EN-N (STOA website) (intranet) (internet) (blog) Blockchain and the General Data Protection Regulation I Executive summary In recent years, there has been ample discussion of Blockchain technologies (or distributed ledger technology DLT1) and their potential for the European Union's digital single market.
8 A recurring argument has been that this class of technologies may, by its very nature, be unable to comply with European data Protection law, which in turn risks stifling its own development to the detriment of the European digital single market project. The present study analyses the relationship between Blockchain and the GDPR, so as to highlight existing tensions and advance possible solutions. It looks into developments up until March 2019. 1. Blockchain technology In essence, a Blockchain is a shared and synchronised digital database that is maintained by a consensus algorithm and stored on multiple nodes (computers that store a local version of the database).
9 Blockchains are designed to achieve resilience through replication, meaning that there are often many parties involved in the maintenance of these databases. Each node stores an integral copy of the database and can independently update the database. In such systems, data is collected, stored and processed in a decentralised manner. Furthermore, blockchains are append-only ledgers to which data can be added but removed only in extraordinary circumstances. It is important to note that blockchains are a class of technology.
10 Indeed, there is not one version of this technology. Rather, the term refers to many different forms of distributed database that present much variation in their technical and governance arrangements and complexity. This also implies, as will be amply stressed in the analysis below, that the compatibility between distributed ledgers and the GDPR can only be assessed on the basis of a detailed case-by-case analysis that accounts for the specific technical design and governance set-up of the relevant Blockchain use case.