Blockchain technology has much to offer, but like most innovation it calls for careful thought and raises new issues that need to be resolved. Blockchains are decentralised digital ledgers, usually open to the public, made up of "blocks" of information linked to one another through cryptographic hashing. They are extremely hard to tamper with, and their decentralised, public and unalterable nature raises the question of what becomes of personal data recorded on a blockchain.
In broad terms, it may be argued that public keys, which can be compared to IBANs in the conventional banking system and which anyone can trace, give network users sufficient anonymity. Contrary to common belief, however, pseudonymous data such as public keys does not ensure full anonymity and can be traced back to the user. Moreover, some blockchains let users enter far more detailed data than the basic transactions that can be tracked through public keys.
One issue regarding personal data recorded on a blockchain is identifying the jurisdiction in which the data is processed. The decentralised nature of blockchains creates trust and security, but it also creates uncertainty about the applicable law. Because the public digital ledgers of permissionless public blockchains are distributed worldwide to any node that wishes to join the network, blockchains can easily be regarded as borderless. As a result, it is unclear which law governs the personal data on a blockchain or any legal disputes that may arise in connection with it.
Another major issue arising from the use of blockchain is identifying the data controllers within a blockchain. Under the Law on the Protection of Personal Data No. 6698 (the "Data Protection Law"), data controllers are the natural or legal persons who determine the purposes and means of processing personal data. For personal data stored on private and permissioned blockchains, data controllers can be identified easily. For public and permissionless blockchains such as the Bitcoin blockchain, however, identifying the data controller is less straightforward. The three main candidates under discussion are the programmers, the miners (or, more broadly, validating nodes) and the users.
The 2018 report "Blockchain and the GDPR", prepared by the EU Blockchain Observatory and Forum, makes clear that the programmers who write the relevant blockchain code should not be treated as data controllers, since they only create the technological tool and have no say in how it is actually used. The status of miners is somewhat more contested, as they oversee the functionality and security of the network. Opinions differ on whether this control over the network amounts to determining the purposes and means of data processing. As for network users, the report states that they may be regarded as data controllers within the blockchain where their purpose relates to commercial activities. Even so, the question of how such users could be sanctioned remains open.
The last data privacy issue linked to blockchain technology is how hard it is to change data stored on a blockchain. Under the Data Protection Law, where the grounds for processing personal data no longer exist, the data controller must erase, destroy or anonymise the data, either ex officio or at the request of the data subject. Yet once data has been entered into a blockchain, altering or deleting it is almost impossible. Most blockchains allow past data to be altered only if a majority of the network nodes agree, with the required ratio depending on the consensus algorithm used. Given the very large number of nodes in many blockchains, reaching majority consensus is objectively difficult.
Considering the disruptive and innovative character of blockchain technology, and the fact that current data privacy laws do not take distributed ledger databases into account, blockchain will inevitably create new legal complexities in this field. We believe that existing data privacy legislation must be continuously adapted to technological innovation in order to realise the full potential of blockchain technology while also protecting personal data. Although such legislation risks running counter to the nature of blockchains, it may indeed be necessary for blockchain technology to survive the age of mass regulation.
