Data Protection Challenges in Distributed Ledger and Blockchain Technologies: A Combined Legal and Technical Analysis
摘要
Blockchain and the blockchain-based cryptocurrency Bitcoin revolutionized our ideas of decentralized data and transaction management. Based on and improving on the ideas of blockchain, a variety of distributed ledger technologies (DLTs) have been proposed in recent years. DLTs promise fully decentralized data and transaction management, with wide-ranging applications that go well beyond cryptocurrencies. However, DLTs are also associated with challenges, particularly with respect to compliance with applicable data protection regulations. This chapter presents a comprehensive analysis of the challenges associated with DLTs’ compliance with the General Data Protection Regulation (GDPR) of the European Union (EU). It analyzes the impact of these challenges on different types of DLT approaches (public or private, permissioned or permissionless). It shows that three fundamental properties of DLTs—immutability, decentralization, and automation—make it very difficult to comply with the GDPR in the public permissionless setting. For other DLTs, GDPR compliance is less problematic, but some challenges remain. In particular, the uncertainty that remains about the exact interpretation of the GDPR in the context of DLTs means that the question of GDPR compliance cannot always be definitely answered.