{"id":1015,"date":"2020-05-22T17:44:26","date_gmt":"2020-05-22T17:44:26","guid":{"rendered":"http:\/\/www.unitedfinances.com\/blog\/?p=1015"},"modified":"2020-05-22T17:44:26","modified_gmt":"2020-05-22T17:44:26","slug":"know-how-blockchain-and-gdpr-are-related-to-each-other","status":"publish","type":"post","link":"https:\/\/www.unitedfinances.com\/blog\/know-how-blockchain-and-gdpr-are-related-to-each-other\/","title":{"rendered":"Know how Blockchain and GDPR are related to each other"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large\" src=\"https:\/\/icommunity.io\/wp-content\/uploads\/2020\/04\/Blockchain-GDRP.jpg\" width=\"661\" height=\"363\" \/><\/p>\n<p class=\"p1\"><span class=\"s1\">The GDPR was created to &#8220;regulate&#8221; the management of privacy linked to the use of user data on the web, apps and social media by web and media companies who are trying to build their competitive advantage on user profiling. The GDPR can be &#8220;interpreted&#8221; as a &#8220;digital rights charter&#8221; of people.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\"><b>The possible relationships between GDPR and blockchain<\/b><\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">The GDPR regulation impacts on a number of areas that relate to the specific characteristics of the Blockchain:<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Data access and visibility &#8211; The data entered in the blockchain are public and accessible by anyone participating in the chain<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Data deletion &#8211; the data stored in a blockchain are tamper-proof, therefore their deletion will not be possible once such data is entered in the distributed chain;<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Data immutability over time &#8211; the data present in the blockchain are kept unlimited and cannot be modified, tampered with or deleted.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Distributed data control &#8211; blockchain are distributed therefore control over data cannot be centralized and it is the responsibility of all participants in the blockchain (it is difficult to identify the Data Protection Officer figures required by the GDPR);<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Automated decision-making processes &#8211; with Smart Contracts, automated decision-making processes or a new type of data management must also be considered<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\"><b>Blockchain and GDPR for a Security by Design<\/b><\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Blockchain and GDPR allow creating &#8220;security by design&#8221; solutions ensuring pseudonymisation (decoupling of data from individual identity) and data minimization (sharing only the data points absolutely necessary).<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">With this setting it is impossible to reconstruct the contents of a transaction from the one- way cryptographic hash. And unless one of the parties to the transaction decides to link a public key to a known identity, it is not possible to map and link transactions to individuals or organizations. This means that even if the blockchain is &#8220;public&#8221; (where anyone can see all the transactions on it), no personal information is made public.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\"><b>Blockchain, GDPR and legislative issues<\/b><\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">The GDPR introduces some rules that may not always be respected by blockchain.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">GDPR and Data Protection Officer &#8211; <span class=\"Apple-converted-space\">\u00a0 <\/span>The GDPR introduces the figure of the DPO &#8211; Data Protection Officer, an expert in data protection legislation and practices who must assist the person who controls or manages them in order to verify internal compliance with the regulation . The DPO must be a person with a good command of IT processes, data security and other business coherence issues regarding the maintenance and processing of personal and sensitive data.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">&#8220;When is it necessary to appoint a personal data controller? In the GDPR, the controller must be appointed in the event that the main processing activities require regular and systematic monitoring of data subjects on a large scale, if the activities include the large-scale processing of particular categories of personal data or of data relating to criminal convictions and offenses, again when the treatment is carried out by a public authority or by a public body. &#8220;<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Which jurisdiction to apply for the law of which country &#8211; In the event of disputes, which laws must be applied and how it all began? You can follow <a href=\"https:\/\/trustpedia.io\"><span class=\"s2\"><b>trustpedia<\/b><\/span><\/a> to read more about crypto.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">In a blockchain (especially if it is public) data is kept on each node of the network &#8211; publicly accessible to anyone &#8211; regardless of the original purpose for which that data was entered and processed in the blockchain. How does this typical blockchain feature fit into a regulatory context that requires that the specific purposes for which personal data are processed must be specified, explicit and legitimate and that personal data must be adequate, relevant and limited to the purposes for which are treated.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">The identity of a user (and therefore his sensitive data) is protected by a code that represents the public key to join the distributed network. From a regulatory point of view, it is necessary to understand what constitutes &#8220;personal data&#8221; in a blockchain context: must public keys be considered personal data? Although a public key appears as pseudonymised data, these do not represent anonymous data and are very often associated with specific natural persons.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Therefore, it is also necessary to deal with legislation on how to manage the &#8220;right to be forgotten&#8221; issue within a blockchain.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The GDPR was created to &#8220;regulate&#8221; the management of privacy linked to the use of user data on the web, apps and social media by web and media companies who are trying to build their competitive advantage on user profiling. The GDPR can be &#8220;interpreted&#8221; as a &#8220;digital rights charter&#8221; of people. The possible relationships &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.unitedfinances.com\/blog\/know-how-blockchain-and-gdpr-are-related-to-each-other\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Know how Blockchain and GDPR are related to each other&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/www.unitedfinances.com\/blog\/wp-json\/wp\/v2\/posts\/1015"}],"collection":[{"href":"https:\/\/www.unitedfinances.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.unitedfinances.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.unitedfinances.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.unitedfinances.com\/blog\/wp-json\/wp\/v2\/comments?post=1015"}],"version-history":[{"count":1,"href":"https:\/\/www.unitedfinances.com\/blog\/wp-json\/wp\/v2\/posts\/1015\/revisions"}],"predecessor-version":[{"id":1016,"href":"https:\/\/www.unitedfinances.com\/blog\/wp-json\/wp\/v2\/posts\/1015\/revisions\/1016"}],"wp:attachment":[{"href":"https:\/\/www.unitedfinances.com\/blog\/wp-json\/wp\/v2\/media?parent=1015"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.unitedfinances.com\/blog\/wp-json\/wp\/v2\/categories?post=1015"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.unitedfinances.com\/blog\/wp-json\/wp\/v2\/tags?post=1015"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}