On July 8, 2026, the European Data Protection Board published the final version of its guidelines on processing personal data through blockchain technologies. The ruling has significant implications that go beyond cryptocurrency — it affects anyone who has ever uploaded personal data, photos, or files to a blockchain-based platform.
The core finding: blockchain’s defining feature — immutability — does not exempt companies from GDPR’s right to erasure. Encrypted or hashed data stored on-chain is still personal data. And that means the “right to be forgotten” applies even to data you can’t actually delete.
What Is the EDPB, and Why Does Its Ruling Matter?
The European Data Protection Board is the EU body responsible for interpreting and enforcing the General Data Protection Regulation. Its guidelines don’t have the same legal force as court rulings, but they are authoritative interpretations that data protection authorities in EU member states apply when investigating complaints and issuing fines.
When the EDPB says something is personal data, that determination shapes how regulators treat it across 27 countries. The July 2026 blockchain guidelines are the final, binding-in-practice version of rules that were consulted on since 2025.
The Core Problem: Blockchain Data Is Permanent
GDPR’s Article 17 gives EU residents the right to erasure — the ability to demand that companies delete their personal data. This right has teeth. Companies that fail to honor erasure requests face fines of up to €20 million or 4% of global annual turnover.
The blockchain industry has long argued that this right creates an impossible situation. Blockchain data is designed to be immutable. Once a transaction is written to the chain, it cannot be altered or deleted by design. Public blockchains like Ethereum or Bitcoin maintain every transaction ever made in their ledgers.
Companies building on blockchain have sometimes used this immutability as a shield: “We can’t delete your data — it’s on the blockchain.” The EDPB’s July 2026 guidelines close that exit.
What the Guidelines Actually Say
The EDPB’s ruling addresses several specific scenarios:
Encrypted Data Is Still Personal Data
Some blockchain operators argued that encrypting personal data before storing it on-chain was sufficient to remove it from GDPR’s scope — the logic being that encrypted data isn’t identifiable and therefore isn’t personal data.
The EDPB rejected this argument. The board confirmed that encrypted data remains personal data as long as there is a key that could decrypt it. The existence of the key means the data remains identifiable, which means it remains personal data.
More significantly, even if the key is destroyed (rendering the data permanently inaccessible), the EDPB indicated that whether this constitutes effective erasure depends on whether the data can genuinely never be decrypted with future technology or alternative keys. Given advances in computing, this is not a guarantee regulators will accept.
Hashed Data Is Still Personal Data
Similar logic applies to hashed data. Cryptographic hashes are one-way functions — you can’t reverse a hash to recover the original data. This led some to argue that storing hashes rather than raw personal data satisfied privacy requirements.
The EDPB’s position: if the hash was derived from personal data and could be linked back to an individual (for example, by being run against a database of known values), it remains personal data. Hashing doesn’t anonymize; it transforms.
Immutability Doesn’t Exempt You From Erasure Obligations
The most important finding for any company using blockchain to store user data: the fact that you cannot delete on-chain data doesn’t excuse you from the legal obligation to honor erasure requests.
Companies must explore pseudonymization, deletion of off-chain data, key destruction, and other mitigation strategies. But the EDPB is clear that these are mitigations, not equivalents. Where genuine erasure isn’t possible, companies face ongoing GDPR obligations and potential liability.
Who Is Actually Affected?
This isn’t just a crypto industry issue. Blockchain technology has been incorporated into a wide range of consumer applications:
NFT Platforms: NFT marketplaces often store metadata — sometimes including personal identifiers or links to personal content — on-chain or in decentralized storage tied to on-chain records.
Web3 Social Networks: Platforms that store posts, profiles, or identity data on-chain include some popular “decentralized social” applications.
Digital Certificate and Credential Services: Some platforms issue educational certificates, professional credentials, or identity documents on blockchain for verifiability.
Healthcare Data Apps: Some health data management platforms use blockchain for immutable audit trails of who accessed medical records.
Photo and File Storage Platforms: A small but real category of “decentralized storage” apps (built on IPFS, Filecoin, Arweave, and similar protocols) marketed to users as alternatives to centralized cloud storage.
If you’ve used any of these services as an EU resident, your personal data may exist in a ledger that cannot be deleted, in a legal framework that now requires it to be.
What About Non-EU Users?
The EDPB’s jurisdiction covers EU residents. However, GDPR’s reach is extraterritorial — it applies to any company offering goods or services to EU residents, regardless of where the company is based.
In practice, this means that any blockchain-based platform with EU users needs to comply, which creates pressure to apply these standards globally rather than maintaining separate data practices per region.
Beyond GDPR, the California Consumer Privacy Act (CCPA) also includes a right to deletion. The California Attorney General has not yet issued blockchain-specific guidance comparable to the EDPB’s, but the underlying tension — immutable ledgers vs. deletion rights — exists in US law as well.
The Practical Implication for Your Personal Data
If you’ve uploaded photos, documents, or personal information to a blockchain-based platform — as an NFT, in a decentralized storage protocol, or as part of a web3 application — here’s what the July 2026 EDPB guidelines mean for you:
You may have a right to erasure, but the company may be unable to honor it. The EDPB’s ruling doesn’t magically enable deletion of on-chain data. It clarifies that companies are legally obligated to try, and that failure to succeed creates ongoing regulatory exposure.
Requesting erasure is still worth doing. Even if the company can’t delete on-chain data, they may be able to destroy encryption keys, delete off-chain data (personal details, contact information, linked accounts), and sever the connections that make on-chain data identifiable.
Future disputes will use these guidelines. If you’re in the EU and have a privacy complaint against a blockchain platform, regulators will now apply the July 2026 EDPB guidelines when evaluating whether the company handled your data lawfully.
Why This Matters for Choosing Where to Store Personal Files
The blockchain ruling highlights a risk that’s easy to underestimate when evaluating storage options marketed as “decentralized” or “trustless.”
The appeal of decentralized storage is genuine: no single company controls your data, there’s no central server to breach, and the architecture distributes trust. These are real properties.
The trade-off is that deletion becomes either impossible or dependent on technical workarounds (key destruction, data pruning) that may or may not work in practice and may or may not satisfy regulators.
For most personal files — photos, documents, journal entries, medical records — the ability to delete data completely and verifiably matters more than decentralized architecture. When you decide to leave a platform or close an account, you want confidence that your data actually goes away.
Traditional encrypted cloud storage, with a clearly stated deletion policy and a defined retention window, offers something blockchain currently cannot: a meaningful, legally honerable right to erasure.
What to Look for in a Storage Provider’s Deletion Policy
Given the EDPB’s ruling, it’s worth applying the same scrutiny to any storage provider you’re evaluating:
- Does deletion remove data from active systems only, or from backups as well, and within what timeframe?
- Is there a defined grace period before permanent deletion?
- Can the company actually honor an erasure request, or does their architecture create permanent records?
- Does the company explicitly commit to irreversible deletion in writing?
The answers reveal a lot about how seriously a provider takes your ability to leave — and your ability to be forgotten.
Daftei’s account deletion policy, for context: after you initiate deletion, there’s a 30-day grace window during which you can reverse the process. After that window closes, deletion is permanent and irreversible. There are no backup copies retained, no archived versions, no residual data.
That kind of verifiable, time-bounded deletion is exactly what the EDPB’s July 2026 guidelines confirm should be the standard — and what blockchain-based storage, by design, currently cannot provide.
The Bigger Picture
The EDPB’s blockchain guidelines aren’t a ruling against decentralized technology. They’re a clarification that privacy law applies to technology choices, not the other way around.
Companies cannot design their way around GDPR by choosing an immutable architecture and claiming the law doesn’t apply. The right to erasure exists regardless of technical constraints, and companies are responsible for building systems that can honor it.
For users, the practical takeaway is simple: before storing personal data anywhere — including platforms that sound inherently private because they’re “decentralized” — ask whether you can actually get that data back out, and deleted, if you want to.
If the answer isn’t clearly yes, that’s the privacy risk.