  • 期刊


Legal Study on Conflicts of Blockchain Technology and EU GDPR




Blockchain technology has the potential to revolutionize many industries, but some features of this hottest technology arise questions under EU General Data Protection Regulation (GDPR). Two most innovative aspects of blockchain, immutability of data and decentralization of control, have caused conflict with provisions of the GDPR. This article found that the complexities of compliance with GDPR will increase significantly when the transaction information contains personal data, but whether encrypted data and public key should be treated as personal data is controversial. Related studies show that encryption and hash functions do not automatically turn personal data into anonymous, encrypted data and public key are regarded as pseudonymized data and may considered as personal data when they combined with other necessary information. Secondly, the decentralized nature of blockchain technology presents challenges in identifying the relevant controllers. The accurate classification of participants as data controllers, joint controllers or data processors under the GDPR, is crucial as different implications arise depending on the said classification. To date, who should assume as the role of a controller or a processor within the blockchain system is still uncertain. Finally, under the GDPR, data subjects are granted a number of rights which appear to be in tension with blockchain's immutable characteristics. Because blocks are linked through hashes, if someone decided to execute his or her right to erasure, it would be a huge challenge and nearly impossible to execute. The article will also compare those disputes with Personal Data Protection Law and related administrative interpretations in Taiwan, through this concrete examination, this article will clarify merits and demerits of the present domestic regulation and puts forward suggestions toward future legal adjustment. While challenges for blockchain technology compliance with the GDPR are quite clear, solutions are not obvious. Ultimately, the passage of time will reveal how the use of blockchain technology and the application of the GDPR relative to that technology will evolve.


楊岳平(2019),〈區塊鏈時代下的證券監管思維挑戰:評金管會最新證券型虛擬通貨監管方案〉,《臺大法學論叢》,48 卷特刊,頁 1279-1374。https://doi.org/10.6199/NTULJ.201911_48(SP).0001
郭戎晉(2020),〈論歐盟個人資料保護立法域外效力規定暨其適用問題〉,《政大法學評論》,161 期,頁 1-70。https://doi.org/10.3966/102398202020060161001
楊岳平(2020),〈論虛擬通貨之法律定性:以民事法與金融法為中心〉,《月旦法學雜誌》,301 期,頁 43-63。https://doi.org/10.3966/102559312020060301003
劉靜怡(2019),〈淺談 GDPR 的國際衝擊及其可能因應之道〉,《月旦法學雜誌》,286 期,頁 5-31。https://doi.org/10.3966/102559312019030286001
Ateniese, G., Magri B., Venturi, D., & Andrade, E. (2017, April 26-28). Redactable Blockchain - or - Rewriting History in Bitcoin and Friends [Paper presentation]. 2017 Ieee European Symposium on Security and Privacy (Euros&P), France, Paris. https://doi.org/10.1109/EuroSP.2017.37
