How a Next-Generation Blockchain Addresses "Privacy Poisoning"
The introduction of the EUs General Data Protection Regulation (GDPR) in 2018 marked a pivotal moment in the history of data privacy. Intended as a blow to the unchecked data harvesting of big tech firms such as Facebook and Google, the regulation brought in far-reaching legislation, putting significant responsibilitieson to companies as data processors. Intriguingly, given that blockchain advocates are also often vocal proponents of privacy rights, GDPR also throws up some interesting problems in the context of data stored on a blockchain. It contains clauses that stipulate data must be “kept in a form which permits identification of data subjects for no longer than is necessary” and perhaps even more critically, introduces the “right to be forgotten.” The latter allows any citizen of the EU to request that their data be permanently deleted. Furthermore, it doesnt matter whether the data processor is in the EU or outside; EU citizens rights must be upheld. Blockchain vs. the GDPR These rights are at odds with one of the core features of a blockchain – that data and transactions are immutable. Nobody can delete or change a transaction once its taken place. In the context of Bitcoin, where addresses arent tied to any personal data,