Law.com Subscribers SAVE 30%

Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.

Issues Between EU Data Protection, Use of Blockchain

By Justin Hectus and Kristy Sambor
August 01, 2018
General Data Protection Regulation (GDPR) Entertainment Law & Finance A Primer for the Entertainment Industry on the Use of Blockchain Technology Smart Contracts and Blockchain
  • The GDPR may be a privacy regulation, but data protection is a core principle. Controllers, processers and sub-processors are held to high standards with respect to broad cybersecurity concepts and specific breach notification requirements. Blockchain's encryption and decentralized structure makes the network and data highly tamper-resistant and, in theory, less vulnerable to unauthorized modification than a single instance database.
  • The GDPR represents a shift to consumer ownership of their own data, requiring companies to provide visibility and control to individuals, on demand. Blockchain is being used as the base technology for dozens of applications focused on consumer control of data from identification to monetization.
  • The GDPR has made great strides by requiring not only transparency into what companies will do with consumer data, but also mandating clear consent mechanisms to ensure that consumers understand what companies are sharing, with whom and for what purpose. Blockchain and cryptocurrency came into existence in part because of a loss of trust in financial institutions. Blockchain continues to be leveraged in ways that bridge the gap in consumer trust in areas as varied as news and insurance.
  • As with most coming of age stories, the tale of these two Generation Z kids is not without conflict. In this case, the GDPR's right to erasure and blockchain's fundamental immutability may be akin to an unstoppable force meeting an immovable object.
Los Angeles Times Chicago Tribune

'Privacy By Design'

  • Increased use of private or enterprise blockchains, which are blockchain systems used by one company or amongst companies in the same industry. Unlike public blockchains, which provide decentralized utility and access to as many users as possible, private and enterprise blockchains limit the dissemination of personal information to just one company or a limited number of companies. In reducing the scale of the chain, fewer individuals have access to sensitive information and the possibility of data breaches significantly diminish.
  • Use of pseudonymization techniques in combination with data stored off-chain. In order for data to be considered pseudonymous under GDPR, the data must “no longer be attributed to a specific data subject without the use of additional information” (GDPR Art. 4(5)). Pseudonymous data, unlike anonymous data, therefore still allows for re-identification. While pseudonymization techniques make it more challenging for users to identify data subjects, it does not scrub all identifying personal information. Pseudonymization with pointers to personal data stored off-chain in a manner that allows the personal data to be destroyed — and thus removes the link to the data on the chain and renders it anonymized — may allow a user to remove all of their personal information from the chain, as required by the GDPR's right to erasure.
  • Development of mutable blockchains. For example, the R3 Corda team is currently exploring “sophisticated anonymization techniques” that would allow users to edit and/or delete their personal information shared on a private blockchain, giving them 100% control over their own data. This “self-sovereign solution” would “ensure provisions in GDPR that allow individuals to access and correct their personal data would be fulfilled and provides a compliant solution to restrict data processing.”
  • Reliance on exceptions to the right to erasure. The right to erasure is not absolute in all circumstances. For instance, the right to erasure does not apply to the extent that processing is necessary for compliance with a legal obligation that requires processing by EU or Member State law, and it does not apply to the extent that processing is necessary to establish, exercise or defend legal claims. (GDPR Art. 17(3)(b) and (e).) Other exceptions may also apply. Businesses might reject a request for erasure of personal data based on recognized exceptions in the GDPR, but there is little guidance in this area and whether these exceptions will successfully apply to blockchain solutions has yet to be tested.
***** Justin Hectus Cybersecurity Law & Strategy Entertainment Law & Finance Kristy Sambor This article has been prepared for informational purposes only and is not intended to be legal advice. Individuals and/or companies should not act upon this information without seeking professional counsel from an attorney.

This premium content is locked for Entertainment Law & Finance subscribers only

  • Stay current on the latest information, rulings, regulations, and trends
  • Includes practical, must-have information on copyrights, royalties, AI, and more
  • Tap into expert guidance from top entertainment lawyers and experts

For enterprise-wide or corporate acess, please contact Customer Service at [email protected] or 877-256-2473

Read These Next
The DOJ's Corporate Enforcement Policy: One Year Later Image

The DOJ's Criminal Division issued three declinations since the issuance of the revised CEP a year ago. Review of these cases gives insight into DOJ's implementation of the new policy in practice.

The Bankruptcy Hotline Image

Recent cases of importance to your practice.

Use of Deferred Prosecution Agreements In White Collar Investigations Image

This article discusses the practical and policy reasons for the use of DPAs and NPAs in white-collar criminal investigations, and considers the NDAA's new reporting provision and its relationship with other efforts to enhance transparency in DOJ decision-making.

The DOJ's New Parameters for Evaluating Corporate Compliance Programs Image

The parameters set forth in the DOJ's memorandum have implications not only for the government's evaluation of compliance programs in the context of criminal charging decisions, but also for how defense counsel structure their conference-room advocacy seeking declinations or lesser sanctions in both criminal and civil investigations.

How AI Has Affected PR Image

When we consider how the use of AI affects legal PR and communications, we have to look at it as an industrywide global phenomenon. A recent online conference provided an overview of the latest AI trends in public relations, and specifically, the impact of AI on communications. Here are some of the key points and takeaways from several of the speakers, who provided current best practices, tips, concerns and case studies.