• Latest
  • Trending
District Court Frankfurt a.M. on the right to be forgotten

Blockchain technology and the GDPR

31. December 2022
ChatGPT and lawyers: recordings of the Weblaw launch event

Private AI use in the company

24. October 2025
Lego brick still protected as a design patent

App purchases, in-app purchases and sales tax

21. October 2025
dsgvo 1

What belongs in a DPA? Data processing agreement in accordance with Art. 28 GDPR

17. October 2025
Smart contracts in the insurance industry: contract design and regulatory compliance for InsurTech start-ups

Contract for work vs. service contract in software, AI and games projects

15. October 2025

Influencer contract: performance profile, rights/buyouts, labeling and AI content

13. October 2025
AI content for subscription platforms

AI content for subscription platforms

29. September 2025
E-sports finally charitable? What the government draft of the Tax Amendment Act 2025 really brings

E-sports finally charitable? What the government draft of the Tax Amendment Act 2025 really brings

23. September 2025
Clubs, photos and minors: managing consent properly

Clubs, photos and minors: managing consent properly

22. September 2025
AI faces, voice clones and deepfakes in advertising: rules of the game under the EU AI Act and German law

AI faces, voice clones and deepfakes in advertising: rules of the game under the EU AI Act and German law

17. September 2025
Modding in EULAs and contracts – what applies legally in Germany?

Modding in EULAs and contracts – what applies legally in Germany?

8. September 2025
Arbitration agreements in EULAs and developer contracts

Arbitration agreements in EULAs and developer contracts

7. September 2025
Chain of title in game development: building a clean chain of rights

Chain of title in game development: building a clean chain of rights

6. September 2025
Fail-fast clauses in media productions – what are they actually?

Fail-fast clauses in media productions – what are they actually?

5. September 2025
Founder’s agreement vs. shareholder agreement: setting the course for startups at an early stage

Founder’s agreement vs. shareholder agreement: setting the course for startups at an early stage

12. August 2025
Cheat software without code intervention: What the BGH really decided in the Sony ./. Datel case (I ZR 157/21)

Cheat software without code intervention: What the BGH really decided in the Sony ./. Datel case (I ZR 157/21)

11. August 2025
Digital integrity as a (new) fundamental right: status in Germany and the EU in 2025

Digital integrity as a (new) fundamental right: status in Germany and the EU in 2025

10. August 2025
European Economic Interest Grouping (EEIG)

EU Digital Decade 2030: Data law, Data Act & eIDAS 2 – what needs to be implemented in 2025

8. August 2025
Upload filters between copyright and personal rights

Upload filters between copyright and personal rights

7. August 2025
On-demand transmission right in the digital space: streaming, Section 19a UrhG and licensing

On-demand transmission right in the digital space: streaming, Section 19a UrhG and licensing

6. August 2025
Q&A: Legal issues for game developers

5-day guide: Founding a game development studio

5. August 2025
  • Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Kurzberatung
Rechtsanwalt Marian Härtel - ITMediaLaw

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Rechtsanwalt Marian Härtel - ITMediaLaw

Blockchain technology and the GDPR

31. December 2022
in Blockchain and web law, Data protection Law
Reading Time: 9 mins read
0 0
A A
0
dsgvo 3589608 1280

Blockchain and the GDPR – what’s the connection?

Content Hide
1. Blockchain and the GDPR – what’s the connection?
2. Deletion of data in a blockchain
3. How can companies reconcile blockchain and the GDPR?
4. Can a user waive his or her right to delete?
5. Conclusion: Blockchain technology and the GDPR – an unsolvable problem?
5.1. Author: Marian Härtel

A blockchain is a decentralized database that allows transactions to be tracked securely and transparently. The technology is already being used successfully in many areas and also has the potential to support the requirements of the General Data Protection Regulation (GDPR). However, there are also some challenges associated with blockchain in terms of the GDPR. One of these challenges is the deletion of data. In a blockchain, all transactions are stored persistently and cannot be easily deleted. This means that companies that want to or must comply with the GDPR must take special care to ensure that all data that should (or must) be deleted is actually deleted. Another challenge is to ensure that all users of the company have given their consent for their data to be processed using blockchain. This is especially important because in a blockchain all transactions are transparent and every user has the possibility to view all data. To ensure that all users of the blockchain have given their consent, companies must take appropriate steps to ensure that each user has given their consent at the time of registration or use. Overall, blockchain can be a useful tool to support the GDPR. However, there are also some challenges to consider. Companies need to carefully plan and assess whether blockchain is fit for purpose and whether it is able to meet all the requirements of the GDPR.

Key Facts
  • Blockchain is a decentralized database that enables secure and transparent transactions.
  • The GDPR requires special care when deleting data in the blockchain.
  • In the blockchain, data is permanent, but masking and anonymization are possible solutions.
  • The hash function protects personal information from unauthorized access.
  • Companies need to implement training programs to expand their knowledge of blockchain technology.
  • Regular audits help to identify security gaps and ensure GDPR compliance.
  • The use of anonymization technologies enables compliance with the GDPR when using blockchain.

Deletion of data in a blockchain

In a blockchain, all data is stored permanently and cannot be deleted. However, some platforms allow data to be masked or anonymized so that it is no longer identifiable. This process is referred to as “data protection through technology” (DPT). This allows companies to comply with the GDPR without having to completely delete their customers’ data. However, this also means that it is difficult to develop a blockchain-based solution for handling personal data that meets the requirements of the GDPR. Therefore, it is important that companies develop an effective system to protect and manage their user data in compliance with the GDPR and other data protection laws. Otherwise, it must be ensured that no personal data is stored on the blockchain at all….

One of the most commonly used tools for processing personal data in the blockchain is the “hash function.” This tool can be used to encrypt personal information, making it unreadable to unauthorized people. It ensures that sensitive or private information can be stored on the blockchain while providing greater security. Organizations can also implement appropriate protocols so that they must follow certain rules before deleting or modifying any personally identifiable records – for example, tracking the origin of the record and any approval processes for third-party change requests. In this way, it can be ensured that all processing operations are legally compliant and the user’s privacy remains protected. In addition, it is also important to note that if records are deleted, the transaction history must still exist for those who participated in that transaction – meaning that some portions of blockchain records may need to continue to exist in order to provide evidence of previous transactions. In summary, then: A blockchain offers strong advantages for companies with regard to the protection of personal data records – but there are various technical challenges in implementing effective data protection in this area with corresponding legal requirements of the GDPR, in particular an efficient deletion system for personal data.

How can companies reconcile blockchain and the GDPR?

Blockchain is a valuable tool that can help companies control and track data. Together with the GDPR, companies can ensure the security of their systems and compliance with legal requirements. But how can companies exploit this potential without violating data protection regulations? Fortunately, there are some sensible solutions to reconcile blockchain and the GDPR. First, companies should follow the GDPR guidelines and ensure that all personal data is stored in accordance with applicable laws and regulations. This means that companies must also take certain security measures when using blockchain to ensure the protection of personal data. In addition, companies should verify whether the blockchain platform they are using has a record deletion feature or whether it is necessary to provide dedicated tools for this task. Companies should also note that ensuring that all employees are up to date and properly informed is critical to the success of data protection. Therefore, companies should provide regular training programs to enhance and update their knowledge on how to use blockchain technology. This makes it possible to ensure that all employees are aware of and follow the latest best practices in handling personal data storage. In addition, it is important for companies to conduct regular audits of their blockchain infrastructure. This can help identify if certain components are no longer needed or if records need to be deleted for GDPR compliance reasons. These audits also enable companies to identify potentially unsafe components in good time and take legal action if necessary.

Can a user waive his or her right to delete?

This is quite controversial. This is not regulated by law, so it is probably at least a clear consent of the user possible, which is why it is probably difficult to implement within GTC, which under German law does not have to be agreed to, but which become valid when a user could reasonably have perceived them. It is true that corporate processes are also conceivable that make it possible to waive the user’s right to deletion. However, if a company thereby forgoes the development of technology for deletion, this means a permanent obligation to protect this data and a business risk that should certainly not be underestimated.

Conclusion: Blockchain technology and the GDPR – an unsolvable problem?

Blockchain technology and the GDPR are in a particularly difficult area of tension. On the one hand, it is important that companies comply with the principles of the GDPR and ensure that sensitive data is not misused. On the other hand, companies need to be able to take advantage of blockchain to increase the security of their data and transactions. The good news is that technologies have been developed to reconcile the two fundamental principles. By using anonymization techniques, companies can process personal data in a way that allows them to leverage the security of a blockchain without violating the GDPR.

It is therefore important for companies to familiarize themselves with the latest developments in blockchain technology and take all necessary measures to ensure that it meets certain data protection requirements.

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Tags: AGBBlockchainComplianceDevelopmentGeneral Data Protection RegulationInformationKILawsPersonal dataPrivacyRegistrationRegulationSicherheit

Weitere spannende Blogposts

Artificial Intelligence and Copyright: A Statement by the German Council for Cultural Affairs

Artificial Intelligence and Copyright: A Statement by the German Council for Cultural Affairs
22. June 2023

The German Cultural Council is the umbrella organization of the federal cultural associations in Germany. It represents the interests of...

Read moreDetails

Facebook may block accounts without clear names

Facebook/Instagram: Court deliveries also permitted in German!
7. November 2022

The Munich Higher Regional Court ruled that Facebook was entitled to prohibit the use of pseudonyms and justified this primarily...

Read moreDetails

Contract for work vs. contract for services: What you need to know in the IT, software and Esports sector

New info on the status of the State Media Treaty
22. September 2023

Introduction: Why the right type of contract is crucial There are many gray areas in the world of contracts that...

Read moreDetails

Birthday offer: First consultation at a special price

Birthday offer: First consultation at a special price
11. December 2019

Actually, as a birthday child you get gifts. But since I am completely satisfied, I distribute presents myself until the...

Read moreDetails

LG Nuremberg bans Twittter ban over AFD tweet

Berlin District Court bans baseless Twitter ban
19. June 2019

The Nuremberg District Court has issued an injunction prohibiting the blocking of a Twitter account based on the tweet "Current...

Read moreDetails

Bitcoin and NFTs are just the beginning: Why Blockchain / DLT can do so much more!

Bitcoin and NFTs are just the beginning: Why Blockchain / DLT can do so much more!
3. February 2023

Blockchain technology has attracted a lot of attention in recent years, especially with the introduction of Bitcoin as a digital...

Read moreDetails

Esport Teams, “Freelancers” and the Federal Labor Court

Artikel zu welchen Themen sind interessant?
7. November 2022

In line with my article from yesterday regarding possible reclaim claims from clients against contractors, I received an inquiry from...

Read moreDetails

Publication of sales advertisements and classification as a trader

Publication of sales advertisements and classification as a trader
7. November 2022

According to the ECJ, if someone publishes several sales advertisements on a website, this does not automatically establish the activity...

Read moreDetails

Reimbursements if trade show is canceled due to Corona virus?

Reimbursements if trade show is canceled due to Corona virus?
7. November 2022

Around the globe, there is currently great concern about a further spread of the Corona virus. Whether justified or not,...

Read moreDetails
ChatGPT and lawyers: recordings of the Weblaw launch event
Law on the Internet

Private AI use in the company

24. October 2025

Private accounts on ChatGPT & Co. for corporate purposes are a gateway to data protection breaches, leaks of secrets and...

Read moreDetails
Lego brick still protected as a design patent

App purchases, in-app purchases and sales tax

21. October 2025
dsgvo 1

What belongs in a DPA? Data processing agreement in accordance with Art. 28 GDPR

17. October 2025
Smart contracts in the insurance industry: contract design and regulatory compliance for InsurTech start-ups

Contract for work vs. service contract in software, AI and games projects

15. October 2025

Influencer contract: performance profile, rights/buyouts, labeling and AI content

13. October 2025

Podcastfolge

d00527fd01b1f807a4f80c0f202069e7

Legal basics for startup founders – how to start on the safe side!

9. November 2024

In this episode of the Itmedialaw podcast, lawyer and entrepreneur Marian Härtel takes you on a journey through the legal...

Read moreDetails
9e9bbb286e0d24cb5ca04eccc9b0c902

Legal challenges of innovative business models

1. October 2024
247f58c28882e230e982fa3a32d34dea

Digital sovereignty: Europe’s path to a self-determined digital future

8. December 2024
238a909c26a0302cbd4792cbd18e4922

Global challenges for start-ups – A legal guide

10. October 2024
Legal challenges in the gaming universe: A guide for developers, esports professionals and gamers

What will 2025 bring for start-ups in legal terms? Opportunities? Risks?

24. January 2025

Video

My transparent billing

My transparent billing

10. February 2025

In this video, I talk a bit about transparent billing and how I communicate what it costs to work with...

Read moreDetails
Fascination between law and technology

Fascination between law and technology

10. February 2025
My two biggest challenges are?

My two biggest challenges are?

10. February 2025
What really makes me happy

What really makes me happy

10. February 2025
What I love about my job!

What I love about my job!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung