20190316 - CLBFest - GDPR & Blockchain - Axel Beelen

Brussels Legal Hackers
Brussels Legal HackersBrussels Legal Hackers
GDPR & BLOCKCHAIN:
BEST ENEMIES?
AXEL BEELEN, DATA LAWYER (@IPNEWSBE) 16TH MARCH 2019
Axel BEELEN, Data lawyer
2
The GDPR song (82 818
views!!)
https://youtu.be/6i5WuBbf
hss
Talking about Law could be fun
(sometimes)
GDPR: MAIN POINTS
25th May 2018
Evolution not a
revolution
A balance between
data protection and
the free movement
of personal data
Extraterritorriality application
(Very) broad definition of personal data and processings
Six principles and six legal grounds
Rights of the data subject (DS)
Obligations towards the data controller (DC) and the data processor (DP)
More powers to the data protection authorities (DPA) & EDPB
HIGH FINES
Axel BEELEN, Data lawyer
3
Axel BEELEN, Data lawyer
4
BLOCKCHAINS : A DE FACTO INTERNATIONAL
DISTRIBUTED TRUSTED INFORMATION TECHNOLOGY
Immutability
and
Irreversibility
(append-only
ledger)
Decentralized,
P2P and
Distributed (no
single point of
failure)
Permissioned
(private) or
permissionless
(public)
Can also be
programmed to
trigger
transactions
automatically
(smart
contracts)
Axel BEELEN, Data lawyer
5
TENSIONS: HOW THE
GDPR APPLIES TO
ECOSYSTEMS WHERE
THERE IS NO SINGLE,
CENTRALIZED
PLATFORM?
The
identificatio
n and
obligations
of DC and
DP
The
(de)anonymi
sation of
personal
data
Tensions
The exercise
of some data
subject rights
Axel BEELEN, Data lawyer
6
Born to kill
GDPR
FOLLOWING MICHÈLE FINCK
“Blockchains are authenticity solutions that do not, in
themselves, provide any privacy guarantees so that
for data sovereignty objectives to be achieved, they
must be combined with additional mechanisms.”
Axel BEELEN, Data lawyer
7
IDENTIFICATION AND OBLIGATIONS OF DC AND
DP
Axel BEELEN, Data lawyer
8
Most of the times, DC & DP can
be identified and comply with
their respective obligations
But, there are also cases where it
is difficult, and perhaps
impossible, to identify a DC,
particularly when blockchain
transactions are written by the
DS themselves
ANONYMISATION OF PERSONAL DATA
Axel BEELEN, Data lawyer
9
Still no consensus on what it takes to
anonymise personal data to the point
where the resulting output can potentially
be stored in a blockchain network
Deanonymization techniques can unravel
the identities of people involved in
blockchain-based transactions
THE EXERCISE OF SOME DATA SUBJECT RIGHTS
Axel BEELEN, Data lawyer
10
If personal data is
recorded in a blockchain
network, it may be
difficult to rectify or
remove it.
Defining what can be
considered erasure in the
context of blockchains is
still under heavy discussion.
FOLLOWING MICHÈLE FINCK
“We conclude that public keys as well as the transactional data
stored on blockchains will often qualify as personal data.
Where blockchain use cases are caught by the GDPR, its
various substantive rights come to apply. ”
Axel BEELEN, Data lawyer
11
ENFORCING SUBSTANTIVE DATA PROTECTION RIGHTS
ON BLOCKCHAINS
Axel BEELEN, Data lawyer
12
Rights of DS Transactional data Public key
Data
Could be ok if
stored off chain
NOK
Right to
Amendment
Could be ok if
stored off chain
NOK
Right to Access
Could be ok if
stored off chain
NOK
Right to be
Forgotten
Could be ok if
stored off chain
Could be ok if…
Data Protection
Design and Data
Protection by
Default
Could be ok if
stored off chain
Data controller Joint controllers Data processor
The data subject
for a professional
activity the
network users)
Infrastructure layers
- The Blockchain
system - The
Blockchain
consortium
The protocol
developers
The developers Smart contract
developers
The miners
altogether? Likely
no
A Miner
The smart contract
publishers?
Person holding the
private key of a
smart contract
RECOMMANDATIONS & SOLUTIONS…
(NOTE THE THREE POINTS)
Axel BEELEN, Data lawyer
13
RECOMMENDATION 1
Start with the big picture of your project:
how is user value created, how is data
used and do you really need blockchain?
Compliance should be easier on a
permissioned ledger
Axel BEELEN, Data lawyer
14
RECOMMENDATION 2
The re-use of the public key enables individuals to be singled out by
reference to their public key
Avoid storing personal data on a blockchain!!
Axel BEELEN, Data lawyer
15
RECOMMENDATION 3
Make full use of data obfuscation,
encryption and aggregation
techniques in order to “anonymise”
data.
Collect personal data off-chain
Article 29 Working Party (now
replaced by the European Data
Protection Board) in its Opinion
05/2014:
Threshold for data to qualify as anonymised is very
high
Hashing may still leave some small possibility of a
successful brute force attack (pseudonymous
data).
Axel BEELEN, Data lawyer
16
RECOMMENDATION 4
Continue to innovate, and be as clear
and transparent as possible with users
Other projects explore how
blockchain could be used to support
the GDPR (see IBM doc)
Axel BEELEN, Data lawyer
17
Follow the news, innovation is daily and worldwide!
Axel BEELEN, Data lawyer
18
Axel BEELEN, Data lawyer
19
Many projects try to be GDPR
“compliant” from the
beginning!
Monero achieves privacy using
Ring Confidential Transactions
and stealth addresses.
Ring signatures add “decoys”
to transactions without
exposing which coins were
really signed, effectively
mixing the coins.
Zcash : based on the Zerocash
protocol design. Zcash uses
shielded addresses to hide
transacting parties and zk-
snarks (a type of zero-
knowledge proof) to hide
transaction amounts.
Second layer
“centralized” privacy
solutions
(Blockstream side
chains)
A “privacy-enhancing and
scalable blockchain
protocol”.
It verifies that all
transactions are valid
without storing the
blockchain’s entire history.
Grin and Beam are its first
two implementations.
Transaction layer
privacy (via wallets
like Breeze,
Samourai and
Wasabi).
Solutions
sometimes focus
on transactional
data, sometimes
on the private
key personal data
issue.
FOCUS ON ZERO-KNOWLEDGE PROOF
Zero-knowledge
proof is a concept in
cryptography that
provides many
interesting
applications to
blockchain.
A zero-knowledge proof exists
where a prover A can prove
that he knows information X
to a verifier B without
communicating any other
information to B other than
the fact that A knows X.
Thus, prover A does not have
to share details, such as the
sender’s or recipient’s identity,
with verifier B. Consequently,
zero-knowledge proof
enforces anonymity in
transactions.
Axel BEELEN, Data lawyer
20
SPECIFICALLY ABOUT BITCOIN
Axel BEELEN, Data lawyer
21
While Bitcoin can support strong privacy,
many ways of using it are usually not very
private. With proper understanding of the
technology, bitcoin can indeed be used in a
very private and anonymous way.Around 2011 most casual enthusiasts
believed it is totally private; which is also
false. As of 2019 most casual enthusiasts
of bitcoin believe it is perfectly traceable;
this is completely false.
There is some nuance - in certain situations bitcoin
can be very private. But it is not simple to understand,
and it takes some time and reading (a lot of reading!).
https://en.bitcoin.it/wiki/Privacy
UPGRADING USERS PRIVACY IS ALSO AN IMPORTANT
TOPIC ON ETHEREUM
Axel BEELEN, Data lawyer
22
At the transaction level,
devs are making their way
into allowing the use
of private
transactions through the
Parity client network.
Following an other path
to privacy, the AZTEC
protocol teams make use
of zero-knowledge proofs
and in particular zk-
SNARKs in their protocol.
The devs at HOPR also
care a lot about privacy.
They think current
encryption in messaging
apps like Whatsapp or
Signal are not enough,
and the messaging app
that they are building not
only encrypts the
message itself, but makes
it hard to know who is
sending that message, the
size of the message, and
the IP addresses involved.
Privacy
EVOLUTIONS23
o On deletion and anonymisation (Austria, 5/12/2018) (//UK)
In a case that did not concern a blockchain, the Austrian data protection authority held that
anonymisation does not have to be proven to be perfect forever. It is sufficient that currently
there is no way to reverse it. Speculations on future technological developments do not have
to be taken into account. This anonymisation then equals deletion.
=> 'erasure' does not have to imply that data is literally deleted.
Making data permanently inaccessible without deletion produce the same result.
=> This is a positive move for the use of blockchains where privacy enhancing techniques
like hashing, zero knowledge proofs or encryption is used.
o CJEU (case C-582/14 P. Breyer) on 19 October 2016 relating to dynamic IP addresses:
disproportionate effort
o CNIL (FRANCE) & NAIH (HUNGARY)
Axel BEELEN, Data lawyer
24
Despite the plethora of options for enhancing privacy, these are all early stage
technologies (including MimbleWimble, Grin and Beam). Each have their own trade-offs
and, at this point, there is no clear answer to the best approach to privacy in crypto.
FOR THE DISCUSSION
Axel BEELEN, Data lawyer
25
But will it be possible to
(totally/partially) adapt
Bitcoin Blockchain?
Or do we have to recreate a total new
GDPRPSD2Mifid2etc. compliant
Blockchain?
• In translating all the laws into the
code
• It will require to allow future law-
technical modifications…
Blockchain can also be used as a
regulatory technology
• Ex: to directly collect VAT when an
economic action is perform
• It will prevent violations before they
even occur
Is it really possible?
Do we really want it?
Where is the flexibility and the humanity in
this algocratic system?
Axel BEELEN, Data lawyer
26
SOME DOC
Papers from Michèle FINCK (Max Planck Institute)
CNIL Guideline « Solutions for a responsible use
of the blockchain in the context of personal data”
The EU Blockchain Observatory and Forum Blockchain report
Primavera DE FILIPPI & Aaron WRIGHT: Blockchain and the Law
(The rule of code)
Articles published on Medium, The Verge, Circle, etc.
Axel BEELEN, Data lawyer
27
DATA LAWYER
o Axel BEELEN
o Linkedin/Twitter:
@ipnewsbe
o Telegram:
Belgium Blockchain
Belgium GDPR
o Email:
axel.beelen@ipnews.be
o Website: www.ipnews.be
28
1 of 28

Recommended

20190316 - CLBFest - Blockchain is WTF - Gerrie Smits by
20190316 - CLBFest - Blockchain is WTF - Gerrie Smits20190316 - CLBFest - Blockchain is WTF - Gerrie Smits
20190316 - CLBFest - Blockchain is WTF - Gerrie SmitsBrussels Legal Hackers
1.7K views81 slides
20190316 - CLBFest - Blockchain & the law - Willem Van de Wiele by
20190316 - CLBFest - Blockchain & the law - Willem Van de Wiele20190316 - CLBFest - Blockchain & the law - Willem Van de Wiele
20190316 - CLBFest - Blockchain & the law - Willem Van de WieleBrussels Legal Hackers
1.4K views50 slides
Code is not law by
Code is not lawCode is not law
Code is not lawTim Swanson
32.6K views34 slides
Supply Chain Management using Blockchain by
Supply Chain Management using BlockchainSupply Chain Management using Blockchain
Supply Chain Management using BlockchainYugn27
196 views13 slides
Blockchain - part 6 of 7 modern trends that every it pro should know about- by
Blockchain  - part 6 of 7 modern trends that every it pro should know about-Blockchain  - part 6 of 7 modern trends that every it pro should know about-
Blockchain - part 6 of 7 modern trends that every it pro should know about-Ibrahim Muhammadi
618 views10 slides
Blockchain by
BlockchainBlockchain
BlockchainÃlîshã Upãdhãyãy
1.7K views19 slides

More Related Content

What's hot

The Studio On Air : blockchain & AI by
The Studio On Air : blockchain & AIThe Studio On Air : blockchain & AI
The Studio On Air : blockchain & AIKoen Vingerhoets
333 views37 slides
From 7331 to legal : a selection of blockchain discussion topics by
From 7331 to legal : a selection of blockchain discussion topicsFrom 7331 to legal : a selection of blockchain discussion topics
From 7331 to legal : a selection of blockchain discussion topicsKoen Vingerhoets
308 views65 slides
Blockchain Technology | Bitcoin | Ethereum Coin | Cryptocurrency by
Blockchain Technology | Bitcoin | Ethereum Coin | CryptocurrencyBlockchain Technology | Bitcoin | Ethereum Coin | Cryptocurrency
Blockchain Technology | Bitcoin | Ethereum Coin | CryptocurrencyUnbiased Technolab
215 views112 slides
Eris Industries - American Banker presentation deck. by
Eris Industries - American Banker presentation deck. Eris Industries - American Banker presentation deck.
Eris Industries - American Banker presentation deck. Preston Byrne
3.4K views57 slides
blockchain governance : opportunities and challenges by
 blockchain governance : opportunities and challenges blockchain governance : opportunities and challenges
blockchain governance : opportunities and challengesRachid Meziani, PhD, CGEIT, PMP
307 views44 slides
Defining Smart Contracts by
Defining Smart ContractsDefining Smart Contracts
Defining Smart ContractsTim Swanson
31K views23 slides

What's hot(20)

From 7331 to legal : a selection of blockchain discussion topics by Koen Vingerhoets
From 7331 to legal : a selection of blockchain discussion topicsFrom 7331 to legal : a selection of blockchain discussion topics
From 7331 to legal : a selection of blockchain discussion topics
Koen Vingerhoets308 views
Blockchain Technology | Bitcoin | Ethereum Coin | Cryptocurrency by Unbiased Technolab
Blockchain Technology | Bitcoin | Ethereum Coin | CryptocurrencyBlockchain Technology | Bitcoin | Ethereum Coin | Cryptocurrency
Blockchain Technology | Bitcoin | Ethereum Coin | Cryptocurrency
Unbiased Technolab215 views
Eris Industries - American Banker presentation deck. by Preston Byrne
Eris Industries - American Banker presentation deck. Eris Industries - American Banker presentation deck.
Eris Industries - American Banker presentation deck.
Preston Byrne3.4K views
Defining Smart Contracts by Tim Swanson
Defining Smart ContractsDefining Smart Contracts
Defining Smart Contracts
Tim Swanson31K views
Blockchain- The Quiet Disruptor - A Guide and a primer to launch Blockchain &... by JP Batra
Blockchain- The Quiet Disruptor - A Guide and a primer to launch Blockchain &...Blockchain- The Quiet Disruptor - A Guide and a primer to launch Blockchain &...
Blockchain- The Quiet Disruptor - A Guide and a primer to launch Blockchain &...
JP Batra373 views
Overcoming the Barriers to Blockchain Adoption by MongoDB
Overcoming the Barriers to Blockchain AdoptionOvercoming the Barriers to Blockchain Adoption
Overcoming the Barriers to Blockchain Adoption
MongoDB2.2K views
Blockchain and Smart Contracts by Nelson Rosario
Blockchain and Smart ContractsBlockchain and Smart Contracts
Blockchain and Smart Contracts
Nelson Rosario782 views
Blockchains and Insurance: Opportunities and Challenges by Christopher Brewster
Blockchains and Insurance: Opportunities and ChallengesBlockchains and Insurance: Opportunities and Challenges
Blockchains and Insurance: Opportunities and Challenges
Blockchain and the Real Estate Life Cycle by Achim Jedelsky
Blockchain and the Real Estate Life CycleBlockchain and the Real Estate Life Cycle
Blockchain and the Real Estate Life Cycle
Achim Jedelsky169 views
Blockchain for Executives, Entrepreneurs and Investors by Fenbushi Capital
Blockchain for Executives, Entrepreneurs and InvestorsBlockchain for Executives, Entrepreneurs and Investors
Blockchain for Executives, Entrepreneurs and Investors
Fenbushi Capital156 views
Introduction to blockchain & cryptocurrencies by Aurobindo Nayak
Introduction to blockchain & cryptocurrenciesIntroduction to blockchain & cryptocurrencies
Introduction to blockchain & cryptocurrencies
Aurobindo Nayak309 views
Blockchain 101 by BirthVenue
Blockchain 101Blockchain 101
Blockchain 101
BirthVenue243 views
Blockchain : A Catalyst for New Approaches in Insurance by VIJAY MUTHU
Blockchain : A Catalyst for New Approaches in Insurance Blockchain : A Catalyst for New Approaches in Insurance
Blockchain : A Catalyst for New Approaches in Insurance
VIJAY MUTHU383 views
What is tokenization in blockchain? by Ulf Mattsson
What is tokenization in blockchain?What is tokenization in blockchain?
What is tokenization in blockchain?
Ulf Mattsson563 views

Similar to 20190316 - CLBFest - GDPR & Blockchain - Axel Beelen

20190316 - CLBFest - 1337 to legal - Koen Vingerhoets by
20190316 - CLBFest - 1337 to legal - Koen Vingerhoets20190316 - CLBFest - 1337 to legal - Koen Vingerhoets
20190316 - CLBFest - 1337 to legal - Koen VingerhoetsBrussels Legal Hackers
1.9K views65 slides
Top 7 industries That Will Be Quickly Disrupted By Blockchain by
Top 7 industries That Will Be Quickly Disrupted By BlockchainTop 7 industries That Will Be Quickly Disrupted By Blockchain
Top 7 industries That Will Be Quickly Disrupted By BlockchainBlockchain Council
22 views17 slides
IRJET-Block Chain based Cyber Security System for Data Transfer by
IRJET-Block Chain based Cyber Security System for Data TransferIRJET-Block Chain based Cyber Security System for Data Transfer
IRJET-Block Chain based Cyber Security System for Data TransferIRJET Journal
31 views7 slides
Top blockchain usage cases in the real world by
Top blockchain usage cases in the real worldTop blockchain usage cases in the real world
Top blockchain usage cases in the real worldGlobal Tech Council
34 views10 slides
The Idea Behind Blockchain Technology by
The Idea Behind Blockchain TechnologyThe Idea Behind Blockchain Technology
The Idea Behind Blockchain TechnologyBlockchain Council
31 views9 slides
How An Ai Blockchain Platform Creates Digital Assets From Personal Data by
How An Ai Blockchain Platform Creates Digital Assets From Personal Data How An Ai Blockchain Platform Creates Digital Assets From Personal Data
How An Ai Blockchain Platform Creates Digital Assets From Personal Data Blockchain Council
42 views12 slides

Similar to 20190316 - CLBFest - GDPR & Blockchain - Axel Beelen(20)

Top 7 industries That Will Be Quickly Disrupted By Blockchain by Blockchain Council
Top 7 industries That Will Be Quickly Disrupted By BlockchainTop 7 industries That Will Be Quickly Disrupted By Blockchain
Top 7 industries That Will Be Quickly Disrupted By Blockchain
IRJET-Block Chain based Cyber Security System for Data Transfer by IRJET Journal
IRJET-Block Chain based Cyber Security System for Data TransferIRJET-Block Chain based Cyber Security System for Data Transfer
IRJET-Block Chain based Cyber Security System for Data Transfer
IRJET Journal31 views
How An Ai Blockchain Platform Creates Digital Assets From Personal Data by Blockchain Council
How An Ai Blockchain Platform Creates Digital Assets From Personal Data How An Ai Blockchain Platform Creates Digital Assets From Personal Data
How An Ai Blockchain Platform Creates Digital Assets From Personal Data
InfiniteChain White Paper by InfiniteChain
InfiniteChain White Paper InfiniteChain White Paper
InfiniteChain White Paper
InfiniteChain282 views
China to legalise blockchain based evidence in courts by Blockchain Council
China to legalise blockchain based evidence in courtsChina to legalise blockchain based evidence in courts
China to legalise blockchain based evidence in courts
7 major problems in blockchain by Celine George
7 major problems in blockchain7 major problems in blockchain
7 major problems in blockchain
Celine George163 views
Block chain technology by Rinshi Singh
Block chain technologyBlock chain technology
Block chain technology
Rinshi Singh113 views
China to legalise blockchain based evidence in courts by Blockchain Council
China to legalise blockchain based evidence in courtsChina to legalise blockchain based evidence in courts
China to legalise blockchain based evidence in courts
IRJET- Blockchain Technology in Cloud Computing : A Systematic Review by IRJET Journal
IRJET-  	  Blockchain Technology in Cloud Computing : A Systematic ReviewIRJET-  	  Blockchain Technology in Cloud Computing : A Systematic Review
IRJET- Blockchain Technology in Cloud Computing : A Systematic Review
IRJET Journal56 views
The Six Biggest Blockchain Trends Everyone Should Know About In 2021 by Bernard Marr
The Six Biggest Blockchain Trends Everyone Should Know About In 2021The Six Biggest Blockchain Trends Everyone Should Know About In 2021
The Six Biggest Blockchain Trends Everyone Should Know About In 2021
Bernard Marr7.8K views
Moving enterprise IT to the cloud by Jan Wiersma
Moving enterprise IT to the cloudMoving enterprise IT to the cloud
Moving enterprise IT to the cloud
Jan Wiersma175 views
Machine learning presentation in using pyhton by masukmia.com
Machine learning presentation in using pyhtonMachine learning presentation in using pyhton
Machine learning presentation in using pyhton
masukmia.com273 views
Bat38 aouini bogosalvarado_zk-snark_blockchain by BATbern
Bat38 aouini bogosalvarado_zk-snark_blockchainBat38 aouini bogosalvarado_zk-snark_blockchain
Bat38 aouini bogosalvarado_zk-snark_blockchain
BATbern195 views
Advanced Blockchain AG - Shareholder Meeting August 16, 2018 by 🌍 Norbert Gehrke
Advanced Blockchain AG - Shareholder Meeting August 16, 2018Advanced Blockchain AG - Shareholder Meeting August 16, 2018
Advanced Blockchain AG - Shareholder Meeting August 16, 2018
Blockchain the inception of a new database of everything by dinis guarda bloc... by Dinis Guarda
Blockchain the inception of a new database of everything by dinis guarda bloc...Blockchain the inception of a new database of everything by dinis guarda bloc...
Blockchain the inception of a new database of everything by dinis guarda bloc...
Dinis Guarda6.6K views

More from Brussels Legal Hackers

20190528 - Guidelines for Trustworthy AI by
20190528 - Guidelines for Trustworthy AI20190528 - Guidelines for Trustworthy AI
20190528 - Guidelines for Trustworthy AIBrussels Legal Hackers
452 views21 slides
20190423 PRiSE model to tackle data protection impact assessments and data pr... by
20190423 PRiSE model to tackle data protection impact assessments and data pr...20190423 PRiSE model to tackle data protection impact assessments and data pr...
20190423 PRiSE model to tackle data protection impact assessments and data pr...Brussels Legal Hackers
535 views27 slides
20190316 - CLBFest - Cryptocurrencies and tax - Hendrik Putman by
20190316 - CLBFest - Cryptocurrencies and tax - Hendrik Putman20190316 - CLBFest - Cryptocurrencies and tax - Hendrik Putman
20190316 - CLBFest - Cryptocurrencies and tax - Hendrik PutmanBrussels Legal Hackers
1.4K views14 slides
20190221 Algorithmic transparency and accountability in practice by
20190221 Algorithmic transparency and accountability in practice20190221 Algorithmic transparency and accountability in practice
20190221 Algorithmic transparency and accountability in practiceBrussels Legal Hackers
227 views33 slides
20190221 Data subject rights in practice by
20190221 Data subject rights in practice20190221 Data subject rights in practice
20190221 Data subject rights in practiceBrussels Legal Hackers
309 views34 slides
20180619 Controller-to-Processor agreements by
20180619 Controller-to-Processor agreements20180619 Controller-to-Processor agreements
20180619 Controller-to-Processor agreementsBrussels Legal Hackers
123 views58 slides

More from Brussels Legal Hackers(19)

20190423 PRiSE model to tackle data protection impact assessments and data pr... by Brussels Legal Hackers
20190423 PRiSE model to tackle data protection impact assessments and data pr...20190423 PRiSE model to tackle data protection impact assessments and data pr...
20190423 PRiSE model to tackle data protection impact assessments and data pr...
20190316 - CLBFest - Cryptocurrencies and tax - Hendrik Putman by Brussels Legal Hackers
20190316 - CLBFest - Cryptocurrencies and tax - Hendrik Putman20190316 - CLBFest - Cryptocurrencies and tax - Hendrik Putman
20190316 - CLBFest - Cryptocurrencies and tax - Hendrik Putman
20190221 Algorithmic transparency and accountability in practice by Brussels Legal Hackers
20190221 Algorithmic transparency and accountability in practice20190221 Algorithmic transparency and accountability in practice
20190221 Algorithmic transparency and accountability in practice
20170620 MEETUP smart contracts proof of concept for prescriptions by Brussels Legal Hackers
20170620 MEETUP smart contracts proof of concept for prescriptions20170620 MEETUP smart contracts proof of concept for prescriptions
20170620 MEETUP smart contracts proof of concept for prescriptions

Recently uploaded

ACTIVITY BOOK key water sports.pptx by
ACTIVITY BOOK key water sports.pptxACTIVITY BOOK key water sports.pptx
ACTIVITY BOOK key water sports.pptxMar Caston Palacio
350 views4 slides
Plastic waste.pdf by
Plastic waste.pdfPlastic waste.pdf
Plastic waste.pdfalqaseedae
110 views5 slides
Structure and Functions of Cell.pdf by
Structure and Functions of Cell.pdfStructure and Functions of Cell.pdf
Structure and Functions of Cell.pdfNithya Murugan
317 views10 slides
Narration lesson plan.docx by
Narration lesson plan.docxNarration lesson plan.docx
Narration lesson plan.docxTARIQ KHAN
99 views11 slides
Universe revised.pdf by
Universe revised.pdfUniverse revised.pdf
Universe revised.pdfDrHafizKosar
108 views26 slides

Recently uploaded(20)

Plastic waste.pdf by alqaseedae
Plastic waste.pdfPlastic waste.pdf
Plastic waste.pdf
alqaseedae110 views
Structure and Functions of Cell.pdf by Nithya Murugan
Structure and Functions of Cell.pdfStructure and Functions of Cell.pdf
Structure and Functions of Cell.pdf
Nithya Murugan317 views
Narration lesson plan.docx by TARIQ KHAN
Narration lesson plan.docxNarration lesson plan.docx
Narration lesson plan.docx
TARIQ KHAN99 views
Universe revised.pdf by DrHafizKosar
Universe revised.pdfUniverse revised.pdf
Universe revised.pdf
DrHafizKosar108 views
American Psychological Association 7th Edition.pptx by SamiullahAfridi4
American Psychological Association  7th Edition.pptxAmerican Psychological Association  7th Edition.pptx
American Psychological Association 7th Edition.pptx
SamiullahAfridi474 views
Class 10 English notes 23-24.pptx by TARIQ KHAN
Class 10 English notes 23-24.pptxClass 10 English notes 23-24.pptx
Class 10 English notes 23-24.pptx
TARIQ KHAN95 views
Scope of Biochemistry.pptx by shoba shoba
Scope of Biochemistry.pptxScope of Biochemistry.pptx
Scope of Biochemistry.pptx
shoba shoba121 views
The Open Access Community Framework (OACF) 2023 (1).pptx by Jisc
The Open Access Community Framework (OACF) 2023 (1).pptxThe Open Access Community Framework (OACF) 2023 (1).pptx
The Open Access Community Framework (OACF) 2023 (1).pptx
Jisc77 views
AI Tools for Business and Startups by Svetlin Nakov
AI Tools for Business and StartupsAI Tools for Business and Startups
AI Tools for Business and Startups
Svetlin Nakov89 views
Education and Diversity.pptx by DrHafizKosar
Education and Diversity.pptxEducation and Diversity.pptx
Education and Diversity.pptx
DrHafizKosar107 views
Ch. 7 Political Participation and Elections.pptx by Rommel Regala
Ch. 7 Political Participation and Elections.pptxCh. 7 Political Participation and Elections.pptx
Ch. 7 Political Participation and Elections.pptx
Rommel Regala69 views
Use of Probiotics in Aquaculture.pptx by AKSHAY MANDAL
Use of Probiotics in Aquaculture.pptxUse of Probiotics in Aquaculture.pptx
Use of Probiotics in Aquaculture.pptx
AKSHAY MANDAL81 views
Lecture: Open Innovation by Michal Hron
Lecture: Open InnovationLecture: Open Innovation
Lecture: Open Innovation
Michal Hron95 views
Solar System and Galaxies.pptx by DrHafizKosar
Solar System and Galaxies.pptxSolar System and Galaxies.pptx
Solar System and Galaxies.pptx
DrHafizKosar79 views

20190316 - CLBFest - GDPR & Blockchain - Axel Beelen

  • 1. GDPR & BLOCKCHAIN: BEST ENEMIES? AXEL BEELEN, DATA LAWYER (@IPNEWSBE) 16TH MARCH 2019
  • 2. Axel BEELEN, Data lawyer 2 The GDPR song (82 818 views!!) https://youtu.be/6i5WuBbf hss Talking about Law could be fun (sometimes)
  • 3. GDPR: MAIN POINTS 25th May 2018 Evolution not a revolution A balance between data protection and the free movement of personal data Extraterritorriality application (Very) broad definition of personal data and processings Six principles and six legal grounds Rights of the data subject (DS) Obligations towards the data controller (DC) and the data processor (DP) More powers to the data protection authorities (DPA) & EDPB HIGH FINES Axel BEELEN, Data lawyer 3
  • 4. Axel BEELEN, Data lawyer 4
  • 5. BLOCKCHAINS : A DE FACTO INTERNATIONAL DISTRIBUTED TRUSTED INFORMATION TECHNOLOGY Immutability and Irreversibility (append-only ledger) Decentralized, P2P and Distributed (no single point of failure) Permissioned (private) or permissionless (public) Can also be programmed to trigger transactions automatically (smart contracts) Axel BEELEN, Data lawyer 5
  • 6. TENSIONS: HOW THE GDPR APPLIES TO ECOSYSTEMS WHERE THERE IS NO SINGLE, CENTRALIZED PLATFORM? The identificatio n and obligations of DC and DP The (de)anonymi sation of personal data Tensions The exercise of some data subject rights Axel BEELEN, Data lawyer 6 Born to kill GDPR
  • 7. FOLLOWING MICHÈLE FINCK “Blockchains are authenticity solutions that do not, in themselves, provide any privacy guarantees so that for data sovereignty objectives to be achieved, they must be combined with additional mechanisms.” Axel BEELEN, Data lawyer 7
  • 8. IDENTIFICATION AND OBLIGATIONS OF DC AND DP Axel BEELEN, Data lawyer 8 Most of the times, DC & DP can be identified and comply with their respective obligations But, there are also cases where it is difficult, and perhaps impossible, to identify a DC, particularly when blockchain transactions are written by the DS themselves
  • 9. ANONYMISATION OF PERSONAL DATA Axel BEELEN, Data lawyer 9 Still no consensus on what it takes to anonymise personal data to the point where the resulting output can potentially be stored in a blockchain network Deanonymization techniques can unravel the identities of people involved in blockchain-based transactions
  • 10. THE EXERCISE OF SOME DATA SUBJECT RIGHTS Axel BEELEN, Data lawyer 10 If personal data is recorded in a blockchain network, it may be difficult to rectify or remove it. Defining what can be considered erasure in the context of blockchains is still under heavy discussion.
  • 11. FOLLOWING MICHÈLE FINCK “We conclude that public keys as well as the transactional data stored on blockchains will often qualify as personal data. Where blockchain use cases are caught by the GDPR, its various substantive rights come to apply. ” Axel BEELEN, Data lawyer 11
  • 12. ENFORCING SUBSTANTIVE DATA PROTECTION RIGHTS ON BLOCKCHAINS Axel BEELEN, Data lawyer 12 Rights of DS Transactional data Public key Data Could be ok if stored off chain NOK Right to Amendment Could be ok if stored off chain NOK Right to Access Could be ok if stored off chain NOK Right to be Forgotten Could be ok if stored off chain Could be ok if… Data Protection Design and Data Protection by Default Could be ok if stored off chain Data controller Joint controllers Data processor The data subject for a professional activity the network users) Infrastructure layers - The Blockchain system - The Blockchain consortium The protocol developers The developers Smart contract developers The miners altogether? Likely no A Miner The smart contract publishers? Person holding the private key of a smart contract
  • 13. RECOMMANDATIONS & SOLUTIONS… (NOTE THE THREE POINTS) Axel BEELEN, Data lawyer 13
  • 14. RECOMMENDATION 1 Start with the big picture of your project: how is user value created, how is data used and do you really need blockchain? Compliance should be easier on a permissioned ledger Axel BEELEN, Data lawyer 14
  • 15. RECOMMENDATION 2 The re-use of the public key enables individuals to be singled out by reference to their public key Avoid storing personal data on a blockchain!! Axel BEELEN, Data lawyer 15
  • 16. RECOMMENDATION 3 Make full use of data obfuscation, encryption and aggregation techniques in order to “anonymise” data. Collect personal data off-chain Article 29 Working Party (now replaced by the European Data Protection Board) in its Opinion 05/2014: Threshold for data to qualify as anonymised is very high Hashing may still leave some small possibility of a successful brute force attack (pseudonymous data). Axel BEELEN, Data lawyer 16
  • 17. RECOMMENDATION 4 Continue to innovate, and be as clear and transparent as possible with users Other projects explore how blockchain could be used to support the GDPR (see IBM doc) Axel BEELEN, Data lawyer 17 Follow the news, innovation is daily and worldwide!
  • 18. Axel BEELEN, Data lawyer 18
  • 19. Axel BEELEN, Data lawyer 19 Many projects try to be GDPR “compliant” from the beginning! Monero achieves privacy using Ring Confidential Transactions and stealth addresses. Ring signatures add “decoys” to transactions without exposing which coins were really signed, effectively mixing the coins. Zcash : based on the Zerocash protocol design. Zcash uses shielded addresses to hide transacting parties and zk- snarks (a type of zero- knowledge proof) to hide transaction amounts. Second layer “centralized” privacy solutions (Blockstream side chains) A “privacy-enhancing and scalable blockchain protocol”. It verifies that all transactions are valid without storing the blockchain’s entire history. Grin and Beam are its first two implementations. Transaction layer privacy (via wallets like Breeze, Samourai and Wasabi). Solutions sometimes focus on transactional data, sometimes on the private key personal data issue.
  • 20. FOCUS ON ZERO-KNOWLEDGE PROOF Zero-knowledge proof is a concept in cryptography that provides many interesting applications to blockchain. A zero-knowledge proof exists where a prover A can prove that he knows information X to a verifier B without communicating any other information to B other than the fact that A knows X. Thus, prover A does not have to share details, such as the sender’s or recipient’s identity, with verifier B. Consequently, zero-knowledge proof enforces anonymity in transactions. Axel BEELEN, Data lawyer 20
  • 21. SPECIFICALLY ABOUT BITCOIN Axel BEELEN, Data lawyer 21 While Bitcoin can support strong privacy, many ways of using it are usually not very private. With proper understanding of the technology, bitcoin can indeed be used in a very private and anonymous way.Around 2011 most casual enthusiasts believed it is totally private; which is also false. As of 2019 most casual enthusiasts of bitcoin believe it is perfectly traceable; this is completely false. There is some nuance - in certain situations bitcoin can be very private. But it is not simple to understand, and it takes some time and reading (a lot of reading!). https://en.bitcoin.it/wiki/Privacy
  • 22. UPGRADING USERS PRIVACY IS ALSO AN IMPORTANT TOPIC ON ETHEREUM Axel BEELEN, Data lawyer 22 At the transaction level, devs are making their way into allowing the use of private transactions through the Parity client network. Following an other path to privacy, the AZTEC protocol teams make use of zero-knowledge proofs and in particular zk- SNARKs in their protocol. The devs at HOPR also care a lot about privacy. They think current encryption in messaging apps like Whatsapp or Signal are not enough, and the messaging app that they are building not only encrypts the message itself, but makes it hard to know who is sending that message, the size of the message, and the IP addresses involved. Privacy
  • 23. EVOLUTIONS23 o On deletion and anonymisation (Austria, 5/12/2018) (//UK) In a case that did not concern a blockchain, the Austrian data protection authority held that anonymisation does not have to be proven to be perfect forever. It is sufficient that currently there is no way to reverse it. Speculations on future technological developments do not have to be taken into account. This anonymisation then equals deletion. => 'erasure' does not have to imply that data is literally deleted. Making data permanently inaccessible without deletion produce the same result. => This is a positive move for the use of blockchains where privacy enhancing techniques like hashing, zero knowledge proofs or encryption is used. o CJEU (case C-582/14 P. Breyer) on 19 October 2016 relating to dynamic IP addresses: disproportionate effort o CNIL (FRANCE) & NAIH (HUNGARY)
  • 24. Axel BEELEN, Data lawyer 24 Despite the plethora of options for enhancing privacy, these are all early stage technologies (including MimbleWimble, Grin and Beam). Each have their own trade-offs and, at this point, there is no clear answer to the best approach to privacy in crypto.
  • 25. FOR THE DISCUSSION Axel BEELEN, Data lawyer 25 But will it be possible to (totally/partially) adapt Bitcoin Blockchain? Or do we have to recreate a total new GDPRPSD2Mifid2etc. compliant Blockchain? • In translating all the laws into the code • It will require to allow future law- technical modifications… Blockchain can also be used as a regulatory technology • Ex: to directly collect VAT when an economic action is perform • It will prevent violations before they even occur Is it really possible? Do we really want it? Where is the flexibility and the humanity in this algocratic system?
  • 26. Axel BEELEN, Data lawyer 26
  • 27. SOME DOC Papers from Michèle FINCK (Max Planck Institute) CNIL Guideline « Solutions for a responsible use of the blockchain in the context of personal data” The EU Blockchain Observatory and Forum Blockchain report Primavera DE FILIPPI & Aaron WRIGHT: Blockchain and the Law (The rule of code) Articles published on Medium, The Verge, Circle, etc. Axel BEELEN, Data lawyer 27
  • 28. DATA LAWYER o Axel BEELEN o Linkedin/Twitter: @ipnewsbe o Telegram: Belgium Blockchain Belgium GDPR o Email: axel.beelen@ipnews.be o Website: www.ipnews.be 28