Vyara Savova - Save Privacy, Save Blockchain: Fighting for Decentralised Rights in Europe
ETHCluj Meetup·Tue, Oct 7, 2025, 12:00 AM
Europe’s privacy laws were meant to protect individuals, but today, they threaten the very foundations of decentralised technologies. As GDPR reform accelerates and new interpretations demand the impossible, like deleting blockchains, the future of Web3 privacy hangs in the balance. This talk will unpack what’s at stake, why decentralised rights matter now more than ever, and how builders can fight to preserve privacy and autonomy.
Transcript
So uh the topic of this discussion is going to be again about surprise surprise blockchain but uh I'm really grateful that the previous speaker actually used quite a lot of abbreviations so you won't be so stressed by the ones that I'll be introducing uh because talking about legal frameworks of the European Union. The European Union sure loves its abbreviations starting with um the one and only uh GDPR. So I'm going to spend some time to discuss the GDPR and its implications on blockchain. That's basically uh the the core. But first of all, let me talk about a bit about why I'm even um focusing on this topic and uh what I'm part of.
So I'm part of the European Crypto Initiative, the EUCI. We are an advocacy organization based in Brussels. And what we do is basically we translate between uh crypto like the industry and the EU policy makers. So whenever a policy maker decides to regulate um some aspect of what we do as an industry or wants to change the interpretation of a law uh in order to somehow capture the blockchain space, we are there to translate all those issues to uh the tech space like to the crypto people. But then we go to the policy makers and say hey this is actually what is going on.
this is what this industry is about and this is why you shouldn't copy paste financial legislations um when you regulate crypto. So we're kind of in the middle focusing very much on decentralization and on privacy as you can imagine as well. Uh so something that you might uh be familiar with are some of our previous campaigns because there are quite a lot of I would say even FUD when it comes to how European regulations would affect the crypto space. Sometimes it's fat, sometimes it's actually underestimating the effect. But for example, there has been quite a lot of discussions around okay, what is the AML and how there's going to be this quote on quote unhosted wallets ban.
Under the ML, there is no unhosted wallets ban. So we oftenimes also have to kind of go public and explain why some things are not as bad as they're described on Twitter. But often we are doing the opposite actually ringing the bell say hey it's actually worse. Uh so you need to keep a uh keep keep that in mind, keep uh keep an eye on on what's happening. And about me, I'm V.
I'm Bulgarian based in Sophia. Um and I'm a lawyer, human rights lawyer doing a PhD on on privacy on chain. So yeah, um one of my favorite personal topics because I really truly believe that we need privacy on chain in order for anything to happen and to continue building. Um because yeah, at the end of the day, it's not a crime. It's it's something that we all deserve, we all need to acknowledge and it's something that although yes we do have some uh brilliant um technological like infrastructures, we still need to align also with the legal framework because the legal framework believe it or not is also there to protect us.
Um so uh we need to figure out how to make this uh conversation to improve this conversation um and to make this work even better. So when I'm talking about privacy and here um I'm going to introduce an abbreviation that we all know and potentially love deeply the GDPR. But when I'm talking about privacy uh in this context in this specific presentation I mean the European Union um meaning of privacy that is the best way that it's described is in this general data protection regulation that you might have started receiving quite a lot more consent boxes um since 2018 because of it. uh but at the end of the day it's also a framework that explains in in a better way uh what uh our rights are when it comes to data protection and also what are the responsibilities um it's also something that is somewhat European specific although whatever happens in Europe very often does not remain in Europe because we are quite a bit of influencers when it comes to regulation because we are often the first ones to regulate so with the GDPR in particular although how it started in Europe, it then influenced a lot of frameworks including in the US. Um so when it was first drafted um it was supposed to be theoretically technology agnostic.
So which means in this context that it needs to apply the exact same way. No matter if you're using quantum, if you're using blockchain, if you're using AI, it needs to offer like whatever you're building on your services need to offer the same level of protection as if it's like just built on the using a very now traditionally speaking like a server um in in the in in like in the back room of your office. Um so when they were drafting the GDPR they were not not thinking okay what about blockchain are we are are we going to uh destroy this industry by drafting this like this because it was never a concern it was always about the Googles and the Facebooks of the world about okay how do we regulate uh what is happening with European citizens data when they end up on a server in the US hosted by Google and when you have zero control over that data and then the uh American services can basically do whatever they want with that. So that was the main concern and that is the framework uh that we are dealing with currently which means that there needs to be some explaining when it comes to okay how do we apply this to blockchain and comes uh here comes the guideline that I'm going to I'm just going to call the guideline as you can see it has a longer uh name but it's about how do we actually um implement the GDPR when it comes to blockchain infrastructures so it came out recently and there was a um consultation two-month period during which we responded as you can see that's our response that's the front page I'm going to go through both uh but what I wanted to stress is that there was this public consultation it's still not final and we still have quite a lot of uh measures to counteract in a sense and work towards improving this so about the guidelines as I said GDPR it's 100% about just data processing no matter what what happens. Um so when it comes to the actual implementation and application of the GDPR you need a bit more context.
So that's why when the regulation was drafted what was decided was there's going to be this European data protection board EDPB you can see there next to the European Union flag that is going to have its main purpose is to provide interpretation of the GDPR when it comes to the use of different technologies or different contexts. So um this guideline was actually supposed to come out in 2020. It did come out in April 2025. So um quite late and it basically it encompasses the worst possible scenarios when it comes to what like how you can process personal data in a blockchain. All of us privacy researchers basically when we were thinking okay what's the worst that can be end up in in this document that's that was actually better than what ended up being the document.
I will just give you one specific example that's a direct screenshot basically uh and it says um you can see the highlighted text I'm not going to read it don't worry but basically it says if you cannot in implement compliance to the infrastructure and that cannot be changed due to the specifics of the technology then the only way to move forward is to actually delete delete the blockchain alongside all the nodes and holding copies of that blockchain. So they are calling basically saying, "Yeah, we don't care that you're using blockchain. You should have acknowledged that it might not be compliant. So now it's too late and you need to simply delete the blockchain." Is it possible?
No. Are they saying that? Yes. So is it problem? Absolutely.
Um so basically here is a an overview. It's a 25page document. If you really feel uh like reading it, I would suggest you do that because there's so many problems. I cannot encompass them all in the next 12 minutes. Um but of course we have the full deletion of blockchain if personal data can be erased.
Okay, that we highlighted public chains are discouraged. Basically what they're saying is you shouldn't basically you shouldn't be using um public permission permissionless blockchains because it's very likely that you can achieve whatever you want to achieve with a private one but if you end up really like if you really want to use a public one then you need to be very careful because there are a lot of issues that can emerge um and something else that's a bit of a kind of a next uh level but um because it's also introduces the data controllers and other functions that are from the GDP PR but they're saying we need a responsible party because as I said GDPR is always about a centralized entity. So also when you're interpreting GDPR and you're entering this interpretation from that mindset basically you're like okay who's going to be the data controller who is going to be responsible for the data processing and all of that and then that um guideliner are like okay so it's going to be the nodes the node operators are going to be the data controllers that's easy um another one okay you might be having some nodes for example in the US in China wherever outside like what's called a third country um in in the in the logic of the GDPR. Uh in this case, those would be international international data transfers and you would need something called the the standard contractual clause to even make it possible. Again, not really what decentralization is about.
And smart contracts, of course, again, not legal contracts. I'm just going to use every opportunity in my life to say that. But apart from that um according to those guidelines they're saying by the way um they can be observed of a as a way of means of automated decision- making under the GDPR which is very much not okay most in most of the cases. So it's very very problematic and I'll be very happy to answer questions. Um but also going a bit deeper something that is more practical I would say because GDPR is about personal data but what is personal data?
It keeps expanding. So whenever there is like the European data protection boards or some other publication publishing something there is a new expansion of the scope of personal data. So now what they're saying is yeah well a public address a wallet address public key is personal data. So pretty much any transaction is already uh a processing of personal data. So it's extremely broad.
Um validator nodes could violate GDPR smart contracts need human overrites and public blockchains are most likely non-compliant by by uh design and by default. So you need to be very very careful with using them if you actually decide to use them. So what's at risk? Basically a lot. This is this is a slide that if you ever need any argumentation that goes beyond this is insane.
Uh here are some of them. uh because for example in the past few years there are these frameworks like marketing crypto assets regulation AML framework that also covers uh crypto/blockchain and the commission and us as an industry and the whole ecosystem spend so much time drafting them to then at some later stage say hey actually it's not a compliance compliant technology you just need to delete the technology because we can't do anything on that which makes absolutely like all those um legal frameworks unnecessary and all those markets that are emerging out of that. Um, and of course something that we know very well when you dis when you you're trying to centralize everything including control privacy actually gets worse. Um, so we responded um you can check this response. It's on our website.
It's on our social media. I can send it to you if you're interested. Uh but basically what we're saying is no, you shouldn't be just doing this like very strict interpretation of the GDPR. You should also acknowledge the specifics of the technology, the specifics of the context, the specifics of the risk. Uh also automatically classifying blockchain participants as data controllers simply because they're for example running a node.
That's not how this works. again using a lot of more legally kind of making it more Brussels but saying exactly those things um also data um chain deletion nope doesn't work nope um something very important and again privacy enhancing technologies that's what what I'm using here PT but that's all those abbreviations that we have been hearing about in the past few days zero knowledge proofs fully homorphic encryption all those things are encry encryption mechanisms. All encrypted data is considered personal data. Encrypted personal data is considered personal data. So it needs to be protected.
So at the same way as the original data. So basically and that's even more enforced through uh the guidelines. Basically what they're saying is you cannot uh easily use all those encryption mechanisms to protect the data sufficiently because this is still considered personal data. basically that's not a good enough level of protection in it on its own. It can build towards a protection but that's not enough.
And of course we sprinkled some um like as a human rights lawyer some core um um fundamental rights uh arguments you can check it out but yeah that's the gist basically saying yeah you that doesn't work but with many many arguments and many examples and basically we did that and while we were doing that we also wanted to kind of raise awareness about what's happening because I don't expect a big chunk of the crypto industry to be just randomly browsing through uh European data protection boards publications and being like oh this affects us. So a lot of the people like that really are affected by this did not know about this. So we tried to make some noise and here we published on of course on Twitter and it was picked up by a French media that said that excuse my French like literally excuse my French resistance and uh kind of I had the feeling that I'm I don't know if you're familiar with that series I'm old so that's that was funny for me and I heard some laughter so for two people in the room but yeah we kind of started organizing the resistance um that would also support it. Uh James Smith from the Ethereum Foundation also announced this, published it on his blog, published it on social media. The fantastic folks at the web privacy now also picked it up.
We united forces and we started basically organized different formats discussions about raising awareness um gathering more examples getting more tools on how to intervene in this case because as lawyers we are just part of the possible solution. We also need all the techies we also need all the communicators. We need all the kind of event organizers such as this brilliant event to make this uh message across to come across. And what we did also with the web three privacy now folks is we did this uh free super short very succinct uh course on WTF GDPR and why should I care. It's available on their web privacy now academy website.
Uh you can take it. It's around 30 minutes uh to run but like to go through all the lessons. There's some extra materials and all of that um so that you have a better understanding of all those things and how they would affect you. Basically it's u more extended version of this talk and what is basically now the safe blockchain safe privacy the safe part um what can be done and what we are doing in the European crypto initiative and why why we are also raising awareness and trying to get more people involved or at least aware is because the GDPR comp um reform is happening it's going to happen it's already on its way so uh even though we have this very very bad set of guidelines and even though we responded to them, we don't expect them to uh to change significantly. So what we need to do is actually change the approach of the regulators towards blockchain and that is very possible through either this GDPR reform or there are some other avenues that are the privacy directive revamp.
I'm not going to go into all these details, but what I want to say is that there's going to be quite a lot of important discussions happening in Brussels around the data um framework in the European Union. So now is the time for us to kind of be more active and try to intervene as much as possible um so that there can be uh we that message can come across that this is not how you should be regulating um an infrastructure a decentralized infrastructure such as blockchain and we need you like all of you uh even simple things like retweets, resharing uh commenting under our posts getting into discussions about that, speaking about that, supporting us, just even [snorts] giving us examples what you're building so that we can then collect it in a very nice sounding legal field document and send it to Brussels. That is already a step towards basically making this whole thing work better. Um and yeah this is uh where you can find us that's a link tree uh based on basically uh where our social media I think is also available but that's my email below and with this I thank you and I look forward to answering your questions because I guess you have plenty of them. You can scream your hot questions.
No, there are few questions uh and I'll read them out for you. As you're doing this work, are you seeing progress and becoming more optimistic or more frustrated in and demoralized?
Me personally, oh, I'm always frustrated, but I'm also very optimistic, honestly. Otherwise, I don't think we would have been in this industry if we're long-term, if we're not very optimistic. Um but what I'm seeing in particular with these guidelines is a very specific I would say an a tailored approach against blockchain. Um because those guidelines do not necessarily speak about an institution that is not aware of the technology. It speaks of an about an institution that does not care that much uh probably about the technology and its specifics and just wants to regulate like by copy pasting this framework that is not about the centralized technology.
It it never has been about that. So what we know still optimistic but more reasons to be concerned.
Thank you for that. No, can you please come and get miked up? Thank you. We have one more question. I try collecting USDC payments for my business in the EU, but it just doesn't work with retail uh retail customers.
Exchanges ask for a lot of PLL or P2. I'm not sure what it is. Uh on the on deposits and customers won't provide it. This regulation just fully kills the uh stable coins payments. So yeah, the stable coins parts is actually a different regulation.
That's what I love about the EU because it's always like five regulations intertwined. Um so the stable coins things to to even be allowed to use stable coin and to um like to be a crypto asset service provider under Mika, you need to have a license and then also the e- money tokens because USDC for example is an e- money token under the marketing crypto assets regulation. So in order for this I simony token to be available in the European Union, it has to be issued by either a bank like a credit institution or a um like a um issuer even issuer. So this is from Mika. Basically what they're saying is yes, if you want to be able to offer this type of services as a centralized crypto asset service provider, you need to a be licensed and in order to to be that b you need to also implement all the AML, anti-money laundering, transfer of funds and other frameworks that uh necessitate the collection of specific data and if you don't provide this data basically you cannot be on boarded and you cannot uh even access that.
Uh but there is another issue that is like the second level of problems when it comes to e- money tokens in particular is that and that's like sorry if that's too uh complicated but is that they're both uh e- money tokens and their crypto assets. So they're regulated under two uh overlapping frameworks which makes it even more difficult because a lot of the crypto asset service providers would still not be able to do all types of like activities with the money tokens without an extra license that would allow them to kind of handle the payment um instrument um half like half uh um phase of the of the money tokens because they're crypto assets and and um payment instrument. So you need basically two licenses in Europe in order to handle them. But that's not a privacy issue that much. It's like other types of frameworks um that still require the collection of data.
Automatic transcript — names and jargon may be misspelled.