# Workshop | Oliver Smith | Ask a Lawyer! Web3 Privacy Workshop | ETHDam 2024

- Channel: [CryptoCanal](https://streameth.org/cryptocanal)
- Date: 2024-10-07
- Duration: 25:55
- Watch: https://streameth.org/watch/yt-Vy29TeVvjeQ
- YouTube: https://www.youtube.com/watch?v=Vy29TeVvjeQ

## Description

Join Oliver Smith for a workshop "Ask a Lawyer! Web3 Privacy Workshop" at ETHDam 2024. A presentation covering the latest regulatory changes privacy projects should be aware of, how to set your project up properly and a chance to ask a lawyer anything!
https://twitter.com/gov_dao http://govdao.io/ 

James Campbell - MC of ETHDam, Hackathon Organiser, and Web3 Developer.

ETHDam - a conference and hackathon held in the heart of Amsterdam, Netherlands from April 12th to 14th, 2024, celebrated its second edition, gathering more than 600 participants. 

In the dynamic space of ETHDam, privacy and security took center stage, featuring groundbreaking discussions on hacks, recovery, and the revolutionary work of figures like Pertsev. Privacy is dead in crypto, people that know, know. People who don’t know, should know. 
ETHDam is powered by CryptoCanal, an education and events platform growing in Amsterdam, spreading its roots to Rotterdam and Zürich.
Keep up with us to see updates on future events: https://www.cryptocanal.org/ 
Follow CryptoCanal on X: https://twitter.com/CryptoCanal
Join CryptoCanal TG Community: https://t.me/CryptoCanalCommunity 
Join CryptoCanal Discord: https://discord.com/invite/XJVjpCqQBz

We would like to thank our partners that made this event possible. 🌷
Battleship Partner 
🛳Oasis Network https://oasisprotocol.org/

Jet Ski Partner
🛩⛷  NEAR https://near.org/

Canoe Partners
🛶WAKU https://waku.org/
🛶Trail of Bits https://www.trailofbits.com/
🛶Avalanche https://www.avax.network/
🛶Privacy + Scaling Explorations https://pse.dev/en
🛶Threshold https://threshold.network/

Our Canoe Partner & Official Node Provider
🛶dRPC https://drpc.org/

Sponsor
🤝EF Ecosystem Support Program https://esp.ethereum.foundation/
Paddle Partners
🚣ChainSecurity https://chainsecurity.com/
🚣Lido https://lido.fi/
🚣Cyber Capital https://www.cyber.capital/
🚣Diva https://www.divastaking.net/
🚣Firn Protocol https://firn.cash/
🚣Beefy https://beefy.com/
🚣0xbow https://www.0xbow.io/
🚣Obscura https://obscura.build/
🚣Panther https://www.pantherprotocol.io/
🚣Maven 11 https://www.maven11.com/
🚣Zama https://www.zama.ai/
🚣zkSync https://zksync.io/
🚣Secret Network https://scrt.network/

ETHDam AfterParty Fren
🥳Bitvavo https://bitvavo.com/en

## Transcript

[Music] uh getting towards the end of the day hope everyone still has some energy if not there's so much coffee available please go and fuel up uh I'd like to welcome Oliver from gov. good afternoon everyone um thank you um yes my name is Oliver I'm the founder of gov. Dow um our mission is to build better governance by building better Dow technology I'm also general counsel to a number of Di and CI protocols and projects um I've been a lawyer in the space for five years but a lawyer for 10 years my backgrounds in investment funds financial and corporate law I'm here today to discuss privacy and the regulations around privacy and particularly how they relate to web 3 and of course that's super relevant for what the hackers are doing today um and it's a really interesting question because of course we have these regulations there are 130 30 countries which have some form of data Protection Law um or Privacy Law um obviously we're probably all aware of the eu's gdpr in the UK we've got the data protection act and in the US there's various forms of of I think it's five different pieces of legislation I'm not here to go into the detail of the regulations because probably there's not enough coffee in the world to get through that um but I but I think that there's four key things really when it comes to data protection or in privacy which is that um projects need to treat data in a fair way in a transparent way with accuracy and with security and those are kind of the four main pillars that all projects should consider when they're thinking about data protection and privacy however that's for web two if you're web 3 it becomes a lot more difficult and the reason why is because of course we're talking about decentralized projects we're talking about if you are truly decentralized there's not one owner there's not one controller there's not one Central entity to protect data now if you're truly decentralized then what do you do because and then this is a huge conflict with uh with web 3 and data protection laws because if you think about what web 2 companies have to do they have to give notice to their users as to how they're going to treat that data they need to give choice to their users and give them the option to opt out of their data being treated in a particular way there's also um an obligation to destroy data after a certain time and also we're going to throw in AML and CTF laws there because one of the big things that we all have to consider when we're providing Financial Services is how we kyc and kyc of course means collecting data so if you're decentralized is there really one entity is there one controller not really so how are you going to give notice how are you going to give a choice to your users how are you going to destroy the data that's already on the public blockchain I mean the whole whole point of blockchain is transparency right if a transaction happens it will be on the blockchain it will be there for the record and how do you destroy that I think probably that's impossible so what do you do well I think there are a number of solutions really which is that if you are truly decentralized and you're offering a service say you've got like a a Dev code structure um and you've got your protocol your project let's say it's a decentralized exchange I think that's a a good uh use case to to discuss in this in this circumstance um you're going to have your your web free wallets interacting with the protocol but they're anonymous but actually perhaps because you're not really decentralized you have to be registered as a virtual asset service provider and that's a whole different talk for another day to whether or not you need to be registered as a virtual asset service provider but at the end of the day there is still things you can do so if you've developed some software you've developed your smart contracts you've deployed them and it's running and you're providing that service the best thing to do is to think about how you can be compliant by managing risk and the best thing to think about is well if the whole whole service that we're providing is actually on the public blockchain then what you need to do is like okay we can maybe have our privacy policy which basically notifies the the users of the pl blockchain as to how the data is treated um but then we're talking about building privacy Solutions the hackers are building privacy Solutions today and that's really important because um and I'll come to the uh case study of FRC which is that if you are offering a service which promises privacy in some way then you're going to have to think about compliance because if you if there is some sort of breach of of privacy and you've promised that something will be private you're in big trouble you're in big trouble um so why have I used uh friendch as as an example here is is anyone familiar with frch here social F yeah so uh last year they they suffered what a lot of users said was a big breach of privacy which is that someone essentially scraped data and published wallets which were tied to public Twitter profiles and there was a huge outra all the users like oh my God this has been a huge data breach U we want to sue frch but what's interesting is that actually um they haven't been sued yet and why haven't they been sued yet well their argument is it was always going to be public there was no expectation of privacy so users can't say well I thought it was Private I thought our chat rooms were private I thought my wallet was Private no you used friends used that protocol knowing that you were going to link your Twitter profile with your wallet and therefore there's no expectation of privacy um and friends interesting enough actually have uh a privacy policy so if you go on to their their main page the first thing you'll see is a privacy policy and this is really important because that takes a couple of the boxes it takes is it takes the uh the notification it it tells the users how how their data is going to be treated but more importantly that particular privacy policy doesn't make a promise that the data will be uh kept private so where does that take us for our hackers today if I was advising the hackers today I would say if you're building something with which is essentially uh privacy as like software as a service privacy and you're selling that to a client you need to make sure that your product does what it says on the tip so if your client is is is basically licensed it from you and they're using it you need to make sure that it does actually maint uh maintain privacy if you're building a service which uh has some sort of privacy layer on top of it you need to make sure that it is actually going to keep data private and you actually maintain uh compliance with all of the things that are required under the regulations I'll put it to the floor for some questions so say that there's like token right that that I bought years from I want my children know that I bought rocket but like rocket isable so they can't delete and that's point I got is there a possibility that we might actually have regulator like saying certain applications of blockchains at least like immutable contracts deleted Areo like incom and therefore illegal or do we think that it's very likely that regulations will like yeah I think that's a very good question um my answer to that would be um don't expect to have any right to privacy in the future because at the time of interacting with the protocol or purchasing those tokens you did so with the knowledge that that was on the blockchain then that would always be public and as I mentioned at the start the big problem for for web 3 projects is that essentially um is built around smart contracts public blockchain um there is no way for them really to comply and the regulations assume that there's a central entity or or Central party which is able to actually take these actions but as I said even if you wanted to destroy the data I mean can anyone tell me here how you go about deleting transactions on the blockchain is that is that possible no you can maintain the transaction but you can like depend how the transaction works right so transaction State and that state itself is mutable then and the owner of the contract has the ability to mutate the state in the future can be like the transaction itself will stay in the past and somebody can rerun the whole state of the blockchain and see that that transac happen but in the current state dat it's like aage from like a Google search engine somebody that scra Google way back in the day we'll still have the link and if that page still exists they can access it type but it removes the element of it being current so that adds right a between immedately AV yeah I would agree with you however I mean I'm assuming that when you've purchased your rocket token that you've you've used an anonymous wallet you don't have to answer that question um and that that's another question because up until now until these new uh AML and CTF regulations have come in which basically will require uh projects even if they're defi projects because let's face it most defi projects aren't really decentralized to collect uh user data like your name your address probably who you're sending to anything over a thousand you may have heard of the um uh the travel rule the travel Ru just coming in which means that any exch any exchange or like any wallet you're sending to or whatever will have to collect the data so up until now actually the only thing that's public is is your wallet right and the transaction so there's nothing really to tie your name or there's no personal data that actually needs to be deleted right but that won't be the case in the future because I think that projects are going to have to collect this data if they want to be compliant and therefore they're going to have to really comply with this stuff but then we're talking more about centralized web2 operations in some ways um and then they're going to have to think about abilities to actually delete that any other questions well well I'm a lawyer I can answer some questions yeah yeah go for it yeah yeah so I mean um what I what I put today I sent something into the Discord chat which was basically so nine pointers that the hackers should think about when it comes to to building their products because I think it's really easy to build a product and then later think oh my God I need to be compliant what do I do and as a lawyer I'm constantly having to advise projects on on being compliant after the fact after they built it so I think it's really important if you're if you're a Dev and you're building really think about how you can build into to the functions of your product ways to be compliant forward think it Forward think how to do it because I I I think it's no longer the case that you can be like Oh I'm just decentralized because we're noncustodial that's just really not the case thank you um so obviously companies Outsource things all the time and the Outsource company may or may not do uh uh a good job of it um so where you have like liability for something then the liability will just go up the chain whoever outsourced them would be would be liable um liable for what though well so for damages for example um but if you have something like uh Micah like you're breaching Micah because you're not collecting enough kyc and that is that was outsourced to a reputable kyc provider and it turned out they weren't doing their job how liable would the project at the top of the chain be um fully liable although if you're wrapped with a a limited company then of course you'll be limited by by shares so um but but that but then again what are you being liable for if it's the regulator coming and suing you then I'd say there's no cap on that right but if you're talking about liability to your users um say there's been a hack on your protocol and they've lost their funds then there would be you know that would obviously go through the court and and liability would be subject to to limitation if there were terms and conditions well um no no 100% it it's much easier to use a third party kyc provider right and there's some great ones like ssub Etc so um I would actually recommend that projects do use um trusted third party providers who have been in the game for a while know what what they need to do and have already started to build in a way which will enable projects to be compliant with things like the uh the travel liability or might liability go back to the outsourc Ser like I mean setting aside like you knowing ahead of time that they're not good at their job right no like you're assuming that they're good at their job you did an appropriate amount of best effort but it turns out that I mean you know maybe this is uh too too simple a response or too simple a view of it but but to be honest you what is a compliance provider they're literally collecting passports address details do doing like a check on on the chain to see if there's any uh sanction wallets interacting with it whatever if as you know that's not that hard in my opinion and as long as you've Pro like you're able to show and you've got records that you've done this you will be complaining no guarantees but um hey hey hello um just 5 cents I suddenly remembered IO times and now I'm like not many people went into jail for those stuff but if they would follow your advice uh they should all be compliant they should all work slow and stuff like that so it's interesting that there's a certain CA Market chaos that always would require support to the lawyers but they don't give a in that sense and it's a bit kind of like oh let's do and then see you later but the second thing is that I always ask compliant to who and basically what not you are pitching but we are in this thing of America Centric compliance trajectory or Europe American Centric so us Cent yes I'm like why why should it's not how the world works so it's interesting how many different compliant geographies you would map uh down in sense of I know someone Works in China for example there's how many of those so-called complain um geographies directions or like continents you would map down it's kind of also with the dialogue with the states in this regards yeah I mean that's a phenomenal question um that's still because I think there's there's a couple of ways is that you have to be compliant you have to obviously maybe be compliant with privacy regulations but then you also have to maybe be compliant with digital asset laws um let's take the digital asset laws because for me this this is a huge question in the projects I work with are okay so if we set up in the BVI we're establish our company then we'll get our vast registration there I'm like great but that only actually gives you permission to operate from the BVI it doesn't give you permission to provide services in the EU because if you want to provide services in the EU then you're going to be mic right and my advice is that just look at where your biggest markets are get license in those markets where where your biggest Market is there's no point being like oh we're going to get UK license BV license Singapore license Hong Kong license because that's expensive for a start I mean that you're talking like millions in terms of being regulated every it's just not an efficient strategy you're going to waste all your money on legal expenses and whatever to to be licensed on these places no be licensed in the place where you establish or you're mainly operating from and then be licensed in those those jurisdictions where your biggest markets are and then for privacy well the reason I have the EU at the top there is because I'd say that the EU is one of the leaders in terms of data protection and it's also important because jurisdictions who interact with EU have to almost ensure that their data protection laws are kind of in line with the EU so I would say that following EU law is is a good way to go to the B compliant however us say saying do we have to be compliant well good question I mean I think uh honestly unless you're truly decentralized and that's really really hard then probably yes but that's just my opinion what would it look like to be truly decentralized yeah that's a great question so I I guide people to the financial action task force recommendations of October 2021 because this is the first time that um that particular governing body brought into into scope virtual assets um and in that in that guidance it basically talks about what defi is and who has to be registered as a virtual asset service provider and what they say is if there is one Central entity which maintains or has uh significant influence or control over a protocol it's likely that they're not going to be Defi and um I think there are some characteristics so for example are you hosting the website the domain you have control are you taking fees are you profiting from the the uh the protocols activities you have control are you uh the owner of the intellectual property are you the sole person who's updating and maintaining it you have control so how how would you be sufficiently decentralized well um good question Udi swap was a good example for a while because they weren't taking fees they flick they flick the fee switch and oh hello they've got a Wells notice from the SEC because that all of a sudden they're profiting from the activities um ipfs spread the uh the host thing around different notes don't take fees um open source um that would be a good stop it's really hot by the way I mean someone someone's got to control something right I mean just based off uh you mentioned there um are you the only one contributing so would you say that being open source is not sufficient you've actually got to be and and all of the contributions coming from one organization that would count as not decentralized you need to have your contributions coming from multiple separate entities I would say that's what I'm saying yes and and I think if we look at decentral decentralized autonomous organizations DS um that's really important because um you know obviously there was the the huge uh Dow boom back in 20121 because everyone thought oh if we're if we're like decentralizing in this way and the communityi is running it and governing it then we're going to be outside of the scope of of of of uh of of legislation um but now following the financial action task force recommendations I just mentioned they say that if there is someone or multiple people with 10% or more control of the tokens then they would likely have to be registered as a virtual asset service provider and what's really weird actually is that everyone's like oh okay so we we'll set up a dow LC that will help us but funny enough that makes it one Central entity in control so is that a good idea I don't know um so let's put something into context uh so because we met Barcelona and stuff like that yes he did and I'm trolling uh in a nice way people from Catalonia that they're building catalon uh stack in dependent from for catalans uh from aragonda Von voting uh rollups blah blah blah identity things and then imagine that they need to be compliant to Spanish government although they are politically not aligned they didn't want to whatever and they don't want to be exposed within their organization within whatever they do I'm not saying militias acting also like supporting horizontal activities supporting local communities if the next Co will be there and stuff like that and you never know what will be the political uh climate within the next government in Madrid and then how you would even approach that uh in sense of what would be your it's not legal advice in sense of official now your state your statement but how you would approach this thing that basically you operate from the locality that should be compliant to your kind of like political opponent to say at least yeah I mean so what you're talking about is outside of the scope of financial laws which are you know we're talking about here um we're talking about political laws I suppose and you know what happened with the referendum and you know what happened to uh can't remember his name now but he basically went into hiding right um was that yeah yeah um but uhhuh um well I mean what what's regulating that what's I mean what's regulating them wanting to form an organization for political purposes um I don't know myself and I'm not familiar with the Spanish law on that either so unfortunately I can't answer that question who's hacking here by the way and what are you building right now okay and uh how are you like what are the Privacy features of that are there any privacy features oh I'm getting looped into an interview here uh I didn't mean to put you on the spot but I think it's good to I'm here I'm here as a mentor guys so and and as I said it's really important if you are building some privacy Solutions or you're providing a service which has privacy aspects to really think about compliance because if you're promising some sort of privacy for something then you need to ensure that you are compliant so in this case it's connecting gitcoin passport uh which has a bunch of stamps that I'm not in control of um and then I get a score and then based on the score I add you to a group in a ZK pool so you can show that you're like a member with a score let's say above five but not what your specific score is okay so you're using uh ZK solutions to ensure privacy so it's like anamin in some respects I think pseudo pseudo pseudo yeah and um based on what I've said do do you think that you would need to collect the user's data or whoever's using that that service that's a this is a test now I'm sorry yeah a CO one uh I don't know because the data is already public because they're exposing it via the gitcoin apis so anybody can car it any time already um I'm just creating a time stamp say like at this moment in time this was a score and then it's being stored that's great so that's what takes us back to the very first point in the fact that if it's already on the public blockchain then it's super hard to actually comply with these these uh these these privacy rules because it's there's already public right so what I would suggest best for you is to just have some like a privacy policies in terms of conditions which basically says this is what we're doing with the data um and then that would probably cover you amazing thank you so much this is some of the best discussion I think we've had all weekend I really really this is so good [Music]
