# Mihaela Rotund - The Privacy Paradox: Rethinking Transparency in Web3

- Channel: [ETHCluj Meetup](https://streameth.org/ethcluj-meetup)
- Date: 2026-06-09
- Duration: 16:27
- Watch: https://streameth.org/watch/yt-ihe-eFccLeg
- YouTube: https://www.youtube.com/watch?v=ihe-eFccLeg

## Description

Public blockchains promise transparency — yet sustainable adoption requires privacy. Balancing those two forces defines the next phase of Web3.

## Transcript

Hello everyone. Uh good afternoon. I'm pleased to be here today to discuss uh about uh data privacy and blockchain. So um a bit of about myself. I will um move quickly through some slides. until I get to the topic of the presentation. So, as uh I was presented before, I'm a lawyer at Maximan Associates, which is a law firm that uh helps clients both with uh disputal litigation, but also with consultancy issues. Our main areas of expertise including uh business law, tax and administrative law, but also uh data assets and technology, data privacy and uh a bit of artificial intelligence. So the topic that I chose today sits basically at the intersection of um innovation, technology and regulation. So what we'll be discussing today will be the relationship between blockchain's transparency and data privacy. So I think we've all observed during the years the impact blockchains systems have in the society. We don't talk about blockchains anymore only when it comes to cryptocurrencies. We talk about it when it comes to digital identity also or um when it comes to tokenization or uh digital applications with ultra integrate AI. Uh but however when it comes to the GDPR regulations we can see that uh at the European Union uh basis uh this has been a topic that takes even more deeper interest within the years. uh we have the latest act that was implemented the digital AI act which I don't know if you all know but will be fully enforced until the 2nd of August of this year. So uh what I can say about um the intuition of European regulators is that they are trying to find more efficient ways to make the regulations to put the regulations in place and find ways to keep up with the new technologies. So that's why I think it's relevant to talk about uh the architecture of the blockchain systems and whether they can be in alignment with the GDPR regulations. So the main topics that we will go through today will be blockchain transparency and u what I want to point out from the beginning is the fact that I would like to talk about this transparency from an architectural system kind of way because I believe most legal issues arise not from the misuse of transparency but rather about how the transparency was built on the system. Uh later on we will touch about the podonomy problem. Uh and I think this is important because maybe a lot of you think podonomy is pretty similar to uh being anonymous. Well, I would like to actually have a few words about that and tell you that from a legal perspective that's not always the case. Uh third, we would like to address whether onchain data can be considered uh personal data and what are the implications of that uh under GDPR. Uh fourthly, we will see some GDPR's core principles and uh put them uh in line with the blockchain architecture and see if there are any problems implementing it in the um real life. And lastly, we will talk about some compliance responses and some emerging solutions that uh can actually make the blockchain system more in alignment with the GDPR regulations. So starting off with blockchain transparency. Uh as we may know one of the main characteristics of a blockchain will be transparency. This uh makes it really easily for people to access the history of the transactions. But what we should know about this transparency are three main uh characteristics. First is permanence. Once the information is ba basically validated on the chain and it's added there there is little few to basically impossible uh possibility to alter it or to delete it. Also uh the information is universally accessible which means that everyone basically with a stable internet connection can look at the history of the transactions. And lastly it consists persist identifiers. A lot of you may uh know that persistent identifiers as a wallet address uh which basically uh tells you the whole transaction the whole history transaction. Um what we should know when it comes to those wallet addresses is that even though we don't have a direct uh personal information about that person, so we don't see their passport number, we don't see uh the user's location or we don't see where uh he actually lives. The wallet address can actually leave a few hints that may in the future make that person behind the transaction more identifiable. But we will move on to that in a couple of minutes. First, let's talk about the podonomy problem. So, we know the psyonomy problem. Uh we know the podonomy as being something that should basically protect the person behind the transaction. But what I want to point out is that sodonomy does not guarantee anonymity. And why is that? Because as I mentioned before, a wallet address may not directly name some uh personal information but it can name some aspects that can lead towards the person behind the transaction and I will give a few examples by that. Uh from a uh wallet address uh wallet addresses you can actually see the behavior behind the transaction. You can see the strategy investment. you can actually see the geographical activity of that transaction and that can actually lead to the person behind it. If you correlate it especially with some uh public records uh you can uh you can link basically where the transaction was being made and then how the behavior uh what behavior you have to the person that actually is behind the wallet address and I will give you a simple example by that for uh if we look at a transaction that has a certain uh number or is of a certain impact and uh we are from a small town where we know that only certain firms or certain individuals can be behind such uh big transactions. Uh if you correlate that information with something you can already find on public um public institutions informations, you can actually have an idea of what type of person was behind that transaction. So uh the next question will be does the data directly name the person? As I said no, but it indicates some aspect that can lead to the person. So moving on will be bad can be that data leaked to an individual and I believe it is and I know a lot of um companies that uh do analytic work regarding this already said and already proved that informations like this can be linked to the person behind the wallet. Um so the next question will be if wallet addresses are considered personal data and uh in this regard it really depends also in the interpretation that was regarded by the European Union and also by other institutions that inter interpret basically the existing GDPR regulations. So to this question, both CNL and EU courts have answered that if the aspects that we can see on a blockchain can actually be linked or give us some data about the person behind it, then the information uh and the system basically falls into the GDPR regulations. And um what can that uh mean exactly? And it's important for us to take into account uh this interpretation did not say only if in the present we can link the transaction to the person. Uh they said if in the present or in the foreseeable future there will be some mechanism or there will be some cor some correlations between informations that can lead us to the person behind the wallet then GDPR applies. So what's the main problem here? if GDPR applies to a blockchain system. Well, I uh have um on the right some GDPR principles, what they mean or what they require and basically why is it pretty difficult to implement it into a blockchain system. So to give you a few example, we have article 17 from the GDPR act which basically tells us that there is a right to erase the personal data of a person from uh a system. Uh when it comes to blockchain reality as I said transactions are immutable. So that being given the architect of the system makes it pretty difficult to alter to modify or delete that information from the system. Also when it comes to data minimizations under GDPR data is collected only uh only the relevant and uh limited to what it is necessary for the purpose to be concluded. Uh when it comes to blockchain um that data is recorded in full which means we have no limitation of it. Moving on, we have the purpose limitation which I said we have a certain purpose. We cannot go uh beyond it when we when it comes to personal data. However, uh if we see a blockchain system where everybody basically has access to it, everybody can also have different purposes for uh looking through it for uh collecting it which means that the purpose limitation is also not being met in the system. Uh also we have storage limitation which means uh the data that is collected does not stay there forever. It needs to stay only for a limited amount of time. What happens in the blockchain system now is that the data is stored permanently. So uh the chain has no basically uh retention uh has a a lot of retention of it. And last but not least, we have transparency under GDPR, which means that once the data is collected and once is being uh used for something, the data subjects must be informed about this. So what it happens now in a blockchain is that it's pretty difficult to implement decentralized permissions when it comes to data subjects. So what I'm trying to say here is is that some aspects of a blockchain system of its structure are pretty hard to implement when it comes to GDPR but it's not impossible. So that is why we have some uh compliance responses and some solutions that can actually be implemented and are being implemented today in order to be in accordance with the GDPR regulations. And what uh that can be is concluding the data process assessment before deployment. Um which can pretty much uh makes us know the risks from the beginning of uh linking the informations that we obtain from blockchains to a certain person behind the wallet address. Also what can also be done will be to store personal data offchain to al to only put the um informations on chain that can uh hardly be traceable back to the person behind the transaction. What else can be done will be to identify the relationship uh between controllers processor and control uh joints. So basically what I'm trying to say to build that relationships to know who acts as a controller, who acts as a processor because accountability will most of the times be uh be under uh be used by the data subjects and uh we need to know who is responsible for that in order to truly uh know where to go for our legal claims. Also, we should establish basically a lawful basis of how we collect the information that we get uh on the chain. And last but not least to review our privacy notices. As we may know uh when it comes to data privacy a lot of the times when there are risks of leaking the data or when the data uh goes off the purpose limitations there are some notices that are being sent to the people that uh are being basically uh leaked or their informations are being leaked. So that's why I believe uh these compliance responses can still uh be relevant in a web tree design in a blockchain system without truly uh getting into their main characteristics and uh their main things that people are looking for when they choose this kind of system. So I think it comes down to meeting in the middle to say so to not um compromise GDPR but also not compromise the system itself. So um uh I hope uh this presentation uh uh helped you today and uh some conclusions that I want you to have in mind when thinking about this will be that um it's most probably beneficial for organizations uh that are using blockchain systems to assume that GDPR applies because as I told you the interpretation of the regulation is pretty broaden so that is why it's uh basically So good to be safe than sorry afterwards. And uh also to know that the architecture is the problem but does not mean that we need to eliminate all the features especially the technological benefits beneficial things from uh the system in order to be in compliance with the GDPR regulations. Also we need to understand that both sides of the paradox are real. So when it comes to the GDPR regulations and fines, yes they can happen but there can be uh some methods can be made in order for the system to not be um to not be under a direct sanction uh features of the European Union. Also the regulatory direction is very clear which means uh we need to know what the interpretation of these lawful bases are and uh what risk we are uh heading on when it comes to using the blockchain systems. So, I'm really looking forward to hear your point of view about this and uh what do you think about GDPR and the transparency of blockchains and uh even tell me if you've seen some compliance responses that were being made in the system that you have seen. Thank you.
