Pseudonymity, Automation, and Responsibility on Public, Permissionless Blockchains under the GDPR

  • Panel
  • Café
  • Thursday 21.05 — 08:45 - 10:00

Organising Institution

European Ethereum Institute (EEI)

Europe

The European Ethereum Institute (EEI), formerly the European Crypto Initiative (EUCI), is a research nonprofit focused on the regulatory and policy environment for Ethereum and the Ethereum ecosystem in Europe. EEI works with EU and UK institutions, regulators, and financial market participants on digital finance, data protection, and emerging technology law.
  • Academic 2
  • Business 2
  • Policy 2
Public, permissionless blockchains increasingly function as foundational digital infrastructure, yet they sit in tension with key assumptions in EU data protection law. Recent developments—the EDPB's draft Guidelines 02/2025, now being finalised, and the Commission's November 2025 Digital Omnibus proposal—have exposed frictions around pseudonymity, identifiability, and the allocation of responsibility in decentralised systems. These mirror the Court of Justice's reasoning in EDPS v SRB, which confirmed that personal data must be assessed contextually, by reference to the means reasonably likely to be used by the actor in question. Using Ethereum as an example, this panel brings together legal, policy, and infrastructure perspectives to examine whether current GDPR interpretations can extend to protocol-level activity, whether the cryptographic tools policymakers rely on are sufficiently mature in Europe, and whether the regulatory direction remains coherent with the EU's broader digital ambitions.

Questions to be answered

  1. How should the GDPR's notion of personal data—and the Court of Justice's contextual test for identifiability in EDPS v SRB—apply on public permissionless blockchains, where what any single participant knows or can do is constrained by protocol design?
  2. Does a participant's position in the stack—running infrastructure, deploying an application, or interacting as a user—change what they actually process, and what governance and enforcement risks arise if data protection law treats these positions as equivalent?
  3. The draft EDPB guidelines recommend off-chain storage with on-chain data limited to proofs of existence such as hashes and cryptographic commitments. Are those tools mature and sufficiently leveraged in Europe, and why is the policy debate moving toward redefining personal data?
  4. s there a meaningful distinction between architectures that make re-identification harder and those that make it structurally impossible for certain participants—and if so, how should that distinction shape how the law classifies the data those participants process?

Moderator

Veronika Hurina

FleishmanHillard EU (Omnicom) - Europe

Veronika Hurina is an Account Manager at FleishmanHillard EU in Brussels, where she advises clients on EU digital policy, with a particular focus on data protection, cybersecurity, and emerging technology regulation, including issues arising at the intersection of EU policy frameworks and decentralised infrastructure. Prior to joining FleishmanHillard, Veronika gained institutional experience at the European Commission and holds a Master's degree in Communication Studies from the Vrije Universiteit Brussel.

Speaker

Ondrej Kovarik

European Ethereum Institute (EEI) - Europe

Ondřej Kovařík served as a Member of the European Parliament from 2019 to 2025, representing the Czech Republic in the Renew Europe group. During his tenure, he sat on the Committee on Economic and Monetary Affairs (ECON) and the Committee on Civil Liberties, Justice and Home Affairs (LIBE), and chaired the Working Group for Access to Finance for SMEs. As Renew Europe’s shadow rapporteur on MiCA, he played a central role in shaping Europe’s landmark crypto-asset regulation, advocating for a framework that balances investor protection with space for innovation. A graduate of the University of Economics in Prague and the École nationale d’administration (ENA) in Strasbourg, Kovařík brings deep institutional knowledge of EU legislative processes, cross-border financial regulation, and the political dynamics that will determine how Europe’s digital asset rules evolve in practice.

Speaker

Vyara Savova

European Ethereum Institute (EEI) - Europe

Vyara Savova is a web3 and human rights lawyer and a Senior Policy Expert with the European Ethereum Institute (EEI, previously the European Crypto Initiative), a research nonprofit focused on the regulatory and policy environment for Ethereum and the Ethereum ecosystem in Europe. EEI works with EU and UK institutions, regulators, and financial market participants on digital finance, data protection, and emerging technology law. Vyara is also a PhD candidate focusing on the issue of privacy on-chain and the use of smart contracts as a solution.

Speaker

Amandine Jambert

European Data Protection Board (EDPB) - Europe

Amandine Jambert is Technology and Cybersecurity Officer at the Secretariat of the European Data Protection Board (EDPB), where she works on the technology and cybersecurity matters supporting the Board's activities. She previously spent more than ten years at the Commission Nationale de l'Informatique et des Libertés (CNIL), the French Data Protection Authority, as an IT and privacy expert within the Technology Department. She holds a PhD in Cryptography from the University of Bordeaux, with a thesis dedicated to cryptographic tools for content and user privacy protection. Both at CNIL and EDPB level, she has contributed to various technological questions in the context of European privacy laws, including anonymisation, pseudonymisation and blockchain.