Is a blockchain private?

10 min read By Trusty Digital Published Updated

No. A public blockchain is pseudonymous, not private: anyone can read every holding and every transfer, and only the name is missing. Once an address is linked to a person, their whole history is public and permanent, and under UK and EU data protection law that address can be personal data which the ledger itself can never erase.

What anyone can see on a public blockchain

Anyone can see every account's holdings and every transfer it has ever made, with the time, the amount and the other party's address, without asking anyone's permission.

Take an account on Algorand. A public explorer shows its balance, each asset it has agreed to hold, every transaction in and out, the counterparty address and the block in which each one was confirmed. For each asset it shows the total supply and the administrative addresses the issuer set when creating it. Each transaction can also carry a free-text note of up to 1,024 bytes, or up to 4,096 bytes for an additional fee (Algorand Developer Portal, transaction reference, checked 3 October 2026). Whatever is written there joins the permanent record.

This openness is deliberate. The Bitcoin white paper of 2008 explains that, because every transaction is announced publicly, privacy depends on "keeping public keys anonymous", and compares the result to a stock exchange tape that shows trades without the parties (Bitcoin white paper, section 10). Public blockchains since then have kept that model: the transactions are public, and only the link to a name is withheld.

Compare a UK company's register of members. It is open to inspection, but a person asking must give their name, their address and the purpose of the request (Companies Act 2006, section 116), and the company can ask a court within five working days to refuse a request that is not for a proper purpose (section 117). A public blockchain asks nothing of whoever is looking, and shows every movement, not only the current holding.

What the ledger proves, and what it proves nothing about

A public ledger is authoritative about its own contents and about nothing else.

On its own contents it is strong. Supply cannot be quietly increased: if an issuer says one million units exist, anyone can check, and later issuance is visible when it happens. A holding recorded three years ago is still recorded, with every movement since. Concentration is visible: if five accounts hold ninety per cent of an instrument, anyone can see it.

About the world off the ledger it proves nothing. A token said to represent a warehouse is a token; the chain has no knowledge of any warehouse. It does not prove that the issuer holds good title, because the ledger records a sound entitlement and a worthless one equally faithfully (see what a token records, and what creates the right behind it). It does not prove value, or that the issuer will pay what it promised, or that the issuance was lawful.

Diagram comparing what a public ledger proves (supply, every transfer, the asset's settings) with what it does not prove (that the asset exists, legal title, lawful issue).

The ledger is authoritative about its own contents and nothing else.

Visible does not mean enforceable either. If an issuer holds the freeze and clawback addresses and uses one, everyone can see the transfer, and the asset has still moved. Whether an issuer can do that is settled when the asset is created, which is why the configuration deserves more attention than the transaction history.

Pseudonymous, not anonymous: how an address gets a name

An address stays anonymous only until one piece of information links it to a person, and from then on every transaction it has ever made, and every one it makes later, is attributed to that person.

The links are ordinary. An exchange that verified your identity knows which address you withdrew to. A shop knows who paid it. A donation page, a social media profile or an email signature can publish an address alongside a name. Trades link addresses to each other: in an atomic transfer, buyer and seller appear in the same group.

Diagram in four steps: an address that looks like random characters, one link such as an exchange withdrawal or a payment, a name attached to the address, and the address's whole history now attributed to that person.

One link is enough, and it works backwards as well as forwards.

Researchers showed how far this goes more than a decade ago. In "A Fistful of Bitcoins" (2013), a team from the University of California, San Diego and George Mason University grouped Bitcoin addresses by evidence of shared control, then made purchases from known services to put names to the groups (Meiklejohn and others, 2013). The white paper had already conceded the point: "if the owner of a key is revealed, linking could reveal other transactions".

For a tokenised instrument, the exposure is specific. Every holder's complete position and trading history in that instrument is public, and it becomes personally identifiable the moment their address does. It is rarely explained to holders before they buy.

Is a blockchain address personal data?

Under the UK GDPR and the EU GDPR, a blockchain address is personal data whenever the person behind it can be identified by means reasonably likely to be used, including by combining it with records held off the chain.

The Information Commissioner's Office (ICO) says so directly. Its guidance on distributed ledger technologies describes wallet addresses as effectively "online identifiers" for the people using them, which therefore could count as personal information, and tells organisations to consider off-chain data such as know-your-customer records and IP logs when judging whether someone can be re-identified (ICO, How does data protection law apply to blockchains?, checked 3 October 2026). Addresses that belong to companies rather than people fall outside data protection law.

Pseudonymous data does not escape the law. The ICO's pseudonymisation guidance cites Recital 26 of the UK GDPR: data that could be attributed to a person by using additional information is information on an identifiable person (ICO, Pseudonymisation). The European Data Protection Board (EDPB) reaches the same view for the EU: the public keys that identify users "qualify as personal data" when they can be linked to a natural person (EDPB Guidelines 02/2025, paragraph 26).

Both documents are recent, and their status matters. The EDPB adopted the final version of Guidelines 02/2025 on processing of personal data through blockchain technologies on 7 July 2026, after a public consultation on the April 2025 draft (EDPB, checked 3 October 2026). The ICO consulted on its guidance from August to November 2025; its plans page lists it as being redrafted, with a final version due in winter 2026 (ICO, plans for new and updated guidance, checked 3 October 2026). EDPB guidelines apply to the EU; in the United Kingdom the ICO's view is the one that counts.

Can personal data be erased from a blockchain?

In practice, no: data written to a public blockchain stays there, which is why both the EDPB and the ICO say the answer is to keep personal data off the chain in the first place.

The rights themselves are not in doubt. A person can require a controller to erase their personal data on the grounds in Article 17 of the UK GDPR and to correct inaccurate data under Article 16. A blockchain is built so that nobody can do either. The EDPB's answer is blunt: "technical impossibility cannot be invoked to justify non-compliance" (paragraph 50).

The EDPB's final guidelines draw the practical conclusions. Storing personal data on a chain in clear text, encrypted or hashed form is "not advisable"; it should be stored off-chain (paragraph 104). Annex A recommends keeping any personal data off-chain beyond the identifiers already present in transaction metadata (Recommendation 2). Encrypted data remains personal data, and encryption that is strong today may not be in decades, while the chain is kept indefinitely (paragraph 51). A correction can be made by a later transaction that cancels an earlier one, but the original stays visible (paragraph 106). Directly identifiable data belongs on a public chain only where the purpose requires it and a data protection impact assessment has concluded the risks are addressed (paragraph 55).

The ICO describes the same design. Personal data sits in ordinary storage, the blockchain holds a pointer and usually a hash to prove integrity, and on an erasure request the off-chain data is deleted so that the pointer points to nothing (ICO).

Diagram showing data placement: on the blockchain sit the asset ID, transfers and a hash or pointer; off the chain sit names, documents and identity records, which can be corrected or deleted.

Personal data off the chain, proof on it. Delete the record and the pointer leads nowhere.

A content-addressed network such as IPFS is not off-chain storage in this sense. Its documentation states that all content on IPFS is public unless encrypted, and that a node which pins a file becomes a permanent reprovider of it (IPFS documentation, Privacy and encryption). Deleting your own copy does not reach anyone else's.

What issuers should do before they issue

Issuers should decide what goes on the chain before the first transaction, because nothing written there can be taken back.

Keep personal data off the chain. No names, emails or identity numbers in transaction notes, asset names, metadata or files published to IPFS. Identity checks belong in a system where records can be corrected and deleted.

Tell holders what will be public. The EDPB recommends informing people in clear terms when they are about to commit data to a blockchain (Recommendation 3). A holder should know, before buying, that their position and every transfer will be visible to anyone for as long as the chain exists.

Publish the asset ID and the administrative addresses. Names are not unique; the numeric ID is the only identifier that means something. State whether manager, freeze and clawback are set, who controls them and when they would be used.

Do not offer transparency as a substitute for disclosure. "It is all on-chain" does not say what the asset is, who owns it or what the holder is entitled to.

Trusty Digital works this way. In its NFT and credential work, no personal data is written to the chain. In a 2024 pilot for a sports organisation, each achievement certificate was issued as one non-transferable NFT, with holder consent for access and public verification without contacting the issuer (pilot projects). The chain proves that the issuer's account issued the certificate; the holder's personal details stay off it. Transaction notes and IPFS content are treated as permanent, because they are.

Should your records go on a public blockchain?

Put records on a public blockchain when public verification is the purpose, and keep everything about people somewhere it can be corrected and deleted.

The ICO suggests a blockchain may be the right choice over a database when you need the state of the records after each entry, several participants write to the ledger, all of them need the same view, and they do not trust each other (ICO, data protection by design and blockchain). The EDPB adds that a public blockchain should be used only if public access is necessary for at least one purpose of the processing (paragraph 49). A share register or a certificate can pass those tests; a holder's identity never needs to.

Questions people also ask

Are blockchain transactions anonymous? No. On a public blockchain they are pseudonymous: the address is visible, the name is not. One link between the address and a person, such as an identity-checked exchange withdrawal, attributes every past and future transaction of that address to them.

Does GDPR apply to a public blockchain? Yes, when the data on it relates to an identifiable person and an organisation decides to process it. The ICO treats wallet addresses as potential online identifiers, and the EDPB treats public keys as personal data where they can be linked to a person. The organisation that chose to put the data there carries the obligations.

Is a hash of personal data on-chain safe? Not by default. The EDPB treats a hash as personal data and calls unsalted or unkeyed hashes insufficient for a public blockchain. A keyed hash, with the key and the original data held off-chain and deletable, is the arrangement the guidelines describe.

The short version

A public blockchain gives you a register that cannot be quietly altered and that anyone can check, and it gives every holder's history to anyone who can put a name to an address. Under UK and EU data protection law that address can be personal data, and the ledger cannot honour a request to erase it. The workable design is the one both regulators describe: proof on the chain, personal data off it, and holders told before they commit.

To see where the ledger sits in a full project, read What is asset tokenisation?.

This article is general information, not legal, tax or investment advice.

Thinking about tokenising an asset?

Tell us what you are working with: the asset, where it sits, and what you are trying to achieve. We will come back to you with an honest view of whether tokenisation fits, including when it does not.