Are crypto wallet addresses personal data?

Never assume. They can easily be…

Are crypto wallet addresses personal data?

They can easily be.

GDPR definition of personal data: “any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier”

CCPA definition of personal information: “information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. Personal information includes, but is not limited to, the following if it identifies, relates to, describes, is reasonably capable of being associated with, or could be reasonably linked, directly or indirectly, with a particular consumer or household.

As the address (or better, the public key) isn’t necessarily linked to real-life data, we may have either (1) anonymous data that isn’t subject to data protection laws, or (2) pseudonymized personal data (i.e. the data subject can be identified by adding other data) that isn’t. How do we tell? The GDPR test (see recital 26) is “account should be taken of all the means reasonably likely to be used … to ascertain whether means are reasonably likely to be used to identify the natural person, account should be taken of all objective factors, such as the costs of and the amount of time required for identification, taking into consideration the available technology at the time of the processing and technological developments.”

So the – somewhat similar-feeling – tests are whether the address: (i) belongs to an identified person or someone who can be identified using means that are reasonably likely to be used; or (ii) is an address reasonably capable of being associated with or linked to a consumer or household.

The Frosties Rug Pull case is one example of this working in practice:

Very briefly, in that case the defendants sold NFTs based on the promise of future value and utility, concealing their real-life identities, but terminated the project and transferred the sale proceeds (ETH) to personal wallets. They used Tornado Cash to try and hide it but eventually transferred it to centralized exchanges (presumably to cash out). The US IRS and DOJ were able to identify them and bring proceedings for fraud and money laundering offences. For this, some not actually very novel techniques were used to associate the addresses linked to the suspicious activity with the real-life identities of the defendants by combining among other information:

  • IP addresses, usernames, phone numbers, and emails from Discord;
  • names and residential addresses from Coinbase KYC records;
  • law enforcement records of who resided at the addresses;
  • IP address activity on Twitter;
  • blockchain transaction records linking the NFT funds with the defendants’ wallets;
  • information from credit card providers, Opensea, Bitpay, GoDaddy, PayPal, Fiverr, etc. (relating to the defendants’ use of services to set up the NFT website and design the images and transfer funds).

Maybe the defendants were careless in leaving traces – but the IRS didn’t have to look very far.

At least the exchange addresses which are firmly linked to real-life identities would seem to fall squarely into the category of personal data. But then private/unhosted addresses also appear to be linkable given enough additional data (not to mention naming services that allow us instead of 0×2113A96bdBfbBd5E192Bca20b46Cc40AE5Fe316F to use “edenlegal.eth” or similar). Returning to the GDPR test, of course, the IRS is able to use different means to obtain additional information – we can’t (and have no reason to) subpoena CEXs or credit card companies. However, we should definitely be looking at the other data we have on the user. Depending on the dApp, game, mint, or other service, we’ll often ask them to connect their Discord ID to their account. And we’ll probably have analytics with unique IDs and IP addresses. And that could be enough. Mandatory KYC is spreading to other crypto applications too.

So we may be in the presence of (pseudonymized) personal data here (also see Blockchain and the General Data Protection Regulation, European Parliamentary Research Service, 2019). Which would mean that the requirements of data protection laws will apply in full: a proper legal basis for processing to be identified; transparency information to be given; documentation and security measures to be put in place; impact assessments to carry out; maybe a data protection officer or EU/UK representative to be appointed; individuals’ legal rights requests to respond to; data breaches to notify; agreements with third parties to put in place; restrictions on international transfers. etc. etc. And fines if we don’t. And not forgetting the extraterritorial scope of these laws. This raises another question – under GDPR we need to apply principles of data minimization, and data protection by design – so we should also be considering what parts of this data we actually need.

Of course, this doesn’t feel very “Web3”. It’s common to hear that “blockchain is different” (see also: IP rights). But yet again, “real life” laws still apply on-chain, and these are the sorts of surprises we need to consider, and either rule out or prepare ourselves for.

Image Credit: FlippyFlink, CC BY-SA 4.0 , via Wikimedia Commons

  • Are crypto wallet addresses personal data?

    Are crypto wallet addresses personal data?

    Never assume. They can easily be…

  • EU International Data Transfers - new 2021 Standard Contractual Clauses

    EU International Data Transfers - new 2021 Standard Contractual Clauses

    The European Commission has issued a new set of standard contractual clauses (“SCCs”) to address new requirements under the GDPR, changes in the digital economy, but most importantly the European Court’s judgment in Schrems II requiring supplementary measures for some exports. The new SCCs are comprehensive and fill some gaps; but they require data importers and exporters to invest significantly in documenting how they will overcome local government surveillance laws.

  • Adtech Regulation under the EU’s draft Digital Services Act

    Adtech Regulation under the EU’s draft Digital Services Act

    A lot has been made of the liability and transparency provisions of the EU’s proposed Digital Services Act.

    However, there are also a few advertising-specific obligations (proposed to be) coming for online platforms that deserve a closer look.

  • "Due diligence" obligations for EU online platforms

    The quickest-possible look at the EU’s draft Digital Services Act and proposed new obligations for intermediaries and online platforms.

    Eden Legal will return with additional posts on: (1) liability for illegal content; and (2) specific adtech-related obligations, under the proposed Regulation.

    #Lawinagraphic – minimum wordiness, maximum user-friendliness.

  • How will Artificial Intelligence Systems be regulated in the EU?

    How will Artificial Intelligence Systems be regulated in the EU?

    The European Commission has put forward a proposed Regulation on a European Approach for Artificial Intelligence, also known as the “Artificial Intelligence Act”. It’s a proposal and before entering into application faces a likely lengthy path through the EU institutions which seems bound to produce a hefty amount of debate and amendments.

  • 2021 will be the Year of Smart Contracts

    2021 will be the Year of Smart Contracts

    Smart contracts are here. Eden Legal’s very initial, very personal thoughts on them.

  • GDPR EU/UK Representative - do we need one?

    GDPR EU/UK Representative - do we need one?

    Everything you need to know about appointing an EU and/or UK representative as required by the GDPR.

    Update 14 February 2021: under the EU Council’s agreed position on the future E-Privacy Regulation, providers of electronic communications services, providers of publicly available directories, senders of direct marketing over electronic communications services, and anyone using processing and storage capabilities or collecting information processed by or emitted by or stored in the end-users’ terminal equipment (i.e. adtech!) will also be required to appoint a representative in the EU and communicate it to the relevant national supervisory authority.

  • GDPR and Brexit - take us to the bridge

    GDPR and Brexit - take us to the bridge

    The EU-UK Trade and Cooperation Agreement has avoided major changes to personal data flows between the EEA and UK at least until 30 April 2021. However, if we process data of individuals in both the EEA and the UK, then we face the prospect of complying with two similar but distinct regulatory regimes.

  • The ICO fines Marriott and BA for GDPR Breaches - 10 Takeaways

    The ICO fines Marriott and BA for GDPR Breaches - 10 Takeaways

    If you’re handling personal data subject to EU (and/or UK) laws then you would do well to read the UK Information Commissioner’s (“ICO”) decisions to fine Marriott and BA for failures to have in place appropriate cyber-security measures. And this post for 10 more easily digestible takeaways.

  • EU Court invalidates Privacy Shield - what to do?

    EU Court invalidates Privacy Shield - what to do?

    The Court of Justice of the EU has struck down the EU Commission’s EU-U.S. Privacy Shield Framework decision, but in principle left in place the EU Commission’s Standard Contractual Clauses, which organisations can sign in order to impose EU-style data protection obligations on non-EU data importers. For now, where we used to rely the Privacy Shield framework, the pragmatic approach may be to sign SCCs – but the story won’t end there.