Overview
ISO/TR 23244:2020 provides a practical overview of privacy and personally identifiable information (PII) protection in blockchain and distributed ledger technologies (DLT). It explains privacy risks, applicable safeguards and how traditional privacy principles (consent, data minimization, accountability, etc.) apply in immutable, distributed systems. The report is intended as guidance - not prescriptive requirements - to help organizations assess and manage privacy in DLT solutions.
Key topics and technical focus
- Privacy framework for blockchain/DLT: components include actors and roles, interactions, recognizing PII, safeguarding requirements, privacy policies and controls.
- Actors and responsibilities: clarification of PII principal, PII controller and PII processor roles in distributed systems, and the legal complexity (for example, nodes or validators potentially being treated as joint controllers).
- PII recognition and rights: guidance on identifying PII in ledger data and reconciling ledger immutability with rights such as amendment or erasure (e.g., GDPR “right to be forgotten”).
- Privacy safeguarding requirements: considerations for legal/regulatory factors, contractual and business factors, and storage decisions (on‑chain vs off‑chain).
- Privacy controls and PETs: overview of privacy-enhancing technologies applicable to blockchain/DLT, including references to techniques such as ZKSNARK (zero-knowledge proofs) and other cryptographic approaches.
- Privacy impact assessment (PIA) and risk management: integrating PIAs into overall risk programs, identifying privacy threats, vulnerabilities, consequences and mitigation strategies.
- Operational lifecycle: personal information management, change management, monitoring, complaint handling, decommissioning and regulatory compliance.
Practical applications
- Designing privacy-aware blockchain applications (financial services, identity, supply chain) that must comply with data protection laws.
- Evaluating whether to store data on-chain or off-chain, and implementing appropriate technical and contractual safeguards.
- Conducting privacy impact assessments for DLT projects to identify PII exposure and mitigation options.
- Selecting and integrating privacy-enhancing technologies (e.g., encryption, anonymization, zero-knowledge proofs) to reduce PII exposure.
- Drafting privacy policies, data processing contracts and governance that address distributed control and accountability.
Who should use this standard
- Solution architects, blockchain developers and security/privacy engineers designing DLT systems.
- Data protection officers, compliance teams and legal counsel assessing regulatory exposure (e.g., GDPR).
- Project managers, auditors and risk teams running PIAs and privacy risk mitigation for DLT deployments.
- Organizations considering public, consortium or private blockchains with PII implications.
Related standards
Keywords: blockchain privacy, DLT privacy, PII protection, GDPR, privacy impact assessment, privacy-enhancing technologies, ZKSNARK, on-chain off-chain, data minimization, PII controller.