On January 20, 2023, The Centre for Information Policy Leadership (“CIPL”) at Hunton Andrews Kurth published “Digital Assets and Privacy,” a discussion paper compiling insights from workshops with CIPL member companies that explored the intersection of privacy and digital assets, with a particular focus on blockchain technology. The paper includes recommendations for developing coherent, tech-friendly, future-focused, and pragmatic regulations and policies.
As financial services authorities move to regulate digital assets in jurisdictions worldwide, the paper highlights the need to bring privacy regulators into the discussion so that data privacy issues affecting blockchain are addressed in tandem. Given the limited dialogue thus far, there is a pressing need for regulators to understand and navigate the overlapping regulatory realities of digital assets, with the hope of advancing a consistent, comprehensive, and workable regulatory approach.
Key areas of concern identified in the discussion paper include basic privacy principles:
- Applicability of existing laws and definitions. Blockchain technology does not readily align with traditional data protection concepts such as data controller or processor, nor is it confined to a specific jurisdiction, which makes application of existing data protection definitions and regimes challenging.
- Accountability. Blockchain is by design a decentralized system where data is not processed in a centrally controlled manner, thereby making any assessment of who is responsible for determining the means and purpose of the processing rather problematic (or possibly irrelevant).
- Data minimization. Blockchain technology stores data in discrete blocks that are linked together and further appended with additional blocks of data, creating an ever-growing network of data that is hosted perpetually on multiple nodes across different jurisdictions.
- Purpose limitation. Given the nature of blockchain, the further processing of data placed on the chain may not be compatible with the original purpose.
- Data security. Stakeholders have yet to reach a consensus or standardization of encryption techniques to achieve a desired level of data security. Moreover, blockchain’s transparency exposes it to vulnerability by enabling malicious actors to target public keys.
- Confidentiality and government access. Blockchain permits anyone, including governments, to see transactions in a more transparent and unprecedented way.
- Individual rights. Blockchain transactions are recorded forever without possibility of deletion. Moreover, no single authority is equipped to address individual rights requests, including the rights to erasure, rectification, objection, and retention.
- Cross-border data transfers and enforcement. Given the borderless nature of the blockchain, stakeholders need to address the applicability of current cross-border transfer mechanisms and assess options for ongoing and future data flows.
CIPL recommends the following policy considerations for legislative and regulatory proposals:
- Address blockchain’s interplay with data privacy and provide direction to stakeholders through regulations, guidance, memoranda of understanding, and other mechanisms.
- Ensure collaboration and cooperation among regulatory authorities that deal with data, including financial services, competition, and data protection authorities, both within a country and across jurisdictions.
- Implement an innovative approach—ideally one that is technology-neutral, functional, and outcome-driven—that aligns with the characteristics and architecture of blockchain technology.
- Build realistic and achievable goals while engaging with innovators and other stakeholders, taking into account users’ expectations.
- Address how the desired outcomes of privacy rights and principles can be achieved in the blockchain, particularly in public blockchain networks.
- Consider alternative approaches to ensure organizational accountability, especially in public permissionless blockchains.
- Incentivize co-regulatory certifications, industry-recognized standards, PETs (e.g., zero-knowledge proof), and sandboxes to support the application of privacy-enhancing outcomes for blockchain.
- Consider tailoring existing enforcement measures to be both effective and relevant to the blockchain environment.
- Encourage the development of secure infrastructure and processes to ensure the integrity of wallet holders and private keys.
- Educate users about the risks associated with the blockchain ecosystem and the benefits of traditional offline methods.
- Promote transparency regarding government access to blockchain data and ensure that appropriate redress measures are in place.
Ideally, the tensions between privacy and blockchain should be reconciled before regulators promulgate rules that could inhibit innovation. The technology is far from having explored all its potential use cases, and should be allowed to “live” before any new regulations constrain it more than necessary.
For more information about CIPL’s policy recommendations, access the Discussion Paper.
The Hunton Andrews Kurth Blockchain Blog features opinions and legal analysis as we follow the development and use of distributed ledger technology known as the blockchain.
Search
Recent Posts
Categories
Tags
- 2019 Leaders’ Declaration
- 2020 National Strategy for Combating Terrorist and Other Illicit Financing (the 2020 Strategy)
- Advancing Innovation to Assist Law Enforcement Act
- Airdrops
- AML compliance program
- AML/CFT
- anonymity-enhanced cryptocurrencies
- Anti-Money Laundering
- Anti-Money Laundering Act of 2020 (AMLA)
- Anti-Money Laundering Compliance
- Antifraud
- Aon and Marsh
- Arizona
- Arkansas
- Artificial Intelligence
- Artificial Intelligence (AI)
- Australia
- Australian Competition and Consumer Commission (ACCC)
- Australian Securities and Investments Commission (ASIC)
- Automated Clearing House (ACH)
- Bank of England
- Bank Secrecy Act
- Bank Secrecy Act (BSA)
- Bank Term Fund Program
- Bermuda
- Biden Administration
- BIS
- Bitcoin
- Bitcoin Cash
- Bitfinex
- BitLicense
- Blockchain
- Blockchain Incubators
- Blockchain Legislation
- Blockchain Regulatory Certainty Act
- Blockchain Technology Act
- Brazil
- Breach of Contract
- Broker-Dealer
- Broker-Dealers
- BSA
- BSA Enforcement
- BTFP
- Bureau of Economic Analysis
- California
- Canada
- Captive Insurance
- CCPA
- Celebrity Endorsers
- Central Bank
- Central Bank Digital Currency (CBDC)
- Centre for Information Policy Leadership (CIPL)
- CFTC
- Chapter 15
- China
- Christopher Giancarlo
- Civil Enforcement
- Class Actions
- Clearweb
- Colorado
- Commissioner
- Commodity Exchange Act
- Commodity Exchange Act (CEA)
- Commodity Futures Trading Commission
- Complaint Bulletin
- Compliance
- Compliance Note
- Congress
- Connecticut
- Consent
- Consumer Financial Protection Bureau (CFPB)
- Consumer Protection
- Convertible Virtual Currency
- Corporate Compliance
- Corporate Governance
- Corporate Transparency Act (CTA)
- Council of Institutional Investors
- Council of the European Union
- Countering the Financing of Terrorism (CFT)
- Cross-Border Data Transfer
- crypto arbitrage trading accounts
- Crypto Assets
- crypto bank
- crypto custody
- Crypto Hackers
- Crypto Mining
- Crypto-commodity
- Crypto-currency
- Cryptoassets
- Cryptocurrency
- Cryptopia Limited
- Cryptosweep
- CVCs
- cybercrime
- Cybersecurity
- Dalia Blass
- DAO Report
- Darknet
- darknet marketplaces
- Data Privacy
- Data Protection Authority
- Davos
- decentralized finance (DeFi)
- DeFi
- Del. Michael San Nicolas
- Delaware
- Department of Business and Industry
- Department of Justice
- Department of Treasury
- DFS
- Digital Asset
- Digital Asset Securities
- Digital Assets
- Digital Commodities Consumer Protection Act of 2022
- digital currency
- digital currency ATM operators
- digital currency exchangers
- digital currency flows
- Digital Financial Assets Law (the Act)
- Digital Token Act
- digital token sales
- Digital Tokens
- Distributed Ledger
- Documentary Stamp Tax (DST)
- Dodd-Frank
- DOJ
- Economic Sanctions
- EDPB
- Eleventh Circuit
- Endorsement Guides
- Enforcement Action
- ePrivacy
- Ether
- Ether Classic
- EU General Data Protection Regulation (GDPR)
- EU Regulation
- European Central Bank
- European Commission
- Exchange Act
- Exchange Traded Fund
- FDIC
- Federal Election Commission
- Federal Reserve
- Federal Reserve Board
- Federal Trade Commission
- FedNow
- fiat currency MSBs
- Fiat-Backed
- Fight Illicit Networks and Detect Trafficking Act
- Figure Lending LLC
- Final Guidance
- Financial Action Task Force (FATF)
- Financial Crimes Enforcement Network (FinCEN)
- Financial Privacy
- Financial Stability Board
- Financial Stability Oversight Council
- Financial Stability Report
- Financial Technology Protection Act
- FinCEN
- FINRA
- FinTech
- Florida
- Foreign Corrupt Practices Act (FCPA)
- Foreign Extortion Prevention Act (FEPA)
- Form BE-12
- fractional interests
- FTC
- Gemini Dollar
- Gemini Trust Company
- Global Consortium for Digital Currency Governance
- Group of Seven
- Group of Twenty (G20) Finance Ministers
- H.R. 5635
- Hard Fork
- Heath Tarbert
- Her Majesty’s Revenue & Customs (HMRC)
- HM Revenue & Customs (HMRC)
- home equity lines of credit (HELOCs)
- Homeland Security Assessment of Terrorists’ Use of Virtual Currencies Act
- House of Representatives
- House of Representatives’ Financial Services Committee
- Howey
- Howey test
- IEO
- iFinex Inc.
- Illinois
- India
- Information Sheet 225
- Initial Chain Offering
- initial exchange offerings (IEOs)
- Insurance
- Intellectual Property
- International
- International Monetary Fund (IMF)
- Investor Protection
- IRS
- Jefferies Funding LLC
- Kenneth Blanco
- KYC/AML requirements
- Lael Brainard
- Large Platform Utility
- Legislation
- Legislature
- Liechtenstein Parliament
- liquidity
- Litecoin
- Litigation
- Louisiana
- Ltd.
- Malicious Cyber Activity
- Malicious Cyber Actor
- managed stablecoin
- Martin Act
- Maryland
- Metaverse
- model rule
- Monetary Policy
- Money Laundering
- Money Service Business
- money services businesses (MSBs)
- Mortgages
- Multi-Level Marketing Program (MLM)
- Mutual Fund
- Nakamoto
- narcotics
- NASAA
- Nebraska
- network maturity
- Nevada
- New Jersey
- New York
- New York Attorney General
- New York Department of Financial Services (DFS)
- New Zealand
- NFT (Non-Fungible Token)
- NFTs
- Non-fungible tokens
- North Dakota
- North Korea
- NY Department of Financial Services
- OFAC
- Office of Investor Education and Advocacy
- Office of the Comptroller of the Currency (OCC)
- Ohio
- Oklahoma
- Patent
- Paxos Standard
- Paxos Trust Company
- peer-to-peer exchangers
- Penalty
- Pennsylvania
- Personal Data
- Personal Information
- President’s Working Group (PWG)
- Privacy
- privacy coins
- Provenance.io
- Proxy Voting
- Public Blockchain
- rapid settlement
- real estate
- Regulation and Enforcement
- Rep. Sylvia Garcia
- Rescission
- Retail
- Ripple
- Ripple Labs
- Rule 233-1
- Russia
- Sanctions
- Sanctions Compliance Program (SHP)
- SAR lookback review
- SD8 coins
- SDN List
- SEC
- SEC crypto-securities
- SEC registration
- Securities
- Securities Act
- Securities Act of 1933
- Securities and Exchange Commission
- Securities and Exchange Commission (SEC)
- Securities Exchange Commission
- security tokens
- Self-disclosure
- Senate Committee on Banking Housing and Urban Affairs
- Shareholder
- Shareholders
- SIFI
- Signature Bank
- Silicon Valley Bank
- South Carolina
- South Dakota
- Spencer Dinwiddie
- stablecoins
- Stablecoins are Securities Act of 2019
- State-Sponsored Malicious Cyber Groups
- Suspicious Activity Report
- suspicious activity reporting (SARs)
- SVB
- SWIFT messaging system
- Swiss Financial Market Supervisory Authority (FINMA)
- Switzerland
- synthetic hegemonic currency
- Taxation
- Templum
- Tennessee
- Terrorist Financing
- Tether Limited
- Texas
- Texas Business Organizations Code (TBOC)
- Texas Senate Bill 1859
- Texas Senate Bill 1971
- The World Bank
- three-year safe harbor
- Token and TT Service Provider Act
- token developers
- token transfer limits
- tokenization
- tokenized assets
- Trademark
- Travel Rule
- Trump Administration
- TT Identifier
- TT System
- TVTG
- U.S. Virtual Currency Market and Regulatory Competitiveness Act of 2019
- UCC Article 12
- UK Tax Rules
- unhosted wallets
- Uniform Commercial Code
- United Kingdom (UK)
- United Specialty Insurance Company
- United States Bankruptcy Code
- United States Patent and Trademark Office
- US central bank digital currency (US CBDC)
- US Department of the Treasury
- US Department of the Treasury’s Office of Foreign Assets Control (OFAC)
- US dollar
- US Treasury
- USTR
- Utah
- Vermont
- Virginia
- Virtual Asset Service Providers
- Virtual currencies
- Virtual Currency
- Virtual Currency Consumer Protection Act of 2019
- Virtual Currency Exchange
- virtual currency license
- Virtual Currency Tax Fairness Act of 2020
- Virtual Markets Integrity Initiative
- Washington
- Weapons of Mass Destruction Proliferators Sanctions Regulations
- World Economic Forum
- Wyoming
- XRP
Authors
- Jimmy Bui
- Mayme Donohue
- Nicholas Drews
- Andrew Feiner
- Jason Feingertz
- Hannah Flint
- Kevin E. Gaunt
- Armin Ghiam
- Carleton Goss
- Gregory G. Hesse
- Scott H. Kimpel
- Marysia Laskowski
- Michael S. Levine
- Phyllis H. Marcus
- Lorelie S. Masters
- Patrick M. McDermott
- Uriel A. Mendieta
- Alex D. Pappas
- Daryl B. Robertson
- Natalia San Juan
- Caitlin A. Scipioni