@web3pm
https://www.theblock.co/post/331713/german-authority-orders-eyeball-scanning-world-project-to-delete-data-after-investigation
This article misses an important distinction by the Bavarian DPA in their decision.
They made a key point twice which should send chills down the spine of any company posting raw data about users onchain:
“Comprehensive erasure following withdrawal of consent”
And
“the unrestricted opportunity to
enforce their right to erasure”
This isn’t accidental, and tho IANAL, I read it as there being no way to be GDPR compliant when posting user data onchain, no matter what consent you receive.
Maybe they will clarify this guidance later but I would recommend any companies doing onchain attestations or the like to investigate partial blind models so that the onchain component doesn’t inherently contain user data