GDPR Article 17 (Right to Erasure)

Ayrıca şöyle anılır Right to Erasure, Right to be Forgotten, GDPR Art. 17

Bir araya getirildiİnşa edilmedi

Article 17 of the GDPR gives people a legal right, in the EU, to ask an organization holding their personal data to delete it, and, in most cases, the organization has to comply. It's popularly called the "right to be forgotten," though that phrase is slightly broader in common usage than the legal right actually is: Article 17 applies when data is no longer needed for the purpose it was collected for, when someone withdraws consent that was the only legal basis for processing it, when the processing was unlawful to begin with, or under a handful of other specific listed grounds, not simply "whenever someone changes their mind." And it isn't absolute: an organization can refuse erasure when the data is needed to comply with a separate legal obligation, to exercise or defend legal claims, for public-interest archiving or research, or where erasure would conflict with freedom of expression.

Where it comes from

The phrase "right to be forgotten" entered wide use before GDPR made a version of it binding law. In 2014, the Court of Justice of the European Union ruled in Google Spain SL and Google Inc. v AEPD, Mario Costeja González (Case C-131/12) that individuals could, under certain conditions, require search engines to delist results about them, a narrower right than what Article 17 later codified, but the precedent that put the phrase in the public vocabulary. GDPR, in force since 25 May 2018, turned a broader erasure right into statute enforceable by national data-protection authorities across all EU member states.

The blockchain tension, genuinely industry-wide, not a Solidus problem alone

The conflict is structural rather than a failing of any one project, and the reason sits in the two designs themselves: a blockchain's core value proposition is that its history is append-only and effectively immutable. You can't quietly rewrite what happened without breaking the property that makes the chain trustworthy in the first place. GDPR erasure, taken literally, asks for the opposite: the ability to make a specific piece of data cease to exist. Writing personal data directly onto an immutable ledger and then promising to honor erasure requests against it is very close to a contradiction.

The standard answer across the industry, not something Solidus invented, is architectural: never put erasable personal data on-chain in the first place. Keep only pseudonymous identifiers, public keys, and cryptographic hashes or commitments on-chain (things that reveal nothing on their own and don't need to be "erased" because they were never personal data to begin with), and keep anything that actually needs to be deletable in an ordinary, off-chain data store where a real delete operation exists.

Solidus's honest position

Solidus's own whitepaper describes this exact pattern, "user data resides in user-controlled Solid pods... on-chain state contains only public keys and cryptographic commitments", under a section titled "GDPR Compliance by Design." Read that for what it is: a design intent stated in Solidus's own specification document, consistent across several of its internal architecture documents, not an independent legal opinion or a regulator's confirmation that it holds. No Data Protection Officer has been appointed, Solidus's own compliance roadmap lists this as a step to take "before EU launch," a future milestone, not a completed one. No Data Protection Impact Assessment has been completed for the biometric data collected during KYC, and the GDPR items on Solidus's own internal compliance checklist are unchecked as of this writing. There is no data-subject erasure request workflow, no [email protected] process that's actually been exercised: that a stranger, or even Solidus's own future DPO, could point to and test today.

Say the two different claims apart, deliberately: "the architecture is designed so personal data never has to be erased from the chain, because it was never written there" is a real, defensible design choice. "Solidus is GDPR compliant" or "Solidus honors Article 17 requests" is a claim nobody at Solidus should make yet, and this entry does not make it.

Check it yourself

There's nothing to check. No compliance program, appointed DPO, completed DPIA, or working erasure workflow exists, this entry names that gap rather than inventing a proof to fill it.

Nereden geliyor

Bunu başkası belirtti. Solidus bir araya getiriyor.

Article 17 of the General Data Protection Regulation (Regulation (EU) 2016/679, in force since 25 May 2018) gives an individual the right to have an organization erase their personal data under specific conditions (the data is no longer needed for its original purpose, consent is withdrawn, the processing was unlawful, or a few other listed grounds) subject to real exceptions (freedom of expression, legal compliance, public-interest archiving and research, and defense of legal claims all can override it). The "right to be forgotten" phrase predates GDPR's codification: the Court of Justice of the EU's 2014 ruling in Google Spain SL and Google Inc. v AEPD, Mario Costeja González (Case C-131/12) established a related, narrower right, to have certain search results delisted, four years before GDPR turned a related, broader right into binding statute across the EU. Solidus wrote none of this law and has no vote in how it's interpreted.

Bunu nasıl doğrularsınız

Solidus bunu inşa etmedi. Girdi kavramı açıklıyor.

None. No compliance program, no appointed DPO, no completed DPIA, and no working data-subject-erasure workflow exists to check. Stated plainly rather than inventing a proof where none exists.

İlgili

GDPR Article 17 (Right to Erasure) · Solidus Lexicon