DSR Knowledge LibraryReusable design knowledge and grounded research support
HomeLibraryChatGive feedback ↗

DSR Knowledge Library

Research prototype · Native Open Knowledge Format

LibraryChatImprintPrivacyEvaluation survey ↗
Library/DP1 - Do not store personal data on a blockchain

Design Principle

DP1 - Do not store personal data on a blockchain

Blockchain's paradigm of tamper-resistant storage jars profoundly with the right to rectification and erasure, so blockchain solution architects should keep personal data off-chain.

OverviewLinked conceptsRelationshipsGraphRaw metadata

01

Overview

Producer metadata and the represented concept document.

Concept identity

design-knowledge/gdpr-workflow-asylum-dp1
Open concept record
Producer label
DP1
Source paper
How to Develop a GDPR-Compliant Blockchain Solution for Cross-Organizational Workflow Management: Evidence from the German Asylum Procedure
Timestamp
2026-07-16T00:00:00+00:00
Bundle path
design-knowledge/gdpr-workflow-asylum-dp1.md
cross-organizationaldesign-principlegdpr-privacygdpr-workflow-asylumpublic-sectorworkflow-management

Design principle DP1: Do not store personal data on a blockchain

Blockchain's paradigm of tamper-resistant storage jars profoundly with the right to rectification and erasure, so we encourage blockchain solution architects to keep personal data off-chain rather than relying on tampering approaches that would allow deletion of on-chain data, which would betray the idea of tamper-resistant storage. This design principle may encourage the creation of a B2B blockchain network that does not process personal data of either the network's participants or third parties.

Source paper

This design principle is proposed by How to Develop a GDPR-Compliant Blockchain Solution for Cross-Organizational Workflow Management: Evidence from the German Asylum Procedure (Florian Guggenmos, Annette Wenninger, Alexander Rieger, Gilbert Fridgen, Jannik Lockl, 2020).

02

Linked concepts

Concepts connected by incoming or outgoing native Markdown links.

1 Design Principle

design-knowledge/gdpr-workflow-asylum-dp2

DP2 - Use a highly secure off-chain mapping architecture for attribution

If a use case requires that data on the blockchain be attributable to a natural person, use a highly secure off-chain mapping architecture.

cross-organizationaldesign-principlegdpr-privacygdpr-workflow-asylum+2

1 Paper

papers/gdpr-workflow-asylum

How to Develop a GDPR-Compliant Blockchain Solution for Cross-Organizational Workflow Management: Evidence from the German Asylum Procedure

Drawing on the German Federal Office for Migration and Refugees (BAMF) case, the paper presents two actionable design principles for GDPR-compliant blockchain solutions in cross-organizational workflow management: do not store personal data on a blockchain, and, where attribution is required, use a highly secure off-chain mapping architecture.

blockchaincross-organizationaldesign-science-researchgdpr-privacy+3

03

Relationships

Directed links from Markdown. Heading context is displayed as derived metadata, not as a formal OKF predicate.

Outgoing links

1
  • →

    How to Develop a GDPR-Compliant Blockchain Solution for Cross-Organizational Workflow Management: Evidence from the German Asylum Procedure

    Paper
    Source
    DP1 - Do not store personal data on a blockchain
    Target
    How to Develop a GDPR-Compliant Blockchain Solution for Cross-Organizational Workflow Management: Evidence from the German Asylum Procedure
    Link label
    How to Develop a GDPR-Compliant Blockchain Solution for Cross-Organizational Workflow Management: Evidence from the German Asylum Procedure
    Status
    Resolved

    Derived heading context: Source paper

Incoming backlinks

2
  • ←

    DP2 - Use a highly secure off-chain mapping architecture for attribution

    Design Principle
    Source
    DP2 - Use a highly secure off-chain mapping architecture for attribution
    Target
    DP1 - Do not store personal data on a blockchain
    Link label
    Design principle DP1: Do not store personal data on a blockchain
    Status
    Resolved

    Derived heading context: Addresses

  • ←

    How to Develop a GDPR-Compliant Blockchain Solution for Cross-Organizational Workflow Management: Evidence from the German Asylum Procedure

    Paper
    Source
    How to Develop a GDPR-Compliant Blockchain Solution for Cross-Organizational Workflow Management: Evidence from the German Asylum Procedure
    Target
    DP1 - Do not store personal data on a blockchain
    Link label
    Design principle DP1: Do not store personal data on a blockchain
    Status
    Resolved

    Derived heading context: Design knowledge

04

Local graph

One-hop by default, with an optional bounded two-hop view. Nodes are concept files and arrows are Markdown links.

Knowledge graph

3 of 3 concepts · 5 directed relationships

Concept types
Press enter or space to select a node.You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.
Design PrincipleSeed

Do not store personal data on a blockchain

Concept identity

Concept ID
design-knowledge/gdpr-workflow-asylum-dp1
Producer label
DP1
Native type
design-principle

Description

Blockchain's paradigm of tamper-resistant storage jars profoundly with the right to rectification and erasure, so we encourage blockchain solution architects to keep personal data off-chain rather than relying on tampering approaches that would allow deletion of on-chain data, which would betray the idea of tamper-resistant storage. This design principle may encourage the creation of a B2B blockchain network that does not process personal data of either the network's participants or third parties.

Tags

  • cross-organizational
  • design-principle
  • gdpr-privacy
  • gdpr-workflow-asylum
  • public-sector
  • workflow-management
Description and publication link from the library record.

05

Raw metadata

The complete producer frontmatter, serialized without server paths or runtime data.

Show producer frontmatter+
{
  "type": "design-principle",
  "title": "DP1 - Do not store personal data on a blockchain",
  "description": "Blockchain's paradigm of tamper-resistant storage jars profoundly with the right to rectification and erasure, so blockchain solution architects should keep personal data off-chain.",
  "resource": "https://hdl.handle.net/10125/64234",
  "source_paper": "How to Develop a GDPR-Compliant Blockchain Solution for Cross-Organizational Workflow Management: Evidence from the German Asylum Procedure",
  "label": "DP1",
  "tags": [
    "gdpr-workflow-asylum",
    "design-principle",
    "gdpr-privacy",
    "cross-organizational",
    "public-sector",
    "workflow-management"
  ]
}