← Back to list

Your web3 users are not anonymous.

Here’s what that actually means…

Iwalola Sobowale · 2026-05-15 19:57 · 6 claps · 4.0 min read paywalled
#web3 #web3-research #blockchain-research #research #data-privacy
Open on Medium ↗
Wiki topics: CRY · Crypto & Web3 🔒 · Cybersecurity

Your web3 users are not anonymous.

Here’s what that actually means…

There’s a claim that circulates in web3 circles — that blockchain is anonymous, that wallet addresses protect user privacy by design, and that crypto gets around the surveillance problems of traditional finance.

It’s not quite right, and the nuance matters.

Wallet addresses are pseudonymous, not anonymous. The distinction sounds technical, but the implications are not.

What “pseudonymous” actually means

A wallet address doesn’t reveal a name. But it exposes every transaction that address has ever made, every counterparty, and the full history of on-chain behaviour; permanently and publicly. Pair that address with KYC data from a centralised exchange (which most active crypto users have interacted with), or layer in device ID, location data, or transaction timing, and you can arrive at a specific, identifiable person.

The other thing that makes this distinct from most digital data: blockchain footprints can’t be deleted. A record you created in 2019 is still there. That permanence changes the risk calculus entirely.

The EU’s data protection regulator, the EDPB (European Data Protection Board), confirmed in its April 2025 blockchain guidelines that wallet addresses and public keys must generally be treated as personal data when combined with other reasonably available information. Nigeria’s NDPR defines personal data as any information that can be used to identify a person. So, wallet addresses, particularly when held alongside KYC or transaction data, fall squarely within that definition. If you are collecting, storing, or sharing wallet addresses in any research, product, or analytical context, you are handling PII, and the obligations that come with it apply.

One important nuance: a September 2025 ruling by the Court of Justice of the EU found that pseudonymised data is not automatically personal data in all hands, and that it depends on whether the specific recipient can reasonably re-identify individuals given their access to other data. For most actors in web3 — i.e. platforms, researchers, and builders who also hold KYC, transactional, or device data — the re-identification risk is real and the personal data classification holds. But this is a live and evolving area of law.

What this means for research practice

If you’re conducting user research in web3 (interviews, surveys, observational studies, anything involving human participants), you can’t treat wallet addresses like ordinary identifiers. You can’t store them in a shared sheet. You can’t include them in reports or transcripts you distribute to stakeholders. You need to pseudonymise participants: assign each one a unique identifier, keep the mapping between identifier and wallet address locked and access-controlled, and ensure that anything shared externally contains no trail that leads back to a specific address.

This is the same standard that applies to names, phone numbers, and biometric data. The fact that a wallet address looks like a random string of characters doesn’t change that.

Consent

One response I often encounter from founders is: “We covered this in our terms of service.” It’s worth being precise about what that does and doesn’t protect.

A contract clause cannot override data protection law. Cambridge Analytica, in 2018, collected data through a research app whose users had consented, but then they used that data to profile millions of their friends, who had consented to nothing. Facebook, for its part, had a 2012 regulatory agreement with the FTC (Federal Trade Commission) that explicitly barred it from sharing user data without permission.

The $5 billion fine that followed wasn’t because consent language was ignored in the abstract. It was because the consent obtained didn’t cover the people whose data was actually used, and Facebook violated a prior binding regulatory commitment in letting it happen.

The lesson isn’t that consent is useless. It’s that consent is only as strong as its scope; and that scope has to match what you’re actually doing with the data.

Expressed consent — where a user actively agrees to a specific, clearly stated use of their data — is not the same as implied consent buried in a Terms of Service that no one reads. Data protection law distinguishes between the two. Thus, web3 platforms that rely on the latter are exposed.

The harder question

There’s a legitimate tension in all of this. Blockchain data is public by design because anyone can look up any wallet address on a block explorer. Does that make it fair game?

The regulatory answer is no. Public availability doesn’t remove the personal data classification. What makes information personal data isn’t whether it’s hidden; it’s whether it can be used to identify an individual. The EDPB’s 2025 blockchain guidelines are clear on this. Wallet addresses meet that test, particularly when combined with other data points, which in practice they almost always are.

The philosophical answer is more interesting. Web3’s promise has always been that users control their own data. But that promise doesn’t hold if the infrastructure being built around it, i.e., the research, the analytics, the product decisions, treats user data with less rigour than traditional finance does. It’s worrisome that the technology can be decentralised while the research practices that inform it remain sloppy and exposed.

The short version

If you’re building in web3 or researching users in this space: wallet addresses are personal data for most practical purposes, so handle them accordingly. Pseudonymise, limit access, don’t share. Your Terms of Service does not protect you from data protection law. And the blockchain’s permanence means any mistake you make in handling this data is harder to walk back than in a traditional database.

TL;DR: Data governance is not an ops problem to solve later. It’s a trust problem. And in web3 infrastructure, trust is the product.

Sources

EDPB Guidelines 02/2025 on Processing of Personal Data through Blockchain Technologies — European Data Protection Board, April 2025

EU Court of Justice Issues Landmark Judgment on Concept of “Personal Data” — Sidley Austin, October 2025

FTC Imposes $5 Billion Penalty and Sweeping New Privacy Restrictions on Facebook — Federal Trade Commission, July 2019


메타데이터
post_id
393be894f03e
slug
your-web3-users-are-not-anonymous-393be894f03e
url
https://medium.com/@iwalola/your-web3-users-are-not-anonymous-393be894f03e
canonical_url
https://medium.com/@iwalola/your-web3-users-are-not-anonymous-393be894f03e
author_url
https://medium.com/@iwalola
status
ok
fetched_at
2026-06-14 11:28:49