We Can’t Delete It. Are We Powerless? (Blockchain & Privacy, Part 2)

The comforting half of the story: even permanent data has weak points.


In Part 1, we landed on a scary conclusion: some data written to a public blockchain can never be deleted. Not by a court, not by the victim, not by anyone.

If that’s where the story ended, blockchain would be a doomsday machine for privacy. But it isn’t the end. “Can’t delete” and “can’t do anything” are two very different sentences. Let’s separate them.

Here are three places where we’re less helpless than it seems.


1. There’s a difference between existing and being found

Ask yourself: what actually hurts when private data leaks?

It’s not the mere existence of the data on some server. It’s that people can find it, read it, and spread it. A secret buried in a location nobody can reach does almost no damage. A secret on the front page does enormous damage.

This gap is our first weapon.

Well-built blockchain systems don’t put the real data on the chain at all. They keep the actual file somewhere else — an ordinary storage system — and write only a kind of fingerprint onto the blockchain. The fingerprint proves the file is genuine, but you can’t rebuild the file from it, the same way you can’t rebuild a person from their fingerprint.

Delete the real file, and the fingerprint on the chain becomes a meaningless string of characters. Permanent, yes. Harmful, no.

“But what if the attacker writes the raw secret directly onto the chain?” Good question — and here’s a quiet piece of good luck: doing that is expensive. Every character you write to a blockchain costs real money in fees. Dumping whole photos or long documents onto it costs an eye-watering amount. It’s not an impossible wall, but it’s a tollbooth that stops most casual abuse.


2. The doors people walk through can be locked

Here’s something most people don’t realize. Almost nobody reads a blockchain directly — that’s like reading raw computer code. Instead, they use websites and apps built on top of it: block explorers, wallets, and services with friendly screens.

And those websites and apps? They’re run by companies. Normal, centralized companies with rules and delete buttons.

So even when harmful data is technically stuck on the chain forever, these front doors can refuse to show it. They already do this for illegal content and blacklisted accounts. The data can sit in the vault, but if every window into that vault is boarded up, ordinary people never see it. “Present but invisible” is a real and achievable state — and for the victim, invisible is most of what matters.


3. The evidence never disappears either — and that cuts both ways

Now for the irony.

The attacker relied on the blockchain’s “never forget” nature to hurt someone. But that knife has two edges. Their action — the act of posting — is also permanently recorded. Every step is timestamped and preserved as flawless evidence.

“But the attacker was anonymous!” Often, less than they think. The moment they touched a real exchange, cashed out, or slipped up on their network address, the trail can lead back to a real name. The same permanence that made the harm impossible to erase makes the crime impossible to hide.

Posting someone’s private data with malicious intent is a crime — defamation and privacy-law violations in nearly every country. The blockchain becomes the prosecutor’s perfect witness.


Honesty check: the gap that’s still open

I won’t oversell this. The worst case — someone writing a small, nasty piece of text onto the main chain and vanishing — still can’t be fully prevented today. Lawmakers and researchers around the world are still arguing about how privacy rights and blockchains can coexist, and nobody has a clean answer yet.

So we’re not invincible. But we’re far from powerless. We can shrink the harm, hide the exposure, and catch the culprit.

Still — reducing harm after the fact is playing defense. Wouldn’t it be better to build systems where this danger can’t appear at all?

That’s Part 3: how the people who build these things can design the problem out of existence.


This is Part 2 of a 3-part series on blockchain and the right to be forgotten. Next: the developer’s first principle.


Tags: Blockchain, Privacy, Web3, Cybersecurity, Data Protection

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *