White paper WP-008
Zero-Knowledge Proofs as GDPR Article 25 Infrastructure
When the schema has nowhere to put PII, minimisation is real.
At a glance
- Paper
- WP-008
- Topic
- Zero-Knowledge Proofs as GDPR Article 25 Infrastructure
- Format
- PDF + web summary
- Signatures
- ML-DSA-65 post-quantum (NIST FIPS 204)
- Sandbox
- Reproducible at affix-io.com/sandbox
- Company
- AffixIO, Wales, UK
Zero-Knowledge Proofs as GDPR Article 25 Infrastructure is an AffixIO technical paper. When the schema has nowhere to put PII, minimisation is real.
Article 25 asks for privacy by design, not checkbox compliance. Zero-knowledge proofs make minimisation structural: witnesses enter the prover, only digests hit storage. We explain how AffixIO's record service schema enforces this by construction.
Summary
Article 25 asks for privacy by design, not checkbox compliance. Zero-knowledge proofs make minimisation structural: witnesses enter the prover, only digests hit storage. We explain how AffixIO's record service schema enforces this by construction.
Download the full PDF for technical detail, diagrams, and reproduction steps. Public sandbox: affix-io.com/sandbox.
Related reading
Frequently asked questions
What is data minimisation by design?
Building systems whose data model cannot accumulate unnecessary personal data, rather than relying on retention policies alone.
How do ZK proofs help ICO audits?
You demonstrate that stored records contain only cryptographic commitments verifiable against published keys.
Is consent still required?
Yes where lawful basis demands it; ZK reduces what you hold after consent is given.