Eugenio Reggianini - Head of Growth at European Blockchain Association | Privacy Academy Interviews
Ethereum Cypherpunk Congress·Thu, Oct 9, 2025, 12:00 AM
This conversation is part of Academy Interviews (https://academy.web3privacy.info/) - our peer-to-peer knowledge project exploring the most important ideas in Web3, privacy, and digital rights. Inspired by the Socratic method, we share in-depth dialogues with experts building the open web. In this episode, we talk to Eugenio Reggianini, Head of Growth at the European Blockchain Association, about privacy, blockchain adoption, and the tension between product growth, regulation, and user protection. If you’re building in Web3 or just want to understand the evolving privacy landscape in blockchain, this is for you. Timecodes 00:00 - Eugenio’s Background & Path to Blockchain 01:50 - Working Across Product, Market, and Regulation 03:00 - Blockchain Accounts: UX, Trust & Compliance 04:45 - Privacy as a Human Right & Its Industry Impact 06:50 - How to Implement Privacy at Blockchain Layers 09:00 - Technology Evolves, Regulations Stay Static (GDPR) 11:00 - User Expectations: Transparency and Privacy Notifications 12:00 - Builders' Privacy Duties & Cryptography in Practice 13:50 - Product Development vs Privacy: Operational Tensions 15:40 - Legal Advice: Beyond Just Regulatory Compliance 16:40 - Privacy Regaining Priority in Blockchain Networks 17:40 - Final Thought: Privacy as a Guiding Principle with Flexibility Useful links http://web3privacy.info http://academy.web3privacy.info Camera & sound: https://x.com/BabyBitProd Interviewer: https://x.com/0xfarbey Let privacy be with you!
Transcript
[Music] Well, my name is General Janini. I if you like to to say I have a funny story why I ended up in this in this industry. I professionally born in the legal space and then I for other reason I move into business uh in consulting advisory and then in a specific moment of time which is more or less during the covid during the pandemic I decided to turn my passion for for blockchain and crypto asset into my profession and starting uh let's say everybody learning curve in the in this face right. So what I do is I do many things. I represent different communities in um in different uh market segmentation for different services, identity, blockchain in general providers.
Um I mainly collaborate with European communities even if I have like an Asian background um in a few countries like Singapore, China and so on. But yeah, most of it's my activity it's in the intersection between product market and regulatory things. I I tend to be very pragmatic. Usually companies build products and over product build the build services right services are identified by use cases which explain practically what the product can do. I'd say that they usually helps the company to uh originate uh scope and define the use cases from all the requirements which pertain to the business dimension of it.
So regulatory design and business itself it's not only compliance at all like there are some uh compliance requirements which usually can be scoped into a use case at the beginning usually um but it's also requiring design skills it's also requiring business and strategy skills so it's a combination which if you like I was able to collect across my overall working experience. I started working almost like 10 years ago. So I did different things and I collected and I package for uh something which can have a fit in in the industry and aside of that I do a lot of let's say community activity even proono and and and research uh especially in the intersection between uh infrastructure things and regulatory compliance and design. uh I I've been focusing a lot on uh the evolution and the innovation which happens in the account features for which interacts over blockchain networks. I find uh this very interesting because uh this match a couple of things.
Uh the need for uh improve the user experience. uh the need for doing more simple things and or things in a more simple way to get more user to get adoption of the technology and also the need of uh trust which are is in another words the need of compliance uh business perspective uh that is that is usually anchored to blockchain accounts right so from users perspective how we can build uh more performant or better blockchain accounts that can solve the issue that we have as a community in terms of adoption but also in terms of compliance. First of all, privacy I would say is a very broad broad uh meaning I would say. Um as an individual I think I I would like to shift what I think from personal perspective and how much does it matter in what I do and the implication for the industry. Right?
So for me also considering my legal background privacy is a fundamental right of human being. Okay. So there are very if not few things that are more important maybe life is more important than privacy. Uh but um but it's a very very important thing and something which should be always taken into consideration when we implement service that are used by others. uh which kind of implication have uh towards the industry and other users different uh in short uh going in more depth of course this privacy can be seen as a uh usually an as an extension of compliance for u uh service providers.
But but at the same time if providers care about the user needs is not just a requirement but also a an index I used to say a metrics for feedback right because especially for an industry which is foundational of an infrastructure which is enabling user to manage their own data. The way in which I communicate this data sharing and the amount of data sharing that I um enable with my action is key uh to determine the um the efficiency of a solution or not. So minimizing this and enabling um a minimize data sharing goes into building more privacy oriented services. So this is to say that yes privacy is um um I would say for people in the industry is uh existent uh persistent and uh a lifetime challenge I would say right um and it's something that is uh not uh living in a in a static state but is evolving as much as the technology evolves you need to adapt uh the level of requirements that you set to yourself as a solution in order to ensure privacy to your users. Especially if you talk about blockchain where like which rely on the assumption that at least for for my personal view uh privacy it's I manage my key, I manage my tokens, I manage my assets.
For me there are like different way in which you can answer this question. Firstly it depends on about what you are building to and where does it stays in the blockchain uh let's say transaction journey right if you're building an application if you're building a smart contract or if you're running a node or building offering a service to node operators. So there are different ways in which you can try to take measure to ensure privacy at different level of this transactional journey. Um generally the easiest way uh is probably uh at the application layer because uh when you are building a application as a service on top of smart context that maybe you even control you are actually in the control of the data that you request from the users. So you can manage with policy with agreements which these data management with the end users.
Then things get a little bit more complicated as long as you go down to the infrastructure. Uh because this requires to uh let's say takes a lot of uh cryptographic features uh to minimize your data shedding to maybe uh run your computation in an isolated environment or uh using cryptographic other cryptographic techniques to ensure private computation only between parties. um so to say that the data is becoming in a way from seed anonymized to anonymized. So once the data becomes anonymized u then the overall infrastructure below architecture which is made by different nodes operator can process anonymize data. uh making sure that um systematic or potential attacks on that infrastructure won't be able to revert the information and getting access to the client or end client information at the end.
Well, GDPR is one regulatory framework which apply for us in Europe. Um I would say that yes you know maybe it may result a little bit simplistic my answer to that but unfortunately regulatory pieces are static pieces technology evolves right. So as we are the like the technologist part is the part that is flexible and evolving. Unfortunately technology needs to adapt to these static things that we have that rules us let's say in the offchain world which is the regulation. So I think it's our um uh it should be our goal trying to build a compliance solution that's that can address principle that are in those regulations.
At the same time it would be good that we have an exchange with institutions that are able to adapt and to modify slightly when is possible those regulation to better fit the evolution of the of the technology itself. I'm saying for blockchain but it's the same for AI. It's just the fact that when you build regulations uh after 10 15 years technology evolves and things go to mainstream that were not uh were not possible to think at the at the beginning. Um so unfortunately is um existential tension that it's up to industry participants and institution try to uh work together to close the gaps for me for me from user perspective I would be happy if for instance um when accessing the services I it's quite clear and communicate the way in which the data is originated is processed I am kept informed if anything's uh anything happens uh if I am potentially subject to unhack and these are all requirements which generally stands to within the GDPR framework okay these are easy things to uh implement uh with communication and to manage then um the problem is that of course Everyone has a different level of minimal privacy, sense of minimal privacy and this get things a little bit more complicated. So um from from builder perspective then instead maybe well the aside of one um one potential um how to say it um aside of the fact that uh if you are building with a privacy preserving mindset of course privacy and um uh compliance should be part of your vision as a corporate as a project as a for development.
uh this imply the adoption of a set of features many some of them I already mentioned I don't I don't want to sponsor one instead of others right but there are different cryptographic features which serve the purpose to uh protect the way in which the data is uh controlled in sense manage and processed uh from my solution with all the other network participants in the blockchain ups in uh with end users or down with uh smart contracts and node operators. So I would say that maybe from user perspective is more principle based for builder perspective is more proactive and more operational also because when you're building services you have risk assessment all these kind of operational requirements which are justified by the fact that you are at the end delivering a service for a market. I would say that generally the the difficulties is uh creating a tension between different interests as a builder. So as a builder I have a multiple tension of uh stakeholder needs which I need to address uh money needs uh investor needs uh distribution needs like business development needs and so we the develop the product development cycle is stretched by different direction that sometimes privacy and consumer protection uh get lost. So this is probably one of the the biggest operational issue that I see in the market that probably because I need to deliver these uh upgrades or I need to make this delivery very very soon to outsmart one competitor or to reach a specific KPI.
I delist those kind of features which in long term are taken care about from feedback perspective by the users. So that's probably the the the biggest short mistake that I see in the in the building uh market. Um another one is probably and is more from let's say advice perspective is trying to uh provide assessment and advice not solution with a solution based approach but more with uh legal a regulatory based approach like to say okay the law says that so that's it I in I I think that if the purpose of An advice is to uh provide an answer to a question. We need to start from where the question is which is from which is in the solution. So we start from the solution.
We understand how the solution treats data and based on that we see what's working and what's potentially not. I'm very happy with um uh the fact that privacy has returned a little bit on the top priority of many blockchain networks. Uh because for some times I think the need of building and developing have overcome the need of for privacy. But now that we are getting to a more mature stage of general adoption of the technology, people are still realizing that and at the end what we post on chain is fully visible and so we need privacy to address also risk which happens offchain um to foster engagement to prevent people uh misbehavior on chain but also offchain. So I'm really happy that from Ethereum starting and other network are um re have reinforced uh the need for privacy as one of the core feature and public good for network operations and development.
That's
uh one advice that I would do to everyone is to take maybe privacy as a principle as a reference but be be flexible because the moment you take it in a very strict way you are um either enter into conflict even with regulatory parameters or with your willing to build something [Music]
Automatic transcript — names and jargon may be misspelled.