Data protection
What goes on the network — and what never does.
Anchoring a credential does not mean publishing it. The network sees a fingerprint and nothing else; the document and every personal detail in it stay in your systems.
Always stays with you
- Name, address, email
- Student number
- Grades and examination records
- The certificate PDF itself
- All personal data
Goes on the public network
- SHA-256 fingerprint of the document
- Public reference ID (no personal link)
- Event type: issued / revoked
- Identifier of the issuing institution
- Consensus timestamp
The fingerprint proves that a particular document exists and is unaltered — without revealing what it says. That is what makes the anchoring privacy-preserving and GDPR-compatible: no personal data in an immutable store.
By construction, not by policy
Three properties you do not have to take on trust.
No personal data in an immutable store
Nothing that identifies a graduate is ever written to the network, so there is nothing to erase from it later. The right to erasure applies to your own systems, where it can actually be exercised.
Verification leaves no trail
A verifier queries a public node directly. Neither ProofLayer nor the university learns who checked which credential, or when — there is no verification log to subpoena or leak.
Minimum disclosure by default
SD-JWT credentials let the graduate reveal single claims instead of a whole document. An employer can confirm the degree without seeing a date of birth, a grade or a student number.
Trust is not claimed.
It is calculated.
Let us take one degree programme and show you. Four to six weeks, on the test network, with no production data.

Motseki Khoarai
Team Lead, Open Elements