Skip to content
EVstring

Compliance mapping

From obligation to capability, with honest status.

Each requirement below is mapped to the EVstring capability that supports it and marked available, in development or roadmap. EVstring helps operators meet obligations; responsibility for compliance stays with the operator.

Last reviewed: 2 October 2026 · See also global regulations

Available
Built and working in the current platform.
In development
In the committed build plan, not yet released.
Roadmap
Planned extension; not yet scheduled for release.
  • 20

    Available

  • 1

    In development

  • 4

    Roadmap

Identity, carrier and access tiers

How a battery is identified, how its passport is reached and who sees what.

RequirementLegal basisEVstring capabilityStatus
Unique identifier per batteryEU Art. 77; CN digital ID; IN BPAN (draft); KR battery IDPassport ID scheme (EVS-{MFR}-{YYYY}-{SERIAL}) with one on-chain token per battery; duplicates rejected by the contractAvailable
Data carrier (QR code) resolving to the passportEU Art. 13(6), 77Stable public URL per passport, printable as a QR code; scanned in the mobile appAvailable
Public tierEU Annex XIII(1)Public passport page and API exposing only public fieldsAvailable
Persons with a legitimate interestEU Annex XIII(2)Restricted tier for service centres, repurposers, recyclers, manufacturer and OEM, enforced by role guardsAvailable
Notified bodies, market surveillance, CommissionEU Annex XIII(3)Regulator / auditor tier with read access to restricted and regulator-only recordsAvailable
Standardised QR payloadsEU Art. 78 (open standards)GS1 Digital Link compatible URLsRoadmap

Passport data categories

Annex XIII content and equivalent national data points.

RequirementLegal basisEVstring capabilityStatus
General battery and manufacturer informationEU Annex XIII; CN traceabilityStructured registration record with metadata hash anchored on-chainAvailable
Material composition and hazardous substancesEU Annex XIIIPublic summary fields per product type; detailed composition as restricted, encrypted documentsAvailable
Carbon-footprint declarationEU Art. 7 (pending delegated act)Declared value and lifecycle-stage split on the public passport, backed by a hashed certificateAvailable
Recycled-content sharesEU Art. 8; IN BWMRRecycled cobalt, lithium, nickel and lead shares with supporting documentsAvailable
Performance, durability and state of healthEU Art. 10, 14; UN GTR No. 22; Colorado SB26-003Rated values at registration; SoH trend from telemetry with Merkle proofsAvailable
Supply-chain due-diligence informationEU Arts. 47–53 (from 18 Aug 2027); US UFLPA evidenceRestricted due-diligence document type, encrypted, with on-chain hashAvailable
Dismantling and safety informationEU Annex XIII(2)Restricted documents for repairers and recyclersAvailable
Lifecycle status (original, repurposed, remanufactured, waste)EU Annex XIII; CN Interim MeasuresOn-chain lifecycle state machine with role and state checksAvailable
Linked passport after repurposingEU Art. 77Second-life state on the same passport today; linked child passport plannedRoadmap
Material recovery at end of lifeEU Art. 71, Annex XII; IN BWMRMaterial-recovery records per battery (kg of Li, Co, Ni, Mn, Cu, Al) and regulator totalsAvailable

Data integrity and trust

Making records tamper-evident and actors accountable.

RequirementLegal basisEVstring capabilityStatus
Integrity and security of passport dataEU Art. 78Canonical-JSON SHA-256 hashes anchored on a permissioned ledger; anyone can re-hash and compareAvailable
Document verificationEU Art. 78; due-diligence evidencePublic verify endpoint: a modified file fails verificationAvailable
Telemetry integritySoH evidenceOne Merkle root per time window on-chain; any reading provableAvailable
Only authorised operators act (e.g. licensed recyclers)IN BWMR; EU Art. 70; CN industry conditionsRole-based permissions in API and contract; a licensed-recycler verifiable credential gates recycling, and revoking it blocks the action at onceAvailable
Audit trail of actions and accessEU Art. 77; IN BWMR recordsImmutable on-chain event history plus an audit log of user actions in the databaseAvailable

Retention, availability and portability

Keeping records available for as long as the law and the business require.

RequirementLegal basisEVstring capabilityStatus
Passport availability over the battery lifeEU Art. 77–78Ledger is the source of truth; the database can be rebuilt by indexer replayAvailable
Resilience to a single operator failingEU Art. 78 (decentralised storage permitted)Multi-validator permissioned network operated by consortium members (one validator in the pilot environment today)Roadmap
Configurable retention of personal dataGDPR Art. 5(1)(e); DPDP Act s. 8(7)Account deletion on request; retention schedules for audit logs set per deploymentIn development
Export in machine-readable formEU Art. 78; regulator reportingDocumented REST API (OpenAPI); report exports for EPR returnsRoadmap

Data protection

Personal data never goes on-chain

Ledgers are immutable; privacy laws give people rights to correction and erasure. EVstring resolves the tension by design: the ledger holds hashes and states, personal data stays in stores where it can be changed or destroyed.

Immutable

Permissioned ledger

  • Passport identifiers and lifecycle states
  • Organisation addresses and roles
  • SHA-256 hashes of records and documents
  • Merkle roots of telemetry windows
  • VIN only as a salted hash

Never: names, emails, phone numbers, addresses, raw documents or raw telemetry.

Erasable

Relational database

  • User accounts and contact details
  • Audit logs of user actions
  • Vehicle identifiers (restricted tier)
  • Searchable mirror of on-chain events

Personal data lives here so it can be corrected, exported and deleted on request.

Crypto-shreddable

Encrypted document storage

  • Restricted documents encrypted with AES-256-GCM
  • One key per document, held outside the store
  • Only the hash and content address go on-chain

Deleting a document’s key renders every copy of the ciphertext unreadable.

EU / EEA · Regulation (EU) 2016/679

GDPR

  • Lawful basis for each purpose (Art. 6); controller–processor contract (Art. 28).
  • Rights to access, rectification, erasure, restriction, portability and objection (Arts. 15–21).
  • Data protection by design and by default (Art. 25); security of processing (Art. 32).
  • Breach notification to the supervisory authority within 72 hours where required (Art. 33).
  • Transfers outside the EEA only with adequacy, SCCs or another Chapter V tool.

Personal data is kept off-chain so erasure and rectification are possible. Customers act as controllers; EVstring acts as processor under a DPA.

India

DPDP Act 2023 and DPDP Rules 2025

  • Processing on consent or for certain legitimate uses; itemised notice in clear language.
  • Data principal rights: information, correction and erasure, grievance redressal and nomination.
  • Consent managers registered with the Data Protection Board (provisions effective November 2026).
  • Reasonable security safeguards and breach intimation to the Board and affected principals.
  • Most obligations apply 18 months after the Rules were notified on 14 November 2025, unless shortened.

Deletion and correction are handled in the database; on-chain records contain no personal data. A grievance contact is published in the privacy policy.

California, United States

CCPA as amended by CPRA

  • Applies to for-profit businesses meeting statutory thresholds, including for B2B and employee data since 1 January 2023.
  • Rights to know, delete, correct, and opt out of sale or sharing; limits on sensitive personal information.
  • Service-provider contracts restricting use of personal information.

EVstring does not sell or share personal information for cross-context behavioural advertising and acts as a service provider to customers.

China · Personal Information Protection Law

PIPL

  • Legal basis such as consent or contract necessity; separate consent for certain processing.
  • Personal information protection impact assessments for higher-risk processing.
  • Cross-border transfers via CAC security assessment, standard contract or certification, unless exempt.

Region-configurable deployment allows data generated in China to be stored in China; on-chain data contains no personal information.

How specific data is handled
DataPersonal?Where it lives
Battery specs, composition, carbon, lifecycle statesNoDatabase, with hashes and states on-chain
Organisation addresses and rolesBusiness dataOn-chain
User names, emails, phone numbers, password hashesYesDatabase only (erasable)
Vehicle identification number (VIN)PotentiallyDatabase (restricted tier); on-chain only as a salted hash. Deleting the salt makes the hash unlinkable
Service photos and restricted documentsPossiblyEncrypted storage with per-document keys; hash on-chain; crypto-shredding on erasure
TelemetryCould become personal if linked to a driverNo GPS or location collected; only Merkle roots on-chain

Crypto-shredding of restricted documents is available: destroying a document's key makes every stored copy unreadable, while its on-chain fingerprint remains. The European Data Protection Board has issued guidelines on processing personal data through blockchain technologies (Guidelines 02/2025), which recommend keeping personal data off-chain where possible; EVstring follows that approach.