GDPR-Compliant Personal Data Management: A Blockchain-Based Solution

被引:161
|
作者
Nguyen Binh Truong [1 ]
Sun, Kai [1 ]
Lee, Gyu Myoung [2 ]
Guo, Yike [1 ]
机构
[1] Imperial Coll London, Data Sci Inst, Dept Comp, London SW7 2AZ, England
[2] Liverpool John Moores Univ, Dept Comp Sci, Liverpool L3 3AF, Merseyside, England
关键词
General Data Protection Regulation; Blockchain; Distributed databases; Bitcoin; Smart contracts; data management; GDPR; personal data; smart contract;
D O I
10.1109/TIFS.2019.2948287
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The General Data Protection Regulation (GDPR) gives control of personal data back to the owners by appointing higher requirements and obligations on service providers who manage and process personal data. As the verification of GDPR-compliance, handled by a supervisory authority, is irregularly conducted; it is challenging to be certified that a service provider has been continuously adhering to the GDPR. Furthermore, it is beyond the data owner's capability to perceive whether a service provider complies with the GDPR and effectively protects her personal data. This motivates us to envision a design concept for developing a GDPR-compliant personal data management platform leveraging the emerging blockchain and smart contract technologies. The goals of the platform are to provide decentralised mechanisms to both service providers and data owners for processing personal data; meanwhile, empower data provenance and transparency by leveraging advanced features of the blockchain technology. The platform enables data owners to impose data usage consent, ensures only designated parties can process personal data, and logs all data activities in an immutable distributed ledger using smart contract and cryptography techniques. By honestly participating in the platform, a service provider can be endorsed by the blockchain network that it is fully GDPR-compliant; otherwise, any violation is immutably recorded and is easily figured out by associated parties. We then demonstrate the feasibility and efficiency of the proposed design concept by developing a profile management platform implemented on top of the Hyperledger Fabric permissioned blockchain framework, following by valuable analysis and discussion.
引用
收藏
页码:1746 / 1761
页数:16
相关论文
共 50 条
  • [1] Lightweight Blockchain-based Platform for GDPR-Compliant Personal Data Management
    Dauden-Esmel, Cristofol
    Castella-Roca, Jordi
    Viejo, Alexandre
    Domingo-Ferrer, Josep
    [J]. 2021 IEEE 5TH INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY (ICCSP), 2021, : 68 - 73
  • [2] Blockchain-based access control system for efficient and GDPR-compliant personal data management
    Dauden-Esmel, Cristofol
    Castella-Roca, Jordi
    Viejo, Alexandre
    [J]. COMPUTER COMMUNICATIONS, 2024, 214 : 67 - 87
  • [3] Enabling Integrity and Compliance Auditing in Blockchain-Based GDPR-Compliant Data Management
    Wang, Lipeng
    Guan, Zhi
    Chen, Zhong
    Hu, Mingsheng
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (23) : 20955 - 20968
  • [4] Towards a GDPR-Compliant Blockchain-Based COVID Vaccination Passport
    Haque, A. K. M. Bahalul
    Naqvi, Bilal
    Islam, A. K. M. Najmul
    Hyrynsalmi, Sami
    [J]. APPLIED SCIENCES-BASEL, 2021, 11 (13):
  • [5] Implementing GDPR-Compliant Surveys Using Blockchain
    Goncalves, Ricardo Martins
    da Silva, Miguel Mira
    da Cunha, Paulo
    [J]. FUTURE INTERNET, 2023, 15 (04)
  • [6] GDPR Compliant Data Storage and Sharing in Smart Healthcare System: A Blockchain-Based Solution
    Bai, Pinky
    Kumar, Sushil
    Kumar, Kirshna
    Kaiwartya, Omprakash
    Mahmud, Mufti
    Lloret, Jaime
    [J]. ELECTRONICS, 2022, 11 (20)
  • [7] GDPR-Compliant Data Breach Detection: Leveraging Semantic Web and Blockchain
    Ansar, Kainat
    Ahmed, Mansoor
    Khalid, Muhammad Irfan
    Helfert, Markus
    [J]. GOOD PRACTICES AND NEW PERSPECTIVES IN INFORMATION SYSTEMS AND TECHNOLOGIES, VOL 6, WORLDCIST 2024, 2024, 990 : 3 - 11
  • [8] An Efficient GDPR-Compliant Data Management for IoHT Applications
    Chuang, I-Hsun
    Huang, ShihHao
    Hong, Wan-Hsuan
    Kuo, Yau-Hwang
    [J]. 2023 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS, ICC WORKSHOPS, 2023, : 1950 - 1955
  • [9] GDPR-Compliant Personal Health Record Sharing Mechanism With Redactable Blockchain and Revocable IPFS
    Yeh, Lo-Yao
    Hsu, Wan-Hsin
    Shen, Chih-Ya
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 3342 - 3356
  • [10] GDPR-Compliant Use of Blockchain for Secure Usage Logs
    Zieglmeier, Valentin
    Daiqui, Gabriel Loyola
    [J]. PROCEEDINGS OF EVALUATION AND ASSESSMENT IN SOFTWARE ENGINEERING (EASE 2021), 2021, : 313 - 320