GDPR-Compliant Personal Data Management: A Blockchain-Based Solution

被引:161
|
作者
Nguyen Binh Truong [1 ]
Sun, Kai [1 ]
Lee, Gyu Myoung [2 ]
Guo, Yike [1 ]
机构
[1] Imperial Coll London, Data Sci Inst, Dept Comp, London SW7 2AZ, England
[2] Liverpool John Moores Univ, Dept Comp Sci, Liverpool L3 3AF, Merseyside, England
关键词
General Data Protection Regulation; Blockchain; Distributed databases; Bitcoin; Smart contracts; data management; GDPR; personal data; smart contract;
D O I
10.1109/TIFS.2019.2948287
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The General Data Protection Regulation (GDPR) gives control of personal data back to the owners by appointing higher requirements and obligations on service providers who manage and process personal data. As the verification of GDPR-compliance, handled by a supervisory authority, is irregularly conducted; it is challenging to be certified that a service provider has been continuously adhering to the GDPR. Furthermore, it is beyond the data owner's capability to perceive whether a service provider complies with the GDPR and effectively protects her personal data. This motivates us to envision a design concept for developing a GDPR-compliant personal data management platform leveraging the emerging blockchain and smart contract technologies. The goals of the platform are to provide decentralised mechanisms to both service providers and data owners for processing personal data; meanwhile, empower data provenance and transparency by leveraging advanced features of the blockchain technology. The platform enables data owners to impose data usage consent, ensures only designated parties can process personal data, and logs all data activities in an immutable distributed ledger using smart contract and cryptography techniques. By honestly participating in the platform, a service provider can be endorsed by the blockchain network that it is fully GDPR-compliant; otherwise, any violation is immutably recorded and is easily figured out by associated parties. We then demonstrate the feasibility and efficiency of the proposed design concept by developing a profile management platform implemented on top of the Hyperledger Fabric permissioned blockchain framework, following by valuable analysis and discussion.
引用
收藏
页码:1746 / 1761
页数:16
相关论文
共 50 条
  • [11] GDPR-Compliant Use of Blockchain for Secure Usage Logs
    Zieglmeier, Valentin
    Daiqui, Gabriel Loyola
    [J]. PROCEEDINGS OF EVALUATION AND ASSESSMENT IN SOFTWARE ENGINEERING (EASE 2021), 2021, : 313 - 320
  • [12] Data cart - designing a tool for the GDPR-compliant handling of personal data by employees
    Tolsdorf, Jan
    Dehling, Florian
    Iacono, Luigi Lo
    [J]. BEHAVIOUR & INFORMATION TECHNOLOGY, 2022, 41 (10) : 2070 - 2105
  • [13] Blockchain-based Personal Data Management: From Fiction to Solution
    Truong, Nguyen B.
    Sun, Kai
    Guo, Yike
    [J]. 2019 IEEE 18TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA), 2019, : 33 - 40
  • [14] GDPR-Compliant Data Processing: Practical Considerations
    Almeida, Joao
    da Cunha, Paulo Rupino
    Pereira, Alexandre Dias
    [J]. INFORMATION SYSTEMS (EMCIS 2021), 2022, 437 : 505 - 514
  • [15] AMNESIA: A Technical Solution towards GDPR-compliant Machine Learning
    Stach, Christoph
    Giebler, Corinna
    Wagner, Manuela
    Weber, Christian
    Mitschang, Bernhard
    [J]. ICISSP: PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2020, : 21 - 32
  • [16] GDPR Compliant Consent Driven Data Protection in Online Social Networks: A Blockchain-Based Approach
    Ahmed, Javed
    Yildirim, Sule
    Nowostaki, Mariusz
    Ramachandra, Raghvendra
    Elezaj, Ogerta
    Abomohara, Mohamad
    [J]. 2020 3RD INTERNATIONAL CONFERENCE ON INFORMATION AND COMPUTER TECHNOLOGIES (ICICT 2020), 2020, : 307 - 312
  • [17] Application of Blockchain in Education: GDPR-Compliant and Scalable Certification and Verification of Academic Information
    Delgado-von-Eitzen, Christian
    Anido-Rifon, Luis
    Fernandez-Iglesias, Manuel J.
    [J]. APPLIED SCIENCES-BASEL, 2021, 11 (10):
  • [18] Towards GDPR-compliant data processing in modern SIEM systems
    Menges, Florian
    Latzo, Tobias
    Vielberth, Manfred
    Sobola, Sabine
    Poehls, Henrich C.
    Taubmann, Benjamin
    Koestler, Johannes
    Puchta, Alexander
    Freiling, Felix
    Reiser, Hans P.
    Pernul, Guenther
    [J]. COMPUTERS & SECURITY, 2021, 103 (103)
  • [19] Implementing and evaluating a GDPR-compliant open-source SIEM solution
    Vazao, Ana Paula
    Santos, Leonel
    Costa, Rogerio Luis de C.
    Rabadao, Carlos
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2023, 75
  • [20] Designing a GDPR compliant blockchain-based IoV distributed information tracking system
    Campanile, Lelio
    Iacono, Mauro
    Marulli, Fiammetta
    Mastroianni, Michele
    [J]. INFORMATION PROCESSING & MANAGEMENT, 2021, 58 (03)