A systematic literature review of the tension between the GDPR and public blockchain systems

被引:18
作者
Belen-Saglam, Rahime [1 ,2 ]
Altuncu, Enes [1 ,2 ]
Lu, Yang [3 ]
Li, Shujun [1 ,2 ]
机构
[1] Univ Kent, Inst Cyber Secur Soc ICSS, Keynes Coll, Canterbury CT2 7NP, England
[2] Univ Kent, Keynes Coll, Sch Comp, Canterbury CT2 7NP, England
[3] St John Univ, Sch Sci Technol & Hlth York, Lord Mayors Walk, York YO31 7EX, England
来源
BLOCKCHAIN-RESEARCH AND APPLICATIONS | 2023年 / 4卷 / 02期
基金
英国工程与自然科学研究理事会;
关键词
Blockchain; Distributed ledgers; Privacy; Data protection law; Legal compliance; GDPR; EU; EEA; UK; DATA PROTECTION;
D O I
10.1016/j.bcra.2023.100129
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Blockchain technology has been rapidly growing since Bitcoin was invented in 2008. The most common type of blockchain system, public (permissionless) blockchain system, has some unique features that lead to a tension with the European Union's General Data Protection Regulation (GDPR) and other similar data protection laws. In this paper, we report the results of a systematic literature review (SLR) on 114 research papers discussing and/or addressing such a tension. To the best of our knowledge, our SLR is the most comprehensive review of this tension, leading to a more in-depth and broader analysis of related research work on this important topic. Our results revealed three main types of issues: (i) difficulties in exercising data subjects' rights such as the 'right to be forgotten' (RTBF) due to the immutable nature of public blockchains; (ii) difficulties in identifying roles and responsibilities in the public blockchain data processing ecosystem (particularly on the identification of data controllers and data processors); and (iii) ambiguities regarding the application of the relevant law(s) due to the distributed nature of blockchains. Our work also led to a better understanding of solutions for improving the GDPR compliance of public blockchain systems. It can help inform not only blockchain researchers and developers but also policymakers and law markers to consider how to reconcile the tension between public blockchain systems and data protection laws (the GDPR and beyond).
引用
收藏
页数:23
相关论文
共 143 条
[1]  
Ahmed Javed, 2020, Advances in Information and Communication. Proceedings of the 2020 Future of Information and Communication Conference (FICC). Advances in Intelligent Systems and Computing (AISC 1129), P113, DOI 10.1007/978-3-030-39445-5_10
[2]   Designing privacy-friendly data repositories: a framework for a blockchain that follows the GDPR [J].
Al-Abdullah, Muhammad ;
Alsmadi, Izzat ;
AlAbdullah, Ruwaida ;
Farkas, Bernie .
DIGITAL POLICY REGULATION AND GOVERNANCE, 2020, 22 (5-6) :389-411
[3]   A Decentralized Personal Data Store based on Ethereum: Towards GDPR Compliance [J].
Alessi, Marco ;
Camillo, Alessio ;
Giangreco, Enza ;
Matera, Marco ;
Pino, Stefano ;
Storelli, Davide .
JOURNAL OF COMMUNICATIONS SOFTWARE AND SYSTEMS, 2019, 15 (02) :79-88
[4]  
Alkouz Akram, 2019, 2019 Sixth HCT Information Technology Trends (ITT), P234, DOI 10.1109/ITT48889.2019.9075126
[5]  
[Anonymous], 2014, ART 29 DAT PROT WORK
[6]  
[Anonymous], 2018, P 15 INT JOINT C E B, DOI DOI 10.5220/0006911005720577
[7]  
Antonopoulos A.M., 2014, Mastering Bitcoin: Unlocking Digital Cryptocurrencies, V1st
[8]  
Arisi M, 2020, BIOLAW J, P477
[9]   Redactable Blockchain - or - Rewriting History in Bitcoin and Friends [J].
Ateniese, Giuseppe ;
Magri, Bernardo ;
Venturi, Daniele ;
Andrade, Ewerton R. .
2017 IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY (EUROS&P), 2017, :111-126
[10]  
Barati M, 2019, P 12 IEEEACM INT C U, P133, DOI [10.1145/3344341.3368812, DOI 10.1145/3344341.3368812]