A systematic literature review of the tension between the GDPR and public blockchain systems

被引:18
作者
Belen-Saglam, Rahime [1 ,2 ]
Altuncu, Enes [1 ,2 ]
Lu, Yang [3 ]
Li, Shujun [1 ,2 ]
机构
[1] Univ Kent, Inst Cyber Secur Soc ICSS, Keynes Coll, Canterbury CT2 7NP, England
[2] Univ Kent, Keynes Coll, Sch Comp, Canterbury CT2 7NP, England
[3] St John Univ, Sch Sci Technol & Hlth York, Lord Mayors Walk, York YO31 7EX, England
来源
BLOCKCHAIN-RESEARCH AND APPLICATIONS | 2023年 / 4卷 / 02期
基金
英国工程与自然科学研究理事会;
关键词
Blockchain; Distributed ledgers; Privacy; Data protection law; Legal compliance; GDPR; EU; EEA; UK; DATA PROTECTION;
D O I
10.1016/j.bcra.2023.100129
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Blockchain technology has been rapidly growing since Bitcoin was invented in 2008. The most common type of blockchain system, public (permissionless) blockchain system, has some unique features that lead to a tension with the European Union's General Data Protection Regulation (GDPR) and other similar data protection laws. In this paper, we report the results of a systematic literature review (SLR) on 114 research papers discussing and/or addressing such a tension. To the best of our knowledge, our SLR is the most comprehensive review of this tension, leading to a more in-depth and broader analysis of related research work on this important topic. Our results revealed three main types of issues: (i) difficulties in exercising data subjects' rights such as the 'right to be forgotten' (RTBF) due to the immutable nature of public blockchains; (ii) difficulties in identifying roles and responsibilities in the public blockchain data processing ecosystem (particularly on the identification of data controllers and data processors); and (iii) ambiguities regarding the application of the relevant law(s) due to the distributed nature of blockchains. Our work also led to a better understanding of solutions for improving the GDPR compliance of public blockchain systems. It can help inform not only blockchain researchers and developers but also policymakers and law markers to consider how to reconcile the tension between public blockchain systems and data protection laws (the GDPR and beyond).
引用
收藏
页数:23
相关论文
共 143 条
[91]  
Moerel L, 2018, EUR REV PRIV LAW, V26, P825
[92]  
Moher D, 2009, PLOS MED, V6, DOI [10.1371/journal.pmed.1000097, 10.1016/j.ijsu.2010.02.007, 10.1136/bmj.b2535, 10.1136/bmj.i4086, 10.1136/bmj.b2700, 10.1186/2046-4053-4-1, 10.1016/j.ijsu.2010.07.299]
[93]   Design principles for constructing GDPR-compliant blockchain solutions [J].
Molina, Fentanda ;
Betarte, Gustavo ;
Luna, Carlos .
2021 IEEE/ACM 4TH INTERNATIONAL WORKSHOP ON EMERGING TRENDS IN SOFTWARE ENGINEERING FOR BLOCKCHAIN (WETSEB 2021), 2021, :1-8
[94]  
Molina F, 2020, Arxiv, DOI [arXiv:2010.12980, DOI 10.1109/I2CT54291.2022.9824282, 10.48550/arxiv.2010.12980]
[95]  
Moslavac B., 2020, MICA ESCOLA SUPERIOR, V12, P149
[96]  
Naik N., 2020, P 2020 7 INT C BEH S, P1, DOI [10.1109/BESC51023.2020.9348298, DOI 10.1109/BESC51023.2020.9348298]
[97]  
Nakamoto S., 2008, Bitcoin: A peer-to-peer electronic cash system
[98]   Blockchain-based Identity Management and Data Usage Control (Extended Abstract) [J].
Neisse, Ricardo ;
Steri, Gary ;
Fovino, Igor Nai .
PRIVACY AND IDENTITY MANAGEMENT: THE SMART REVOLUTION, 2018, 526 :237-239
[99]   A Blockchain-based Approach for Data Accountability and Provenance Tracking [J].
Neisse, Ricardo ;
Steri, Gary ;
Nai-Fovino, Igor .
PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2017), 2017,
[100]   Chronicle of a Clash Foretold: Blockchains and the GDPR's Right to Erasure [J].
Pagallo, Ugo ;
Bassi, Eleonora ;
Crepaldi, Marco ;
Durante, Massimo .
LEGAL KNOWLEDGE AND INFORMATION SYSTEMS (JURIX 2018), 2018, 313 :81-90