TECHNICAL AND LEGAL ASPECTS OF DATABASE'S SECURITY IN THE LIGHT OF IMPLEMENTATION OF GENERAL DATA PROTECTION REGULATION

被引:0
作者
Drag, Pawel [1 ]
Szymura, Mateusz [2 ]
机构
[1] Wroclaw Univ Sci & Technol, Dept Control Syst & Mechatron, Wroclaw, Poland
[2] Univ Wroclaw, Fac Law Adm & Econ, Wroclaw, Poland
来源
CBU INTERNATIONAL CONFERENCE PROCEEDINGS 2018: INNOVATIONS IN SCIENCE AND EDUCATION | 2018年 / 6卷
关键词
Data Protection Regulation; Database; Security; ANALYTICS;
D O I
10.12955/cbup.v6.1294
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
In the modern era, information is not only a valuable commodity, but also a potential source of threat, especially when it comes to personal data. The implementation of the General Data Protection Regulation seeks to unify regulations and safeguards in a same manner across the EU. The following paper surveys how the legal aspects of GDPR influence the existing technical framework of databases containing personal data. In this research we want to show if the already existing technical infrastructure and safeguards implemented in databases containing personal data are sufficient and if not, if implementing new ways of protecting of data will require creating entire new system of databases or only changing of existing framework. Therefore, we combine an analysis of legal texts with a technical analysis of existing and newly implemented safeguards. While the GDPR doesn't answer what safeguards should be implemented (in the spirit of technological neutrality), the notion of pseudonymisation of the data is strongly advocated through the Regulation. In our paper we tried to show the algorithm, which create a pseudonymisation function that can change personal data into generic data with the possibility to reverse that process ad utilise data after de-pseudonymisation. Implementing safeguards based on the following function create a more safe environment for data safekeeping, while give nearly immediate access to data for authorised person, who can reverse pseudonymisation and transform generic data once more into personal data.
引用
收藏
页码:1056 / 1061
页数:6
相关论文
共 9 条
[1]   Privacy-aware Big Data Analytics as a service for public health policies in smart cities [J].
Anisetti, Marco ;
Ardagna, Claudio ;
Bellandi, Valerio ;
Cremonini, Marco ;
Frati, Fulvio ;
Damiani, Ernesto .
SUSTAINABLE CITIES AND SOCIETY, 2018, 39 :68-77
[2]   A Privacy-Aware Conceptual Model for Handling Personal Data [J].
Antignac, Thibaud ;
Scandariato, Riccardo ;
Schneider, Gerardo .
LEVERAGING APPLICATIONS OF FORMAL METHODS, VERIFICATION AND VALIDATION: FOUNDATIONAL TECHNIQUES, PT I, 2016, 9952 :942-957
[3]   Integrated Data Repository Toolkit (IDRT) A Suite of Programs to Facilitate Health Analytics on Heterogeneous Medical Data [J].
Bauer, C. R. K. D. ;
Ganslandt, T. ;
Baum, B. ;
Christoph, J. ;
Engel, I. ;
Loebe, M. ;
Mate, S. ;
Staeubert, S. ;
Drepper, J. ;
Prokosch, H. -U. ;
Winter, A. ;
Sax, U. .
METHODS OF INFORMATION IN MEDICINE, 2016, 55 (02) :125-135
[4]  
Demir L, 2017, IEEE COMMUNICATIONS, V20, P551, DOI DOI 10.1109/C0MST.2017.2747598
[5]  
Duncan B, 2017, INT J ADV SECURITY, V10, P155
[6]   Viewing the GDPR through a de-identification lens: a tool for compliance, clarification, and consistency [J].
Hintze, Mike .
INTERNATIONAL DATA PRIVACY LAW, 2018, 8 (01) :86-101
[7]  
Hu R, 2017, DATA PROTECTION PRIV
[8]   The trouble with European data protection law [J].
Koops, Bert-Jaap .
INTERNATIONAL DATA PRIVACY LAW, 2014, 4 (04) :250-261
[9]   What Does Anonymization Mean? DataSHIELD and the Need for Consensus on Anonymization Terminology [J].
Wallace, Susan E. .
BIOPRESERVATION AND BIOBANKING, 2016, 14 (03) :224-230