Bitcoin and the GDPR: Allocating responsibility in distributed networks

被引:16
作者
Buocz, Thomas [1 ]
Ehrke-Rabel, Tina [2 ]
Hoedl, Elisabeth [3 ]
Eisenberger, Iris [1 ]
机构
[1] Univ Nat Resources & Life Sci, Inst Law, Dept Econ & Social Sci, Feistmantelstr 4, A-1180 Vienna, Austria
[2] Karl Franzens Univ Graz, Dept Fiscal Law, Univ Str 15-B2, A-8010 Graz, Austria
[3] Ubifacts EU Social Legal & Sci Trends, Petersgasse 25a, A-8010 Graz, Austria
关键词
Bitcoin; Blockchain; Distributed networks; General Data Protection Regulation; Legal responsibility; Data protection; Personal data; GENERAL-DATA-PROTECTION;
D O I
10.1016/j.clsr.2018.12.003
中图分类号
D9 [法律]; DF [法律];
学科分类号
0301 ;
摘要
This article uses the example of the cryptocurrency Bitcoin and the General Data Protection Regulation (GDPR) to show how distributed networks challenge existing legal mechanisms of allocating responsibility. The Bitcoin network stores personal data by automated means. Furthermore, full nodes qualify as establishments and the network offers a service to citizens in the EU. The data processing within the Bitcoin network therefore falls into the material and territorial scope of the GDPR. To protect data subjects, the GDPR allocates responsibility to the controller, who determines the 'how' and the 'why' of the data processing. However, the distributed structure of the Bitcoin network blurs the lines between actors who are responsible and actors who are worth protecting. Neither the Bitcoin users running lightweight nodes or full nodes nor the miners determine the 'how' and the 'why' of the data processing. They carry out their network activities according to the Bitcoin protocol, which can only be adopted and enforced by a collective of full nodes and miners. Members of this collective are joint controllers under Article 26 GDPR, which obliges them to clearly and transparently determine their respective responsibilities for compliance with the GDPR. However, this mechanism fails because of the very structure it aims to eliminate. Therefore, a solution to allocating responsibility for data protection in distributed networks lies outside the GDPR. (C) 2019 Thomas Buocz, Tina Ehrke-Rabel, Elisabeth Hodl, Iris Eisenberger. Published by Elsevier Ltd. All rights reserved.
引用
收藏
页码:182 / 198
页数:17
相关论文
共 94 条
[1]  
Androulaki E., 2013, LECT NOTES COMPUTER, V7859
[2]  
[Anonymous], 2016, European Data Protection Law Review
[3]  
[Anonymous], 1999, CODE AND OTHER LAWS OF CYBERSPACE
[4]  
[Anonymous], MIT TECHNOLOGY REV
[5]  
[Anonymous], INTERNET POLICY REV
[6]  
Apodaca Rich, 2017, BITZUMA 0928
[7]  
Atik J., 2018, STANFORD J BLOCKCHAI, V1
[8]  
Baran P., 1964, On distributed communications: I. Introduction to distributed communications networks in Memorandum RM-3420-PR, P1
[9]  
Bartoletti Massimo, 2017, Financial Cryptography and Data Security. FC 2017 International Workshops WAHC, BITCOIN, VOTING, WTSC, and TA. Revised Selected Papers: LNCS 10323, P218, DOI 10.1007/978-3-319-70278-0_14
[10]  
Berberich Matthias, 2016, EUR PROT L REV, V2, P424