Delegation-Based Personal Data Processing Request Notarization Framework for GDPR Based on Private Blockchain

被引:6
作者
Jung, Sung-Soo [1 ]
Lee, Sang-Joon [2 ]
Euom, Ieck-Chae [2 ]
机构
[1] Res Ctr, DISEC, Daegu 41069, South Korea
[2] Chonnam Natl Univ, Syst Secur Res Ctr, Gwangju 61186, South Korea
来源
APPLIED SCIENCES-BASEL | 2021年 / 11卷 / 22期
关键词
GDPR; personal data; delegation; notarization; blockchain; non-repudiation; OPPORTUNITIES; CHALLENGES; PROTECTION;
D O I
10.3390/app112210574
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
With the growing awareness regarding the importance of personal data protection, many countries have established laws and regulations to ensure data privacy and are supervising managements to comply with them. Although various studies have suggested compliance methods of the general data protection regulation (GDPR) for personal data, no method exists that can ensure the reliability and integrity of the personal data processing request records of a data subject to enable its utilization as a GDPR compliance audit proof for an auditor. In this paper, we propose a delegation-based personal data processing request notarization framework for GDPR using a private blockchain. The proposed notarization framework allows the data subject to delegate requests to process of personal data; the framework makes the requests to the data controller, which performs the processing. The generated data processing request and processing result data are stored in the blockchain ledger and notarized via a trusted institution of the blockchain network. The Hypderledger Fabric implementation of the framework demonstrates the fulfillment of system requirements and feasibility of implementing a GDPR compliance audit for the processing of personal data. The analysis results with comparisons among the related works indicate that the proposed framework provides better reliability and feasibility for the GDPR audit of personal data processing request than extant methods.
引用
收藏
页数:29
相关论文
共 42 条
  • [1] Agarwal Sushant, 2018, Privacy Technologies and Policy. 6th Annual Privacy Forum (APF 2018). Revised Selected Papers: Lecture Notes in Computer Science (LNCS 11079), P131, DOI 10.1007/978-3-030-02547-2_8
  • [2] Blockchain technology in Named Data Networks: A detailed survey
    Asaf, Khizra
    Rehman, Rana Asif
    Kim, Byung-Seo
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2020, 171
  • [3] Privacy-Preserving Solutions for Blockchain: Review and Challenges
    Bernal Bernabe, Jorge
    Luis Canovas, Jose
    Hernandez-Ramos, Jose L.
    Torres Moreno, Rafael
    Skarmeta, Antonio
    [J]. IEEE ACCESS, 2019, 7 : 164908 - 164940
  • [4] Evolutionary optimization: A big data perspective
    Bhattacharya, Maumita
    Islam, Rafiqul
    Abawajy, Jemal
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2016, 59 : 416 - 426
  • [5] Camilo J, 2019, OPEN IDENTITY SUMMIT, V2019, P165
  • [6] Designing a GDPR compliant blockchain-based IoV distributed information tracking system
    Campanile, Lelio
    Iacono, Mauro
    Marulli, Fiammetta
    Mastroianni, Michele
    [J]. INFORMATION PROCESSING & MANAGEMENT, 2021, 58 (03)
  • [7] Carvalho R.M., 2020, SN COMPUT SCI, V1, P217, DOI [10.1007/s42979-020-00218-8, DOI 10.1007/S42979-020-00218-8]
  • [8] Casaleiro R., 2020, J DATA PROTECTION PR, V3, P199
  • [9] Blockchain as a Notarization Service for Data Sharing with Personal Data Store
    Chowdhury, Mohammad Jabed Morshed
    Colman, Alan
    Kabir, Muhammad Ashad
    Han, Jun
    Sarda, Paul
    [J]. 2018 17TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (IEEE TRUSTCOM) / 12TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (IEEE BIGDATASE), 2018, : 1330 - 1335
  • [10] Cimina V, 2021, ERA FORUM, V21, P639, DOI [10.1007/s12027-020-00632-8, DOI 10.1007/S12027-020-00632-8]