通用数据保护条例
1998年数据保护法
计算机科学
服务提供商
个人可识别信息
计算机安全
互联网隐私
欧洲联盟
信息隐私
资料保护方针
数据管理
订单(交换)
议会
服务(商务)
数据泄露
业务
数据库
欧盟法
法学
政治
经济政策
政治学
营销
财务
作者
Cristòfol Daudén-Esmel,Jordi Castellà‐Roca,Alexandre Viejo
标识
DOI:10.1016/j.comcom.2023.11.017
摘要
New digital technologies generate large amounts of information. This data is processed by Service Providers in order to improve and develop new services and products, but also to fund themselves. However, processing personal data may result in the extraction of sensitive information, which, in turn, may lead to jeopardizing the users' privacy. To mitigate this significant risk, the European Parliament and Council of the European Union elaborated the General Data Protection Regulation (GDPR). This regulation forces Service Providers to obtain Data Subjects' explicit consent prior to collecting and processing their personal data. Nevertheless, the GDPR's legislative text does not define how Service Providers must transparently demonstrate that they already have these consents. Moreover, most individuals do not know the rights they have over their personal data, neither does this regulation provide them with efficient methods to be aware of what third parties are doing with such data. In order to address this situation, we propose a lightweight blockchain-based GDPR-compliant personal data management platform. The new solution provides public access to immutable evidences that reflect the reached agreements between Data Subjects and Service Providers. In this way, Service Providers can effectively demonstrate that they are fulfilling the regulation, and Data Subjects are able to control and manage their personal data according to their legitimate rights. We have implemented the new system, and we have performed a detailed study which includes: GDPR-compliance, provided functionality, security and privacy issues, and the cost in terms of gas and US dollars of the different operations to be run on the blockchain.
科研通智能强力驱动
Strongly Powered by AbleSci AI