This document considers the counteracting requirements of privacy and accountability applied to identity management. Based on the requirements of GDPR 1 applied to identity attributes two forms of identity, with differing balances between privacy and accountability, are suggested termed "publicly-recognised identity" and "domain-specific identity". These forms of identity can be further refined using "pseudonymisation" and as described in GDPR. This leads to the different forms of identity on the spectrum of accountability vs privacy. It is recommended that the privacy and accountability requirements, and hence the appropriate form of identity, is considered in designing an identification scheme, and in the adoption of a scheme by data processing systems. Also, users should be aware of the implications of the form of identity requested by a system so that they can decide whether this is acceptable.
翻译:该文件考虑了对适用于身份管理的隐私和问责制的反制要求,根据适用于身份属性两种身份的GDPR 1的要求,在隐私和问责之间有不同的平衡,建议称为“公开承认的身份”和“特定领域的身份”。这些身份形式可以使用“假名化”和在GDPR中描述的方式进一步完善。这导致问责与隐私之间的不同身份形式。建议在设计身份识别计划时,以及在数据处理系统采用计划时,考虑隐私和问责要求,从而考虑适当的身份形式。此外,用户应了解系统所要求的身份形式的影响,以便他们能够决定这种形式是否可接受。