In the current connected world - Websites, Mobile Apps, IoT Devices collect a large volume of users' personally identifiable activity data. These collected data is used for varied purposes of analytics, marketing, personalization of services, etc. Data is assimilated through site cookies, tracking device IDs, embedded JavaScript, Pixels, etc. to name a few. Many of these tracking and usage of collected data happens behind the scenes and is not apparent to an average user. Consequently, many Countries and Regions have formulated legislations (e.g., GDPR, EU) - that allow users to be able to control their personal data, be informed and consent to its processing in a comprehensible and user-friendly manner. This paper proposes a protocol and a platform based on Blockchain Technology that enables the transparent processing of personal data throughout its lifecycle from capture, lineage to redaction. The solution intends to help service multiple stakeholders from individual end-users to Data Controllers and Privacy Officers. It intends to offer a holistic and unambiguous view of how and when the data points are captured, accessed, and processed. The framework also envisages how different access control policies might be created and enforced through a public blockchain including real time alerts for privacy data breach.
翻译:在目前连通的世界中——网站、移动应用程序、IoT设备等,收集了大量用户个人可识别的活动数据,这些收集的数据用于分析、销售和服务的个人化等各种目的。数据通过网站饼干、跟踪设备ID、嵌入的 JavaScript、像素等等将数据同化为几个例子。许多对所收集数据的追踪和使用发生在幕后,一般用户并不明显。因此,许多国家和地区制定了立法(例如,GDPR、EU),使用户能够控制其个人数据,以易懂和方便用户的方式知情并同意其处理。本文件还提出了一个协议和平台,以链式技术为基础,使个人数据在整个生命周期从捕捉、线状到重新行动都能透明处理。解决方案旨在为各个终端用户到数据管理员和隐私官员的多个利益攸关方提供服务。它打算对数据点如何被采集、访问和处理以及何时被采集、访问和处理提供整体和明确的观点。这个框架还设想了如何通过真实时间链建立不同的访问控制安全,包括实施安全链。