Employee data can be used to facilitate work, but their misusage may pose risks for individuals. Inverse transparency therefore aims to track all usages of personal data, allowing individuals to monitor them to ensure accountability for potential misusage. This necessitates a trusted log to establish an agreed-upon and non-repudiable timeline of events. The unique properties of blockchain facilitate this by providing immutability and availability. For power asymmetric environments such as the workplace, permissionless blockchain is especially beneficial as no trusted third party is required. Yet, two issues remain: (1) In a decentralized environment, no arbiter can facilitate and attest to data exchanges. Simple peer-to-peer sharing of data, conversely, lacks the required non-repudiation. (2) With data governed by privacy legislation such as the GDPR, the core advantage of immutability becomes a liability. After a rightful request, an individual's personal data need to be rectified or deleted, which is impossible in an immutable blockchain. To solve these issues, we present Kovacs, a decentralized data exchange and usage logging system for inverse transparency built on blockchain. Its new-usage protocol ensures non-repudiation, and therefore accountability, for inverse transparency. Its one-time pseudonym generation algorithm guarantees unlinkability and enables proof of ownership, which allows data subjects to exercise their legal rights regarding their personal data. With our implementation, we show the viability of our solution. The decentralized communication impacts performance and scalability, but exchange duration and storage size are still reasonable. More importantly, the provided information security meets high requirements. We conclude that Kovacs realizes decentralized inverse transparency through secure and GDPR-compliant use of permissionless blockchain.
翻译:员工数据可用于促进工作,但其错误使用可能对个人构成风险。因此,逆向透明旨在跟踪个人数据的所有使用情况,允许个人监控它们以确保对潜在错误使用的问责。这需要一个可信日志来建立一个经过商定且不可否认的时间线。区块链的独特特性通过提供不可变性和可用性来实现这一点。对于强势不对称环境,如工作场所,无需信任的第三方,开放式区块链特别有利。但是,仍存在两个问题:(1)在分散环境中,没有仲裁者可以促进和证明数据交换。相反,简单的点对点数据共享缺乏所需的不可否认性。 (2)由GDPR等隐私法规管理的数据,不可变性的核心优势成为一项责任。在合理的请求之后,个人的个人数据需要得到纠正或删除,在不可变的区块链中是不可能的。为了解决这些问题,我们提出了科瓦奇(Kovacs),这是一种基于区块链的去中心化数据交换和使用日志系统,逆向透明度。其新用途协议确保了逆向透明度的不可否认性和因此问责制。其一次性伪名生成算法保证了不可链接性并启用所有权证明,使数据主体能够行使其个人数据相关的法律权利。通过我们的实施,我们展示了我们解决方案的可行性。分散通信影响性能和可伸缩性,但交换持续时间和存储大小仍然合理。更重要的是,提供的信息安全符合高要求。我们得出结论,科瓦奇通过对开放式区块链的安全和符合GDPR的使用,实现了去中心化的逆向透明度。