Purpose limitation is an important privacy principle to ensure that personal data may only be used for the declared purposes it was originally collected for. Ensuring compliance with respective privacy regulations like the GDPR, which codify purpose limitation as an obligation, consequently, is a major challenge in real-world enterprise systems. Technical solutions under the umbrella of purpose-based access control (PBAC), however, focus mostly on data being held at-rest in databases, while PBAC for communication and publish-subscribe messaging in particular has received only little attention. In this paper, we argue for PBAC to be also applied to data-in-transit and introduce and study a concrete proof-of-concept implementation, which extends a popular MQTT message broker with purpose limitation. On this basis, purpose limitation as a core privacy principle can be addressed in enterprise IoT and message-driven integration architectures that do not focus on databases but event-driven communication and integration instead.
翻译:目的限制是一个重要的隐私原则,以确保个人数据只能用于最初收集的公开目的; 确保遵守诸如GDPR(将目的限制规定为一项义务)等各自隐私条例,因此,这是实体企业系统的一项重大挑战; 然而,目的访问控制(PBAC)框架下的技术解决办法主要侧重于数据库中处于静止状态的数据,而用于通信和发布订阅信息的PBAC尤其很少受到注意; 在本文件中,我们主张将PBAC也应用于过境数据,并引入和研究具体的概念验证实施,以目的限制扩大广受欢迎的MQT信息经纪人的范围;在此基础上,目的限制作为核心隐私原则,可以在IoT企业中处理,而信息驱动的整合结构则不侧重于数据库,而是以事件驱动的通信和整合。