论文标题

允许区块链的第二层数据治理:隐私管理挑战

Second layer data governance for permissioned blockchains: the privacy management challenge

论文作者

Alves, Paulo Henrique, Frajhof, Isabella Z., Correia, Fernando A., de Souza, Clarisse, Lopes, Helio

论文摘要

数据隐私是互联网时代的一个趋势主题。鉴于如此重要​​的是,为了收集,管理,处理和发布数据而出现了许多挑战。从这个意义上讲,个人数据引起了人们的关注,并且出现了许多法规,例如欧盟的GDPR和巴西的LGPD。该法规模型旨在保护用户的数据免受滥用和泄漏的侵害,并允许用户在需要时要求公司的解释。在大流行状况(例如Covid-19和埃博拉疫情)中,与不同组织之间共享健康数据有关的行动对于发展重大运动以避免大规模感染并减少死亡人数至关重要。但是,数据主体(即用户)应有权要求数据使用,匿名和数据删除的目的。从这个意义上讲,允许的区块链技术是为了授权用户通过由智能合约统治的不可变,统一和分布式数据库获得数据所有权,透明度和安全性的权利。区块链应用中讨论的治理模型通常与第一层治理,即公共和许可模型有关。但是,此讨论太肤浅,并且不涵盖遵守数据法规。因此,为了组织数据所有者与利益相关者(即公司和政府实体)之间的关系,我们基于在允许的区块链中开发了第二层数据治理模型,该模型基于在规定中使用的治理分析框架原则,以保留用户的隐私和职责,以实现的规定分析框架原则。从法律的角度来看,我们基于数据隐私问题的UE GDPR。

Data privacy is a trending topic in the internet era. Given such importance, many challenges emerged in order to collect, manage, process, and publish data. In this sense, personal data have got attention, and many regulations emerged, such as GDPR in the European Union and LGPD in Brazil. This regulation model aims to protect users' data from misusage and leakage and allow users to request an explanation from companies when needed. In pandemic situations, such as the COVID-19 and Ebola outbreak, the action related to sharing health data between different organizations is/ was crucial to develop a significant movement to avoid the massive infection and decrease the number of deaths. However, the data subject, i.e., the users, should have the right to request the purpose of data use, anonymization, and data deletion. In this sense, permissioned blockchain technology emerges to empower users to get their rights providing data ownership, transparency, and security through an immutable, unified, and distributed database ruled by smart contracts. The governance model discussed in blockchain applications is usually regarding the first layer governance, i.e., public and permissioned models. However, this discussion is too superficial, and they do not cover compliance with the data regulations. Therefore, in order to organize the relationship between data owners and the stakeholders, i.e., companies and governmental entities, we developed a second layer data governance model for permissioned blockchains based on the Governance Analytical Framework principles applied in pandemic situations preserving the users' privacy and their duties. From the law perspective, we based our model on the UE GDPR in regard to data privacy concerns.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源