Formalizing Data Deletion in the Context of the Right to be Forgotten

02/25/2020
by   Sanjam Garg, et al.
0

The right of an individual to request the deletion of their personal data by an entity that might be storing it – referred to as the right to be forgotten – has been explicitly recognized, legislated, and exercised in several jurisdictions across the world, including the European Union, Argentina, and California. However, much of the discussion surrounding this right offers only an intuitive notion of what it means for it to be fulfilled – of what it means for such personal data to be deleted. In this work, we provide a formal definitional framework for the right to be forgotten using tools and paradigms from cryptography. In particular, we provide a precise definition of what could be (or should be) expected from an entity that collects individuals' data when a request is made of it to delete some of this data. Our framework captures several, though not all, relevant aspects of typical systems involved in data processing. While it cannot be viewed as expressing the statements of current laws (especially since these are rather vague in this respect), our work offers technically precise definitions that represent possibilities for what the law could reasonably expect, and alternatives for what future versions of the law could explicitly require. Finally, with the goal of demonstrating the applicability of our framework and definitions, we consider various natural and simple scenarios where the right to be forgotten comes up. For each of these scenarios, we highlight the pitfalls that arise even in genuine attempts at implementing systems offering deletion guarantees, and also describe technological solutions that provably satisfy our definitions. These solutions bring together techniques built by various communities.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
10/30/2019

Forgotten @ Scale: A Practical Solution for Implementing the Right To Be Forgotten in Large-Scale Systems

The European General Data Protection Regulation asserts data subjects' r...
research
03/09/2020

Towards Probabilistic Verification of Machine Unlearning

Right to be forgotten, also known as the right to erasure, is the right ...
research
01/10/2022

Deletion-Compliance in the Absence of Privacy

Garg, Goldwasser and Vasudevan (Eurocrypt 2020) invented the notion of d...
research
07/11/2019

Making AI Forget You: Data Deletion in Machine Learning

Intense recent discussions have focused on how to provide individuals wi...
research
07/08/2023

Right to be Forgotten in the Era of Large Language Models: Implications, Challenges, and Solutions

The Right to be Forgotten (RTBF) was first established as the result of ...
research
08/25/2023

ExD: Explainable Deletion

This paper focuses on a critical yet often overlooked aspect of data in ...

Please sign up or login with your details

Forgot password? Click here to reset