The Seven Sins of Personal-Data Processing Systems under GDPR

03/08/2019
by   Supreeth Shastri, et al.
0

In recent years, our society is being plagued by unprecedented levels of privacy and security breaches. To rein in this trend, the European Union, in 2018, introduced a comprehensive legislation called the General Data Protection Regulation (GDPR). In this paper, we review GDPR from a system design perspective, and identify how its regulations conflict with the design, architecture, and operation of modern systems. We illustrate these conflicts via the seven GDPR sins: storing data forever; reusing data indiscriminately; walled gardens and black markets; risk-agnostic data processing; hiding data breaches; making unexplainable decisions; treating security as a secondary goal. Our findings reveal a deep-rooted tussle between GDPR requirements and how modern systems have evolved. We believe that achieving compliance requires comprehensive, grounds up solutions, and anything short would amount to fixing a leaky faucet in a sinking ship.

READ FULL TEXT
research
03/08/2019

How Design, Architecture, and Operation of Modern Systems Conflict with GDPR

In recent years, our society is being plagued by unprecedented levels of...
research
10/02/2019

Understanding and Benchmarking the Impact of GDPR on Database Systems

The General Data Protection Regulation (GDPR) was introduced in Europe t...
research
10/31/2019

GDPR Anti-Patterns: How Design and Operation of Modern Cloud-scale Systems Conflict with GDPR

In recent years, our society is being plagued by unprecedented levels of...
research
01/04/2023

Identifying Personal Data Processing for Code Review

Code review is a critical step in the software development life cycle, w...
research
02/27/2022

Associating eHealth Policies and National Data Privacy Regulations

As electronic data becomes the lifeline of modern society, privacy conce...
research
06/20/2023

Helping Code Reviewer Prioritize: Pinpointing Personal Data and its Processing

Ensuring compliance with the General Data Protection Regulation (GDPR) i...
research
12/08/2018

Achieving Data Truthfulness and Privacy Preservation in Data Markets

As a significant business paradigm, many online information platforms ha...

Please sign up or login with your details

Forgot password? Click here to reset