论文标题
识别问责制与隐私
Identification for Accountability vs Privacy
论文作者
论文摘要
本文档考虑了应用于身份管理的隐私和问责制的抵消要求。根据GDPR应用于身份属性的要求,建议两种形式的身份,在隐私和问责制之间具有不同的平衡,称为“公开认可的身份”和“特定于领域的身份”。这些形式的身份可以使用“假名”进一步完善,如GDPR所述。这导致了在问责制和隐私方面的不同形式的身份。建议在设计标识方案以及通过数据处理系统采用方案时考虑隐私和责任要求及其身份的适当形式。此外,用户应了解系统要求的身份形式的含义,以便他们可以决定是否可以接受。
This document considers the counteracting requirements of privacy and accountability applied to identity management. Based on the requirements of GDPR applied to identity attributes, two forms of identity, with differing balances between privacy and accountability, are suggested, termed "publicly-recognised identity" and "domain-specific identity". These forms of identity can be further refined using "pseudonymisation" and as described in GDPR. This leads to the different forms of identity on the spectrum of accountability vs privacy. It is recommended that the privacy and accountability requirements, and hence the appropriate form of identity, are considered in designing an identification scheme and in the adoption of a scheme by data processing systems. Also, users should be aware of the implications of the form of identity requested by a system, so that they can decide whether this is acceptable.