论文标题

GDPR和公共区块链系统之间紧张的系统文献综述

A Systematic Literature Review of the Tension between the GDPR and Public Blockchain Systems

论文作者

Belen-Saglam, Rahime, Altuncu, Enes, Lu, Yang, Li, Shujun

论文摘要

自2008年发明比特币以来,区块链技术一直在迅速增长。公共(无限)区块链系统最常见的区块链系统具有一些独特的功能,这会导致与欧盟的通用数据保护法规(GDPR)和其他类似数据保护法的紧张关系。在本文中,我们向114个研究论文进行了系统文献综述(SLR)的结果,讨论和/或解决了这种紧张关系。众所周知,我们的SLR是对该主题的最全面的评论,对有关此重要主题的相关研究工作进行了更深入和更广泛的分析。我们的结果表明,三种主要问题:(i)行使数据主体的权利(例如“被遗忘的权利”(RTBF))遇到的困难,因为公共区块链的不变性; (ii)在公共区块链数据处理生态系统中识别角色和责任的困难(尤其是在数据控制器和数据处理器的识别上); (iii)由于区块链的分布性质,有关相关法律适用的歧义。我们的工作还使人们对改善公共区块链系统的GDPR合规性的解决方案有了更好的了解。我们的工作不仅可以帮助区块链的研究人员和开发人员,还可以告知政策制定者和法律标记,以考虑如何调和公共区块链系统与数据保护法(GDPR及以后)之间的紧张局势。

The blockchain technology has been rapidly growing since Bitcoin was invented in 2008. The most common type of blockchain systems, public (permisionless) blockchain systems have some unique features that lead to a tension with European Union's General Data Protection Regulation (GDPR) and other similar data protection laws. In this paper, we report the results of a systematic literature review (SLR) on 114 research papers discussing and/or addressing such a tension. To be the best of our know, our SLR is the most comprehensive review of this topic, leading a more in-depth and broader analysis of related research work on this important topic. Our results revealed that three main types of issues: (i) difficulties in exercising data subjects' rights such as the `right to be forgotten' (RTBF) due to the immutable nature of public blockchains; (ii) difficulties in identifying roles and responsibilities in the public blockchain data processing ecosystem (particularly on the identification of data controllers and data processors); (iii) ambiguities regarding the application of the relevant law(s) due to the distributed nature of blockchains. Our work also led to a better understanding of solutions for improving the GDPR compliance of public blockchain systems. Our work can help inform not only blockchain researchers and developers, but also policy makers and law markers to consider how to reconcile the tension between public blockchain systems and data protection laws (the GDPR and beyond).

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源