How Design, Architecture, and Operation of Modern Systems Conflict with GDPR

How Design, Architecture, and Operation of Modern Systems Conflict with GDPR
复制标题

现代系统的设计、架构和操作如何与 GDPR 发生冲突

DOI:
--
复制
发表时间:
2019
期刊:
arXiv.org
影响因子:
--
通讯作者:
Vijay Chidambaram
Vijay Chidambaram
中科院分区:
--
文献类型:
--
作者:
Supreeth Shastri;Melissa Wasserman;Vijay Chidambaram

文献摘要

被引文献

相似文献

近年来,我们的社会正受到前所未有的隐私和安全漏洞的困扰。为了遏制这一趋势,欧盟在2018年推出了一项名为《通用数据保护条例》(GDPR)的综合立法。在本文中,我们从系统设计的角度回顾GDPR,并确定其法规如何与现代系统的设计,架构和操作相冲突。我们通过七种隐私罪来说明这些冲突:永久存储数据;不加选择地重复使用数据;围墙花园和黑市;风险不可知的数据处理;隐藏数据泄露;做出无法解释的决定;将安全视为次要目标。我们的研究结果揭示了GDPR要求与现代系统如何演变之间根深蒂固的斗争。我们认为,实现合规需要全面的、有根据的解决方案,任何短缺都相当于在燃烧的建筑物中修复一个漏水的水龙头。
In recent years, our society is being plagued by unprecedented levels of privacy and security breaches. To rein in this trend, the European Union, in 2018, introduced a comprehensive legislation called the General Data Protection Regulation (GDPR). In this paper, we review GDPR from a system design perspective, and identify how its regulations conflict with the design, architecture, and operation of modern systems. We illustrate these conflicts via the seven privacy sins: storing data forever; reusing data indiscriminately; walled gardens and black markets; risk-agnostic data processing; hiding data breaches; making unexplainable decisions; treating security as a secondary goal. Our findings reveal a deep-rooted tussle between GDPR requirements and how modern systems have evolved. We believe that achieving compliance requires comprehensive, grounds up solutions, and anything short would amount to fixing a leaky faucet in a burning building.