As a new privacy regulation, the European General Data Privacy Regulation (GDPR) will disrupt the data collection industry which must comply with its clauses regarding transparency, traceability and data governance. In particular, the GDPR confers three important rights to individuals : the right to erasure, the right to data portability and the right to restrict processing. In this paper, we leverage the immutability offered by distributed ledger technologies (DLTs), combined with transparent and reliable validation logic execution via smart contracts, to support GDPR-compliant data collection. We propose a novel data tokenization format, which records consent and provide an audit trail capturing the data processing flows. We show how our data tokenization approach can be combined with a decentralized file storage system (such as IPFS) in order to efficiently store large volumes of data. We also demonstrate how data deletion can be supported by manipulating the data availability mechanism provided by IPFS.We describe a case study for machine learning training, showcasing the ability of our model to comply with GDPR. We implement our model using Solidity, provide an evaluation of our system performance using Ethereum and IPFS, and conduct a sensitivity analysis of the main functions provided by our decentralized application.
| Date | 13 Jul 2020 |
|---|
| Original language | French |
|---|
| Awarding Institution | - École de technologie supérieure
|
|---|
| Supervisor | Kaiwen Zhang (Supervisor) & Talhi Chamseddine (Co-supervisor) |
|---|
Chouchane, A. (Author),
Zhang (Supervisor) & Chamseddine (Co-supervisor),
13 Jul 2020Student thesis: Master's thesis › Master in Engineering: Information Technology Engineering