Logo des Repositoriums
 

Towards Building GDPR-Friendly Consent Management Systems on Top of Self-Sovereign Identity Ecosystems

dc.contributor.authorSchramm, Julia
dc.contributor.authorEichinger, Tobias
dc.contributor.editorRoßnagel, Heiko
dc.contributor.editorSchunck, Christian H.
dc.contributor.editorSousa, Filipe
dc.date.accessioned2024-06-07T08:59:58Z
dc.date.available2024-06-07T08:59:58Z
dc.date.issued2024
dc.description.abstractConsent is a legal basis that legitimizes the processing of personal data under the General Data Protection Regulation (GDPR). Implementing consent management systems in a GDPR-compliant fashion has proven difficult. A major pain point of current implementations is that users only have insufficient means to prove that they withdrew consent. Controllers can, therefore, plausibly deny having received a notification of consent withdrawal and it is thus at their discretion to continue the processing of personal data against the user’s will. As a remedy, it has been proposed to log consent withdrawal events in blockchains to make them non-repudiable by controllers. This approach is typically at odds with the GDPR’s fundamental principle of Storage Limitation. The issue is that a consent withdrawal event has to permit identification of the user who submitted it, yet only until the controller has received it. However, if they are logged in a blockchain, identification is possible indefinitely, as blockchains are append-only databases that do not facilitate deletion. In the paper at hand, we alleviate this issue and present work in progress on a consent management system in which users (i) give consent by issuing a verifiable credential to a controller and (ii) withdraw consent by revoking it. These two functions are natively provided in Self-Sovereign Identity (SSI) ecosystems.en
dc.identifier.doi10.18420/OID2024_08
dc.identifier.isbn978-3-88579-744-9
dc.identifier.pissn1617-5468
dc.identifier.urihttps://dl.gi.de/handle/20.500.12116/44107
dc.language.isoen
dc.publisherGesellschaft für Informatik e.V.
dc.relation.ispartofOpen Identity Summit 2024
dc.relation.ispartofseriesLecture Notes in Informatics (LNI) - Proceedings, Volume P-350
dc.subjectConsent Management System
dc.subjectUser-centric
dc.subjectSelf-Sovereign Identity
dc.subjectGDPR
dc.subjectIdentity Management System
dc.subjectStorage Limitation
dc.titleTowards Building GDPR-Friendly Consent Management Systems on Top of Self-Sovereign Identity Ecosystemsen
dc.typeText/Conference Paper
gi.citation.endPage102
gi.citation.publisherPlaceBonn
gi.citation.startPage93
gi.conference.date20.-21. June 2024
gi.conference.locationPorto, Portugal
gi.conference.sessiontitleRegular Research Papers

Dateien

Originalbündel
1 - 1 von 1
Vorschaubild nicht verfügbar
Name:
proceedings-08.pdf
Größe:
244.96 KB
Format:
Adobe Portable Document Format