首页> 外文会议>Annual international conference on the theory and applications of cryptographic techniques >Formalizing Data Deletion in the Context of the Right to Be Forgotten
【24h】

Formalizing Data Deletion in the Context of the Right to Be Forgotten

机译:在被遗忘权的背景下正式删除数据

获取原文

摘要

The right of an individual to request the deletion of their personal data by an entity that might be storing it - referred to as the right to be forgotten - has been explicitly recognized, legislated, and exercised in several jurisdictions across the world, including the European Union, Argentina, and California. However, much of the discussion surrounding this right offers only an intuitive notion of what it means for it to be fulfilled - of what it means for such personal data to be deleted. In this work, we provide a formal definitional framework for the right to be forgotten using tools and paradigms from cryptography. In particular, we provide a precise definition of what could be (or should be) expected from an entity that collects individuals' data when a request is made of it to delete some of this data. Our framework captures most, though not all, relevant aspects of typical systems involved in data processing. While it cannot be viewed as expressing the statements of current laws (especially since these are rather vague in this respect), our work offers technically precise definitions that represent possibilities for what the law could reasonably expect, and alternatives for what future versions of the law could explicitly require. Finally, with the goal of demonstrating the applicability of our framework and definitions, we consider various natural and simple scenarios where the right to be forgotten comes up. For each of these scenarios, we highlight the pitfalls that arise even in genuine attempts at implementing systems offering deletion guarantees, and also describe technological solutions that provably satisfy our definitions. These solutions bring together techniques built by various communities.
机译:在包括欧洲在内的多个司法管辖区中,人们已明确承认,立法并行使了个人要求其可能由存储实体的个人删除其个人数据的权利(称为被遗忘的权利)。联盟,阿根廷和加利福尼亚。但是,围绕此权利的许多讨论仅提供了一个直观的概念,即实现该权利意味着什么-删除此类个人数据意味着什么。在这项工作中,我们为使用密码术中的工具和范例而被遗忘的权利提供了一个正式的定义框架。尤其是,我们提供了一个精确的定义,该定义是在要求删除个人数据的实体收集个人数据时可能(或应该)期望的。我们的框架捕获了数据处理所涉及的典型系统的大部分(尽管不是全部)相关方面。尽管不能将其视为表达当前法律的陈述(特别是因为这方面的陈述含糊不清),但我们的工作提供了技术上精确的定义,这些定义代表了法律可能合理预期的可能性以及未来法律版本的替代方案可以明确要求。最后,为了证明我们的框架和定义的适用性,我们考虑了各种自然而又简单的情况,在这种情况下,人们会忘记被遗忘的权利。对于每种情况,我们都强调即使在真正实施提供删除保证的系统的尝试中也会出现的陷阱,并描述可证明满足我们定义的技术解决方案。这些解决方案汇集了各种社区构建的技术。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号