首页> 外文会议>European Symposium on Research in Computer Security >GDPR - Challenges for Reconciling Legal Rules with Technical Reality
【24h】

GDPR - Challenges for Reconciling Legal Rules with Technical Reality

机译:GDPR - 通过技术现实协调法律规则的挑战

获取原文

摘要

The main real impact of the GDPR regulation of the EU should be improving the protection of data concerning physical persons. The sharp GDPR rules have to create a controllable information environment, and to prevent misuse of personal data. The general legal norms of GDPR may, indeed, be regarded as justified and well motivated by the existing threats, however, substantial problems emerge when we attempt to implement GDPR in a real information processing systems setting. This paper aims at bringing attention to some critical challenges related to the GDPR regulation from this technical implementation perspective. Our goal is to alert the community that due to incompatibility between the legal concepts (as understood by a layman) and the technical state-of-the-art, a literal implementation of the GDPR may, in fact, lead to a decrease in the attainable real security level, thus hurting privacy. Further, this situation may create barriers to information processing environments - including in critical evolving areas which are very important for citizens' security and safety. Demonstrating the problem, we provide a (possibly incomplete) list of concrete major clashes between the legal concepts of GDPR and security technologies. We also discuss possible solutions to these problems (from a technology perspective), and review related activities. We hope that this work will encourage people to seek improvements and reforms of GDPR based on realistic privacy needs and computing goals, rather than the current situation where people involved in IT projects, merely attempt to only do things that are justified (and perhaps severely restricted) by GDPR.
机译:欧盟的GDPR规定的主要实际影响应改善有关物理人员的数据保护。锐利的GDPR规则必须创建可控的信息环境,并防止滥用个人数据。实际上,GDPR的一般法律规范可能被视为现行威胁的合理和充分激励,但是当我们试图在真实信息处理系统设置中实施GDPR时出现了大量问题。本文旨在从本技术实施的角度来关注与GDPR规定相关的一些关键挑战。我们的目标是提醒社会,由于法律概念(如理解一个门外汉)之间不兼容的技术状态的最先进的,字面实施GDPR的可能,事实上,导致下降可实现的真正安全级别,从而伤害隐私。此外,这种情况可能会为信息处理环境创造障碍 - 包括对公民安全性和安全性非常重要的临界不断发展的区域。展示问题,我们提供了(可能不完整的)在GDPR和安全技术的法律概念之间的具体重大冲突清单。我们还讨论了对这些问题的可能解决方案(从技术角度来看),并查看相关活动。我们希望,这项工作将鼓励人们基于现实的隐私需要,计算的目标,寻求改进和GDPR的改革,而不是目前的情况来看,人们参与的IT项目,仅仅试图只能做的事情是合理的(也许是受到严格限制)通过gdpr。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号