Cargando…

A Smart Contract-Based Dynamic Consent Management System for Personal Data Usage under GDPR

A massive amount of sensitive personal data is being collected and used by scientists, businesses, and governments. This has led to unprecedented threats to privacy rights and the security of personal data. There are few solutions that empower individuals to provide systematic consent agreements on...

Descripción completa

Detalles Bibliográficos
Autores principales: Merlec, Mpyana Mwamba, Lee, Youn Kyu, Hong, Seng-Phil, In, Hoh Peter
Formato: Online Artículo Texto
Lenguaje:English
Publicado: MDPI 2021
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8659597/
https://www.ncbi.nlm.nih.gov/pubmed/34883997
http://dx.doi.org/10.3390/s21237994
_version_ 1784613000960802816
author Merlec, Mpyana Mwamba
Lee, Youn Kyu
Hong, Seng-Phil
In, Hoh Peter
author_facet Merlec, Mpyana Mwamba
Lee, Youn Kyu
Hong, Seng-Phil
In, Hoh Peter
author_sort Merlec, Mpyana Mwamba
collection PubMed
description A massive amount of sensitive personal data is being collected and used by scientists, businesses, and governments. This has led to unprecedented threats to privacy rights and the security of personal data. There are few solutions that empower individuals to provide systematic consent agreements on distinct personal information and control who can collect, access, and use their data for specific purposes and periods. Individuals should be able to delegate consent rights, access consent-related information, and withdraw their given consent at any time. We propose a smart-contract-based dynamic consent management system, backed by blockchain technology, targeting personal data usage under the general data protection regulation. Our user-centric dynamic consent management system allows users to control their personal data collection and consent to its usage throughout the data lifecycle. Transaction history and logs are recorded in a blockchain that provides trusted tamper-proof data provenance, accountability, and traceability. A prototype of our system was designed and implemented to demonstrate its feasibility. The acceptability and reliability of the system were assessed by experimental testing and validation processes. We also analyzed the security and privacy of the system and evaluated its performance.
format Online
Article
Text
id pubmed-8659597
institution National Center for Biotechnology Information
language English
publishDate 2021
publisher MDPI
record_format MEDLINE/PubMed
spelling pubmed-86595972021-12-10 A Smart Contract-Based Dynamic Consent Management System for Personal Data Usage under GDPR Merlec, Mpyana Mwamba Lee, Youn Kyu Hong, Seng-Phil In, Hoh Peter Sensors (Basel) Article A massive amount of sensitive personal data is being collected and used by scientists, businesses, and governments. This has led to unprecedented threats to privacy rights and the security of personal data. There are few solutions that empower individuals to provide systematic consent agreements on distinct personal information and control who can collect, access, and use their data for specific purposes and periods. Individuals should be able to delegate consent rights, access consent-related information, and withdraw their given consent at any time. We propose a smart-contract-based dynamic consent management system, backed by blockchain technology, targeting personal data usage under the general data protection regulation. Our user-centric dynamic consent management system allows users to control their personal data collection and consent to its usage throughout the data lifecycle. Transaction history and logs are recorded in a blockchain that provides trusted tamper-proof data provenance, accountability, and traceability. A prototype of our system was designed and implemented to demonstrate its feasibility. The acceptability and reliability of the system were assessed by experimental testing and validation processes. We also analyzed the security and privacy of the system and evaluated its performance. MDPI 2021-11-30 /pmc/articles/PMC8659597/ /pubmed/34883997 http://dx.doi.org/10.3390/s21237994 Text en © 2021 by the authors. https://creativecommons.org/licenses/by/4.0/Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
spellingShingle Article
Merlec, Mpyana Mwamba
Lee, Youn Kyu
Hong, Seng-Phil
In, Hoh Peter
A Smart Contract-Based Dynamic Consent Management System for Personal Data Usage under GDPR
title A Smart Contract-Based Dynamic Consent Management System for Personal Data Usage under GDPR
title_full A Smart Contract-Based Dynamic Consent Management System for Personal Data Usage under GDPR
title_fullStr A Smart Contract-Based Dynamic Consent Management System for Personal Data Usage under GDPR
title_full_unstemmed A Smart Contract-Based Dynamic Consent Management System for Personal Data Usage under GDPR
title_short A Smart Contract-Based Dynamic Consent Management System for Personal Data Usage under GDPR
title_sort smart contract-based dynamic consent management system for personal data usage under gdpr
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8659597/
https://www.ncbi.nlm.nih.gov/pubmed/34883997
http://dx.doi.org/10.3390/s21237994
work_keys_str_mv AT merlecmpyanamwamba asmartcontractbaseddynamicconsentmanagementsystemforpersonaldatausageundergdpr
AT leeyounkyu asmartcontractbaseddynamicconsentmanagementsystemforpersonaldatausageundergdpr
AT hongsengphil asmartcontractbaseddynamicconsentmanagementsystemforpersonaldatausageundergdpr
AT inhohpeter asmartcontractbaseddynamicconsentmanagementsystemforpersonaldatausageundergdpr
AT merlecmpyanamwamba smartcontractbaseddynamicconsentmanagementsystemforpersonaldatausageundergdpr
AT leeyounkyu smartcontractbaseddynamicconsentmanagementsystemforpersonaldatausageundergdpr
AT hongsengphil smartcontractbaseddynamicconsentmanagementsystemforpersonaldatausageundergdpr
AT inhohpeter smartcontractbaseddynamicconsentmanagementsystemforpersonaldatausageundergdpr