skip to main content
10.1145/3341105.3374066acmconferencesArticle/Chapter ViewAbstractPublication PagessacConference Proceedingsconference-collections
poster

Self-sovereign identity on public blockchains and the GDPR

Authors Info & Claims
Published:30 March 2020Publication History

ABSTRACT

This paper studies three existing technical solutions for a self-sovereign identity on blockchains and analyzes the arising issues related to the General Data Protection Regulation (GDPR) of the European Union (EU). In particular, the paper provides an overview of the existing Sovrin self-sovereign identity on the Hyperledger Indy public permissioned blockchain as well as uPort and Jolocom on the Ethereum public permissionless blockchain. The paper then concludes with a discussion on the GDPR-compliance of the blockchain-based identity concepts.

References

  1. EU Blockchain Observatory and Forum, "Blockchain and Digital Identity," 2019. Available at https://www.eublockchainforum.eu/reports (All links accessed December 2019)Google ScholarGoogle Scholar
  2. F. Zbinden and G. Kondova, "Economic Development in Mexico and the Role of Blockchain," Advances in Economics and Business, vol. 7, no. 1, pp. 55--64, Jan. 2019.Google ScholarGoogle Scholar
  3. D. He et al., "Virtual Currencies and Beyond: Initial Considerations," IMF Staff Discussion Notes, vol. 16, no. 03, p. 1, 2016.Google ScholarGoogle ScholarCross RefCross Ref
  4. EU Blockchain Observatory and Forum, "Blockchain and the GDPR," 2019. Available at https://www.eublockchainforum.eu/reportsGoogle ScholarGoogle Scholar
  5. World Wide Web Consortium (W3C), "Decentralized Identifiers (DIDs) v1.0: Core Data Model and Syntaxes," 2019. Available at https://w3c.github.io/did-core/#did-documentGoogle ScholarGoogle Scholar
  6. World Wide Web Consortium (W3C), "DID Method Registry", 2019. Available at https://w3c-ccg.github.io/did-method-registry/Google ScholarGoogle Scholar
  7. Sovrin Foundation, "Sovrin: A Protocol and Token for Self-Sovereign Identity and Decentralized Trust," 2018. Available at https://sovrin.org/library/sovrin-protocol-and-token-white-paper/Google ScholarGoogle Scholar
  8. A. Tobin, "Sovrin: What Goes on the Ledger?," Evernym White Paper, 2018. Available at https://www.evernym.com/wp-content/uploads/2017/07/What-Goes-On-The-Ledger.pdfGoogle ScholarGoogle Scholar
  9. uPort Specs, 2019. Available at: https://github.com/uport-project/specsGoogle ScholarGoogle Scholar
  10. uPort PKI, 2019. Available at: https://github.com/uport-project/specs/blob/develop/pki/index.mdGoogle ScholarGoogle Scholar
  11. Jolocom, A Decentralized, Open Source Solution for Digital Identity and Access Management, Whitepaper 2.1, December 2019. Available at https://jolocom.io/wp-content/uploads/2019/12/Jolocom-Whitepaper-v2.1-A-Decentralized-Open-Source-Solution-for-Digital-Identity-and-Access-Management.pdfGoogle ScholarGoogle Scholar
  12. General Data Protection Regulation (GDPR), 2016. Available at https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679Google ScholarGoogle Scholar
  13. aepd EDPS, Introduction to the Hash Function as a Personal Data Pseudonymisation Technique, October 2019. Available at https://edps.europa.eu/sites/edp/files/publication/19-10-30_aepd-edps_paper_hash_final_en.pdfGoogle ScholarGoogle Scholar
  14. J. Erbguth, "Datenschutzkonforme Verwendung von Hashwerten auf Blockchains," Multimedia und Recht 2019, no. 10, pp. 654--660.Google ScholarGoogle Scholar
  15. J. Erbguth, "Five Ways to GDPR-Compliant Use of Blockchains," European Data Protection Law Review 2019, no. 3, pp. 427--433.Google ScholarGoogle ScholarCross RefCross Ref
  16. Article 29 Working Party, "Opinion 1/2010 on the concepts of 'controller' and 'processor'," 2010, 00264/10/EN WP 169, 9, endorsed by the European Data Protection Board on 25 May 2018. Available at https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2010/wp169_en.pdfGoogle ScholarGoogle Scholar
  17. B. G. Rauber, "Grzeszick/Rauber: Anwendbarkeit der DS-GVO durch Einschaltung Dritter?," Zeitschrift für Datenschutz, no. 12, pp. 560--564, 2018.Google ScholarGoogle Scholar
  18. CNIL, "Premiers éléments d'analyse de la CNIL - Blockchain," Sep-2018. Available at https://www.cnil.fr/sites/default/files/atoms/files/la_blockchain.pdfGoogle ScholarGoogle Scholar
  19. J. Erbguth and J. Galileo, "Erbguth/Fasching: Wer ist Verantwortlicher einer Bitcoin-Transaktion?," Zeitschrift für Datenschutz, no. 12, pp. 560--565, 201.Google ScholarGoogle Scholar
  20. European Court of Justice, Case C-101/01 Lindqvist (2003) ECR I-12971Google ScholarGoogle Scholar

Index Terms

  1. Self-sovereign identity on public blockchains and the GDPR

    Recommendations

    Comments

    Login options

    Check if you have access through your login credentials or your institution to get full access on this article.

    Sign in
    • Published in

      cover image ACM Conferences
      SAC '20: Proceedings of the 35th Annual ACM Symposium on Applied Computing
      March 2020
      2348 pages
      ISBN:9781450368667
      DOI:10.1145/3341105

      Copyright © 2020 Owner/Author

      Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the Owner/Author.

      Publisher

      Association for Computing Machinery

      New York, NY, United States

      Publication History

      • Published: 30 March 2020

      Check for updates

      Qualifiers

      • poster

      Acceptance Rates

      Overall Acceptance Rate1,650of6,669submissions,25%

    PDF Format

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader