Llanos, JT;
Carr, M;
Rana, O;
(2023)
Using the blockchain to enable transparent and auditable processing of personal data in cloud- based services: Lessons from the Privacy-Aware Cloud Ecosystems (PACE) project.
Computer Law and Security Review
, Article 105873. 10.1016/j.clsr.2023.105873.
(In press).
Preview |
Text
Carr_Using the blockchain to enable transparent and auditable processing of personal data in cloud- based services_AOP.pdf - Published Version Download (4MB) | Preview |
Abstract
The architecture of cloud-based services is typically opaque and intricate. As a result, data subjects cannot exercise adequate control over their personal data, and overwhelmed data protection authorities must spend their limited resources in costly forensic efforts to ascertain instances of non-compliance. To address these data protection challenges, a group of computer scientists and socio-legal scholars joined forces in the Privacy-Aware Cloud Ecosystems (PACE) project to design a blockchain-based privacy-enhancing technology (PET). This article presents the fruits of this collaboration, highlighting the capabilities and limits of our PET, as well as the challenges we encountered during our interdisciplinary endeavour. In particular, we explore the barriers to interdisciplinary collaboration between law and computer science that we faced, and how these two fields’ different expectations as to what technology can do for data protection law compliance had an impact on the project's development and outcome. We also explore the overstated promises of techno-regulation, and the practical and legal challenges that militate against the implementation of our PET: most industry players have no incentive to deploy it, the transaction costs of running it make it prohibitively expensive, and there are significant clashes between the blockchain's decentralised architecture and GDPR's requirements that hinder its deployability. We share the insights and lessons we learned from our efforts to overcome these challenges, hoping to inform other interdisciplinary projects that are increasingly important to shape a data ecosystem that promotes the protection of our personal data.
Type: | Article |
---|---|
Title: | Using the blockchain to enable transparent and auditable processing of personal data in cloud- based services: Lessons from the Privacy-Aware Cloud Ecosystems (PACE) project |
Open access status: | An open access version is available from UCL Discovery |
DOI: | 10.1016/j.clsr.2023.105873 |
Publisher version: | https://doi.org/10.1016/j.clsr.2023.105873 |
Language: | English |
Additional information: | © 2023 The Authors. Published by Elsevier Ltd. under a Creative Commons license (http://creativecommons.org/licenses/by/4.0/). |
Keywords: | Data protection, Privacy, GDPR, Blockchain, PETData protection-by-design |
UCL classification: | UCL UCL > Provost and Vice Provost Offices > UCL BEAMS UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science > Dept of Computer Science |
URI: | https://discovery-pp.ucl.ac.uk/id/eprint/10180948 |
Archive Staff Only
![]() |
View Item |