Blockchain-Based Platform for Consent Management ofPersonal Data Processing in the IoT Ecosystem

Rantos, Konstantinos ; Drosatos, George ; Kritsas, Antonios ; Ilioudis, Christos ; Papanikolaou, Alexandros ; Filippidis, Adam P. (2019-10)

Article

In the Internet of Things (IoT) ecosystem, the volume of data generated by devices in the user’s environment is continuallyincreasing and becoming of particular value. In such an environment the average user is bound to face considerable difficultiesin understanding the size and scope of his/her collected data. However, the provisions of the European General Data ProtectionRegulation (GDPR) require data subjects to be able to control their personal data, be informed, and consent to its processing in anintelligible manner. This paper proposes ADVOCATE platform, a user-centric solution that allows data subjects to easily manageconsents regarding access to their personal data in the IoT ecosystem. The proposed platform also assists data controllers to meetGDPR requirements, such as informing data subjects in a transparent and unambiguous manner about the data they will manage,the processing purposes, and periods. The integrity of personal data processing consents and the immutable versioning control ofthem are protected by a blockchain infrastructure. Finally, the paper provides a prototype implementation of the proposed platformthat supports the main consents management functionality.

Collections:
Copyright © 2019 Konstantinos Rantos et al
Except where otherwise noted, this item's license is described as Copyright © 2019 Konstantinos Rantos et al