Off-Chain Blockchain Architecture for GDPR Compliant PII Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current blockchain architectures are inadequate for managing personally identifiable information (PII) due to their 'invariability' nature, which conflicts with the General Data Protection Regulation (GDPR) requirements for data deletion and modification, as they do not allow for dynamic changes or user consent-based data handling.
Innovation Solution
An off-chain blockchain architecture is proposed that uses both a local database and a distributed ledger, where PII is stored in the database and its hash is stored on the blockchain, allowing for user consent-based data sharing, deletion, and modification, with a consensus mechanism ensuring compliance with GDPR.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PII is stored in blockchain using traditional architecture, then data immutability and security are improved, but ability to delete or modify data according to GDPR is lost
Solution Approach 1:
The patent divides data into two categories: PII (personally identifiable information) that requires deletion capability and is stored in traditional databases, and non-PII data that benefits from blockchain immutability. This segmentation allows each type of data to be stored in the most appropriate system, resolving the contradiction between security/immutability and deletion capability.
Solution Approach 2:
The patent introduces a hybrid architecture that acts as an intermediary between blockchain and traditional databases. This intermediary layer manages data placement, consent tracking, and deletion operations, allowing the system to maintain both blockchain security benefits and GDPR compliance for PII deletion.
2Productivity
If all user data is collected and stored for business analysis, then business value and user profiling capability are improved, but user privacy control and data security are worsened
Solution Approach 1:
The patent implements dynamic consent management where users can control their data sharing preferences at different times. The system adapts to user choices by dynamically adjusting what data is collected and shared with third parties, allowing business value extraction while respecting user privacy control.
Solution Approach 2:
The patent establishes feedback mechanisms where users are notified about data collection and sharing activities, and can provide or revoke consent. This feedback loop ensures that data processing aligns with user intentions, reducing privacy risks while maintaining business operations.
3Ease of operation
If third party services are used for customer authentication, then service functionality is improved, but data breach risk and security vulnerability are increased
Solution Approach 1:
The patent extracts sensitive PII from third-party service dependencies by implementing decentralized authentication mechanisms. Users maintain control of their authentication data locally, and only necessary non-sensitive information is shared with third parties, reducing the attack surface and data breach risks associated with third-party services.
Data Source
AI summary
Incidents involving confidentiality and vigilance against user privacy invasions raise doubts as to current third-party data collection procedures. Personally identifiable information (PII) is being abused for medical data breaches, identity theft, spam, phishing, cyber spying, etc. A great amount of data is flowing from users to companies for prediction and analysis of data-centric markets. It is thus difficult to track PII flow and genuineness. Blockchain technology, which is an “immutable” distributed ledger, can efficiently track PII exchange, storing, and distribution. In contrast, the EU general data protection regulation (GDPR) in progress claims “a right to forget” and a right “to delete”. However, the present specification proposes an off-chain blockchain architecture using both a local database and a distributed ledger to guarantee a trustable PII life cycle.


