A position paper on GDPR compliance in sharded blockchains: rehash of old ideas or new interesting challenges?

Narasimha Raghavan Veeraragavan,Kaiwen Zhang
DOI: https://doi.org/10.48550/arXiv.2011.01367
2020-11-03
Abstract:Sharding has emerged as one of the common techniques to address the scalability problems of blockchain systems. To this end, various sharding techniques for blockchain systems have been proposed in the literature. When sharded blockchains process personal data, the data controllers and the data processors associated with the sharded blockchains need to be compliant with the General Data Protection Regulation (GDPR). To this end, this article makes the first attempt to address the following key question: to what extent the existing techniques developed by different communities such as the distributed computing community, the distributed systems community, the database community, identity and access control community and the dependability community can be used by the data controllers and data processors for complying with the GDPR requirements of data subject rights in sharded blockchains? As part of answering this question, this article argues that there is a need for cross-disciplinary research towards finding optimal solutions for implementing the data subject rights in sharded blockchains.
Cryptography and Security,Distributed, Parallel, and Cluster Computing
What problem does this paper attempt to address?
The problem that this paper attempts to solve is the challenges in implementing the rights of individual data subjects stipulated in the General Data Protection Regulation (GDPR) in sharded blockchain systems. Specifically, the paper explores the capabilities and limitations of existing technologies in supporting the "Right of Access" in sharded blockchains, as well as the interdisciplinary research required to meet this right. The paper points out that when sharded blockchains process personal data, data controllers and data processors need to comply with GDPR regulations, but whether the existing technologies in the distributed computing, distributed systems, databases, identity and access control, and reliability communities can meet these requirements remains an open question. The paper also emphasizes several key steps in implementing data subject rights in the sharded blockchain environment, including verifying the identity of the data subject, finding the nodes storing relevant personal data, collecting data from multiple nodes and providing it to the data subject requester, etc., and proposes a series of open research questions in these steps.