SlideShare uma empresa Scribd logo
1 de 47
Baixar para ler offline
The impact of
the GDPR on
blockchain & SSI
Silvan Jongerius - Managing Partner
Silvan Jongerius / @silvanjongerius / @techgdpr / silvan@techgdpr.com
This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
SSIMeetup.org
1. Empower global SSI communities
2. Open to everyone interested in SSI
3. All content is shared with CC BY SA
SSIMeetup.org
Alex Preukschat @SSIMeetup @AlexPreukschat
Coordinating Node SSIMeetup.org
https://creativecommons.org/licenses/by-sa/4.0/
SSIMeetup objectives
• Discovery Workshop
• Data Mapping
• GDPR Assessment & Report
• DPO-as-a-Service
• Privacy by Design Consulting
• Staff / Developer Training
GDPR for DeepTech
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
@techgdpr
GDPR for DeepTech
This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
https://www.forbes.com/sites/darrynpollock/2019/01/31/zcash-out-to-prove-privacy-is-key-to-crypto-adoption-with-gdpr-avoiding-use-cases/#
About Privacy
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
European Convention on Human Rights
Article 8.1: Everyone has the right to
respect for his private and family life, his
home and his correspondence.
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Privacy & Information Asymmetry
Corporations
Government
Individuals
Startups
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Facebook 2010:
Privacy is no longer a social norm
This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Facebook 2018:
“Data Privacy”
Facebook 2019:
Researching blockchain identity
This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Giovanni Buttarelli,
European Data
Protection Supervisor
“There might well be a market for personal data, just like
there is, tragically, a market for live human organs, but that
does not mean that we can or should give that market the
blessing of legislation.”
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
The GDPR
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Fines & Risks
@techgdpr
• Up to 20 Million Euro
• Or 4% of annual world wide group turnover
• Whichever is higher
• Disclosure requirements: reputation
• Order to stop processing
This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
1. lawfulness, fairness and transparency
2. purpose limitation
3. data minimisation
4. accuracy
5. storage limitation
6. integrity and confidentiality
7. accountability
Principles (Art 5)
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Risk-based approach
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Scope
• Data of natural persons in the EU
• Personal Data
• Pseudonymised, but not anonymised
• Not: for household use
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Personal Data
@techgdpr
Behavioural Patterns
@techgdpr
• Meta data can re-construct patterns leading to Personal
Data
• Large datasets have a high risk of leaking meta data
• Location data can help constructing whereabouts that
can lead to identification
This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Personal Data Breach
?
‘personal data breach’ means a breach of security
leading to the accidental or unlawful destruction, loss,
alteration, unauthorised disclosure of, or access to,
personal data transmitted, stored or otherwise
processed;
Article 4 (12) GDPR
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Breaches & Notifications
• Risk: Notify authorities within 72h
• High risk: Notify affected subject
(reputational risk)
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Controller/Processor Roles
• Clearly defined roles
• the Controller determines the purposes and means of the
processing of personal data
• the Processor processes personal data on behalf of the
controller
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Legal base for processing
A. Consent
B. Performance of a contract
C. Legal obligation
D. Protect vital interests of subject
E. Task in the public interest/authority
F. Legitimate Interest*
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Valid consent?
@techgdpr
How was it collected?
This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Consent
@techgdpr
• Freely given
• Specific
• Informed
This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Valid Consent: UX
@techgdpr
• Promoted choice
• Bundling
• Illusion of choice
This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Subject (Access) Rights
1.Right of information
2.Right of access
3.Right of erasure
4.Right of rectification
5.Right to data portability
6.Right not to be subjected to automated decision making.
7.Right to object
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Personal data,
blockchain & SSI
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Public Permissionless Public Permissioned
Private Permissionless Private Permissioned
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Controller & Processor in Blockchain
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Right to erasure & rectification
@techgdpr
• Right of erasure (Article 17)
• Right of rectification (Article 16)
This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Encrypting on-chain personal data?
@techgdpr
• May be broken in the future
• Encryption is a ‘technical measure’ not a way to
move it out of scope of the GDPR.
This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
“How about those hashes?”
518c4ae77dda05590f2789ec0d598d119f947001ceacc30ef1cadb8ceef4ebca
Hash Function
Can I store hashes of personal data?
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
SILVAN
JONGERIUS
a8dc5a7432088955c01dd420b5e2a2e17a1fc3e15901f6d76ecddad95a20fa5b
@techgdpr
Passport
This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Guidance
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
https://www.cnil.fr/sites/default/files/atoms/files/blockchain.pdf
@techgdpr
Opportunities
of GDPR in blockchain
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
GDPR compliance tracking
@techgdpr
• Immutable history of events
• Consent given or revoked
• Record of processing activities
This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Alternative Governance Models
@techgdpr
• Clarity on roles
• Contractual way to enforce rights
• Only within Europe
This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Contracted Nodes
@techgdpr
• Transparency
• Control
• Purpose limitation
• Data minimisation
• Storage limitation
This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Self-Sovereign Identity
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Self-sovereign Identity
@techgdpr
• What is stored on-chain and off-chain?
• Who is responsible for personal data?
• On-device personal data may still be in scope of the
GDPR
This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Zero-knowledge proofs
@techgdpr
• Minimised amount of personal data revealed
• High level of control over personal data
• Need-to-know basis
This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
GDPR principles and SSI
@techgdpr
• Transparency
• Control
• Purpose limitation
• Data minimisation
• Storage limitation
This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
GDPR & SSI
@techgdpr
• Powerful tool for privacy protection
• Visionary alignment with GDPR
• Foundation technology
• Both promote the free flow of data
• Layer of trust and autonomy
This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Letter of the law
Spirit of the law?
@techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
Silvan Jongerius / @silvanjongerius / @techgdpr / silvan@techgdpr.com
Thank
You
DPO Service - GDPR Assessment - Privacy by Design
Data Protection Impact Assessment
for Blockchain, AI & IoT
This presentation is released under a Creative Commons license. (CC BY-SA 4.0).

Mais conteúdo relacionado

Mais de SSIMeetup

PolygonID Zero-Knowledge Identity Web2 & Web3
PolygonID Zero-Knowledge Identity Web2 & Web3PolygonID Zero-Knowledge Identity Web2 & Web3
PolygonID Zero-Knowledge Identity Web2 & Web3SSIMeetup
 
Building SSI Products: A Guide for Product Managers
Building SSI Products: A Guide for Product ManagersBuilding SSI Products: A Guide for Product Managers
Building SSI Products: A Guide for Product ManagersSSIMeetup
 
Solving compliance for crypto businesses using Decentralized Identity – Pelle...
Solving compliance for crypto businesses using Decentralized Identity – Pelle...Solving compliance for crypto businesses using Decentralized Identity – Pelle...
Solving compliance for crypto businesses using Decentralized Identity – Pelle...SSIMeetup
 
The Pan-Canadian Trust Framework (PCTF) for SSI
The Pan-Canadian Trust Framework (PCTF) for SSIThe Pan-Canadian Trust Framework (PCTF) for SSI
The Pan-Canadian Trust Framework (PCTF) for SSISSIMeetup
 
Identity-centric interoperability with the Ceramic Protocol
Identity-centric interoperability with the Ceramic ProtocolIdentity-centric interoperability with the Ceramic Protocol
Identity-centric interoperability with the Ceramic ProtocolSSIMeetup
 
The SSI Ecosystem in South Korea
The SSI Ecosystem in South KoreaThe SSI Ecosystem in South Korea
The SSI Ecosystem in South KoreaSSIMeetup
 
Introducing the SSI eIDAS Legal Report – Ignacio Alamillo
Introducing the SSI eIDAS Legal Report – Ignacio AlamilloIntroducing the SSI eIDAS Legal Report – Ignacio Alamillo
Introducing the SSI eIDAS Legal Report – Ignacio AlamilloSSIMeetup
 
Learn about the Trust Over IP (ToIP) stack
Learn about the Trust Over IP (ToIP) stackLearn about the Trust Over IP (ToIP) stack
Learn about the Trust Over IP (ToIP) stackSSIMeetup
 
How to avoid another identity nightmare with SSI? Christopher Allen
How to avoid another identity nightmare with SSI? Christopher AllenHow to avoid another identity nightmare with SSI? Christopher Allen
How to avoid another identity nightmare with SSI? Christopher AllenSSIMeetup
 
Self-Sovereign Identity: Ideology and Architecture with Christopher Allen
Self-Sovereign Identity: Ideology and Architecture with Christopher AllenSelf-Sovereign Identity: Ideology and Architecture with Christopher Allen
Self-Sovereign Identity: Ideology and Architecture with Christopher AllenSSIMeetup
 
eIDAS regulation: anchoring trust in Self-Sovereign Identity systems
eIDAS regulation: anchoring trust in Self-Sovereign Identity systemseIDAS regulation: anchoring trust in Self-Sovereign Identity systems
eIDAS regulation: anchoring trust in Self-Sovereign Identity systemsSSIMeetup
 
Explaining SSI to C-suite executives, and anyone else for that matter
Explaining SSI to C-suite executives, and anyone else for that matterExplaining SSI to C-suite executives, and anyone else for that matter
Explaining SSI to C-suite executives, and anyone else for that matterSSIMeetup
 
Decentralized Identifier (DIDs) fundamentals deep dive
Decentralized Identifier (DIDs) fundamentals deep diveDecentralized Identifier (DIDs) fundamentals deep dive
Decentralized Identifier (DIDs) fundamentals deep diveSSIMeetup
 
The 2nd Official W3C DID Working Group Meeting (The Netherlands)
The 2nd Official W3C DID Working Group Meeting (The Netherlands)The 2nd Official W3C DID Working Group Meeting (The Netherlands)
The 2nd Official W3C DID Working Group Meeting (The Netherlands)SSIMeetup
 
The Hyperledger Indy Public Blockchain Node
The Hyperledger Indy Public Blockchain NodeThe Hyperledger Indy Public Blockchain Node
The Hyperledger Indy Public Blockchain NodeSSIMeetup
 
Peer DIDs: a secure and scalable method for DIDs that’s entirely off-ledger –...
Peer DIDs: a secure and scalable method for DIDs that’s entirely off-ledger –...Peer DIDs: a secure and scalable method for DIDs that’s entirely off-ledger –...
Peer DIDs: a secure and scalable method for DIDs that’s entirely off-ledger –...SSIMeetup
 
Streetcred: Improving the Developer Experience in SSI – Michael Boyd
Streetcred: Improving the Developer Experience in SSI – Michael BoydStreetcred: Improving the Developer Experience in SSI – Michael Boyd
Streetcred: Improving the Developer Experience in SSI – Michael BoydSSIMeetup
 
Blockcerts: The Open Standard for Blockchain Credentials
Blockcerts: The Open Standard for Blockchain CredentialsBlockcerts: The Open Standard for Blockchain Credentials
Blockcerts: The Open Standard for Blockchain CredentialsSSIMeetup
 
Internet Identity Workshop #29 highlights with Drummond Reed
Internet Identity Workshop #29 highlights with Drummond ReedInternet Identity Workshop #29 highlights with Drummond Reed
Internet Identity Workshop #29 highlights with Drummond ReedSSIMeetup
 
Kiva protocol: building the credit bureau of the future using SSI
Kiva protocol: building the credit bureau of the future using SSIKiva protocol: building the credit bureau of the future using SSI
Kiva protocol: building the credit bureau of the future using SSISSIMeetup
 

Mais de SSIMeetup (20)

PolygonID Zero-Knowledge Identity Web2 & Web3
PolygonID Zero-Knowledge Identity Web2 & Web3PolygonID Zero-Knowledge Identity Web2 & Web3
PolygonID Zero-Knowledge Identity Web2 & Web3
 
Building SSI Products: A Guide for Product Managers
Building SSI Products: A Guide for Product ManagersBuilding SSI Products: A Guide for Product Managers
Building SSI Products: A Guide for Product Managers
 
Solving compliance for crypto businesses using Decentralized Identity – Pelle...
Solving compliance for crypto businesses using Decentralized Identity – Pelle...Solving compliance for crypto businesses using Decentralized Identity – Pelle...
Solving compliance for crypto businesses using Decentralized Identity – Pelle...
 
The Pan-Canadian Trust Framework (PCTF) for SSI
The Pan-Canadian Trust Framework (PCTF) for SSIThe Pan-Canadian Trust Framework (PCTF) for SSI
The Pan-Canadian Trust Framework (PCTF) for SSI
 
Identity-centric interoperability with the Ceramic Protocol
Identity-centric interoperability with the Ceramic ProtocolIdentity-centric interoperability with the Ceramic Protocol
Identity-centric interoperability with the Ceramic Protocol
 
The SSI Ecosystem in South Korea
The SSI Ecosystem in South KoreaThe SSI Ecosystem in South Korea
The SSI Ecosystem in South Korea
 
Introducing the SSI eIDAS Legal Report – Ignacio Alamillo
Introducing the SSI eIDAS Legal Report – Ignacio AlamilloIntroducing the SSI eIDAS Legal Report – Ignacio Alamillo
Introducing the SSI eIDAS Legal Report – Ignacio Alamillo
 
Learn about the Trust Over IP (ToIP) stack
Learn about the Trust Over IP (ToIP) stackLearn about the Trust Over IP (ToIP) stack
Learn about the Trust Over IP (ToIP) stack
 
How to avoid another identity nightmare with SSI? Christopher Allen
How to avoid another identity nightmare with SSI? Christopher AllenHow to avoid another identity nightmare with SSI? Christopher Allen
How to avoid another identity nightmare with SSI? Christopher Allen
 
Self-Sovereign Identity: Ideology and Architecture with Christopher Allen
Self-Sovereign Identity: Ideology and Architecture with Christopher AllenSelf-Sovereign Identity: Ideology and Architecture with Christopher Allen
Self-Sovereign Identity: Ideology and Architecture with Christopher Allen
 
eIDAS regulation: anchoring trust in Self-Sovereign Identity systems
eIDAS regulation: anchoring trust in Self-Sovereign Identity systemseIDAS regulation: anchoring trust in Self-Sovereign Identity systems
eIDAS regulation: anchoring trust in Self-Sovereign Identity systems
 
Explaining SSI to C-suite executives, and anyone else for that matter
Explaining SSI to C-suite executives, and anyone else for that matterExplaining SSI to C-suite executives, and anyone else for that matter
Explaining SSI to C-suite executives, and anyone else for that matter
 
Decentralized Identifier (DIDs) fundamentals deep dive
Decentralized Identifier (DIDs) fundamentals deep diveDecentralized Identifier (DIDs) fundamentals deep dive
Decentralized Identifier (DIDs) fundamentals deep dive
 
The 2nd Official W3C DID Working Group Meeting (The Netherlands)
The 2nd Official W3C DID Working Group Meeting (The Netherlands)The 2nd Official W3C DID Working Group Meeting (The Netherlands)
The 2nd Official W3C DID Working Group Meeting (The Netherlands)
 
The Hyperledger Indy Public Blockchain Node
The Hyperledger Indy Public Blockchain NodeThe Hyperledger Indy Public Blockchain Node
The Hyperledger Indy Public Blockchain Node
 
Peer DIDs: a secure and scalable method for DIDs that’s entirely off-ledger –...
Peer DIDs: a secure and scalable method for DIDs that’s entirely off-ledger –...Peer DIDs: a secure and scalable method for DIDs that’s entirely off-ledger –...
Peer DIDs: a secure and scalable method for DIDs that’s entirely off-ledger –...
 
Streetcred: Improving the Developer Experience in SSI – Michael Boyd
Streetcred: Improving the Developer Experience in SSI – Michael BoydStreetcred: Improving the Developer Experience in SSI – Michael Boyd
Streetcred: Improving the Developer Experience in SSI – Michael Boyd
 
Blockcerts: The Open Standard for Blockchain Credentials
Blockcerts: The Open Standard for Blockchain CredentialsBlockcerts: The Open Standard for Blockchain Credentials
Blockcerts: The Open Standard for Blockchain Credentials
 
Internet Identity Workshop #29 highlights with Drummond Reed
Internet Identity Workshop #29 highlights with Drummond ReedInternet Identity Workshop #29 highlights with Drummond Reed
Internet Identity Workshop #29 highlights with Drummond Reed
 
Kiva protocol: building the credit bureau of the future using SSI
Kiva protocol: building the credit bureau of the future using SSIKiva protocol: building the credit bureau of the future using SSI
Kiva protocol: building the credit bureau of the future using SSI
 

Último

On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024APNIC
 
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girl
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call GirlVIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girl
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girladitipandeya
 
horny (9316020077 ) Goa Call Girls Service by VIP Call Girls in Goa
horny (9316020077 ) Goa  Call Girls Service by VIP Call Girls in Goahorny (9316020077 ) Goa  Call Girls Service by VIP Call Girls in Goa
horny (9316020077 ) Goa Call Girls Service by VIP Call Girls in Goasexy call girls service in goa
 
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445ruhi
 
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...SofiyaSharma5
 
Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
Challengers I Told Ya ShirtChallengers I Told Ya Shirt
Challengers I Told Ya ShirtChallengers I Told Ya ShirtChallengers I Told Ya ShirtChallengers I Told Ya Shirt
Challengers I Told Ya ShirtChallengers I Told Ya Shirtrahman018755
 
10.pdfMature Call girls in Dubai +971563133746 Dubai Call girls
10.pdfMature Call girls in Dubai +971563133746 Dubai Call girls10.pdfMature Call girls in Dubai +971563133746 Dubai Call girls
10.pdfMature Call girls in Dubai +971563133746 Dubai Call girlsstephieert
 
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark WebGDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark WebJames Anderson
 
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779Delhi Call girls
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...APNIC
 
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night StandHot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Standkumarajju5765
 
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...Neha Pandey
 
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLLucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLimonikaupta
 
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.soniya singh
 

Último (20)

Call Girls In South Ex 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICE
Call Girls In South Ex 📱  9999965857  🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICECall Girls In South Ex 📱  9999965857  🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICE
Call Girls In South Ex 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICE
 
On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024
 
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girl
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call GirlVIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girl
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girl
 
horny (9316020077 ) Goa Call Girls Service by VIP Call Girls in Goa
horny (9316020077 ) Goa  Call Girls Service by VIP Call Girls in Goahorny (9316020077 ) Goa  Call Girls Service by VIP Call Girls in Goa
horny (9316020077 ) Goa Call Girls Service by VIP Call Girls in Goa
 
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
 
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...
 
Dwarka Sector 26 Call Girls | Delhi | 9999965857 🫦 Vanshika Verma More Our Se...
Dwarka Sector 26 Call Girls | Delhi | 9999965857 🫦 Vanshika Verma More Our Se...Dwarka Sector 26 Call Girls | Delhi | 9999965857 🫦 Vanshika Verma More Our Se...
Dwarka Sector 26 Call Girls | Delhi | 9999965857 🫦 Vanshika Verma More Our Se...
 
Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝
 
Challengers I Told Ya ShirtChallengers I Told Ya Shirt
Challengers I Told Ya ShirtChallengers I Told Ya ShirtChallengers I Told Ya ShirtChallengers I Told Ya Shirt
Challengers I Told Ya ShirtChallengers I Told Ya Shirt
 
10.pdfMature Call girls in Dubai +971563133746 Dubai Call girls
10.pdfMature Call girls in Dubai +971563133746 Dubai Call girls10.pdfMature Call girls in Dubai +971563133746 Dubai Call girls
10.pdfMature Call girls in Dubai +971563133746 Dubai Call girls
 
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
 
Rohini Sector 6 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 6 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 6 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 6 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark WebGDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
 
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
 
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night StandHot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
 
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
 
Call Girls In Noida 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICE
Call Girls In Noida 📱  9999965857  🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICECall Girls In Noida 📱  9999965857  🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICE
Call Girls In Noida 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICE
 
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLLucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
 
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
 

The impact of the GDPR on Blockchain & SSI – Silvan Jongerius

  • 1. The impact of the GDPR on blockchain & SSI Silvan Jongerius - Managing Partner Silvan Jongerius / @silvanjongerius / @techgdpr / silvan@techgdpr.com This presentation is released under a Creative Commons license. (CC BY-SA 4.0). SSIMeetup.org
  • 2. 1. Empower global SSI communities 2. Open to everyone interested in SSI 3. All content is shared with CC BY SA SSIMeetup.org Alex Preukschat @SSIMeetup @AlexPreukschat Coordinating Node SSIMeetup.org https://creativecommons.org/licenses/by-sa/4.0/ SSIMeetup objectives
  • 3. • Discovery Workshop • Data Mapping • GDPR Assessment & Report • DPO-as-a-Service • Privacy by Design Consulting • Staff / Developer Training GDPR for DeepTech @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 4. @techgdpr GDPR for DeepTech This presentation is released under a Creative Commons license. (CC BY-SA 4.0). https://www.forbes.com/sites/darrynpollock/2019/01/31/zcash-out-to-prove-privacy-is-key-to-crypto-adoption-with-gdpr-avoiding-use-cases/#
  • 5.
  • 6. About Privacy @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 7. @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 8. European Convention on Human Rights Article 8.1: Everyone has the right to respect for his private and family life, his home and his correspondence. @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 9. Privacy & Information Asymmetry Corporations Government Individuals Startups @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 10. Facebook 2010: Privacy is no longer a social norm This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 11. Facebook 2018: “Data Privacy” Facebook 2019: Researching blockchain identity This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 12. Giovanni Buttarelli, European Data Protection Supervisor “There might well be a market for personal data, just like there is, tragically, a market for live human organs, but that does not mean that we can or should give that market the blessing of legislation.” @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 13. The GDPR @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 14. Fines & Risks @techgdpr • Up to 20 Million Euro • Or 4% of annual world wide group turnover • Whichever is higher • Disclosure requirements: reputation • Order to stop processing This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 15. 1. lawfulness, fairness and transparency 2. purpose limitation 3. data minimisation 4. accuracy 5. storage limitation 6. integrity and confidentiality 7. accountability Principles (Art 5) @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 16. Risk-based approach @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 17. Scope • Data of natural persons in the EU • Personal Data • Pseudonymised, but not anonymised • Not: for household use @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 19. Behavioural Patterns @techgdpr • Meta data can re-construct patterns leading to Personal Data • Large datasets have a high risk of leaking meta data • Location data can help constructing whereabouts that can lead to identification This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 20. Personal Data Breach ? ‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed; Article 4 (12) GDPR @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 21. Breaches & Notifications • Risk: Notify authorities within 72h • High risk: Notify affected subject (reputational risk) @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 22. Controller/Processor Roles • Clearly defined roles • the Controller determines the purposes and means of the processing of personal data • the Processor processes personal data on behalf of the controller @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 23. Legal base for processing A. Consent B. Performance of a contract C. Legal obligation D. Protect vital interests of subject E. Task in the public interest/authority F. Legitimate Interest* @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 24. Valid consent? @techgdpr How was it collected? This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 25. Consent @techgdpr • Freely given • Specific • Informed This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 26. Valid Consent: UX @techgdpr • Promoted choice • Bundling • Illusion of choice This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 27. Subject (Access) Rights 1.Right of information 2.Right of access 3.Right of erasure 4.Right of rectification 5.Right to data portability 6.Right not to be subjected to automated decision making. 7.Right to object @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 28. Personal data, blockchain & SSI @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 29. Public Permissionless Public Permissioned Private Permissionless Private Permissioned @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 30. Controller & Processor in Blockchain @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 31. Right to erasure & rectification @techgdpr • Right of erasure (Article 17) • Right of rectification (Article 16) This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 32. Encrypting on-chain personal data? @techgdpr • May be broken in the future • Encryption is a ‘technical measure’ not a way to move it out of scope of the GDPR. This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 33. “How about those hashes?” 518c4ae77dda05590f2789ec0d598d119f947001ceacc30ef1cadb8ceef4ebca Hash Function Can I store hashes of personal data? @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 35. Guidance @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 37. Opportunities of GDPR in blockchain @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 38. GDPR compliance tracking @techgdpr • Immutable history of events • Consent given or revoked • Record of processing activities This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 39. Alternative Governance Models @techgdpr • Clarity on roles • Contractual way to enforce rights • Only within Europe This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 40. Contracted Nodes @techgdpr • Transparency • Control • Purpose limitation • Data minimisation • Storage limitation This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 41. Self-Sovereign Identity @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 42. Self-sovereign Identity @techgdpr • What is stored on-chain and off-chain? • Who is responsible for personal data? • On-device personal data may still be in scope of the GDPR This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 43. Zero-knowledge proofs @techgdpr • Minimised amount of personal data revealed • High level of control over personal data • Need-to-know basis This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 44. GDPR principles and SSI @techgdpr • Transparency • Control • Purpose limitation • Data minimisation • Storage limitation This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 45. GDPR & SSI @techgdpr • Powerful tool for privacy protection • Visionary alignment with GDPR • Foundation technology • Both promote the free flow of data • Layer of trust and autonomy This presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 46. Letter of the law Spirit of the law? @techgdprThis presentation is released under a Creative Commons license. (CC BY-SA 4.0).
  • 47. Silvan Jongerius / @silvanjongerius / @techgdpr / silvan@techgdpr.com Thank You DPO Service - GDPR Assessment - Privacy by Design Data Protection Impact Assessment for Blockchain, AI & IoT This presentation is released under a Creative Commons license. (CC BY-SA 4.0).