Author:
Ana Ferreira
Affiliation:
CINTESIS - Centre for Health Technology and Services Research, Faculty of Medicine of Porto, Porto, Portugal
Keyword(s):
General Data Protection Regulation, Literature Review, GDPR Compliant Solutions, Privacy and Security.
Abstract:
This paper aims to investigate, with a literature review, how the research community has been tackling the security and privacy requirements mandated by the General Data Protection Legislation (GDPR), over the last year and a half. We assessed what proposed solutions have been implemented since GDPR came into force, if and where they were tested in real settings, with what technologies and what specific GDPR requirements were targeted. No similar review has been found by the authors as works in the literature mostly provide recommendations for GDPR compliance or assess if current solutions are GDPR compliant. Results show that most proposed solutions focus on Consent, PrivacybyDefault/Design and are assessed on IoT and healthcare domains. However, almost none is tested and used in a real setting. Although it may be still early days for this review, it is clear that: a) there is the need for more GDPR compliant novel solutions, tests and evaluations in real settings; b) the obtained k
nowledge be quickly shared so that proper feedback is given to the legal authorities and business/research organizations; and c) solutions on privacy must integrate socio-technical components that can face, in an all-inclusive way, infrastructures, activities and processes, where GDPR must apply.
(More)