A GDPR Controller for IoT Systems: Application to e-Health
Mouna Rhahla, Takoua Abdellatif, Rabah Attia, Wassel Berrayana · 2019
General Data Protection Regulation (GDPR) targets personal data protection of the European Union citizens, with a strong input on the rights of people to control their data. Current GDPR solutions are adhoc and are still challenging for scalable systems like Internet of Things (IoT). In this paper, we propose a general solution of a GDPR Controller in IoT systems. The controller gives the data owner a full control of his data: setting security policies, modifying them on run time, tracking data flow and notifying him for any illicit access. The controller architecture is validated and evaluated using an e-health use case with acceptable overhead on the system performance.