GDPR Related Requirements and Recommendations for the IDS Reference Architecture Model

Benjamin Heitmann, Dr.-Ing. Erik Krempel, Michael Ochs, Dustin Schutzeichel · Zenodo (CERN European Organization for Nuclear Research) · 2019

This paper aims at a derivation of requirements for the IDS reference architecture model (IDS RAM) in order to support the compliance with the General Data Protection Regulation (GDPR). The fundament for this is the identification, detailed documentation andanalysis of the use cases in the International DataSpace, which involve the processing of personal data, thus being relevant for the GDPR. For the description of the use cases see the documentD1 –Identification and Documentation of Relevant Use Cases1. Further information on the analysis and the GDPR compliance can be found in D2-Analysis of the GDPR along the Use Cases2. First, a summary of necessary functionalities for the IDS is given that originates from the analysis of our use cases presented in D2 –Analysis of the GDPR along the Use Cases. Based on the identified functionalities, more fine-grained requirements are formulated. Finally, we elaborate a categorization and prioritization of the requirements serving as our recommendation for the future work of the IDS initiative with respect to GDPR compliance. We argue to what extent the IDS ecosystem can contribute to GDPR compliance of organizations processing and sharing personal data -and which aspects are out of scope of the IDS.

Read the paper · More papers on PaperTik