Technical Solutions for the Processing, Management and Anonymisation of Personal Data in Databases According to EU Data Protection Regulations

M. Murín, S. Molčan, M. Michalkc, Ondrej Kainz, David Cymbalak · 2024

The adoption of the European GDPR regulation created an obligation for operators to implement this regulation into their systems. One of its points mandates the immediate anonymization of personal data if an individual exercises their right to be forgotten. The goal of this thesis was to create a system that provides tools for anonymizing personal data in relational databases. The system allows for defining where in the database different types of personal data are located and how to search for them. Based on this configuration, the system can anonymize selected personal data of an individual or anonymize the data of all individuals across the database. The system was implemented as a web application and web server connected to a relational database. Tree traversal algorithms were used for searching data. Testing showed that the system can save on average 89% of the time needed for anonymizing an individual's data compared to manual anonymization, while eliminating errors and enabling oversight of the process through an audit. It also allows less technically skilled users to perform data anonymization. The main benefit of this system is its deployment in production environments, particularly in the information systems of state organizations of the Slovak Republic.

Read the paper · More papers on PaperTik