Information (Feb 2023)

Making Sense of Solid for Data Governance and GDPR

  • Harshvardhan J. Pandit

DOI
https://doi.org/10.3390/info14020114
Journal volume & issue
Vol. 14, no. 2
p. 114

Abstract

Read online

Solid is a new radical paradigm based on decentralising control of data from central organisations to individuals that seeks to empower individuals to have active control of who and how their data is being used. In order to realise this vision, the use-cases and implementations of Solid also require us to be consistent with the relevant privacy and data protection regulations such as the GDPR. However, to do so first requires a prior understanding of all actors, roles, and processes involved in a use-case, which then need to be aligned with GDPR’s concepts to identify relevant obligations, and then investigate their compliance. To assist with this process, we describe Solid as a variation of ‘cloud technology’ and adapt the existing standardised terminologies and paradigms from ISO/IEC standards. We then investigate the applicability of GDPR’s requirements to Solid-based implementations, along with an exploration of how existing issues arising from GDPR enforcement also apply to Solid. Finally, we outline the path forward through specific extensions to Solid’s specifications that mitigate known issues and enable the realisation of its benefits.

Keywords