This blog post is the second episode of a blog post series on Self-Sovereign Identity (SSI) and the GDPR, the first part of which is covered here. The first part looks into the similarities between the GDPR and the conceptual framework consisting of principles of the SSI ideal.
Overview
The GDPR covers the handling of digital identity data; hence the SSI principles should be consistent with the GDPR rules. However, technical and legal terminology may have diverse meanings due to discipline-specific interpretations as a common issue. In other words, while SSI principles include concepts similar to GDPR articles and principles, a closer examination reveals that they may have different interpretations. The second part focuses on the conceptual differences observed when the principles are contextualized within their specific domain: digital identity management.
Conceptual Differences
Existence: Identity management requires the truth: the personal information processed through identity management systems should reflect accurate information about a person. However, the GDPR covers all types of personal information regardless of whether they reflect the truth. In her book titled Digital Identity, Claire Sullivan states that identity and privacy are separate and distinct concepts, although they are closely related and often overlap. The right to identity and privacy are both fundamental human rights that relate to individual autonomy, but they protect different interests in different ways. Everyone has the right to be recognized as a person before the law, as enshrined in Article 6 of the Universal Declaration on Human Rights and Article 16 of the International Covenant on Civil and Political Rights. This is mainly provided by the legal identity, which falls under the GDPR.
Control: The main difference about control is that while in the GDPR the term does refer to a principle or provision, it is one of the SSI principles. Besides, it is an elusive term challenging to define, specifically in relation to personal data. As mentioned in the first blogpost, control is an umbrella notion and in the GDPR it relates to the whole data subject rights and principles such as transparency and accountability.
Access: In terms of the SSI, access is provided by (i) the visualization of personal data in the digital wallets; (ii) public blockchain layers displaying the transaction history. As will also be explained under the section titled ‘transparency’ below, the GDPR governs access rights only to provide bilateral transparency between the data controller and the subject, typically not to third parties.
Transparency is possible in SSI because of the public and auditable nature of the blockchains.However, transparency under the GDPR does not refer to public transparency, as mentioned above.
Persistence might be seen as one of the only principles that have not been mentioned or implied under the GDPR.
Portability: The right to data portability, as explained in the previous blog post, does not require the transferred data to be deleted; but Article 17 (the right to erasure) can still be duly invoked, which points to another divergence or conflict that should be analyzed from a technical point of view, as the blockchain ledgers are immutable., meaning that once registered to the blocks the data cannot be practically deleted. This technical aspect will be discussed in the following blog post.
Consent: Consent is one of the most used legal bases in the GDPR for processing personal data; however, it is only one of the legal bases. Arguably, most cases that involve digital identity data processing would not rely on consent, which might render this principle inefficient.Nonetheless, consent is also one of the most crucial legal bases, as it is associated with the right to informational self-determination.
Minimization: As discussed in another blog post by Jessica Schroers and me, SSI systems (also promoted under the new eIDAS Proposal) create a set of personal data to uniquely and persistently represent natural persons. At first sight, using different identifiers (DIDs ) and encryption to facilitate selective disclosure can be seen as a way to minimize the data processed. However, one should keep in mind that the data minimization principle under the GDPR also refers to retaining the data only for as long as it is necessary to fulfill the specific purpose for which the data has been processed. Here, the primary purpose can be seen as identity verification (authentication), which is typically done in a second, and access to the service is given. Moreover, considering the data registered in the system are immutable, SSI seems not to align with the principle.
Protection: As mentioned in the first blogpost, protection is a very general term, and in fact, it might refer to data protection in general. It can also refer to the security of the data, which includes several other aspects, such as confidentiality and integrity. Article 5(6) reads that personal data shall be “processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).” Moreover, Article 32 adds the availability and resilience of the data processing systems. One thing to consider here is that the GDPR is a techno-neutral regulation, meaning that it does not refer to any specific technology. However, SSI as a concept relies (at least currently) on public blockchain technologies built to keep the registered data publicly and immutable; thus, whether it provides sufficient protection or security shall be discussed later from a technical perspective.
Conclusion
This brief comparison indicates significant differences – and even contradictions – in the understanding of the key concepts. Some principles, while seemingly similar, are likely to mean different things. For example, transparency in SSI has a whole different meaning from the principle of transparency under the GDPR. However, the concept seems to be quickly adopted by the EU, as observed in the policy-related discourse and even in proposals. It should be borne in mind that data protection has both- among others- technical and legal aspects and terminology, and the correct understanding of the concepts is crucial. This is why a following blog post will explore the technical aspects of the concept in order to have a more comprehensive view of the conceptual analysis.
The PriMa project has received funding by the European Union’s Horizon 2020 research and innovation program under the Marie Sklodowska-Curie Grant agreement No 860315.


Comments