Table of contents

  • This session has been presented October 25, 2019.

Description

  • Speaker

    Cédric Lauradoux (INRIA Rhône-Alpes)

The GDPR (General Data Protection Regulation) provides rights on our data: access, rectification, objection, etc. However, this regulation is not binding on how we can exercise these rights. Data controllers have therefore deployed various methods to authenticate subject requests. We have analyzed how this authentication process can fail and examined its consequences. Our study shows that a key concept is missing in the GDPR: Proof of ownership for our data.

Practical infos

Previous sessions

Show previous sessions