Towards Software-Defined Data Protection: GDPR Compliance at the Storage Layer is Within Reach
Zsolt Istvan (IMDEA Software Institute, Madrid), Soujanya Ponnapalli, (University of Texas, Austin), Vijay Chidambaram (University of Texas,, Austin, VMWare)

TL;DR
This paper introduces Software-Defined Data Protection (SDP), a method to enforce GDPR compliance at the storage layer efficiently by decoupling policy management from enforcement, leveraging smart storage solutions.
Contribution
It proposes a novel SDP approach adapting software-defined storage principles for privacy rule enforcement at line-rate, addressing performance and complexity challenges.
Findings
SDP enables GDPR compliance at storage layer.
Smart storage solutions can implement SDP functionalities.
Decoupling policies from enforcement improves efficiency.
Abstract
Enforcing data protection and privacy rules within large data processing applications is becoming increasingly important, especially in the light of GDPR and similar regulatory frameworks. Most modern data processing happens on top of a distributed storage layer, and securing this layer against accidental or malicious misuse is crucial to ensuring global privacy guarantees. However, the performance overhead and the additional complexity for this is often assumed to be significant -- in this work we describe a path forward that tackles both challenges. We propose "Software-Defined Data Protection" (SDP), an adoption of the "Software-Defined Storage" approach to non-performance aspects: a trusted controller translates company and application-specific policies to a set of rules deployed on the storage nodes. These, in turn, apply the rules at line-rate but do not take any decisions on…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCloud Data Security Solutions · Cryptography and Data Security · Privacy-Preserving Technologies in Data
