TL;DR
VICEROY is a scalable, privacy-preserving framework enabling accountless consumers to authenticate and exercise data rights under GDPR and CCPA without revealing sensitive identity information.
Contribution
The paper introduces VICEROY, a novel framework that allows accountless consumers to prove data ownership securely and privately, requiring minimal changes for service providers.
Findings
VICEROY effectively enables privacy-preserving consumer requests.
The framework is scalable and practical for real-world deployment.
Extensive experiments demonstrate its usability and security.
Abstract
Recent data protection regulations (such as GDPR and CCPA) grant consumers various rights, including the right to access, modify or delete any personal information collected about them (and retained) by a service provider. To exercise these rights, one must submit a verifiable consumer request proving that the collected data indeed pertains to them. This action is straightforward for consumers with active accounts with a service provider at the time of data collection, since they can use standard (e.g., password-based) means of authentication to validate their requests. However, a major conundrum arises from the need to support consumers without accounts to exercise their rights. To this end, some service providers began requiring such accountless consumers to reveal and prove their identities (e.g., using government-issued documents, utility bills, or credit card numbers) as part of…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
