GDPR, PII 및 UUID

Sep 08 2020

GDPR에 따르면

개인은 다른 개인과 구별 할 수있는 경우 '식별'또는 '식별 가능'합니다.

그리고 또한

GDPR은 다음과 같은 식별자 목록을 제공합니다 : 이름; 식별 번호; 위치 데이터; 및 온라인 식별자.

이를 염두에두고 나는 그것이 실제적인 의미에서 무엇을 의미하는지에 대해 머리를 감싸려고 노력하고 있습니다. 두 개의 데이터베이스 테이블이 있으면 둘 다 암호화됩니다.

하나의 테이블은 전역 적으로 사용 가능하며 사용자 세션을 포함합니다. 대화를 위해 전 세계적으로 EU가 보호 측면에서 동등하다고 간주 할 수있는 국가에서 물리적으로 호스팅된다는 것을 의미한다고 가정합니다. PII가 없으며 세션 상태와 만료 시간 만 있습니다. 또한 무작위로 생성되었지만 사용자의 수명에 연결된 사용자 UUID를 보유합니다. 즉, 사용자에게 할당 된 후에는 변경되지 않습니다.

The other table is physically hosted in EU, and holds a UUID to email mapping.

If a breach results in the first table being leaked the data is anonymous, it is only when joined with the second that that the user session can be tied to PII (email address).

Does this mean that both tables fall under GDPR and thus must be placed in EU (or equivalent), or is it sufficient that only the table containing PII is located there?

답변

3 amon Sep 09 2020 at 01:05

이 UUID를 설명하는 방식은 가명 데이터입니다 (GDPR Art 4 (5) 및 Recitals 28–29 참조). 즉, 직접 식별하는 것은 아니지만이 데이터를 다시 식별하는 데 사용할 수있는 가명과 식별자 사이에 매핑이 있습니다. 효과적인 가명 화는 데이터가 논리적으로 분리되어 있어야 할뿐만 아니라 권한이없는 사람이 재결합하는 것을 방지하는 효과적인 조직 및 기술적 조치가 있어야합니다. 암호화와 함께 가명 화는 적절할 때마다 GDPR이 명시 적으로 요구하는 안전 조치 중 하나입니다 (Art 25, Art 32 참조).

Pseudonymous data is still personal data, because you can easily re-identify the data. The PII concept is US-specific and is misleading in a GDPR context, where it is not the inherently identifying characteristics of the information that matters, but the realistic ability of the data controller to single out data subjects to whom this data relates (compare Art 4(1) and Recital 26).

However, were you to irrevocably erase the UUID–email mapping, things are more tricky. There is no longer any connection with directly identifying data, so this data might be anonymous. On the other hand, such a persistent UUID still allows you to recognize/distinguish persons, so it might still be personal data. This might be the case especially when the UUID is used in long-lived cookies of website visitors, thus matching the GDPR's concept of an “online identifier”. This conclusion could be avoided by limiting reuse of UUIDs, e.g. creating a new UUID after some context-dependent appropriate duration.

GDPR은 모든 데이터를 EU에 저장하도록 요구하지는 않지만 충분한 보호를 위해 개인 데이터의 국제 전송을 요구합니다. 적절한 법적 보호가없는 국가 (예 : 미국)에서 이러한 데이터를 처리하는 경우 추가 보호 장치를 사용해야합니다. 가명 화는 이러한 보호 조치의 일부가 될 수 있으며 Schrems II 판결 이후 일부 데이터 보호 당국에서 제안했습니다. 그러나 가명 화만으로는 국제 이전을 합법적으로 만들 수 없으며 나머지 위험을 줄이는 전략에 가깝습니다.

I think that your systems has a good chance of being OK, but not neccessarily so. If in doubt, perform a DPIA and possibly consult your data protection authority under GDPR Art 36. If feasible, storing/processing data only in the EEA or in countries with an adequacy decision will simplify compliance. Safeguards such as pseudonymisation could be strengthened by rotating UUIDs, and by restricting access to the table with identifiers.

2 Matthew Sep 08 2020 at 22:05

Does this mean that both tables fall under GDPR and thus must be placed in EU (or equivalent), or is it sufficient that only the table containing PII is located there?

There is no requirement for data falling under GDPR to be physically located in the EU. It can be held in a country deemed to provide the same level of protection as existing EU data laws.

"세션"테이블이 이론적으로 "이메일"테이블과 결합되어 자연인을 식별하는 데 사용될 수 있으므로 두 테이블 모두 GDPR에 해당됩니다.