| Literature DB >> 33802673 |
Suada Hadzovic1, Sasa Mrdovic1, Milutin Radonjic2.
Abstract
The Internet of Things (IoT) is a leading trend with numerous opportunities accompanied by advantages as well as disadvantages. Parallel with IoT development, significant privacy and personal data protection challenges are also growing. In this regard, the General Data Protection Regulation (GDPR) is often considered the world's strongest set of data protection rules and has proven to be a catalyst for many countries around the world. The concepts and interaction of the data controller, the joint controllers, and the data processor play a key role in the implementation of the GDPR. Therefore, clarifying the blurred IoT actors' relationships to determine corresponding responsibilities is necessary. Given the IoT transformation reflected in shifting computing power from cloud to the edge, in this research we have considered how these computing paradigms are affecting IoT actors. In this regard, we have introduced identification of IoT actors according to a new five-computing layer IoT model based on the cloud, fog, edge, mist, and dew computing. Our conclusion is that identifying IoT actors in the light of the corresponding IoT data manager roles could be useful in determining the responsibilities of IoT actors for their compliance with data protection and privacy rules.Entities:
Keywords: GDPR; Internet of things; IoT actor; computing; data manager
Year: 2021 PMID: 33802673 PMCID: PMC8002385 DOI: 10.3390/s21062093
Source DB: PubMed Journal: Sensors (Basel) ISSN: 1424-8220 Impact factor: 3.576
General Data Protection Regulation (GDPR) actors.
| GDPR Actor | Description by the GDPR [ |
|---|---|
| Controller | Article 4 point (7) ‘’controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data’’. |
| Joint Controller | Article paragraph 26 ‘’Where two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers’’. |
| Processor | Article 4 point (8) ‘’processor means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller’’. |
| Third Party | Article 4 point (10) ‘’third party means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data’’. |
| Data | Article 37 paragraph 1. ‘’The controller and the processor shall designate a data protection officer in any case where:’’…b) ‘’the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale;’’ |
| Supervisory Authority | Article 51 paragraph 1 ‘’Each Member State shall provide for one or more independent public authorities to be responsible for monitoring the application of this Regulation, …’’ |
| Lead | Article 56 paragraph 1 ‘’… the supervisory authority of the main establishment or of the single establishment of the controller or processor shall be competent to act as lead supervisory authority for the cross-border processing carried out by that controller or processor…’’ |
Computing hardware locations and corresponding Internet of Things (IoT) actors.
| Cloud Computing | Fog Computing | Edge Computing | Mist Computing | Dew Computing | |
|---|---|---|---|---|---|
| Computing hardware location | Large Cloud, | Mini Cloud | The first hop from the IoT device | The far edge of the IoT network | Server located inside the user’s PC and Information processing devices |
| IoT actor | Cloud Data Manager | Fog Data | Edge Data Manager | Mist Data Manager Device provider | Dew Data |
Mappings between the IoT actors and business roles in selected International Telecommunication Union (ITU) recommendations.
| IoT Actors Identified in ITU Recommendations | Business Roles in Informative Appendix I of Recommendation ITU-T Y.4000 [ |
|---|---|
| Data Manager is responsible for managing the capture, processing, storage, and transfer of IoT data to meet the IoT service provision requirements [ | Application provider |
| Service Provider provides services related to things, such as location tracking, monitoring, and service discovery [ | Application provider, |
| IoT User uses services related to things, such as location tracking, monitoring, and service discovery [ | Application customer |
| IoT Data Provider collects data from things and injects the data processed within the IoT system as well as data from external sources and provides them via the IoT data carrier to the IoT data consumer [ | Device provider, |
| IoT Data Consumer consumes IoT data. Usage of the consumed data depends on application purposes [ | Device provider, |
| IoT Data Framework Provider provides general IoT data processing capabilities and related infrastructure (e.g., storage and computing resources, data processing run time environment) as required by the IoT data provider, IoT data carrier, IoT data application provider, and IoT data consumer for the support of data operations execution [ | Network provider, |
| IoT Data Application Provider provides applications related to the execution of IoT data operations (e.g., applications for data analysis, data pre-processing, data visualization, and data query) [ | Device provider, |
| IoT Data Carrier carries data among the IoT data provider, the IoT data framework provider, the IoT data application provider, and the IoT data consumer [ | Network provider. |
Mappings between the IoT actors identified from various perspectives.
| IoT Actors | IoT Actors Identified from Various Perspectives |
|---|---|
| IoT Developer | IoT service developer [ |
| IoT Security | Security specialists [ |
| IoT Data Protection and Privacy | Data protection officer [ |
| IoT Data | Data manager [ |
| IoT Device | Device provider [ |
| IoT Network equipment | Suppliers of the middleware [ |
| IoT Platform | Connectivity platforms [ |
| IoT Connectivity Provider | Network provider [ |
| IoT Service | Service provider [ |
| IoT Application Provider | Application provider [ |
| IoT Integrator | IoT service integrator [ |
| IoT User | IoT user [ |
| End User | End user [ |
Figure 1IoT Model.