DBCompliant: Extending Database Management Systems to Support Compliance Functionality


연구 분야: Databases



학회: International Conference on Database Systems for Advanced Applications


초록

Data privacy policy requirements are a quickly evolving part of the data management domain. Healthcare (e.g., HIPAA), financial (e.g., GLBA), and general laws such as GDPR or CCPA impose controls on how personal data should be managed. Relational databases do not offer built-in features to support data management features to comply with such laws. As a result, many organizations implement ad-hoc solutions or use third party tools to ensure compliance with privacy policies. However, external compliance framework can conflict with the internal activity in a database (e.g., trigger side-effects or aborted transactions). In our prior work, we introduced a framework that integrates data retention and data purging compliance into the database itself, requiring only the support for triggers and encryption, which are already available in any mainstream database engine. In this demonstration paper, we introduce DBCompliant – a tool that demonstrates how our approach can seamlessly integrate comprehensive policy compliance (defined via SQL queries). Although we use PostgreSQL as our back-end, DBCompliant could be adapted to any other relational database. Finally, our approach imposes low (less than 5%) user query overhead.


Author Profile
Alexander Rasin

DePaul University Chicago IL 60604 USA

Israel
Author Profile
Nick Scope

DePaul University Chicago IL 60604 USA

Israel
Author Profile
Ben Lenard

DePaul University Chicago IL 60604 USA

Israel

📄 논문 정보

발행 연도 2024년
인용수 0
출판 국가 Laos, Israel
사이트 Springer
좋아요 수 0

연관 논문 목록 (390건)