DSR Knowledge LibraryReusable design knowledge and grounded research support
HomeLibraryChatChat accessGive feedback ↗

DSR Knowledge Library

Research prototype · Native Open Knowledge Format

LibraryChatChat accessMethod and limitationsPrivacy noteEvaluation survey ↗
Library/Papers/How to Develop a GDPR-Compliant Blockchain Solution for Cross-Organizational Workflow Management: Evidence from the German Asylum Procedure

Research paper

How to Develop a GDPR-Compliant Blockchain Solution for Cross-Organizational Workflow Management: Evidence from the German Asylum Procedure

Drawing on the German Federal Office for Migration and Refugees (BAMF) case, the paper presents two actionable design principles for GDPR-compliant blockchain solutions in cross-organizational workflow management: do not store personal data on a blockchain, and, where attribution is required, use a highly secure off-chain mapping architecture.

PaperOpen source resource ↗
OverviewDSR gridDesign knowledgePaper design mapPublication metadata

01

Overview

Publication metadata and narrative from the current library record.

Authors
Florian Guggenmos, Annette Wenninger, Alexander Rieger, Gilbert Fridgen, Jannik Lockl
Year
2020
Venue
HICSS 53 (2020)
Methodology
Case study of the BAMF pilot; derivation of tentative design principles.
blockchaincross-organizationaldesign-science-researchgdpr-privacygdpr-workflow-asylumpublic-sectorworkflow-management

How to Develop a GDPR-Compliant Blockchain Solution for Cross-Organizational Workflow Management: Evidence from the German Asylum Procedure

Authors: Florian Guggenmos, Annette Wenninger, Alexander Rieger, Gilbert Fridgen, Jannik Lockl
Venue: HICSS 53 (2020)
Link: https://hdl.handle.net/10125/64253 (opens in a new tab)

Summary

Drawing on the German Federal Office for Migration and Refugees (BAMF) case, the paper presents two actionable design principles for GDPR-compliant blockchain solutions in cross-organizational workflow management: do not store personal data on a blockchain, and, where attribution is required, use a highly secure off-chain mapping architecture.

Artifact

A GDPR-compliant blockchain solution for the German asylum procedure (BAMF case).

Methodology

Case study of the BAMF pilot; derivation of tentative design principles.

Citations

[1] Florian Guggenmos, Annette Wenninger, Alexander Rieger, Gilbert Fridgen, Jannik Lockl. How to Develop a GDPR-Compliant Blockchain Solution for Cross-Organizational Workflow Management: Evidence from the German Asylum Procedure. HICSS 53 (2020). https://hdl.handle.net/10125/64253 (opens in a new tab) [2] Source document: How to Develop a GDPR-Compliant Blockchain Solution for cross-organizational workflow management.pdf

02

DSR grid

Six dimensions represented in the current paper record.

01

Problem description

Reconciling blockchain's tamper-resistant storage with the GDPR's rights to rectification and erasure in cross-organizational workflow management.

02

Input knowledge

GDPR and privacy-by-design principles; pseudonymization approaches; the German BAMF asylum-procedure case; prior IS research on data-privacy management.

03

Research process

A case study of the BAMF pilot, from which two tentative design principles are derived.

04

Key concepts

Blockchain, GDPR, cross-organizational workflow management, pseudonymization, asylum procedure.

05

Solution description

A GDPR-compliant blockchain architecture that keeps personal data off-chain and, where attribution is required, uses a highly secure off-chain mapping. Solution-space representation: Instantiation (BAMF architecture) plus two tentative design principles.

06

Output knowledge

Two actionable design principles for GDPR-compliant blockchain workflow design.

03

Design knowledge

Directly linked concepts, grouped by their represented design-knowledge category.

Design Principle

Design Principle2
Design Principle
design-knowledge/gdpr-workflow-asylum-dp1

DP1 - Do not store personal data on a blockchain

Keep personal data off-chain, since blockchain's tamper-resistant storage conflicts with the rights to rectification and erasure;

cross-organizationaldesign-principlegdpr-privacygdpr-workflow-asylum+2
Design Principle
design-knowledge/gdpr-workflow-asylum-dp2

DP2 - Use a highly secure off-chain mapping architecture for attribution

If a use case requires that data on the blockchain be attributable to a natural person, employ pseudonymization:

cross-organizationaldesign-principlegdpr-privacygdpr-workflow-asylum+2

04

Paper design map

The default semantic design map canonicalizes stored design relationships; Raw links retains the complete technical Markdown-link view.

Design-knowledge map

2 stored concepts / 0 canonical semantic relationships

Concept types
Design Principles
Press enter or space to select a node.You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

05

Publication metadata

Additional metadata represented in the current library record.

Show additional metadata+
{
  "type": "paper",
  "title": "How to Develop a GDPR-Compliant Blockchain Solution for Cross-Organizational Workflow Management: Evidence from the German Asylum Procedure",
  "description": "Drawing on the German Federal Office for Migration and Refugees (BAMF) case, the paper presents two actionable design principles for GDPR-compliant blockchain solutions in cross-organizational workflow management: do not store personal data on a blockchain, and, where attribution is required, use a highly secure off-chain mapping architecture.",
  "resource": "https://hdl.handle.net/10125/64253",
  "authors": "Florian Guggenmos, Annette Wenninger, Alexander Rieger, Gilbert Fridgen, Jannik Lockl",
  "year": 2020,
  "venue": "HICSS 53 (2020)",
  "methodology": "Case study of the BAMF pilot; derivation of tentative design principles.",
  "dsr_grid": true,
  "dsr_solution_space": "Instantiation (BAMF architecture) plus two tentative design principles.",
  "tags": [
    "gdpr-workflow-asylum",
    "gdpr-privacy",
    "cross-organizational",
    "public-sector",
    "workflow-management",
    "design-science-research",
    "blockchain"
  ]
}