Understanding and benchmarking the impact of GDPR on database

50Citations
Citations of this article
90Readers
Mendeley users who have this article in their library.
Get full text

Abstract

The General Data Protection Regulation (GDPR) provides new rights and protections to European people concerning their personal data. We analyze GDPR from a systems perspective, translating its legal articles into a set of capabilities and characteristics that compliant systems must support. Our analysis reveals the phenomenon of metadata explosion, wherein large quantities of metadata needs to be stored along with the personal data to satisfy the GDPR requirements. Our analysis also helps us identify new workloads that must be supported under GDPR. We design and implement an open-source benchmark called GDPRbench that consists of workloads and metrics needed to understand and assess personal-data processing database systems. To gauge the readiness of modern database systems for GDPR, we follow best practices and developer recommendations to modify Redis, PostgreSQL, and a commercial database system to be GDPR compliant. Our experiments demonstrate that the resulting GDPR-compliant systems achieve poor performance on GPDR workloads, and that performance scales poorly as the volume of personal data increases. We discuss the real-world implications of these findings, and identify research challenges towards making GDPRcompliance efficient in production environments. We release all of our software artifacts and datasets at http://www:gdprbench:org.

Cite

CITATION STYLE

APA

Shastri, S., Banakar, V., Wasserman, M., Kumar, A., & Chidambaram, V. (2020). Understanding and benchmarking the impact of GDPR on database. In Proceedings of the VLDB Endowment (Vol. 13, pp. 1064–1077). VLDB Endowment. https://doi.org/10.14778/3384345.3384354

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free