TrustChain OC2 : User Privacy and Data Governance
ClosedDescription
TRUSTCHAIN overall objective is to create a portfolio of Next Generation Internet protocols and an ecosystem of decentralised identity management software solutions that is transparent to the user, interoperable, privacy aware and regulatory compliant that can seamlessly integrate and interoperate with any of the existing decentralised applications. Today, it becomes increasingly important to minimize the amount of data needed for specific online services. As more and more organizations share business sensitive data, it is important to preserve privacy while maintaining data utility. Therefore, to give the control of their online data sharing back to the user and ensure privacy preserving ways of data exchange on the future internet is currently needed. Establishing privacy, security and consent in specific data management processes should be a pre-requisite condition of online data sharing. In order to achieve TRUSTCHAIN vision and overall objective, TRUSTCHAIN Open Call 2 (OC2) applicants are expected to develop tools, cryptographic mechanisms, and other algorithms for data handling and sharing as well as for the management of data lakes in compliance with GDPR and other regulations that implement techniques such as: Mechanisms for multi-party data sharing that lies in the scope of the call and addresses the stated challenges below, Protocols for privacy-preserving data sharing using techniques from technologies such as federated learning both vertical and horizontal framework, Privacy-preserving data processing, data storage and data computation techniques such as differential privacy, data obfuscation/perturbation, anonymization techniques, Encrypted data analytics based on homomorphic encryption and Trusted Execution environment, Protocols to verify authenticity and accuracy of data using technologies like zero knowledge proofs, Protocols to support the digital sovereignty-based data flow and data spaces initiatives, Data identification, data provenance, data tracking mechanisms or protocols should be built so that the data that is exchanged can be tracked, so that trustworthy data handling according to the user consent can be verified. In order to develop effective user privacy preserving and state-of-the-art consent- based data management, the following challenges that exist today will have to be addressed: The online data sharing model is flawed as it encourages data duplication, long term data retention and intensive data collection across service providers. There is also lack of data traceability and accountability in online data sharing. Privacy is important when user data is employed for training machine learning models and computation. Information leakage in training models is a persistent problem. Local differential privacy with federated learning models can be explored to address this challenge. Data accuracy vs privacy trade-off in privacy-preserving techniques like differential privacy is an open challenge and its solution can be key to solving many open-source data sharing issues. Privacy-aware data processing needs to be encouraged from the design phase of any data sharing/processing protocol. Similarly, illegal data copying is a big challenge in user privacy and data governance models today which needs to be addressed. A trust layer is missing, and it is often difficult to ensure authenticity of data. Thus, trustworthy data access and data integrity mechanisms based on SSI technologies, including decentralized identifiers and Verifiable Credentials, need to be designed. In line with providing a trust layer supporting user privacy, data provenance ontologies and data transaction logging should be available to users. Users have little to no control over access to their personal data shared online. Therefore, automated user consent/smart user consent for data sharing needs to be implemented. Data owners currently do not have means to be compensated or to enable fair data value sharing with the big players in the market. When users want to participate in the data economy, they should be able to do so by means of data tokenization/trading capabilities. Users should be empowered to add the necessary levels of anonymity to share their data with a third party. A user centric design approach should frame the developed solution and carefully consider the following: data privacy protection, privacy aware data processing, data provenance, data use policies, data retention and data deletion, right to be forgotten, data minimization, and trustworthiness. data minimization and user informed data deletion It should in any case cover real needs of the end-users in one of the sectors (Not limited to) such as for example banking, education, healthcare, e-democracy and soforth. The target applicants of this call are developers, innovators, researchers, SMEs, and entrepreneurs working on different NGI relevant topics and application domains at the intersection between the technical field (e.g., Software Engineering, Network Security, Semantic Web, Cryptography, Blockchain, Digital Twin, Blockchain Security, Digital Identity, Blockchain Protocol), the Social sciences and Humanities (e.g., Social Innovation, not-for-profit sector, Social Entrepreneurship, public goods) as well as any others including economics, environment, art, design, which can contribute to the NGI TrustChain relevant vision.
Beneficiary & submission
Proposals are submitted in a single stage and the evaluation process is composed of three phases as presented hereafter: o Phase 1: Admissibility & eligibility check oPhase 2: Proposals evaluation carried out by the TRUSTCHAIN Consortium with the assistance of independent experts. o Phase 3: Online interviews (10 minutes pitching & 20 minutes of Q&As) and final selection carried out by the TRUSTCHAIN Consortium and the TRUSTCHAIN Advisory Board Members. The evaluation of proposals is carried out by the TRUSTCHAIN Consortium with the assistance of independent & multidisciplinary experts knowledgeable in the technological field as well as in Social Sciences and Humanities. TRUSTCHAIN Consortium staff ensures that the process is fair and in line with the principles contained in the European Commission's rules on Proposal submission and evaluation.
Further information
The TRUSTCHAIN consortium will provide information to the applicants only via trustchain@ngi.eu No binding information will be provided via any other means (e.g., telephone or email). Further details and kit for application are available at: https://trustchain.ngi.eu/apply Apply via: https://www.f6s.com/trustchain-open-call-2/apply