The compliance gap in data supply chains: contract specification languages and smart contracts as compliance technologies
摘要
This paper investigates the use of Contract Specification Languages (CSLs), smart contracts, and their associated software methods and tools for formally specifying, verifying, and monitoring contracts, as a means to improve compliance with data protection laws, by harnessing the back end of data supply chains. The privacy literature has focused predominantly on B2C relationships (front end data processing) to assess corporate compliance with data protection laws and has explored the use of technologies primarily as a means to empower data subjects vis-à-vis data processors. This article shifts the perspective. First, it shows that the effective implementation of data subjects’ rights hinges upon the capacity of data processors to monitor compliance in back-end processing, i.e., the data supply chain. Second, it spells out the way CSLs and smart contracts can contribute to bridge the compliance gap in the data supply chain, which currently hinders data controllers from effectively monitoring the flow and use of data documents and practices across the networks of subcontractors. Indeed, while data is processed in an iterative and dynamic manner through a wide variety of means by actors within and across companies in the supply chain (e.g., controller, processors, and sub-processors), the legal instruments used to ensure compliance are dispersed, static, convoluted and legalistic, ultimately lacking the capability to operationalize data protection across different management levels (legal, technical, business, etc.). This paper proposes methods for specifying and controlling obligations related to data processing and distributions by using CSLs and smart contracts, and the contribution these methods can make for monitoring compliance in the data supply chain. It briefly introduces the Symboleo CSL for the formal specification of contracts. It then offers a concrete case study testing the properties of the Symboleo in a dataset composed of contractual documents used in the data supply chain of a network of IT companies. The paper concludes with a discussion of the challenges laying ahead to narrow the compliance gap and highlights how the proposed methods can evolve to become effective compliance tools in data protection.