Irina Saavedra
This document establishes general principles for and methods of processing personal identifiable information (PII) in BC/DLT systems and provides requirements and recommendations derived from legal requirements and recommendations in the GDPR. The document clarifies relevant terms for both technical as well as legal experts. It establishes a methodological framework that helps identifying types of PII as well as mapping legal principles of the GDPR to technical measures available to improve data protection or mitigate the risk of processing PII in BC/DLT-systems. This document is aimed towards establishing a high level of privacy in BC/DLT-systems. This document is applicable to all BC/DLT-systems.
This document specifies:
This document does not define requirements for:
This document specifies the functionality of the Wallet Unit for Access Control to Wallet Held Assets (WHAs) i.e. personal data relating to the Wallet User and stored in the Wallet Unit. It defines the Wallet Access Control decision Engine (WACE) and the corresponding functional requirements, resulting in recommendations to the user on decision to be made. This document aims at: 1) describing and specifying an Access Control Model supporting access control to the various possible operations on WHA(s); 2) providing the definitions and classification of the various types of data and metadata, and supporting access control to the various possible operations on WHA(s) ; 3) describing and specifying a W ACE controlling the access to the various possible operations on WHA(s) and the notification returned by the Wallet Access Control Decision Engine to a Wallet Unit; 4) identifying requirements applicable to the Wallet Access Control Decision Engine; This document also:
provides examples and use cases; The Access Control Model and Wallet Access Control Decision Engine defined in this document aim to comply with the regulator requirements regarding access control.
The following areas are out of the scope of this document: 1) content and encoding of the policies assigned for the disclosure of WHA(s), 2) implementation choice and encoding of Wallet Held Access Control Metadata; 3) encoding of electronic attestation(s) of attributes which are in the remit of ETSI/TC ESI.
This fellowship supported my work in updating to the IEEE 802.11 standard to prevent a recently discovered security weakness. This weakness is related to mesh networks, where, without extra defenses, an adversary could inject arbitrary packets into protected mesh networks. We designed a defense to mitigate this challenging gap. Unique about our created defense is that it is fully backward compatible, meaning each individual mesh client can independently enable this defense. As a proof-of-concept, we also implemented this defense in the Linux kernel to demonstrate practicality and confirm it prevents attacks.
This fellowship targets consumer-centric privacy by design in international standards work. Moreover, the Specific priorities, gaps and challenges identified are:
How the fellowship addressed these
This fellowship supports my engagement as the chair of Chair of ISO/IEC JTC 1/SC 44. The group’s Strategic Business Plan (SBP) aims to respond the the challenges identified above in the following manners:
The fellowship tackles the lack of international, or European, standard or technical specification that focuses explicitly on privacy and data protection capabilities of DLT systems. With this regards, ISO TS 24946 “Requirements and guidance for improving, preserving, and
assessing the privacy capability of DLT systems” has now reached CD stage (July 2025) and will endeavour to move through this process and be completed in 2026. This process requires continued support from experts to ensure delivery, as scheduled. In this sense, the priority of this activity focuses at the European level, CEN/CENELEC JTC 19/WG3 to produce a European standard on PII protection within DLT which is strongly influenced by ‘DIN Spec 4997 - Privacy by Blockchain Design’ and the aforementioned ISO TS 24946. This European specification will seek to harmonise the GDPR and recent EDPB guidance to produce a technical specification intended for the European DLT ecosystem.
This European specification will provide much needed clarity for the DLT ecosystem as regards data protection and privacy capabilities, affordances, and assessment. Further harmonisation between the international specification at ISO and the European standard will support interoperability, and ensure that privacy and data protection capabilities are harmonised globally. The main challenges concerns exacting requirements from regulations such as Article 76(3) of MiCAR, as well as Article 79(1) of the European AMLR will require navigation. Standards
require alignment and compatibility with those legal texts, as well as corresponding regulations regarding personal data, data markets, and trust services (e.g., GDPR, Data Act, eIDAS2). Ensuring there are no gaps between regulatory texts and the proposed European standards will be a primary focus. Also, it must be ensured that there are no substantial gaps between international specifications and European standards will be the second focus. Standards alignment between ISO and CEN/CENELEC is viewed as a key outcome to benefit the global DLT ecosystem, and one that requires strong consensus building, given slightly different international privacy perspectives and preferences.
The expected impact of the project is to provide stakeholders with a certification as defined in article 42 of the GDPR, thus improving trust between actors in a context of PII processing.
I estimate that digital identities, and the way to ensure appropriate levels of assurance and handling of corresponding credentials, are key for the digital society.