Defining personal data Sovereignty: An ontologically-based framework facilitating subject privacy control

This paper presents the implementation and evaluation of the Data Capsule framework, a novel approach for achieving personal data sovereignty. Our framework uses formal knowledge representation to understand both the context of personal data collection across heterogeneous systems and define compreh...

Full description

Saved in:
Bibliographic Details
Published inData and information management p. 100108
Main Authors Baraku, Vijon, Ramadani, Edon, Paraskakis, Iraklis, Veloudis, Simeon, Yadav, Poonam
Format Journal Article
LanguageEnglish
Published Elsevier Ltd 01.08.2025
Subjects
Online AccessGet full text

Cover

Loading…
More Information
Summary:This paper presents the implementation and evaluation of the Data Capsule framework, a novel approach for achieving personal data sovereignty. Our framework uses formal knowledge representation to understand both the context of personal data collection across heterogeneous systems and define comprehensive usage policies - from access control to monetisation opportunities. As organisations increasingly collect and process personal data, individuals continue to lack effective mechanisms to control how their information is processed and/or shared across heterogeneous systems. We tackle this problem with two key contributions: (1) an ontology-based federation system that allows for seamless federation of personal data across databases using schema.org as a semantic foundation, and (2) a semantically driven dynamic usage control mechanism that allows individuals to define and enforce granular access rules. Our implementation demonstrates that effective personal data sovereignty can be achieved and serves as a foundation for future systems contributing to the empowerment of individuals in the digital economy. •Develops novel ontology-based framework for achieving personal data sovereignty•Overcomes data migration challenges through federation-based sovereignty approach•Provides more fine-grained control over personal data than current solutions•Implementation demonstrates feasibility of personal data sovereignty in practice•Validates practical deployment without extensive infrastructure modifications
ISSN:2543-9251
2543-9251
DOI:10.1016/j.dim.2025.100108