- DPDPA (India’s Digital Personal Data Protection Act)
- FERPA (Family Educational Rights and Privacy Act in the USA), which governs student education records
- GDPR (General Data Protection Regulation in the EU)
Key Features of CRBAC
- Hierarchical Access Control: Supports parent-child relationships in data access, enabling fine-grained permissions.
- Context-Aware Policies: Defines access based on specific attributes like user roles, organizational structures, and compliance requirements.
- Dynamic Consent Enforcement: Incorporates consent management for accessing PII.
- Group-Based Roles: Databunker supports groups of users, where each member within a group can have distinct roles. For instance, in an educational group, roles like Teacher and Student can be assigned, or in a family group, roles such as Parent and Child.
- Similar to AWS IAM Policies: Uses a declarative approach to grant or deny access based on conditions.
Policy Structure
CRBAC policies resemble AWS IAM policies, defining who (principale) can perform what (actions) on which (resources) under which conditions.Example Policy: Parent-Child Relationship Enforcement
In Databunker Pro, you can create a custom group for family members. Within this group, parents will have read and write access to their child’s information. You can use the following policy to grant parents access to their child’s PII and consent information.Example Policy: Teacher-Parent Access
This policy will grant to a teacher entity access to the student’s parent information.Why Choose CRBAC?
- Compliance-Ready: CRBAC ensures organizations meet legal and regulatory requirements, including FERPA and DPDPA.
- Dynamic Access Control: Unlike static RBAC, CRBAC adapts access rights based on real-time conditions.
- Fine-Grained Permissions: Allows precise control over PII data access, reducing the risk of unauthorized exposure.
Implementing CRBAC with Databunker Pro
Databunker Pro simplifies CRBAC implementation by providing:- Built-in support for conditional access policies
- Secure PII storage with compliance enforcement
- A developer-friendly API for managing role-based conditions