ARCHITECTURAL APPROACHES TO ENSURING DATA INTEGRITY AND CONFIDENTIALITY IN PSYCHO-EMOTIONAL STATE MONITORING SYSTEMS

Authors

DOI:

https://doi.org/10.31673/2409-7292.2026.037413

Abstract

The article explores architectural approaches to personal data management in psycho-emotional monitoring
systems using the author's digital platform "Sensera" as an example. The fundamental contradiction between the need for
deep longitudinal analytics of psycho-emotional states and strict requirements for the protection of personally identifiable
information (PII) is considered. The aim of the work is the theoretical justification and practical testing of the architectural
model "PII Isolation", which provides physical and logical separation of identification and clinical data directly at the
level of the relational database schema. The study is based on the methods of comparative analysis of approaches to PII
protection (k-anonymity, differential privacy, Privacy by Design), structural modeling of the database schema and
practical prototyping on the FastAPI 0.128.0 / PostgreSQL 17.4 / SQLAlchemy 2.0 stack. Additionally, the unification of
metadata using enumerated types (ENUM) and the optimization of asynchronous query processing through the Eager
Loading strategy (joinedload/ selectinload) were investigated. Practical testing on a sample of 30 clinical profiles and 102
assessments confirmed the effectiveness of the solutions: automated verification of PII isolation was completed with the
status PASSED in accordance with GDPR Art. 4(5); the Eager Loading strategy reduced the number of SQL queries from
11 to 1 (-91%); the implementation of 4 ENUM types eliminated 4 classes of incorrect input errors and reduced the
estimated query cost by 9.4% with absolute accuracy of the planner statistics (14/14 versus 1/14 for TEXT CAST). The
compliance of the architecture was confirmed according to 8 articles of Regulation (EU) 2016/679. It is concluded that
the proposed approach implements the principle of "positive sum" - provides full analytical accuracy without
compromising privacy. The practical value lies in the reproducibility of the model for scalable e-Health platforms that
require simultaneous implementation of GDPR and HIPAA requirements.
Keywords: PII isolation, data integrity, psycho-emotional monitoring, PostgreSQL, FastAPI, metadata
unification, personal data protection.

References
1. The Future of Jobs Report 2025. World Economic Forum. URL: https://www.weforum.org/publications/thefuture-of-jobs-report-2025/.
2. World mental health today: latest data. World Health Organization (WHO). URL: https://www.
who.int/publications/i/item/9789240113817.
3. Samarati P. Protecting Respondents' Identities in Microdata Release. IEEE Transactions on Knowledge and
Data Engineering. 2001. Vol. 13, no. 6. P. 1010–1027. URL: https://www.cs.colostate.edu/~cs656/reading/samarati.pdf.
4. Sweeney L. K-ANONYMITY: A MODEL FOR PROTECTING PRIVACY. International journal of
uncertainty, fuzziness and knowledge-based systems. 2002. Vol. 10, no. 05. P. 557–570. DOI: https://doi.org/ 10.
1142/s0218488502001648.
5. Machanavajjhala A., Kifer D., Gehrke J., Venkitasubramaniam M. l-Diversity: Privacy Beyond k-Anonymity.
ACM Transactions on Knowledge Discovery from Data. 2007. Vol. 1, no. 1. Art. 3. DOI: https://doi.org/10.1145/
1217299.1217302.
6. Li N., Li T., Venkatasubramanian S. t-Closeness: Privacy Beyond k-Anonymity and l-Diversity. IEEE Xplore.
2007. URL: https://ieeexplore.ieee.org/document/4221659.
7. Narayanan A., Shmatikov V. Robust De-anonymization of Large Sparse Datasets. IEEE Xplore. 2008. URL:
https://ieeexplore.ieee.org/document/4531148.
8. Sung M., Cha D., Park Y. R. Local differential privacy in medical domain to protect sensitive information:
Algorithm Development and Real-World Validation (Preprint). JMIR Medical Informatics. 2021. DOI:
https://doi.org/10.2196/26914.
9. Cavoukian A. Privacy by Design: The 7 Foundational Principles. Computer Science Computing Facility |
Computer Science Computing Facility (CSCF) | University of Waterloo. URL: https://student.cs. uwaterloo.ca/
~cs492/papers/7foundationalprinciples_longer.pdf.
10. Regulation - 2016/679 - EN - gdpr - EUR-Lex. EUR-Lex – Access to European Union law. URL: https://eurlex.europa.eu/eli/reg/2016/679/oj/eng.
11. OWASP Foundation. 2021. OWASP Application Security Verification Standard (ASVS) 4.0. URL:
https://owasp.org/www-project-application-security-verification-standard/.
12. HL7 International. 2023. HL7 FHIR Release 5. URL: https://hl7.org/fhir/.
13. Blobel, B., & Ruotsalainen, P. 2018. Privacy and Security in Personal Health Monitoring Systems. Studies in
Health Technology and Informatics, 251, 3–15. URL: https://doi.org/10.3233/978-1-61499-922-3-3.
14. Ramírez, S. 2023. FastAPI: Concurrency and async/await. URL: https://fastapi.tiangolo.com/async/.
15. SQLAlchemy Authors. 2024. SQLAlchemy 2.0 Unified Tutorial. URL: https://docs.sqlalchemy.org/en/20/
tutorial/.
16. PostgreSQL Global Development Group. 2024. Enumerated Types (8.7). PostgreSQL Documentation. URL:
https://www.postgresql.org/docs/current/datatype-enum.html.

Published

2026-09-15

Issue

Section

Articles