3.8 Article

Practical evaluation of a reference architecture for the management of privacy level agreements

Journal

INFORMATION AND COMPUTER SECURITY
Volume 26, Issue 5, Pages 711-730

Publisher

EMERALD GROUP PUBLISHING LTD
DOI: 10.1108/ICS-04-2019-0052

Keywords

Security requirements engineering; Privacy requirements engineering; Practical evaluation; Privacy level agreement

Ask authors/readers for more resources

Purpose The enforcement of the General Data Protection Regulation imposes specific privacy- and -security related requirements that any organisation that processes European Union citizens' personal data must comply with. The application of privacy- and security-by-design principles are assisting organisation in achieving compliance with the Regulation. The purpose of this study is to assist data controllers in their effort to achieve compliance with the new Regulation, by proposing the adoption of the privacy level agreement (PLA). A PLA is considered as a formal way for the data controllers and the data subjects to mutually agree the privacy settings of a service provisioned. A PLA supports privacy management, by analysing privacy threats, vulnerabilities and information systems' trust relationships. Design/methodology/approach However, the concept of PLA has only been proposed on a theoretical level. To this aim, two different domains have been selected acting as real-life case studies, the public administration and the health care, where special categories of personal data are processed. Findings The results of the evaluation of the adoption of the PLA by the data controllers are positive. Furthermore, they indicate that the adoption of such an agreement facilitates data controllers in demonstrating transparency of their processes. Regarding data subjects, the evaluation process revealed that the use of the PLA increases trust levels on data controllers. Originality/value This paper proposes a novel reference architecture to enable PLA management in practice and reports on the application and evaluation of PLA management.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

3.8
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available