3.8 Proceedings Paper

Supporting Privacy Impact Assessment by Model-Based Privacy Analysis

Journal

33RD ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING
Volume -, Issue -, Pages 1467-1474

Publisher

ASSOC COMPUTING MACHINERY
DOI: 10.1145/3167132.3167288

Keywords

Privacy impact assessment; Model-based engineering; Privacy; GDPR; Privacy by design

Funding

  1. Design For Future Managed Software Evolution (DFG's SPP 1593) [JU 2734/2-2]
  2. Engineering Responsible Information Systems (University of Koblenz Landau)

Ask authors/readers for more resources

According to Article 35 of the General Data Protection Regulation (GDPR), data controllers are obligated to conduct a privacy impact assessment (PIA) to ensure the protection of sensitive data. Failure to properly protect sensitive data may affect data subjects negatively, and damage the reputation of data processors. Existing PIA approaches cannot be easily conducted, since they are mainly abstract or imprecise. Moreover, they lack a methodology to conduct the assessment concerning the design of IT systems. We propose a novel methodology to support PIA by performing model-based privacy and security analyses in the early phases of the system development. In our methodology, the design of a system is analyzed and, where necessary, appropriate security and privacy controls are suggested to improve the design. Hence, this methodology facilitates privacy by design as prescribed in Article 25 of the GDPR. We evaluated our methodology based on three industrial case studies and a quality-based comparison to the state of the art.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

3.8
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available