3.8 Proceedings Paper

Supporting Privacy Impact Assessment by Model-Based Privacy Analysis

期刊

出版社

ASSOC COMPUTING MACHINERY
DOI: 10.1145/3167132.3167288

关键词

Privacy impact assessment; Model-based engineering; Privacy; GDPR; Privacy by design

资金

  1. Design For Future Managed Software Evolution (DFG's SPP 1593) [JU 2734/2-2]
  2. Engineering Responsible Information Systems (University of Koblenz Landau)

向作者/读者索取更多资源

According to Article 35 of the General Data Protection Regulation (GDPR), data controllers are obligated to conduct a privacy impact assessment (PIA) to ensure the protection of sensitive data. Failure to properly protect sensitive data may affect data subjects negatively, and damage the reputation of data processors. Existing PIA approaches cannot be easily conducted, since they are mainly abstract or imprecise. Moreover, they lack a methodology to conduct the assessment concerning the design of IT systems. We propose a novel methodology to support PIA by performing model-based privacy and security analyses in the early phases of the system development. In our methodology, the design of a system is analyzed and, where necessary, appropriate security and privacy controls are suggested to improve the design. Hence, this methodology facilitates privacy by design as prescribed in Article 25 of the GDPR. We evaluated our methodology based on three industrial case studies and a quality-based comparison to the state of the art.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

3.8
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据