Towards Scalable Management of Privacy Obligations in Enterprises
نویسنده
چکیده
Privacy management is important for enterprises that collect, store, access and disclose personal data. Among other things, the management of privacy includes dealing with privacy obligations: privacy obligations dictate duties and expectations an enterprise has to comply with, in terms of data retention, deletion, notice requirements, etc. This is a green area open to research and innovation. This paper provides an overview of the work we have done in this space to explicitly represent, enforce and monitor privacy obligations: this includes an obligation management model and framework, a working prototype and its integration both in the context of PRIME project and with an HP identity management solution. This paper then focuses on an important issue: how to make our approach scalable, in case large amounts of personal data have to be managed. Thanks to our integration work and the feedback we received, we learnt a few lessons on how users and enterprises are likely to deal with privacy obligations. We describe these findings and how to leverage them. Specifically, in the final part of this paper we introduce and discuss the concepts of parametric obligation and hybrid obligation management model and how this could help to make our system both scalable and flexible at the same time. Our work is in progress. Further research and development is going to be done in the context of the PRIME project and an HP Labs project.
منابع مشابه
A System to Handle Privacy Obligations in Enterprises
Privacy obligations dictate expectations and duties that need to be carried out by enterprises when storing, processing and disclosing personal data. Privacy obligations can be defined by data subjects, by laws and/or enterprises’ internal guidelines. They require enterprises to deal with data governance and data lifecycle management activities, including data retention and deletion aspects, no...
متن کاملDealing with Privacy Obligations in Enterprises
This paper focuses on the problem of dealing with privacy obligations in enterprises. Privacy obligations dictate expected behaviours, tasks and constraints that must be satisfied when handling personal and confidential data. This includes being compliant with data retention policies and satisfying constraints dictated by customers’ opt-in and opt-out choices. It is important for enterprises to...
متن کاملA Systematic Approach to Privacy Enforcement and Policy Compliance Checking in Enterprises
Privacy management is important for enterprises that handle personal data: they must deal with privacy laws and people’s expectations. Currently much is done by means of manual processes, which make them difficult and expensive to comply. Key enterprises’ requirements include: automation, simplification, cost reduction and leveraging of current identity management solutions. This paper describe...
متن کاملA Systemic Approach to Automate Privacy Policy Enforcement in Enterprises
It is common practice for enterprises and other organisations to ask people to disclose their personal data in order to grant them access to services and engage in transactions. This practice is not going to disappear, at least in the foreseeable future. Most enterprises need personal information to run their businesses and provide the required services, many of whom have turned to identity man...
متن کاملExtending HP Identity Management Solutions to Enforce Privacy Policies and Obligations for Regulatory Compliance by Enterprises
This paper describes issues and requirements related to privacy management as an aspect of improved governance in enterprises. It focuses on the privacy enforcement aspect, in particular related to privacy-aware access control and enforcement of privacy obligations: this is still a green field and, at the same time, is a key aspect to be taken into account to ensure compliance both with regulat...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2006