Personal Data Management for Privacy Engineering: An Abstract Personal Data Lifecycle Model

نویسندگان

  • Andrew Simpson
  • Majed Alshammari
چکیده

It is well understood that processing personal data without effective data management models may lead to privacy violations. Such concerns have motivated the development of privacy-preserving systems and legal frameworks such as the EU General Data Protection Regulation. However, there is a disconnect between policy-makers and engineers with respect to the meaning of privacy. In addition, it is challenging to establish that a system complies with its privacy requirements, to provide technical assurances, and to meet data subjects’ expectations. In the spirit of engineering privacy, we propose an abstract personal data lifecycle (APDL) model to support the management of personal data. The APDL model represents data processing activities in a way that is amenable to analysis using an appropriate privacy risk management model. As such, it helps facilitate the identification of potentially harmful data processing activities; it also has the potential to demonstrate compliance with legal frameworks and standards.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Abstract Privacy Policy Framework: Addressing Privacy Problems in SOA

Privacy Policy Framework: Addressing Privacy Problems in SOA Laurent Bussard and Ulrich Pinsdorf European Microsoft Innovation Center, Aachen, Germany {LBussard, Ulrich.Pinsdorf}@microsoft.com Abstract. This paper argues that privacy policies in SOA needs a lifeThis paper argues that privacy policies in SOA needs a lifecycle model. We formalize the lifecycle of personal data and associated priv...

متن کامل

A Method for Data Minimization in Personal Information Sharing

A fundamental privacy principle, which is enforced in many privacy-enhancing technologies, is data minimization, i.e. the amount of personal data that are revealed to others and extend to which they are processed should be minimized. Privacy-enhancing identity management is important for processing personal data, the purpose of which is to protect personal data. This is especially relevant for ...

متن کامل

ارایه یک روش جدید انتشار داده‌ها با حفظ محرمانگی با هدف بهبود دقّت طبقه‌‌بندی روی داده‌های گمنام

Data collection and storage has been facilitated by the growth in electronic services, and has led to recording vast amounts of personal information in public and private organizations databases. These records often include sensitive personal information (such as income and diseases) and must be covered from others access. But in some cases, mining the data and extraction of knowledge from thes...

متن کامل

On Privacy-aware Information Lifecycle Management in Enterprises: Setting the Context

This paper aims at setting the context for privacy-aware information lifecycle management within enterprises, i.e. the process of handling the lifecycle of personal and confidential information in a way that is compliant with privacy laws and people’s expectations (including data retention, deletion, notifications, data transformation, etc.). Despite the fact that enterprises are already using ...

متن کامل

A System to Handle Privacy Obligations in Enterprises

Privacy obligations dictate expectations and duties that need to be carried out by enterprises when storing, processing and disclosing personal data. Privacy obligations can be defined by data subjects, by laws and/or enterprises’ internal guidelines. They require enterprises to deal with data governance and data lifecycle management activities, including data retention and deletion aspects, no...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2017