Generating evidence on privacy outcomes to inform privacy risk management: A way forward?

被引:0
|
作者
Strech, Daniel [1 ]
Haven, Tamarinde [1 ]
Madai, Vince I. [1 ,2 ]
Meurers, Thierry [3 ]
Prasser, Fabian [3 ]
机构
[1] Charite Univ Med Berlin, Berlin Inst Hlth, QUEST Ctr Responsible Res, Charitepl 1, D-10117 Berlin, Germany
[2] Birmingham City Univ, City Ctr Campus, Sch Comp & Digital Technol, City Ctr Campus, Birmingham B4 7XG, England
[3] Charite Univ Med Berlin, Berlin Inst Hlth, Ctr Hlth Data Sci, Charitepl 1, D-10117 Berlin, Germany
关键词
Privacy; Risk management; Data sharing; Evidence;
D O I
10.1016/j.jbi.2022.104257
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Effective and efficient privacy risk management (PRM) is a necessary condition to support digitalization in health care and secondary use of patient data in research. To reduce privacy risks, current PRM frameworks are rooted in an approach trying to reduce undesired technical/organizational outcomes such as broken encryption or unintentional data disclosure. Comparing this with risk management in preventive or therapeutic medicine, a key difference becomes apparent: in health-related risk management, medicine focuses on person-specific health outcomes, whereas PRM mostly targets more indirect, technical/organizational outcomes. In this paper, we illustrate and discuss how a PRM approach based on evidence of person-specific privacy outcomes might look using three consecutive steps: i) a specification of undesired person-specific privacy outcomes, ii) empirical assessments of their frequency and severity, and iii) empirical studies on how effectively the available PRM interventions reduce their frequency or severity. After an introduction of these three steps, we cover their status quo and outline open questions and PRM-specific challenges in need of further conceptual clarification and feasibility studies. Specific challenges of an outcome-oriented approach to PRM include the potential delays between concrete threats manifesting and the resulting person/group-specific privacy outcomes. Moreover, new ways of exploiting privacy-sensitive information to harm individuals could be developed in the future. The challenges described are of technical, legal, ethical, financial and resource-oriented nature. In health research, however, there is explicit discussion about how to overcome such challenges to make important outcome-based assessments as feasible as possible. This paper concludes that it might be the time to have this discussion in the PRM field as well.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] Accountability as a Way Forward for Privacy Protection in the Cloud
    Pearson, Siani
    Charlesworth, Andrew
    CLOUD COMPUTING, PROCEEDINGS, 2009, 5931 : 131 - +
  • [2] Privacy risk management
    Tang, Andrea
    ISACA Journal, 2020, 4 : 32 - 42
  • [3] Protection of privacy in Bangladesh: issues, challenges and way forward
    Islam, Md. Toriqul
    INTERNATIONAL JOURNAL OF HUMAN RIGHTS, 2024, 28 (01): : 89 - 124
  • [4] Privacy and data sharing: The way forward for public services? - Editorial
    Computer Law and Security Report, 2002, 18 (03):
  • [5] Challenges Posed by Biometric Technology on Data Privacy Protection and the Way Forward
    Woo, Roderick B.
    ETHICS AND POLICY OF BIOMETRICS, 2010, 6005 : 1 - 6
  • [6] Risk Management and Privacy Violation Detection in the PoSeID-on Data Privacy Platform
    Silva P.
    Casaleiro R.
    Simões P.
    Antunes N.
    Curado M.
    Monteiro E.
    SN Computer Science, 2020, 1 (4)
  • [7] Data protection and privacy: a model for evidence management
    Freund, Gislaine Parra
    de Macedo, Douglas Dyllon Jeronimo
    Fagunde, Priscila Basto
    EM QUESTAO, 2023, 29
  • [8] A Forward Secure RFID Privacy Protection Scheme with Two-way Authentication
    Gan Yong
    He Lei
    Zhang Tao
    Li Na-na
    APPLIED MECHANICS AND MECHANICAL ENGINEERING, PTS 1-3, 2010, 29-32 : 2262 - 2266
  • [9] Privacy and Informational Self-determination Through Informed Consent: The Way Forward
    Gharib, Mohamad
    COMPUTER SECURITY: ESORICS 2021 INTERNATIONAL WORKSHOPS, 2022, 13106 : 171 - 184
  • [10] Integrating privacy impact assessment in risk management
    Wright, David
    Wadhwa, Kush
    Lagazio, Monica
    Raab, Charles
    Charikane, Eric
    INTERNATIONAL DATA PRIVACY LAW, 2014, 4 (02) : 155 - 170