A privacy scoring framework: Automation of privacy compliance and risk evaluation with standard indicators

被引:2
|
作者
Kim, Nakyoung [1 ]
Oh, Hyeontaek [1 ]
Choi, Jun Kyun [2 ]
机构
[1] Korea Adv Inst Sci & Technol, Inst Informat Technol Convergence, Daejeon, South Korea
[2] Korea Adv Inst Sci & Technol, Sch Elect Engn, Daejeon, South Korea
基金
新加坡国家研究基金会;
关键词
Personal data; Privacy indicator; Risk evaluation; Privacy policy analysis; jkchoi59@kaist; edu (J; K; Choi);
D O I
10.1016/j.jksuci.2022.12.019
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Personal data have become the key to data-driven services and applications whereas privacy require-ments are now strongly imposed by regulations. Meanwhile, people find it difficult to understand whether the services and applications handle personal data to comply with their agreements and regu-lations. Therefore, the need for privacy indicators, which summarize privacy contents as forms of privacy scoring, labels, etc., has increased to empower the users' rights by providing understandable information about privacy. For firm privacy indicators, proper criteria and methods for evaluating the level of privacy risks and compliance are required. Accordingly, this paper proposes a privacy scoring framework for ser-vices in the context of handling personal data, inspired by six standardized indicators. This paper intro-duces detailed information on standardized indicators and proposes privacy indicators to quantify privacy scores. Also, this paper proposes methods for evaluating privacy policy based on a set of machine learning-based hierarchical binary classifiers and processes for quantifying the level of privacy risks and compliance from privacy-related information. Through analyzing privacy policies and data access lists of more than 10,000 mobile applications on Google Play Store and investigating case studies on privacy scoring of some mobile applications, this paper shows the feasibility of the proposed framework.& COPY; 2023 The Authors. Published by Elsevier B.V. on behalf of King Saud University. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).
引用
收藏
页码:514 / 525
页数:12
相关论文
共 50 条
  • [21] Privacy-Preserving Scoring of Tree Ensembles: A Novel Framework for AI in Healthcare
    Fritchman, Kyle
    Saminathan, Keerthanaa
    Dowsley, Rafael
    Hughes, Tyler
    De Cock, Martine
    Nascimento, Anderson
    Teredesai, Ankur
    2018 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2018, : 2413 - 2422
  • [22] On the Evaluation of Privacy Impact Assessment and Privacy Risk Assessment Methodologies: A Systematic Literature Review
    Wairimu, Samuel
    Iwaya, Leonardo Horn
    Fritsch, Lothar
    Lindskog, Stefan
    IEEE ACCESS, 2024, 12 : 19625 - 19650
  • [23] Privacy Scoring of Social Network User Profiles Through Risk Analysis
    De, Sourya Joyee
    Imine, Abdessamad
    RISKS AND SECURITY OF INTERNET AND SYSTEMS, CRISIS 2017, 2018, 10694 : 227 - 243
  • [24] The Role of Risk Perceptions in Privacy Concerns Evaluation
    Rohunen, Anna
    Markkula, Jouni
    2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, : 1029 - 1036
  • [25] Analysis and Compliance Evaluation of Cookies Setting Websites with Privacy Protection Laws
    Aladeokin, Adeyemi
    Zavarsky, Pavol
    Memon, Neelam
    2017 TWELFTH INTERNATIONAL CONFERENCE ON DIGITAL INFORMATION MANAGEMENT (ICDIM), 2017, : 121 - 126
  • [26] Developing A Privacy Risk Analysis Framework for Heterogeneous IoT Network
    Gupta, Sanonda Datta
    2022 30TH IEEE INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE (RE 2022), 2022, : 207 - 212
  • [27] pQUANT: A User-Centered Privacy Risk Analysis Framework
    Tesfay, Welderufael B.
    Nastouli, Dimitra
    Stamatiou, Yannis C.
    Serna, Jetzabel M.
    RISKS AND SECURITY OF INTERNET AND SYSTEMS (CRISIS 2019), 2020, 12026 : 3 - 16
  • [28] A Framework for a Privacy-aware Feature Selection Evaluation Measure
    Jafer, Yasser
    Matwin, Stan
    Sokolova, Marina
    2015 THIRTEENTH ANNUAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2015, : 62 - 69
  • [29] Comprehensive evaluation of privacy policies using the contextual integrity framework
    Ghahremani, Shahram
    Nguyen, Uyen Trang
    SECURITY AND PRIVACY, 2024, 7 (04)
  • [30] An Evaluation Framework for Assessing the Impact of Location Privacy on Geospatial Analysis
    Zurbaran, Mayra A.
    Salazar, Augusto
    Brovelli, Maria Antonia
    Wightman, Pedro M.
    IEEE ACCESS, 2020, 8 : 158224 - 158236