A privacy scoring framework: Automation of privacy compliance and risk evaluation with standard indicators

被引:2
|
作者
Kim, Nakyoung [1 ]
Oh, Hyeontaek [1 ]
Choi, Jun Kyun [2 ]
机构
[1] Korea Adv Inst Sci & Technol, Inst Informat Technol Convergence, Daejeon, South Korea
[2] Korea Adv Inst Sci & Technol, Sch Elect Engn, Daejeon, South Korea
基金
新加坡国家研究基金会;
关键词
Personal data; Privacy indicator; Risk evaluation; Privacy policy analysis; jkchoi59@kaist; edu (J; K; Choi);
D O I
10.1016/j.jksuci.2022.12.019
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Personal data have become the key to data-driven services and applications whereas privacy require-ments are now strongly imposed by regulations. Meanwhile, people find it difficult to understand whether the services and applications handle personal data to comply with their agreements and regu-lations. Therefore, the need for privacy indicators, which summarize privacy contents as forms of privacy scoring, labels, etc., has increased to empower the users' rights by providing understandable information about privacy. For firm privacy indicators, proper criteria and methods for evaluating the level of privacy risks and compliance are required. Accordingly, this paper proposes a privacy scoring framework for ser-vices in the context of handling personal data, inspired by six standardized indicators. This paper intro-duces detailed information on standardized indicators and proposes privacy indicators to quantify privacy scores. Also, this paper proposes methods for evaluating privacy policy based on a set of machine learning-based hierarchical binary classifiers and processes for quantifying the level of privacy risks and compliance from privacy-related information. Through analyzing privacy policies and data access lists of more than 10,000 mobile applications on Google Play Store and investigating case studies on privacy scoring of some mobile applications, this paper shows the feasibility of the proposed framework.& COPY; 2023 The Authors. Published by Elsevier B.V. on behalf of King Saud University. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).
引用
收藏
页码:514 / 525
页数:12
相关论文
共 50 条
  • [31] Performance Evaluation of a Privacy-Enhancing Framework for Personalized Websites
    Wang, Yang
    Kobsa, Alfred
    USER MODELING, ADAPTATION, AND PERSONALIZATION, PROCEEDINGS, 2009, 5535 : 78 - 89
  • [32] Privacy Risk Evaluation of Re-identification of Pseudonyms
    Takeuchi, Yuma
    Kitajima, Shogo
    Fukushima, Kazuya
    Mambo, Masahiro
    2019 14TH ASIA JOINT CONFERENCE ON INFORMATION SECURITY (ASIAJCIS 2019), 2019, : 165 - 172
  • [33] Compliance Is Doable! A Framework for Navigating Privacy Regulations in Public Health and Public Safety Partnerships
    Worobiec, Michele
    Firesheets, Kelly C.
    JOURNAL OF PUBLIC HEALTH MANAGEMENT AND PRACTICE, 2022, 28 : S367 - S371
  • [34] A Privacy Policy Text Compliance Reasoning Framework with Large Language Models for Healthcare Services
    Chen, Jintao
    Wang, Fan
    Pang, Shengye
    Chen, Mingshuai
    Xi, Meng
    Zhao, Tiancheng
    Yin, Jianwei
    TSINGHUA SCIENCE AND TECHNOLOGY, 2025, 30 (04): : 1831 - 1845
  • [35] A GDPR International Transfer Compliance Framework Based on an Extended Data Privacy Vocabulary (DPV)
    Hickey, David
    Brennan, Rob
    LEGAL KNOWLEDGE AND INFORMATION SYSTEMS, 2021, 346 : 161 - 170
  • [36] VOIP FOR TELEREHABILITATION: A RISK ANALYSIS FOR PRIVACY, SECURITY AND HIPAA COMPLIANCE: PART II
    Watzlaf, Valerie J. M.
    Moeini, Sohrab
    Matusow, Laura
    Firouzan, Patti
    INTERNATIONAL JOURNAL OF TELEREHABILITATION, 2011, 3 (01): : 3 - 9
  • [37] Risk-Based Packet Routing for Privacy and Compliance-Preserving SDN
    Budhraja, Karan K.
    Malvankar, Abhishek
    Bahrami, Mehdi
    Kundu, Chinmay
    Kundu, Ashish
    Singhal, Mukesh
    2017 IEEE 10TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD), 2017, : 761 - 765
  • [38] Towards User-centered Privacy Risk Detection and Quantification Framework
    Tesfay, Welderufael B.
    Serna-Olvera, Jetzabel
    2016 8TH IFIP INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES, MOBILITY AND SECURITY (NTMS), 2016,
  • [39] Integrated Security, Safety, and Privacy Risk Assessment Framework for Medical Devices
    Yaqoob, Tahreem
    Abbas, Haider
    Shafqat, Narmeen
    IEEE JOURNAL OF BIOMEDICAL AND HEALTH INFORMATICS, 2020, 24 (06) : 1752 - 1761
  • [40] An End-to-end Framework for Privacy Risk Assessment of AI Models
    Goldsteen, Abigail
    Shachor, Shlomit
    Raznikov, Natalia
    PROCEEDINGS OF THE 15TH ACM INTERNATIONAL CONFERENCE ON SYSTEMS AND STORAGE, SYSTOR 2022, 2022, : 142 - 142