On the Evaluation of Privacy Impact Assessment and Privacy Risk Assessment Methodologies: A Systematic Literature Review

被引:7
|
作者
Wairimu, Samuel [1 ]
Iwaya, Leonardo Horn [1 ]
Fritsch, Lothar [1 ,2 ]
Lindskog, Stefan [1 ]
机构
[1] Karlstad Univ, Dept Math & Comp Sci, Privacy & Secur PriSec Res Grp, S-65188 Karlstad, Sweden
[2] Oslo Metropolitan Univ, Fac Technol Art & Design, Dept Comp Sci, N-0130 Oslo, Norway
关键词
Privacy; Risk management; Systematics; Threat modeling; Bibliographies; Guidelines; Protocols; General Data Protection Regulation; Privacy impact assessment; data protection impact assessment; general data protection regulation; privacy by design; privacy; review; threat modeling; privacy risks; validity; maturity; REQUIREMENTS; DESIGN;
D O I
10.1109/ACCESS.2024.3360864
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Assessing privacy risks and incorporating privacy measures from the onset requires a comprehensive understanding of potential impacts on data subjects. Privacy Impact Assessments (PIAs) offer a systematic methodology for such purposes, which are closely related to Data Protection Impact Assessments (DPIAs), particularly outlined in Article 35 of the General Data Protection Regulation (GDPR). The core of a PIA is a Privacy Risk Assessment (PRA). PRAs can be integrated as part of full-fledged PIAs or independently developed to support PIA processes. Although these methodologies have been identified as essential enablers of privacy by design, their effectiveness has been criticized because of the lack of evidence of their rigorous and systematic evaluation. Hence, we conducted a Systematic Literature Review (SLR) to identify published PIA and PRA methodologies and assess how and to what extent they have been scientifically validated or evaluated. We found that these methodologies are rarely evaluated for their performance in practice, and most of them have only been validated in limited studies. Most validation evidence is found with PRA methodologies. Of the evaluated methodologies, PIAs were the most evaluated, where case studies were the predominant evaluation method. These evaluated methodologies can be easily transferred to an industrial setting or used by practitioners, as they provide evidence of their use in practice. In addition, the findings in this study can be used to inform researchers of the current state-of-the-art, and practitioners can understand the benefits and current limitations of the methodologies and adopt evidence-based practices.
引用
收藏
页码:19625 / 19650
页数:26
相关论文
共 50 条
  • [31] Privacy Risk Assessment of Individual Psychometric Profiles
    Mariani, Giacomo
    Monreale, Anna
    Naretto, Francesca
    DISCOVERY SCIENCE (DS 2021), 2021, 12986 : 411 - 421
  • [32] A Privacy Risk Assessment Model for Open Data
    Ali-Eldin, Amr
    Zuiderwijk, Anneke
    Janssen, Marijn
    BUSINESS MODELING AND SOFTWARE DESIGN, BMSD 2017, 2018, 309 : 186 - 201
  • [33] PRADroid: Privacy Risk Assessment for Android Applications
    Yang, Yang
    Du, Xuehui
    Yang, Zhi
    2021 IEEE 5TH INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY (ICCSP), 2021, : 90 - 95
  • [34] An Ontology for Privacy Requirements via a Systematic Literature Review
    Gharib, Mohamad
    Giorgini, Paolo
    Mylopoulos, John
    JOURNAL ON DATA SEMANTICS, 2020, 9 (04) : 123 - 149
  • [35] Privacy Design Strategies and the GDPR: A Systematic Literature Review
    Saltarella, Marco
    Desolda, Giuseppe
    Lanzilotti, Rosa
    HCI FOR CYBERSECURITY, PRIVACY AND TRUST (HCI-CPT 2021), 2021, 12788 : 241 - 257
  • [36] A Systematic Literature Review on Privacy by Design in the Healthcare Sector
    Semantha, Farida Habib
    Azam, Sami
    Yeo, Kheng Cher
    Shanmugam, Bharanidharan
    ELECTRONICS, 2020, 9 (03)
  • [37] Security and Privacy for Big Data: A Systematic Literature Review
    Nelson, Boel
    Olovsson, Tomas
    2016 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2016, : 3693 - 3702
  • [38] Privacy by Design and Software Engineering a Systematic Literature Review
    Andrade, Vinicius Camargo
    Gomes, Rhodrigo Deda
    Reinehr, Sheila
    Freitas, Cinthia Obladen de A.
    Malucelli, Andreia
    PROCEEDINGS OF THE 21TH BRAZILIAN SYMPOSIUM ON SOFTWARE QUALITY, SBOS 2022, 2022,
  • [39] A Review on Privacy and Security Assessment of Cloud Computing
    Jain, Khushboo
    Gupta, Manali
    Abraham, Ajith
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2021, 16 (05): : 161 - 168
  • [40] Privacy:: a review of the literature
    Leino-Kilpi, H
    Välimäki, M
    Dassen, T
    Gasull, M
    Lemonidou, C
    Scott, A
    Arndt, M
    INTERNATIONAL JOURNAL OF NURSING STUDIES, 2001, 38 (06) : 663 - 671