Privacy Requirements: Findings and Lessons Learned in Developing a Privacy Platform

被引:18
|
作者
Gharib, Mohamad [1 ]
Salnitri, Mattia [1 ]
Paja, Elda [1 ]
Giorgini, Paolo [1 ]
Mouratidis, Haralambos [2 ]
Pavlidis, Michalis [2 ]
Ruiz, Jose F. [3 ]
Fernandez, Sandra [4 ]
Della Siria, Andrea [5 ]
机构
[1] Univ Trento, Trento, Italy
[2] Univ Brighton, Brighton, E Sussex, England
[3] Atos, Madrid, Spain
[4] Bambino Gesu Pediat Hosp, Rome, Italy
[5] Business E, Rome, Italy
关键词
Privacy requirements; requirements engineering; elicitation; classification; prioritization; validation;
D O I
10.1109/RE.2016.13
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information practices and systems that make use of personal and health-related information are governed by European laws and regulations to prevent unauthorized use and disclosure. Failure to comply with these laws and regulations results in huge monetary sanctions, which both private companies and public administrations want to avoid. How to comply with these laws, requires understanding the privacy requirements imposed on information systems. A holistic approach to privacy requirements specification calls for understanding not only the requirements derived from law, but also citizens' needs with respect to privacy. In this paper, we report on our experience in conducting privacy requirements engineering as part of a H2020 European Project, namely VisiOn (Visual Privacy Management in User Centric Open Requirements) for the development of a privacy platform to improve the interaction between Public Administrations (PA) and citizens, while guarding the privacy of the latter. Specifically, we present the process for eliciting, classifying, prioritizing, and validating privacy requirements for the two types of users, namely PA and citizen. The process is applied to different cases spanning from healthcare to other e-governmental initiatives, with the active involvement of the corresponding PAs. We report on findings and lessons learned from this experience.
引用
收藏
页码:256 / 265
页数:10
相关论文
共 50 条
  • [21] Mobile Privacy Requirements on Demand
    Nuseibeh, Bashar
    PRODUCT-FOCUSED SOFTWARE PROCESS IMPROVEMENT, 2010, 6156 : 1 - 1
  • [22] Requirements Model for a High-Privacy Decentralized Carbon Emissions Trading Platform
    Alkawasmi, Enas
    Arnautovic, Edin
    Svetinovic, Davor
    2012 IEEE INTERNATIONAL CONFERENCE ON GREEN COMPUTING AND COMMUNICATIONS, CONFERENCE ON INTERNET OF THINGS, AND CONFERENCE ON CYBER, PHYSICAL AND SOCIAL COMPUTING (GREENCOM 2012), 2012, : 450 - 453
  • [23] Understanding Privacy Disclosure in the Online Market for Lemons: Insights and Requirements for Platform Providers
    Engelmann, Andreas
    Schwabe, Gerhard
    INNOVATION THROUGH INFORMATION SYSTEMS, VOL II: A COLLECTION OF LATEST RESEARCH ON TECHNOLOGY ISSUES, 2021, 47 : 422 - 439
  • [24] THE BROADER LESSONS OF PRIVACY LAW
    Viljoen, Salome
    BOSTON UNIVERSITY LAW REVIEW, 2024, 104 (04) : 1131 - 1149
  • [25] Engineering Privacy by Design - Lessons from the Design and Implementation of an Identity Wallet Platform
    Veseli, Fatbardh
    Olvera, Jetzabel Serna
    Pulls, Tobias
    Rannenberg, Kai
    SAC '19: PROCEEDINGS OF THE 34TH ACM/SIGAPP SYMPOSIUM ON APPLIED COMPUTING, 2019, : 1475 - 1483
  • [26] REQUIREMENTS Privacy Requirements in an Age of Increased Sharing
    Breaux, Travis
    IEEE SOFTWARE, 2014, 31 (05) : 24 - 27
  • [28] Communicating Privacy: User Priorities for Privacy Requirements in Home Energy Applications
    Diamond, Lisa
    Froehlich, Peter
    HUMAN-COMPUTER INTERACTION, INTERACT 2021, PT IV, 2021, 12935 : 665 - 675
  • [29] A privacy threat analysis framework: supporting the elicitation and fulfillment of privacy requirements
    Deng, Mina
    Wuyts, Kim
    Scandariato, Riccardo
    Preneel, Bart
    Joosen, Wouter
    REQUIREMENTS ENGINEERING, 2011, 16 (01) : 3 - 32
  • [30] Contact Tracing Apps: Lessons Learned on Privacy, Autonomy, and the Need for Detailed and Thoughtful Implementation
    Hogan, Katie
    Macedo, Briana
    Macha, Venkata
    Barman, Arko
    Jiang, Xiaoqian
    JMIR MEDICAL INFORMATICS, 2021, 9 (07)