Supporting Data Protection by Design and Default

被引:3
|
作者
Lodge, Tom [1 ]
Crabtree, Andy [1 ]
Brown, Anthony [2 ]
机构
[1] Univ Nottingham, Sch Comp Sci, Nottingham, England
[2] Univ Nottingham, Horizon Digital Econ Res, Nottingham, England
基金
英国工程与自然科学研究理事会;
关键词
Internet of Things; edge computing; Databox; data protection; GDPR; trusted application development; IDE;
D O I
10.1145/3267305.3274151
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In the domestic IoT domain, data is often collected by physical sensors and actuators embedded in the household and used to provide contextually relevant services to end users. Given that this data is often personal, the EU's General Data Protection Regulation can implicate IoT app developers, requiring them to adhere to "data protection by design and default" to ensure safeguards that protect a data subject's rights. Yet the simple-to-use task-oriented development environments that are commonly used to build domestic IoT apps provide little support for developers to engage with data protection measures. In this paper we present an overview of an IoT development environment that has been designed to help developers engage with data protection at app design time. We describe a data tracking feature, which makes all personal flows in an app explicit at development time and which provides the foundation for an additonal set of data protection measures, including personal data disclosure risk assessments, transparency of processing and runtime inspection.
引用
收藏
页码:901 / 910
页数:10
相关论文
共 50 条
  • [1] Data Protection by Design and by Default a la European General Data Protection Regulation
    Hansen, Marit
    [J]. PRIVACY AND IDENTITY MANAGEMENT: FACING UP TO NEXT STEPS, 2016, 498 : 27 - 38
  • [2] Data protection by design and default as a preventive legal obligation of home automation
    Reza, Idoia Landa
    [J]. RED-REVISTA ELECTRONICA DE DIREITO, 2024, 34 (02): : 206 - 228
  • [3] The trouble with Article 25 (and how to fix it): the future of data protection by design and default
    Rubinstein, Ira S.
    Good, Nathaniel
    [J]. INTERNATIONAL DATA PRIVACY LAW, 2020, 10 (01) : 37 - 56
  • [4] Designing for Privacy and its Legal Framework: Data Protection by Design and Default for the Internet of Things
    Suwannakit, Methinee
    [J]. INTERNATIONAL DATA PRIVACY LAW, 2019, 9 (04) : 302 - 304
  • [5] Curtailing the Cookie Monster through Data Protection by Default
    Naithani, Paarth
    [J]. TILBURG LAW REVIEW-JOURNAL OF INTERNATIONAL AND EUROPEAN LAW, 2022, 27 (01): : 22 - 36
  • [6] Supporting Users in Data Outsourcing and Protection in the Cloud
    di Vimercati, S. De Capitani
    Foresti, S.
    Livraga, G.
    Samarati, P.
    [J]. CLOUD COMPUTING AND SERVICES SCIENCE, CLOSER 2016, 2017, 740 : 3 - 15
  • [7] The information system supporting the Data Protection Law
    Raic, G
    [J]. MEDINFO 2001: PROCEEDINGS OF THE 10TH WORLD CONGRESS ON MEDICAL INFORMATICS, PTS 1 AND 2, 2001, 84 : 1281 - 1281
  • [8] Data protection and fairness by design
    Rachadell, J.
    [J]. EUROPEAN JOURNAL OF PUBLIC HEALTH, 2022, 32
  • [9] DataBlinder: A distributed data protection middleware supporting search and computation on encrypted data
    Heydari, Emad
    Lagaisse, Bert
    Joosen, Wouter
    Aly, Abdelrahaman
    Brackx, Michael
    [J]. PROCEEDINGS OF THE 2019 20TH INTERNATIONAL MIDDLEWARE CONFERENCE INDUSTRIAL TRACK (MIDDLEWARE INDUSTRY '19), 2019, : 50 - 57
  • [10] Tool-supporting Data Protection Impact Assessments with CAIRIS
    Coles, Joshua
    Faily, Shamal
    Ki-Aries, Duncan
    [J]. 2018 IEEE 5TH INTERNATIONAL WORKSHOP ON EVOLVING SECURITY & PRIVACY REQUIREMENTS ENGINEERING (ESPRE 2018), 2018, : 21 - 27