Supporting Privacy Impact Assessment by Model-Based Privacy Analysis

被引:25
|
作者
Ahmadian, Amir Shayan [1 ]
Strueber, Daniel [1 ]
Riediger, Volker [1 ]
Juerjens, Jan [1 ,2 ]
机构
[1] Univ Koblenz Landau, Mainz, Germany
[2] Fraunhofer ISST, Dortmund, Germany
关键词
Privacy impact assessment; Model-based engineering; Privacy; GDPR; Privacy by design;
D O I
10.1145/3167132.3167288
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
According to Article 35 of the General Data Protection Regulation (GDPR), data controllers are obligated to conduct a privacy impact assessment (PIA) to ensure the protection of sensitive data. Failure to properly protect sensitive data may affect data subjects negatively, and damage the reputation of data processors. Existing PIA approaches cannot be easily conducted, since they are mainly abstract or imprecise. Moreover, they lack a methodology to conduct the assessment concerning the design of IT systems. We propose a novel methodology to support PIA by performing model-based privacy and security analyses in the early phases of the system development. In our methodology, the design of a system is analyzed and, where necessary, appropriate security and privacy controls are suggested to improve the design. Hence, this methodology facilitates privacy by design as prescribed in Article 25 of the GDPR. We evaluated our methodology based on three industrial case studies and a quality-based comparison to the state of the art.
引用
收藏
页码:1467 / 1474
页数:8
相关论文
共 50 条
  • [1] Supporting Model-based Privacy Analysis by Exploiting Privacy Level Agreements
    Ahmadian, Amir Shayan
    Juerjens, Jan
    [J]. 2016 8TH IEEE INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM 2016), 2016, : 360 - 365
  • [2] Supporting Privacy Impact Assessments Using Problem-Based Privacy Analysis
    Meis, Rene
    Heisel, Maritta
    [J]. SOFTWARE TECHNOLOGIES (ICSOFT 2015), 2016, 586 : 79 - 98
  • [3] Model-Based Privacy Analysis in Industrial Ecosystems
    Ahmadian, Amir Shayan
    Strueber, Daniel
    Riediger, Volker
    Juerjens, Jan
    [J]. MODELLING FOUNDATIONS AND APPLICATIONS, ECMFA 2017, 2017, 10376 : 215 - 231
  • [4] Model-Based Privacy and Security Analysis with CARiSMA
    Ahmadian, Amir Shayan
    Peldszus, Sven
    Ramadan, Qusai
    Juerjens, Jan
    [J]. ESEC/FSE 2017: PROCEEDINGS OF THE 2017 11TH JOINT MEETING ON FOUNDATIONS OF SOFTWARE ENGINEERING, 2017, : 989 - 993
  • [5] A model-based analysis of tunability in privacy services
    Lundin, Reine
    Lindskog, Stefan
    Brunstrom, Anna
    [J]. FUTURE OF IDENTITY IN THE INFORMATION SOCIETY, 2008, : 343 - 356
  • [6] A Model-Based Privacy Compliance Checker
    Pearson, Siani
    Allison, Damien
    [J]. INTERNATIONAL JOURNAL OF E-BUSINESS RESEARCH, 2009, 5 (02) : 63 - 83
  • [7] Extending Model-Based Privacy Analysis for the Industrial Data Space by Exploiting Privacy Level Agreements
    Ahmadian, Amir Shayan
    Juerjens, Jan
    Strueber, Daniel
    [J]. 33RD ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, 2018, : 1142 - 1149
  • [8] An Attribtue-based Statistic Model for Privacy Impact Assessment
    Wang, Yong
    Liu, Jun
    [J]. 2016 INTERNATIONAL CONFERENCE ON COLLABORATION TECHNOLOGIES AND SYSTEMS (CTS), 2016, : 619 - 621
  • [9] A model-based approach to support privacy compliance
    Alshammari, Majed
    Simpson, Andrew
    [J]. INFORMATION AND COMPUTER SECURITY, 2018, 26 (04) : 437 - 453
  • [10] Robustness analysis of privacy-preserving model-based recommendation schemes
    Bilge, Alper
    Gunes, Ihsan
    Polat, Huseyin
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2014, 41 (08) : 3671 - 3681