Supporting Privacy Impact Assessments Using Problem-Based Privacy Analysis

被引:6
|
作者
Meis, Rene [1 ]
Heisel, Maritta [1 ]
机构
[1] Univ Duisburg Essen, Paluno Ruhr Inst Software Technol, Duisburg, Germany
来源
关键词
Privacy impact assessment; Privacy analysis; Problem frames; Requirements engineering; DESIGN;
D O I
10.1007/978-3-319-30142-6_5
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Privacy-aware software development is gaining more and more importance for nearly all information systems that are developed nowadays. As a tool to force organizations and companies to consider privacy properly during the planning and the execution of their projects, some governments advise to perform privacy impact assessments (PIAs). During a PIA, a report has to be created that summarizes the consequence on privacy the project may have and how the organization or company addresses these consequences. As basis for a PIA, it has to be documented which personal data is collected, processed, stored, and shared with others in the context of the project. Obtaining this information is a difficult task that is not yet well supported by existing methods. In this paper, we present a method based on the problem-based privacy analysis (ProPAn) that helps to elicit the needed information for a PIA systematically from a given set of functional requirements. Our tool-supported method shall reduce the effort that has to be spent to elicit the information needed to conduct a PIA in a way that the information is as complete and consistent as possible.
引用
收藏
页码:79 / 98
页数:20
相关论文
共 50 条
  • [1] Supporting Privacy Impact Assessment by Model-Based Privacy Analysis
    Ahmadian, Amir Shayan
    Strueber, Daniel
    Riediger, Volker
    Juerjens, Jan
    [J]. 33RD ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, 2018, : 1467 - 1474
  • [2] Privacy Points as a Method to Support Privacy Impact Assessments
    Himmel, Julia
    Siebler, Nikolas
    Laegeler, Felix
    Grupe, Marco
    Langweg, Hanno
    [J]. 2015 IEEE/ACM 1ST INTERNATIONAL WORKSHOP ON TECHNICAL AND LEGAL ASPECTS OF DATA PRIVACY AND SECURITY TELERISE 2015, 2015, : 50 - 53
  • [3] Evaluating privacy impact assessments
    Wadhwa, Kush
    Rodrigues, Rowena
    [J]. INNOVATION-THE EUROPEAN JOURNAL OF SOCIAL SCIENCE RESEARCH, 2013, 26 (1-2) : 161 - 180
  • [4] The emergence of privacy impact assessments
    Tancock, David
    Pearson, Siani
    Charlesworth, Andrew
    [J]. HP Laboratories Technical Report, 2010, (63):
  • [5] Analysis of Privacy Impact Assessments within Major Jurisdictions
    Tancock, David
    Pearson, Siani
    Charlesworth, Andrew
    [J]. PST 2010: 2010 EIGHTH INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST, 2010, : 118 - 125
  • [6] Problem-Based Consideration of Privacy-Relevant Domain Knowledge
    Meis, Rene
    [J]. PRIVACY AND IDENTITY MANAGEMENT FOR EMERGING SERVICES AND TECHNOLOGIES, 2014, 421 : 150 - 164
  • [7] Supporting Model-based Privacy Analysis by Exploiting Privacy Level Agreements
    Ahmadian, Amir Shayan
    Juerjens, Jan
    [J]. 2016 8TH IEEE INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM 2016), 2016, : 360 - 365
  • [8] Supporting Privacy by Design Using Privacy Process Patterns
    Diamantopoulou, Vasiliki
    Kalloniatis, Christos
    Gritzalis, Stefanos
    Mouratidis, Haralambos
    [J]. ICT SYSTEMS SECURITY AND PRIVACY PROTECTION, SEC 2017, 2017, 502 : 491 - 505
  • [9] Should Privacy Impact Assessments Be Mandatory?
    Wright, David
    [J]. COMMUNICATIONS OF THE ACM, 2011, 54 (08) : 121 - 131
  • [10] Integrating privacy and ethical impact assessments
    Wright, David
    Friedewald, Michael
    [J]. SCIENCE AND PUBLIC POLICY, 2013, 40 (06) : 755 - 766