2019
DOI: 10.1002/spy2.101
|View full text |Cite
|
Sign up to set email alerts
|

Challenges in assessing privacy impact: Tales from the front lines

Abstract: Data protection impact assessments (DPIAs) aim to identify, rank, and mitigate privacy risks. Even though DPIAs are legally mandated in some cases and privacy professionals perform DPIAs on a daily basis, facilitating the systematic measurement of privacy risks is an open problem. Research on privacy risk measurement often does not take into account the practical needs and requirements for DPIAs in real organizations. In this article, we fill this gap by reporting on focus groups we held with a diverse group o… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1

Citation Types

0
4
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
3
2
2

Relationship

0
7

Authors

Journals

citations
Cited by 7 publications
(4 citation statements)
references
References 18 publications
0
4
0
Order By: Relevance
“…Thus, defining privacy by sensitivity alone is problematic because sensitivity is usually at the discretion of the provider, who may not always act in the consumer's best interests [9][10][11]. There is also an inherent limitation in computing sensitivity as nuances of social interaction are often abstracted away [12], bounded by statistical models and computing resources. Even back in 1969, the measure of "sensitivity" is already recognized as being vary "…depends in large measure upon the context in which it was first given, and the context in which it is later used" [13].…”
Section: Introductionmentioning
confidence: 99%
“…Thus, defining privacy by sensitivity alone is problematic because sensitivity is usually at the discretion of the provider, who may not always act in the consumer's best interests [9][10][11]. There is also an inherent limitation in computing sensitivity as nuances of social interaction are often abstracted away [12], bounded by statistical models and computing resources. Even back in 1969, the measure of "sensitivity" is already recognized as being vary "…depends in large measure upon the context in which it was first given, and the context in which it is later used" [13].…”
Section: Introductionmentioning
confidence: 99%
“…A privacy impact assessment (PIA) addresses the causes of data leakage and privacy breaches [ 19 ]. In PIA, the vital step is to identify information that will originate, terminate in, or pass through the IoT-enabled system.…”
Section: Literature Reviewmentioning
confidence: 99%
“…Verifying compliance of a system against the GDPR. Data protection impact assessment (DPIA) approaches [4], [22], [23] involve extensive reasoning about legal obligations at the basis of legal abstractions, typically encoded in models. These models can subsequently be analyzed to assess and identify problematic data processing operations.…”
Section: Translation Of Legal Obligations To Requirementsmentioning
confidence: 99%