Dealing with Privacy Obligations: Important Aspects and Technical Approaches
نویسنده
چکیده
obligations, privacy, policies, enforcement, monitoring, stickiness, accountability, identity management The management and enforcement of privacy obligations is a challenging task: it involves legal, organizational, behavioral and technical aspects. In particular, the management of privacy obligations for identity and confidential data can require ongoing efforts, both in the short and very long term. It can be affected by events. Work has already been done for the management of obligations subordinated to authorization aspects (triggered by interactions and transactional events) and simple long-term obligations for data retention. Dealing with ongoing and long-term aspects of obligations is still a green field and open to research. This area is of particular relevance for enterprises, organizations and government agencies that deal with personal identity information. Privacy and data protection laws already dictate obligations involving ongoing and longterm constraints and duties. This paper explores and analyses the explicit management of privacy obligations for identity information by considering privacy obligations as first-class citizens. We focus on the technical aspects even if we recognize that the problem cannot be solved only by deploying technological solutions. Mechanisms are required to represent, manage, monitor and enforce obligation policies in complex and heterogeneous environments. Policy-driven scheduling mechanisms coupled with secure workflows and auditing techniques can be useful to address aspects of the problem. It is also important to be able to strongly couple these policies to confidential data, track their storage, distribution and deal with relevant events. Our research is work in progress: we illustrate some of our technical work and investigation in this space.
منابع مشابه
Dealing with Privacy Obligations in Enterprises
This paper focuses on the problem of dealing with privacy obligations in enterprises. Privacy obligations dictate expected behaviours, tasks and constraints that must be satisfied when handling personal and confidential data. This includes being compliant with data retention policies and satisfying constraints dictated by customers’ opt-in and opt-out choices. It is important for enterprises to...
متن کاملHandling Privacy Obligations and Constraints to Underpin Trust and Assurance
Trust is important to enable interactions on the web, in particular with enterprises. The trust that people have in enterprises can be built, reinforced or modified via a variety of means and tools, including personal experience, analysis of prior history, recommendations, certification and auditing by known authorities. The behaviour of an enterprise and the fact that it performs as predicted ...
متن کاملA System to Handle Privacy Obligations in Enterprises
Privacy obligations dictate expectations and duties that need to be carried out by enterprises when storing, processing and disclosing personal data. Privacy obligations can be defined by data subjects, by laws and/or enterprises’ internal guidelines. They require enterprises to deal with data governance and data lifecycle management activities, including data retention and deletion aspects, no...
متن کاملA Systemic Approach to Automate Privacy Policy Enforcement in Enterprises
It is common practice for enterprises and other organisations to ask people to disclose their personal data in order to grant them access to services and engage in transactions. This practice is not going to disappear, at least in the foreseeable future. Most enterprises need personal information to run their businesses and provide the required services, many of whom have turned to identity man...
متن کاملPrivacy Management in User-Centred Multi-agent Systems
In all user-centred agent-based applications, for instance in the context of ambient computing, the user agent is often faced to a difficult trade-off between the protection of its own privacy, and the fluidity offered by the services. In existing applications, the choice is almost never on the user’s side, even though the law grants him a number of rights in order to guarantee his privacy. We ...
متن کامل