Towards Improving Transparency, Intervenability, and Consent in HCI
نویسنده
چکیده
Transparency of personal data processing is enforced by most Western privacy laws, including the new General Data Protection Regulation (GDPR) which will be effective from May 2018. The GDPR specifies that personal data shall be processed lawfully, fairly, and in a transparent manner. It strengthens people’s rights for both ex-ante and ex-post transparency and intervenability. Equally important is the strict legal requirements for informed consent established by the GDPR. On the other hand, the legal privacy principles have Human-Computer Interaction (HCI) implications. People should comprehend the principles, be aware of when the principles may be used, and be able to use them. Transparent information about personal data processing should be concise, intelligible, and provided in an easily accessible form, pursuant to the GDPR. Nonetheless, the answer to the question about howHCI implications can be addressed depends on the attempts to decrease the gap between legal and user-centric transparency, intervenability, and consent. Enhancing individuals’ control in a usable way helps people to be aware of the flow of their personal information, control their data, make informed decisions, and finally preserve their privacy. The objective of this thesis is to propose usable tools and solutions, to enhance people’s control and enforce legal privacy principles, especially transparency, intervenability, and informed consent. To achieve the goal of the thesis, different ways to improve ex-ante transparency and informed consent are investigated by designing and testing new solutions to make effective consent forms. Moreover, ex-post transparency and intervenability are improved by designing a transparency enhancing tool and investigating users’ perceptions of data portability and transparency in the tool. The results of this thesis contribute to the body of knowledge by mapping legal privacy principles to HCI solutions, unveiling HCI problems and answers when aiming for legal compliance, and proposing effective designs to obtain informed consent.
منابع مشابه
Computer-Aided Identification and Validation of Intervenability Requirements
Privacy as a software quality is becoming more important these days and should not be underestimated during the development of software that processes personal data. The privacy goal of intervenability, in contrast to unlinkability (including anonymity and pseudonymity), has so far received little attention in research. Intervenability aims for the empowerment of end-users by keeping their pers...
متن کاملUnderstanding the Privacy Goal Intervenability
Privacy is gaining more and more attention in society and hence, gains more importance as a software quality that has to be considered during software development. A privacy goal that has not yet been deeply studied is the empowerment of end-users to have control over how their personal data is processed by information systems. This privacy goal is called intervenability. Several surveys have s...
متن کاملTowards Patient-Centered Conflicts of Interest Policy
Financial conflicts of interest exist between industry and physicians, and these relationships have the power to influence physicians’ medical practice. Transparency about conflicts matters for ensuring adequate informed consent, controlling healthcare expenditure, and encouraging physicians’ reflection on professionalism. The US Centers for Medicare & Medicaid Services (CMS) launched the Open ...
متن کاملPrivacy Protection Goals and Their Implications for eID Systems
Protection goals such as confidentiality, integrity and availability have proved to be successful in evaluating information security risks and choosing appropriate safeguards. The recently developed privacy-specific protection goals unlinkability, transparency and intervenability complement these classic goals and thereby provide cornerstones to define requirements concerning information securi...
متن کاملIdentifying and Prioritizing Strategies for Improving Financing Systems of Iran's Oil and Gas Industry
The oil and gas industry has huge financial turnover and major projects, especially in the upstream areas, require substantial financing. Hence, securing financing is one of the most important requirements for successful implementation of projects in this industry. In this research, we adopt a descriptive approach and rely on the opinion of experts, to identify and prioritize strategies for imp...
متن کامل