Dealing with Privacy Obligations in Enterprises
نویسنده
چکیده
This paper focuses on the problem of dealing with privacy obligations in enterprises. Privacy obligations dictate expected behaviours, tasks and constraints that must be satisfied when handling personal and confidential data. This includes being compliant with data retention policies and satisfying constraints dictated by customers’ opt-in and opt-out choices. It is important for enterprises to address this problem to preserve their reputation and brand and be compliant with legislation and customers’ requirements. This paper describes important related issues and requirements to be kept into account, including dealing with transactional, ongoing and long-term obligations. Technical work has already been done for the management of obligations subordinated to authorization aspects and simple obligations for data retention: however, dealing with ongoing and long-term aspects of obligations is still a green field and open to research. We introduce and describe a trusted system, currently under research and development at HP Labs, dealing with the monitoring, enforcement and tracking of privacy obligations: this system will support the strong association of privacy obligations to data, accountability management and users’ involvement.
منابع مشابه
Dealing with Privacy Obligations: Important Aspects and Technical Approaches
obligations, privacy, policies, enforcement, monitoring, stickiness, accountability, identity management The management and enforcement of privacy obligations is a challenging task: it involves legal, organizational, behavioral and technical aspects. In particular, the management of privacy obligations for identity and confidential data can require ongoing efforts, both in the short and very lo...
متن کاملHandling Privacy Obligations and Constraints to Underpin Trust and Assurance
Trust is important to enable interactions on the web, in particular with enterprises. The trust that people have in enterprises can be built, reinforced or modified via a variety of means and tools, including personal experience, analysis of prior history, recommendations, certification and auditing by known authorities. The behaviour of an enterprise and the fact that it performs as predicted ...
متن کاملTowards Scalable Management of Privacy Obligations in Enterprises
Privacy management is important for enterprises that collect, store, access and disclose personal data. Among other things, the management of privacy includes dealing with privacy obligations: privacy obligations dictate duties and expectations an enterprise has to comply with, in terms of data retention, deletion, notice requirements, etc. This is a green area open to research and innovation. ...
متن کاملA Systemic Approach to Automate Privacy Policy Enforcement in Enterprises
It is common practice for enterprises and other organisations to ask people to disclose their personal data in order to grant them access to services and engage in transactions. This practice is not going to disappear, at least in the foreseeable future. Most enterprises need personal information to run their businesses and provide the required services, many of whom have turned to identity man...
متن کاملA System to Handle Privacy Obligations in Enterprises
Privacy obligations dictate expectations and duties that need to be carried out by enterprises when storing, processing and disclosing personal data. Privacy obligations can be defined by data subjects, by laws and/or enterprises’ internal guidelines. They require enterprises to deal with data governance and data lifecycle management activities, including data retention and deletion aspects, no...
متن کامل