【24h】

Analyzing GDPR Compliance Through the Lens of Privacy Policy

机译:通过隐私政策分析GDPR的合规性

获取原文

摘要

With the arrival of the European Union's General Data Protection Regulation (GDPR), several companies are making significant changes to their systems to achieve compliance. The changes range from modifying privacy policies to redesigning systems which process personal data. Privacy policy is the main medium of information dissemination between the data controller and the users. This work analyzes the privacy policies of large-scaled cloud services which seek to be GDPR compliant. We show that many services that claim compliance today do not have clear and concise privacy policies. We identify several points in the privacy policies which potentially indicate non-compliance; we term these GDPR dark patterns. We identify GDPR dark patterns in ten large-scale cloud services. Based on our analysis, we propose seven best practices for crafting GDPR privacy policies.
机译:随着欧盟通用数据保护条例(GDPR)的到来,几家公司正在对其系统进行重大更改以实现合规性。变化范围从修改隐私策略到重新设计处理个人数据的系统。隐私政策是数据控制者与用户之间信息传播的主要媒介。这项工作分析了寻求符合GDPR的大型云服务的隐私策略。我们证明,如今许多声称合规的服务都没有清晰简洁的隐私权政策。我们在隐私政策中指出了几处可能表明不合规的地方;我们称这些GDPR黑暗模式。我们在十个大型云服务中确定了GDPR暗模式。根据我们的分析,我们提出了七个制定GDPR隐私政策的最佳实践。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号