首页> 外文会议>IFIP WG 9.2, 9.6/11.7, 11.4, 11.6/PrimeLife international summer school >A Conceptual Model for Privacy Policies with Consent and Revocation Requirements
【24h】

A Conceptual Model for Privacy Policies with Consent and Revocation Requirements

机译:具有同意和撤销要求的隐私策略的概念模型

获取原文

摘要

This paper proposes a conceptual model for privacy policies that takes into account privacy requirements arising from different stakeholders, with legal, business and technical backgrounds. Current approaches to privacy management are either high-level, enforcing privacy of personal data using legal compliance, risk and impact assessments, or low-level, focusing on the technical implementation of access controls to personal data held by an enterprise. High-level approaches tend to address privacy as an afterthought in ordinary business practice, and involve ad hoc enforcement practices; low-level approaches often leave out important legal and business considerations focusing solely on technical management of privacy policies. Hence, neither is a panacea and the low level approaches are often not adopted in real environments. Our conceptual model provides a means to express privacy policy requirements as well as users' privacy preferences. It enables structured reasoning regarding containment and implementation between various policies at the high level, and enables easy traceability into the low-level policy implementations. Thus it offers a means to reason about correctness that links low-level privacy management mechanisms to stakeholder requirements, thereby encouraging exploitation of the low-level methods. We also present the notion of a consent and revocation policy. A consent and revocation policy is different from a privacy policy in that it defines not enterprise practices with regards to personal data, but more specifically, for each item of personal data held by an enterprise, what consent preferences a user may express and to what degree, and in what ways he or she can revoke their personal data. This builds on earlier work on defining the different forms of revocation for personal data, and on formal models of consent and revocation processes. The work and approach discussed in this paper is currently carried out in the context of the UK collaborative project EnCoRe (Ensuring Consent and Revocation).
机译:本文提出了一种隐私策略的概念模型,该模型考虑了来自不同利益相关者的法律,商业和技术背景下的隐私要求。当前的隐私管理方法是高级的(使用法律合规性,风险和影响评估来加强个人数据的隐私),或者是低级的(侧重于企业对个人数据的访问控制的技术实现)。高级方法倾向于将隐私作为普通业务实践中的事后考虑,并涉及临时执行实践;低级方法通常会忽略重要的法律和业务注意事项,而这些注意事项仅侧重于隐私策略的技术管理。因此,万灵药也不是万能药,在实际环境中通常不采用低级方法。我们的概念模型提供了一种表达隐私策略要求以及用户隐私偏好的方法。它可以在高层对各种策略之间的包含和实施进行结构化的推理,并可以轻松地追溯到低级策略的实施中。因此,它提供了推理正确性的方法,该方法将低级隐私管理机制与利益相关者的需求联系在一起,从而鼓励了对低级方法的利用。我们还提出了同意和撤销政策的概念。同意和撤销策略与隐私策略的不同之处在于,它不定义关于个人数据的企业惯例,而是更具体地,对于企业持有的每项个人数据,用户可以表达什么同意偏好以及在什么程度上表达同意偏好,以及他或她可以通过哪些方式撤消其个人数据。这是基于较早的工作,即为个人数据定义不同形式的撤销,以及基于同意和撤销过程的正式模型。本文讨论的工作和方法目前是在英国合作项目EnCoRe(确保同意和撤销)的背景下进行的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号