2019
DOI: 10.1007/978-3-030-35055-0_1
|View full text |Cite
|
Sign up to set email alerts
|

Privacy Impact Assessment: Comparing Methodologies with a Focus on Practicality

Abstract: Privacy and data protection have become more and more important in recent years since an increasing number of enterprises and startups are harvesting personal data as a part of their business model. One central requirement of the GDPR is the implementation of a data protection impact assessment for privacy critical systems. However, the law does not dictate or recommend the use of any particular framework. In this paper we compare different data protection impact assessment frameworks. We have developed a comp… Show more

Help me understand this report
View preprint versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
14
0

Year Published

2020
2020
2024
2024

Publication Types

Select...
3
3
1

Relationship

0
7

Authors

Journals

citations
Cited by 12 publications
(14 citation statements)
references
References 3 publications
0
14
0
Order By: Relevance
“…A comprehensive guidance for carrying out a PIA presented in ISO/IEC 29134:2017 [20], however, it solely describes the the basic concepts for the impact analysis while the provided information for the risk assessor is inadequate [19]. Moreover, several privacy metrics have been documented in the literature by now, however these generally utilise criteria of privacy-enhancing technologies (PETs), such as the the quantification of leaked information or the number of indistinguishable users, instead of the privacy impact [21]. More recently, the NIST proposed a privacy framework in the form of a solid documentation and a methodology to manage the privacy risks of an organization by prioritizing privacy protection activities through enterprise risk management [10].…”
Section: Methodologies Standards and Gdpr Guidelinesmentioning
confidence: 99%
See 1 more Smart Citation
“…A comprehensive guidance for carrying out a PIA presented in ISO/IEC 29134:2017 [20], however, it solely describes the the basic concepts for the impact analysis while the provided information for the risk assessor is inadequate [19]. Moreover, several privacy metrics have been documented in the literature by now, however these generally utilise criteria of privacy-enhancing technologies (PETs), such as the the quantification of leaked information or the number of indistinguishable users, instead of the privacy impact [21]. More recently, the NIST proposed a privacy framework in the form of a solid documentation and a methodology to manage the privacy risks of an organization by prioritizing privacy protection activities through enterprise risk management [10].…”
Section: Methodologies Standards and Gdpr Guidelinesmentioning
confidence: 99%
“…The GDPR commands controllers to perform a risk oriented approach for the personal data, the Data Protection Impact Assessment (DPIA) [20]. However, GDPR does not dictate a special assessment method, while at the same time mandates a good overview of the PIIs, since any inappropriate management of PIIs can possibly violate the GDPR [21]. Such an overview is a challenging task especially for complex systems designed before the GDPR era.…”
Section: Methodologies Standards and Gdpr Guidelinesmentioning
confidence: 99%
“…Given that the guidelines of ISO/IEC 27005:2011 do not include PIAs, and that data protection standards such as BS 10012:2017, ISO/IEC 29151:2017 and ISO/IEC 27018:2014, require PIA in addition to conducting information security risk assessments, in 2017 ISO issued the ISO/IEC 29134:2017 standard with guidelines for PIA, superseding ISO 22307:2008 ("financial servicesprivacy impact assessment") and related guidelines (WP29 Guidelines on Data Protection Impact Assessment, 2017). In addition, apart from a handful of notable exceptions (Horák et al, 2019), state of the art methodologies and tools to implement PIA are still immature (Bisztray and Gruschka, 2019) and there is a lack of data privacy impact assessment (DPIA) methodologies to investigate the risks of information sharing in software engineering practice under the new requirements imposed by GDPR. The DEFeND platform will advance the current state of the art in data protection impact assessment by providing an in-depth processing analysis based on a recognized methodology and international standards.…”
Section: Literature State Of the Artmentioning
confidence: 99%
“…The efficiency of their synergy in terms of security and privacy threat modelling is proven by the SPARTA tool introduced in [28]. Since STRIDE and LINDDUN miss on risk assessment [7], SPARTA tries to enrich them with FAIR [13] risk analysis, but it does not provide means for managing variability and providing scoring for system configurations. There were some attempts to cover architectural trade-offs and variant explosions (e.g.…”
Section: Identified Gap and Research Questionmentioning
confidence: 99%