A systematic methodology for privacy impact assessments: a design science approach Article (Accepted for Publication) (Refereed)
AbstractFor companies that develop and operate IT applications that process the personal data of customers and employees, a major problem is protecting this data and preventing privacy breaches. Failure to adequately address this problem can result in considerable damage to the company's reputation and finances, as well as negative affects for customers or employees (data subjects). We address this problem by proposing a methodology that systematically considers privacy issues by using a step-bystep privacy impact assessment (so called 'PIA'). Existing PIA approaches lack easy applicability because they are either insufficiently structured or imprecise and lengthy. We argue that companies that employ the PIA proposed in this article can achieve 'privacy-by-design', which is widely heralded by data protection authorities. In fact, the German Federal Office for Information Security (BSI) ratified the approach we present in this article for the technical field of RFID and published it as a guideline in November 2011. The contribution of the artefacts we created is twofold: First, we provide a formal problem representation structure for the analysis of privacy requirements. Second, we reduce the complexity of the privacy regulation landscape for practitioners who need to make privacy management decisions for their IT applications.