数据保护影响评估及其他场景中组合风险的识别
Identification of Compositional Risks in Data Protection Impact Assessments and Beyond
浏览论文内容
中文总结 AI 辅助
针对服务组合中被忽视的隐私组合风险,本文提出一种新协议以识别并管理此类风险,从而优化数据保护影响评估结果。
中文摘要 AI 辅助
当个人数据由合作服务提供商以分布式方式处理时,隐私风险可能仅源于组合中包含的数据处理者的选择。例如,不同的数据处理者可能在不知情的情况下依赖同一云服务提供商,导致个人数据在该提供商处发生意外可链接性。由于这类隐私组合风险超出了单个风险评估的范围,在执行数据保护影响评估时很可能被忽视。在本文中,我们提出了一种新的协议,用于检测和管理这类隐私组合风险。在完成初始问题定义和需求获取后,我们详细阐述了该协议如何识别组合风险的候选对象,以及如何利用这些信息改进包含多个数据处理者的服务组合的数据保护影响评估结果。
英文摘要
When personal data is processed in a distributed manner by cooperating service providers, privacy risks may emerge solely from the choice of data processors included in the composition. For instance, different data processors may unknowingly rely on the same cloud provider, allowing for unintended linkability of personal data at that very provider. As such compositional risks to privacy are beyond the scope of each individual risk assessment, they are likely to be overseen when performing a data protection impact assessment. In this paper, we propose a novel protocol to detect and manage such compositional risks to privacy. Following an initial problem definition and requirements elicitation, we elaborate how our protocol identifies candidates for compositional risks and how this information may be used to improve the results of a data protection impact assessment over service compositions including multiple data processors.
发表机构
- Karlstad University(卡尔斯特德大学)
- University of Oslo(奥斯陆大学)
机构由 AI 辅助整理,请以论文原文为准。