• DocumentCode
    541925
  • Title

    EnCoRe: Towards a holistic approach to privacy

  • Author

    Papanikolaou, Nick ; Creese, Sadie ; Goldsmith, Michael ; Mont, Marco Casassa ; Pearson, Siani

  • Author_Institution
    International Digital Laboratory, University of Warwick, U.K.
  • fYear
    2010
  • fDate
    26-28 July 2010
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    We make the case for an integrated approach to privacy management within organisations. Current approaches to privacy management are either too high-level, enforcing privacy of personal data using legal compliance, risk and impact assessments, or too low-level, focusing only on the technical implementation of access controls to personal data held by an enterprise. High-level approaches tend to address privacy as an afterthought in ordinary business practice, and involve ad hoc enforcement practices; low-level approaches often leave out important legal and business considerations. As part of the EnCoRe project we are developing a methodology which tries to bridge the gap between privacy risk and impact assessment with the technical management of privacy policies. We are working to define a conceptual model as a means of expressing policy requirements as well as users´ privacy preferences and as a way to bridge the gap described above. We aim to show the value of this approach in collaborative case studies (including corporate personnel management, biobanks and assisted living) in the context of the EnCoRe project.
  • Keywords
    Access control; Business; Data privacy; Law; Privacy; Policy hierarchy; Policy refinement; Privacy policies;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Cryptography (SECRYPT), Proceedings of the 2010 International Conference on
  • Conference_Location
    Athens
  • Type

    conf

  • Filename
    5741646