CRCYOct 14, 2021

Privacy Impact Assessment: Comparing methodologies with a focus on practicality

arXiv:2110.07366v121 citations
Originality Synthesis-oriented
AI Analysis

This addresses the practical implementation of privacy assessments for enterprises handling personal data, but is incremental as it evaluates existing frameworks.

The paper compared three popular data protection impact assessment frameworks required by GDPR, revealing that none fully meet all desired properties, highlighting the need for improved frameworks.

Privacy and data protection have become more and more important in recent years since an increasing number of enterprises and startups are harvesting personal data as a part of their business model. One central requirement of the GDPR is the implementation of a data protection impact assessment for privacy critical systems. However, the law does not dictate or recommend the use of any particular framework. In this paper we compare different data protection impact assessment frameworks. We have developed a comparison and evaluation methodology and applied this to three popular impact assessment frameworks. The result of this comparison shows the weaknesses and strengths, but also clearly indicates that none of the tested frameworks fulfill all desired properties. Thus, the development of a new or improved data protection impact assessment framework is an important open issue for future work, especially for sector specific applications.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes