The Experts below are selected from a list of 1668 Experts worldwide ranked by ideXlab platform

Lukasz Olejnik - One of the best experts on this subject based on the ideXlab platform.

  • shedding light on web privacy impact assessment a case study of the ambient light sensor api
    IEEE European Symposium on Security and Privacy, 2020
    Co-Authors: Lukasz Olejnik
    Abstract:

    As modern web browsers gain new and increasingly powerful features the importance of impact assessments of the new functionality becomes crucial.A web privacy impact assessment of a planned web browser feature, the Ambient Light Sensor API, indicated risks arising from the exposure of overly precise information about the lighting conditions in the user environment. The analysis led to the demonstration of direct risks of leaks of user data, such as the list of visited websites or exfiltration of sensitive content across distinct browser contexts.Our work contributed to the creation of web standards leading to decisions by browser vendors (i.e. obsolescence, non-implementation or modification to the operation of browser features). We highlight the need to consider broad risks when making reviews of new features. We offer practically-driven high-level observations lying on the intersection of web security and privacy risk engineering and modeling, and standardization. We structure our work as a case study from activities spanning over three years.

  • EuroS&P Workshops - Shedding light on web privacy impact assessment: A case study of the Ambient Light Sensor API
    2020 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), 2020
    Co-Authors: Lukasz Olejnik
    Abstract:

    As modern web browsers gain new and increasingly powerful features the importance of impact assessments of the new functionality becomes crucial.A web privacy impact assessment of a planned web browser feature, the Ambient Light Sensor API, indicated risks arising from the exposure of overly precise information about the lighting conditions in the user environment. The analysis led to the demonstration of direct risks of leaks of user data, such as the list of visited websites or exfiltration of sensitive content across distinct browser contexts.Our work contributed to the creation of web standards leading to decisions by browser vendors (i.e. obsolescence, non-implementation or modification to the operation of browser features). We highlight the need to consider broad risks when making reviews of new features. We offer practically-driven high-level observations lying on the intersection of web security and privacy risk engineering and modeling, and standardization. We structure our work as a case study from activities spanning over three years.

David Wright - One of the best experts on this subject based on the ideXlab platform.

  • privacy principles, risks and harms
    International Review of Law Computers & Technology, 2014
    Co-Authors: David Wright, Charles D. Raab
    Abstract:

    The protection of privacy is predicated on the individual's right to privacy and stipulates a number of principles that are primarily focused on information privacy or data protection and, as such, are insufficient to apply to other types of privacy and to the protection of other entities beyond the individual. This article identifies additional privacy principles that would apply to other types of privacy and would enhance the consideration of risks or harms to the individual, to groups and to society as a whole if they are violated. They also relate to the way privacy impact assessment (PIA) may be conducted. There are important reasons for generating consideration of and debate about these principles. First, they help to recalibrate a focus in Europe on data protection to the relative neglect of other types of privacy. Second, it is of critical importance at a time when PIA (renamed ‘data protection impact assessment’, or DPIA) may become mandatory under the European Commission's proposed Data Protecti...

  • Integrating privacy and ethical impact assessments
    Science and Public Policy, 2013
    Co-Authors: David Wright, Michael Friedewald
    Abstract:

    New and emerging technologies often raise both ethical and privacy issues. The analysis and assessment of such issues is the task of privacy impact assessments and ethical impact assessments. Although there are various privacy impact assessment methodologies and ethical impact assessment methodologies, the two have not been integrated. Nevertheless, some researchers have been thinking about the utility and feasibility of integrating privacy and ethical impact assessment methodologies. Copyright The Author 2013. Published by Oxford University Press. All rights reserved. For Permissions, please email: journals.permissions@oup.com, Oxford University Press.

  • Making privacy impact assessment More Effective
    The Information Society, 2013
    Co-Authors: David Wright
    Abstract:

    Europe's proposed Data Protection Regulation is expected to make data protection impact assessment (DPIA) mandatory, a development that could impact hundreds of thousands of organizations (both governmental and private sector) in Europe, as well as non-European entities offering their wares and services there. This article reviews the DPIA provisions outlined in the new regulation. For the nuts and bolts of a privacy impact assessment (PIA) methodology, Europe could select features from the PIA methodologies used in Australia, Canada, Ireland, New Zealand, the United Kingdom, and the United States, the countries with the most experience in PIA. A European Commission (EC)-funded project, called PIAF, reviewed these various methodologies and proposed an “optimized” PIA for Europe (and elsewhere) based on the best practices of the aforementioned countries. Based on these best practices, this article outlines a 16-step PIA process. It argues that while some organizations may regard a PIA as a hassle, in fact,...

  • A Comparative Analysis of privacy impact assessment in Six Countries
    Journal of Contemporary European Research, 2013
    Co-Authors: David Wright, Rachel L. Finn, Rowena Rodrigues
    Abstract:

    The European Commission is revising the EU’s data protection framework. One of the changes concerns privacy impact assessment (PIA). This paper argues that the European Commission and the EU Member States should draw on the experience of other countries that have adopted PIA policies and methodologies to construct its own framework. There are similarities and differences in the approaches of Australia, Canada, Ireland, New Zealand, the UK and US, the countries with the most experience in PIA. Each has its strong points, but also shortcomings. Audits have identified some of the latter in the instance of Canada. This paper provides a comparative analysis of the six countries to identify some of the best elements that could be used to improve Article 33 in European Commission’s proposed Data Protection Regulation.

  • Constructing a surveillance impact assessment
    Computer Law & Security Review, 2012
    Co-Authors: David Wright, Charles D. Raab
    Abstract:

    Abstract This paper describes surveillance impact assessment (SIA), a methodology for identifying, assessing and resolving risks, in consultation with stakeholders, posed by the development of surveillance systems. This paper appears to be the first such to elaborate an SIA methodology. It argues that the process of conducting an SIA should be similar to that of a privacy impact assessment (PIA), but that an SIA must take account of a wider range of issues, impacts and stakeholders. The paper categorises the issues and impacts to be considered in the conduct of an SIA and identifies the benefits of a properly conducted SIA.

Jan Zibuschka - One of the best experts on this subject based on the ideXlab platform.

  • CyberICPS/SECPRE/SPOSE/ADIoT@ESORICS - Analysis of Automation Potentials in privacy impact assessment Processes
    Lecture Notes in Computer Science, 2020
    Co-Authors: Jan Zibuschka
    Abstract:

    With the recent introduction of the EU’s General Data Protection Regulation (GDPR), privacy impact assessments (PIA) have become mandatory in many cases. To support organisations in correctly implementing those, researchers and practitioners have provided reference processes and tooling. Integrating automation features into PIA tools can streamline the implementation of compliant privacy impact assessments in organizations. Based on a general reference architecture and reference process based on guidance by authorities, this contribution offers a systematic analysis of which process steps show the most promise with regard to this, and discusses impediments to this approach and directions for future research.

  • analysis of automation potentials in privacy impact assessment processes
    Lecture Notes in Computer Science, 2019
    Co-Authors: Jan Zibuschka
    Abstract:

    With the recent introduction of the EU’s General Data Protection Regulation (GDPR), privacy impact assessments (PIA) have become mandatory in many cases. To support organisations in correctly implementing those, researchers and practitioners have provided reference processes and tooling. Integrating automation features into PIA tools can streamline the implementation of compliant privacy impact assessments in organizations. Based on a general reference architecture and reference process based on guidance by authorities, this contribution offers a systematic analysis of which process steps show the most promise with regard to this, and discusses impediments to this approach and directions for future research.

Guttorm Sindre - One of the best experts on this subject based on the ideXlab platform.

Yoichi Seto - One of the best experts on this subject based on the ideXlab platform.

  • proposal for a privacy impact assessment manual conforming to iso iec 29134 2017
    Computer Information Systems and Industrial Management Applications, 2018
    Co-Authors: Sanggyu Shin, Yoichi Seto, Kumi Hasegawa, Ryotaro Nakata
    Abstract:

    In this paper, we compared the requirements of previously developed manual and ISO/IEC 29134:2017 and analyzed the changes. As a result, there were no major differences in requirements. It is useful to conduct a privacy impact assessment (PIA) before actually operating the system to appropriately construct and operate a system that handles personal information. A manual (procedure manual) is necessary to implement PIA efficiently. In June 2017, ISO issued the ISO/IEC 29134:2017 as an international standard on PIA. Cause the past PIA manual developed based on ISO 22307:2008, development of a PIA manual conforming to ISO/IEC 29134:2017 was required. By our analysis, as a newly stated matter, ISO/IEC 29134:2017 explicitly indicated Due Diligence, stakeholder engagement, and risk countermeasures. Based on the analysis results, we propose a new PIA manual reflecting the requirements of ISO/IEC 29134:2017.

  • CISIM - Proposal for a privacy impact assessment Manual Conforming to ISO/IEC 29134:2017
    Computer Information Systems and Industrial Management, 2018
    Co-Authors: Sanggyu Shin, Yoichi Seto, Kumi Hasegawa, Ryotaro Nakata
    Abstract:

    In this paper, we compared the requirements of previously developed manual and ISO/IEC 29134:2017 and analyzed the changes. As a result, there were no major differences in requirements. It is useful to conduct a privacy impact assessment (PIA) before actually operating the system to appropriately construct and operate a system that handles personal information. A manual (procedure manual) is necessary to implement PIA efficiently. In June 2017, ISO issued the ISO/IEC 29134:2017 as an international standard on PIA. Cause the past PIA manual developed based on ISO 22307:2008, development of a PIA manual conforming to ISO/IEC 29134:2017 was required. By our analysis, as a newly stated matter, ISO/IEC 29134:2017 explicitly indicated Due Diligence, stakeholder engagement, and risk countermeasures. Based on the analysis results, we propose a new PIA manual reflecting the requirements of ISO/IEC 29134:2017.

  • CSA/CUTE - Consideration of privacy Risk assessment of the My Number in the Financial Industry in Japan
    Advances in Computer Science and Ubiquitous Computing, 2017
    Co-Authors: Sanggyu Shin, Yoichi Seto, Kei Sakamoto, Mayumi Sasaki
    Abstract:

    In Sep. 2015, the Act on the Use of Numbers to Identify a Specific Individual in the Administrative Procedure was revised. It was decided to link personal numbers to deposit numbers of financial institutions. Currently, the privacy impact assessment which is obliged to implement this law is required to implement safety control measures for the private sector. However, there is no system to conduct a risk assessment of the law. In the financial industry, which is a highly private sector of public nature, some privacy risk assessment is required because it has many individual numbers. In this paper, we propose a framework for privacy risk assessment on this law in the financial industry, using the privacy impact assessment prescribed as an international standard.

  • consideration of privacy risk assessment of the my number in the financial industry in japan
    CSA CUTE, 2017
    Co-Authors: Sanggyu Shin, Yoichi Seto, Kei Sakamoto, Mayumi Sasaki
    Abstract:

    In Sep. 2015, the Act on the Use of Numbers to Identify a Specific Individual in the Administrative Procedure was revised. It was decided to link personal numbers to deposit numbers of financial institutions. Currently, the privacy impact assessment which is obliged to implement this law is required to implement safety control measures for the private sector. However, there is no system to conduct a risk assessment of the law. In the financial industry, which is a highly private sector of public nature, some privacy risk assessment is required because it has many individual numbers. In this paper, we propose a framework for privacy risk assessment on this law in the financial industry, using the privacy impact assessment prescribed as an international standard.

  • Application of privacy impact assessment in the smart city
    Electronics and Communications in Japan, 2015
    Co-Authors: Yoichi Seto
    Abstract:

    The Smart City project is currently being promoted in various countries around the world. That is to take advantage of personal information and utilization of energy more appropriately. Therefore, it is said that when there are privacy issues. However, it specifically discuss the privacy risks in the specific project of Smart City is premature. We discuss the privacy risks around the smart grid standardization advances which technology is the core of the Smart City. In this paper, we have verified the effectiveness of the privacy impact assessment, such as privacy risks in Smart City. © 2013 The Institute of Electrical Engineers of Japan.