[Paper Review] Exploring the Relationships between Privacy by Design Schemes and Privacy Laws: A Comparative Analysis
This paper proposes a Combined Privacy Law Framework (CPLF) by harmonizing key principles and individual rights from five major global privacy laws—GDPR, PIPEDA, CCPA, APPs, and New Zealand Privacy Act 1993—and maps them to existing Privacy by Design (PbD) schemes. The study identifies gaps in current PbD patterns, revealing that many do not fully support core rights like data portability or complaint mechanisms, highlighting a critical disconnect between legal compliance and technical implementation in software development.
Internet of Things (IoT) applications have the potential to derive sensitive information about individuals. Therefore, developers must exercise due diligence to make sure that data are managed according to the privacy regulations and data protection laws. However, doing so can be a difficult and challenging task. Recent research has revealed that developers typically face difficulties when complying with regulations. One key reason is that, at times, regulations are vague, and could be challenging to extract and enact such legal requirements. In our research paper, we have conducted a systematic analysis of the data protection laws that are used across different continents, namely: (i) General Data Protection Regulations (GDPR), (ii) the Personal Information Protection and Electronic Documents Act (PIPEDA), (iii) the California Consumer Privacy Act (CCPA), (iv) Australian Privacy Principles (APPs), and (v) New Zealand's Privacy Act 1993. In this technical report, we presented the detailed results of the conducted framework analysis method to attain a comprehensive view of different data protection laws and highlighted the disparities, in order to assist developers in adhering to the regulations across different regions, along with creating a Combined Privacy Law Framework (CPLF). After that, we gave an overview of various Privacy by Design (PbD) schemes developed previously by different researchers. Then, the key principles and individuals' rights of the CPLF were mapped with the privacy principles, strategies, guidelines, and patterns of the Privacy by Design (PbD) schemes in order to investigate the gaps in existing schemes.
Motivation & Objective
- To identify and harmonize core privacy principles and individual rights across major international data protection laws.
- To develop a unified Combined Privacy Law Framework (CPLF) that enables cross-jurisdictional compliance for software developers.
- To assess the alignment between existing Privacy by Design (PbD) schemes and the principles/rights of the CPLF.
- To identify gaps in current PbD patterns regarding legal rights enforcement, especially in technical implementation.
- To guide developers in selecting appropriate PbD patterns that support legal compliance across diverse regulatory environments.
Proposed method
- Conduct a systematic comparative analysis of five major privacy laws: GDPR, PIPEDA, CCPA, APPs, and New Zealand Privacy Act 1993.
- Extract and map key principles and individual rights from each law to form the Combined Privacy Law Framework (CPLF).
- Survey and categorize existing Privacy by Design (PbD) schemes, including principles, strategies, guidelines, and patterns.
- Establish a correlation matrix between the CPLF's principles/rights and PbD patterns using two criteria: direct (•) and indirect (○) relationships.
- Analyze the coverage of each PbD pattern across the CPLF components to identify unmet legal requirements.
- Identify legal provisions that are not technically implementable in the development phase due to their organizational or procedural nature.
Experimental results
Research questions
- RQ1Which core privacy principles and individual rights are consistently present across major global privacy laws?
- RQ2To what extent do existing Privacy by Design (PbD) patterns support the principles and rights defined in the Combined Privacy Law Framework (CPLF)?
- RQ3Which principles and rights in the CPLF are not addressed by any existing PbD patterns, and why?
- RQ4What are the technical and legal barriers that prevent full alignment between PbD patterns and privacy law requirements?
- RQ5How can developers be guided to select PbD patterns that ensure compliance with cross-jurisdictional privacy regulations?
Key findings
- The Combined Privacy Law Framework (CPLF) successfully unifies core privacy principles and individual rights from five major data protection laws, including GDPR, PIPEDA, CCPA, APPs, and New Zealand’s Privacy Act 1993.
- Most PbD patterns are associated with multiple principles or rights in the CPLF, indicating strong potential for cross-compliance, but some patterns like 'Discouraging Blanket Strategies' and 'Reciprocity' show limited alignment.
- The principles 'Source', 'Cross-border Disclosure of Personal Data', 'Dealing with Unsolicited Data', and 'Adoption, Use or Disclosure of an identifier' are only relevant to Australia and New Zealand, and thus not covered by most PbD patterns.
- The rights 'Right to Data Portability', 'Right to Complain', and 'Right of Individuals not to be Discriminated' are not supported by any of the analyzed PbD patterns, indicating a significant technical gap.
- Legal provisions requiring organizational or procedural compliance—such as those involving internal governance or enforcement mechanisms—cannot be implemented through technical PbD patterns, creating a disconnect between law and implementation.
- The study reveals that while PbD patterns are effective for technical privacy controls, they are insufficient for enforcing rights that depend on legal processes or institutional mechanisms.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.