Skip to main content
QUICK REVIEW

[论文解读] Exploring the Relationships between Privacy by Design Schemes and Privacy Laws: A Comparative Analysis

Atheer Aljeraisy, Masoud Barati|ORCA Online Research @Cardiff (Cardiff University)|Oct 6, 2022
Privacy, Security, and Data Protection参考文献 3被引用 4
一句话总结

本文通过协调五大全球隐私法——GDPR、PIPEDA、CCPA、APPs 和新西兰隐私法 1993 年版——的关键原则与个人权利,提出了一种综合隐私法框架(CPLF),并将其映射至现有的隐私设计(PbD)方案。研究发现现有 PbD 模式存在缺陷,许多模式未能充分支持数据可携权或投诉机制等核心权利,凸显了软件开发中法律合规与技术实现之间的关键脱节。

ABSTRACT

Internet of Things (IoT) applications have the potential to derive sensitive information about individuals. Therefore, developers must exercise due diligence to make sure that data are managed according to the privacy regulations and data protection laws. However, doing so can be a difficult and challenging task. Recent research has revealed that developers typically face difficulties when complying with regulations. One key reason is that, at times, regulations are vague, and could be challenging to extract and enact such legal requirements. In our research paper, we have conducted a systematic analysis of the data protection laws that are used across different continents, namely: (i) General Data Protection Regulations (GDPR), (ii) the Personal Information Protection and Electronic Documents Act (PIPEDA), (iii) the California Consumer Privacy Act (CCPA), (iv) Australian Privacy Principles (APPs), and (v) New Zealand's Privacy Act 1993. In this technical report, we presented the detailed results of the conducted framework analysis method to attain a comprehensive view of different data protection laws and highlighted the disparities, in order to assist developers in adhering to the regulations across different regions, along with creating a Combined Privacy Law Framework (CPLF). After that, we gave an overview of various Privacy by Design (PbD) schemes developed previously by different researchers. Then, the key principles and individuals' rights of the CPLF were mapped with the privacy principles, strategies, guidelines, and patterns of the Privacy by Design (PbD) schemes in order to investigate the gaps in existing schemes.

研究动机与目标

  • 识别并协调主要国际数据保护法律中的核心隐私原则与个人权利。
  • 开发一种统一的综合隐私法框架(CPLF),使软件开发者能够实现跨司法管辖区的合规。
  • 评估现有隐私设计(PbD)方案与 CPLF 原则/权利之间的对齐程度。
  • 识别当前 PbD 模式在法律权利执行方面,特别是在技术实现方面的缺口。
  • 指导开发者选择能够支持多样监管环境法律合规的适当 PbD 模式。

提出的方法

  • 对五大主要隐私法(GDPR、PIPEDA、CCPA、APPs 和新西兰隐私法 1993 年版)进行系统性比较分析。
  • 从每部法律中提取并映射关键原则与个人权利,以构建综合隐私法框架(CPLF)。
  • 调查并分类现有隐私设计(PbD)方案,包括原则、策略、指南与模式。
  • 使用两个标准(直接关系:•,间接关系:○)建立 CPLF 原则/权利与 PbD 模式之间的相关性矩阵。
  • 分析每种 PbD 模式在 CPLF 各组成部分中的覆盖程度,以识别未满足的法律要求。
  • 识别因组织或程序性质而无法在开发阶段进行技术实现的法律条款。

实验结果

研究问题

  • RQ1哪些核心隐私原则与个人权利在主要全球隐私法中保持一致?
  • RQ2现有隐私设计(PbD)模式在多大程度上支持综合隐私法框架(CPLF)所定义的原则与权利?
  • RQ3CPLF 中哪些原则与权利未被任何现有 PbD 模式覆盖,原因是什么?
  • RQ4哪些技术和法律障碍阻碍了 PbD 模式与隐私法要求之间的完全对齐?
  • RQ5如何指导开发者选择能够确保符合跨司法管辖区隐私法规的 PbD 模式?

主要发现

  • 综合隐私法框架(CPLF)成功整合了五大主要数据保护法(包括 GDPR、PIPEDA、CCPA、APPs 和新西兰隐私法 1993 年版)中的核心隐私原则与个人权利。
  • 大多数 PbD 模式与 CPLF 中的多个原则或权利相关联,表明其具备实现跨合规的强潜力,但部分模式如‘反对一刀切策略’和‘互惠性’的对齐程度有限。
  • ‘来源’、‘个人数据跨境披露’、‘处理未经请求的数据’以及‘标识符的采用、使用或披露’等原则仅与澳大利亚和新西兰相关,因此未被大多数 PbD 模式覆盖。
  • ‘数据可携权’、‘投诉权’以及‘个人不受歧视的权利’均未被任何分析的 PbD 模式所支持,表明存在显著的技术缺口。
  • 要求组织或程序合规的法律条款(如涉及内部治理或执行机制的条款)无法通过技术性 PbD 模式实现,导致法律与实现之间出现脱节。
  • 研究揭示,尽管 PbD 模式在技术隐私控制方面有效,但其不足以支持依赖法律程序或制度机制的权利执行。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。