Data protection auditing, problematic and challenges
Dina Kampouraki
Abstract
Dina Kampouraki
Abstract
For most Data Protection Authorities and Bodies, effective supervision of the data protection principles and requirements call for strong auditing techniques and methodologies. Living in this new information era a data protection auditor needs special data protection knowledge, constant training with the new information technology tools, and willingness to adapt to the modern world. In order to audit the privacy compliance of data processors within the data protection regime, various Data Protection Authorities and Bodies on an ad-hoc base, have developed appropriate practices, methods and methodologies. In this article a comprehensive presentation of the audit approaches adopted by various Data Protection Authorities and Bodies, along with a detailed review and set criteria useful to create a comparative framework is presented.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
For most Data Protection Authorities and Bodies, effective supervision of the data protection principles and requirements call for strong auditing techniques and methodologies. Living in this new information era a data protection auditor needs special data protection knowledge, constant training with the new information technology tools, and willingness to adapt to the modern world. In order to audit the privacy compliance of data processors within the data protection regime, various Data Protection Authorities and Bodies on an ad-hoc base, have developed appropriate practices, methods and methodologies. In this article a comprehensive presentation of the audit approaches adopted by various Data Protection Authorities and Bodies, along with a detailed review and set criteria useful to create a comparative framework is presented.
Key concepts: Audit, Data Protection Act 1998, Computer security, Computer science, Information privacy, Business, Internet privacy, Risk analysis (engineering)