2004NPARCOpen access

Privacy policy compliance for Web services

George Yee, Larry Korba

Open full text 35 citations

Abstract

The growth of the Internet has been accompanied by the growth of web services (e.g. e-commerce, e-health). This proliferation of web services and the increasing regulatory and legal requirements for personal privacy have fueled the need to protect the personal privacy of web service users. We advocate a privacy policy negotiation approach to protecting personal privacy [1,2]. We provided semi-automated approaches for deriving personal privacy policies in [3]. However, it is evident that approaches are also needed to ensure that providers of web services comply with the privacy policies of service users. In this paper, we examine privacy legislation to derive requirements for privacy policy compliance systems. We then propose an architecture for a privacy policy compliance system that satisfies the requirements and discuss the strengths and weaknesses of our proposed architecture.

Open-access reader

About this research paper

What this paper is about

The growth of the Internet has been accompanied by the growth of web services (e.g. e-commerce, e-health). This proliferation of web services and the increasing regulatory and legal requirements for personal privacy have fueled the need to protect the personal privacy of web service users. We advocate a privacy policy negotiation approach to protecting personal privacy [1,2]. We provided semi-automated approaches for deriving personal privacy policies in [3]. However, it is evident that approaches are also needed to ensure that providers of web services comply with the privacy policies of service users. In this paper, we examine privacy legislation to derive requirements for privacy policy compliance systems. We then propose an architecture for a privacy policy compliance system that satisfies the requirements and discuss the strengths and weaknesses of our proposed architecture.

Why it matters

OpenAlex reports 35 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

The growth of the Internet has been accompanied by the growth of web services (e.g. e-commerce, e-health). This proliferation of web services and the increasing regulatory and legal requirements for personal privacy have fueled the need to protect the personal privacy of web service users. We advocate a privacy policy negotiation approach to protecting personal privacy [1,2]. We provided semi-automated approaches for deriving personal privacy policies in [3]. However, it is evident that approaches are also needed to ensure that providers of web services comply with the privacy policies of service users. In this paper, we examine privacy legislation to derive requirements for privacy policy compliance systems. We then propose an architecture for a privacy policy compliance system that satisfies the requirements and discuss the strengths and weaknesses of our proposed architecture.

Key concepts: Privacy policy, Privacy by Design, Information privacy, Internet privacy, Privacy software, Privacy law, Web service, Computer science

Related papers

Back to paper searchBrowse research topicsOriginal source
Privacy policy compliance for Web services — Research Paper | ScholarLens