Privacy Rights Management
Larry Korba, Ronggong Song, George Yee
Abstract
Larry Korba, Ronggong Song, George Yee
Abstract
Managing privacy is important because organizations must meet legislative and organizational requirements. Some countries, such as the United States of America, have a patchwork of legislation, making it difficult to understand technical requirements. Other countries, such as Canada and the European Union, have well-established and understood privacy laws. As well, many different technologies that may be applied to provide compliance with those laws exist, but there are no established technological solutions suited for handling all of the challenging requirements expressed by privacy regulations. The question remains: how can a citizen’s privacy rights be managed or enforced? This article describes extensions to a privacy architecture that employs digital rights management technologies to manage individual data privacy. Several scenarios related to the management of personally identifiable information are described, illustrating how the system operates in support of the requirements expressed in the European Union privacy principles.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Managing privacy is important because organizations must meet legislative and organizational requirements. Some countries, such as the United States of America, have a patchwork of legislation, making it difficult to understand technical requirements. Other countries, such as Canada and the European Union, have well-established and understood privacy laws. As well, many different technologies that may be applied to provide compliance with those laws exist, but there are no established technological solutions suited for handling all of the challenging requirements expressed by privacy regulations. The question remains: how can a citizen’s privacy rights be managed or enforced? This article describes extensions to a privacy architecture that employs digital rights management technologies to manage individual data privacy. Several scenarios related to the management of personally identifiable information are described, illustrating how the system operates in support of the requirements expressed in the European Union privacy principles.
Key concepts: Privacy by Design, Information privacy law, Privacy policy, Information privacy, Privacy law, Business, European union, Data Protection Act 1998