메뉴 건너뛰기




Volumn 28, Issue 1, 2012, Pages 54-61

The state of the art in privacy impact assessment

Author keywords

New data protection framework; PIAF; Privacy impact assessment; Stakeholder consultation; Threshold analysis; Transparency; Trust

Indexed keywords

COMPUTER NETWORKS; TRANSPARENCY;

EID: 84856456490     PISSN: 02673649     EISSN: None     Source Type: Journal    
DOI: 10.1016/j.clsr.2011.11.007     Document Type: Article
Times cited : (80)

References (28)
  • 1
    • 84856415986 scopus 로고    scopus 로고
    • European Commission, A comprehensive approach on personal data protection in the European Union, Communication from the Commission to the European Parliament, the Council, the Economic and Social Committee and the Committee of the Regions 609 final, Brussels, 4.11.2010
    • European Commission, A comprehensive approach on personal data protection in the European Union, Communication from the Commission to the European Parliament, the Council, the Economic and Social Committee and the Committee of the Regions, COM(2010) 609 final, Brussels, 4.11.2010. http://ec.europa.eu/ justice/news/consulting-public/0006/com-2010-609-en.pdf.
    • (2010) COM
  • 2
    • 84856448827 scopus 로고    scopus 로고
    • http://www.piafproject.eu.
  • 3
    • 84856490509 scopus 로고    scopus 로고
    • Health Information and Quality Authority Dublin, December
    • Health Information and Quality Authority, Guidance on Privacy Impact Assessment in Health and Social Care, Dublin, December 2010. http://www.hiqa.ie/resource-centre/professionals.
    • (2010) Guidance on Privacy Impact Assessment in Health and Social Care
  • 4
    • 84856448824 scopus 로고    scopus 로고
    • The Art 29 Working Partys Opinion on the revised Industry Proposal for a Privacy and Data Protection Impact Assessment Framework for RFID Applications can be found here: http://ec.europa.eu/justice/policies/privacy/docs/wpdocs/ 2011/wp180-en.pdf
    • The PIAF project does not include a review of the RFID PIA Framework which was published several months after our consortium submitted its proposal to DG Justice. A copy of the revised RFID PIA Framework can be found here: http://ec.europa.eu/justice/policies/privacy/docs/wpdocs/2011/wp180-annex-en. pdf. The Art 29 Working Partys Opinion on the revised Industry Proposal for a Privacy and Data Protection Impact Assessment Framework for RFID Applications can be found here: http://ec.europa.eu/justice/policies/privacy/docs/wpdocs/ 2011/wp180-en.pdf.
  • 7
    • 84856470730 scopus 로고    scopus 로고
    • Double-take: Getting to the RFID PIA Framework
    • both in David Wright and Paul De Hert (eds.) Springer, Dordrecht
    • and Beslay, Laurent, and Ann-Christine Lacoste, "Double-take: getting to the RFID PIA Framework", both in David Wright and Paul De Hert (eds.), Privacy Impact Assessment, Springer, Dordrecht, 2012. See also footnote 5 above. Beslay and Lacoste point out that PIA can be "used in two different contexts: in the first case, it represents a possible alternative to the adoption of a specific and binding regulation on RFID, while in the second case, it is part of the regulatory process, as a pre-condition to assess whether legislation is needed."
    • (2012) Privacy Impact Assessment
    • Beslay, L.1    Lacoste, A.-C.2
  • 9
    • 84856411240 scopus 로고    scopus 로고
    • Wright and De Hert, Deadman and Chandler are senior privacy officials at Vodafone Group
    • Deadman, Stephen, and Amanda Chandler, "Vodafones approach to privacy impact assessments", in Wright and De Hert, op. cit. Deadman and Chandler are senior privacy officials at Vodafone Group.
    • Vodafones Approach to Privacy Impact Assessments
    • Deadman, S.1    Chandler, A.2
  • 10
    • 84856470745 scopus 로고    scopus 로고
    • Office of the Victorian Privacy Commissioner (OVPC) Edition 2, April
    • Office of the Victorian Privacy Commissioner (OVPC), Privacy Impact Assessments: A guide for the Victorian Public Sector, Edition 2, April 2009, p. 5. http://www.privacy.vic.gov.au/privacy/web2.nsf/pages/publication-types? opendocument&Subcategory=Guidelines&s=.
    • (2009) Privacy Impact Assessments: A Guide for the Victorian Public Sector , pp. 5
  • 11
    • 78549232777 scopus 로고    scopus 로고
    • Information Commissioners Office (ICO) Version 2.0, Wilmslow, Cheshire, June
    • Information Commissioners Office (ICO), Privacy Impact Assessment Handbook, Version 2.0, Wilmslow, Cheshire, June 2009. http://www.ico.gov.uk/for- organisations/data-protection/topic-guides/privacy-impact-assessment.aspx.
    • (2009) Privacy Impact Assessment Handbook
  • 12
    • 84856411241 scopus 로고    scopus 로고
    • Wright and De Hert
    • Canadas Privacy Commissioner, as an example, has referred to the possibility of generic PIAs: "In other cases, as with shared services or system initiatives where entities use the same or similar approaches to the collection, use and disclosure of personal information, generic assessments might be better employed." See Stoddart, Jennifer, "Auditing privacy impact assessments: the Canadian experience", in Wright and De Hert, op. cit.
    • Auditing Privacy Impact Assessments: The Canadian Experience
    • Stoddart, J.1
  • 14
    • 84856448181 scopus 로고    scopus 로고
    • ICO Handbook, op. cit., 2009, p. 14.
    • (2009) ICO Handbook , pp. 14
  • 15
    • 84860046939 scopus 로고    scopus 로고
    • Roger Clarke distinguished these different dimensions (or types) of privacy some years ago. See Clarke, Roger, "Whats privacy?", 2006. http://www.rogerclarke.com/DV/Privacy.html.
    • (2006) Whats Privacy?
    • Clarke, R.1
  • 17
    • 84856448830 scopus 로고    scopus 로고
    • Section 64 of Albertas Health Information Act 2000 says "(1) Each custodian must prepare a privacy impact assessment that describes how proposed administrative practices and information systems relating to the collection, use and disclosure of individually identifying health information may affect the privacy of the individual who is the subject of the information. (2) The custodian must submit the privacy impact assessment to the Commissioner for review and comment before implementing any proposed new practice or system described in subsection (1) or any proposed change to existing practices and systems described in subsection (1)." http://www.canlii.org/en/ab/laws/ stat/rsa-2000-c-h-5/latest.
  • 18
    • 84856434026 scopus 로고    scopus 로고
    • Immigration Act 2009, Public Act 2009 No 51
    • Section 32 of the NZ Immigration Act 2009 explicitly requires that a PIA be conducted if biometric information is processed. It requires PIAs regarding the collection and processing of biometric data to be published on the departments website. See Immigration Act 2009, Public Act 2009 No 51. http://www.legislation.govt.nz/act/public/2009/0051/latest/096be8ed806837b3.pdf.
  • 19
    • 77955619458 scopus 로고    scopus 로고
    • Should privacy impact assessments be mandatory?
    • August
    • For more on this issue, see Wright, David, "Should privacy impact assessments be mandatory?", Communications of the ACM, Vol. 54, No. 8, August 2011. http://cacm.acm.org/magazines/2011/8.
    • (2011) Communications of the ACM , vol.54 , Issue.8
    • Wright, D.1
  • 20
    • 70349797065 scopus 로고    scopus 로고
    • ICO p. 58
    • ICO, PIA Handbook, p. 56, p. 58.
    • PIA Handbook , pp. 56
  • 21
    • 84856411245 scopus 로고    scopus 로고
    • PIAs in Australia: A work-in-progress report
    • Wright and De Hert Xamax Consultancy Pty Ltd, February
    • Clarke Roger, "PIAs in Australia: A work-in-progress report", in Wright and De Hert, op. cit. Clarke cites his earlier article: "Privacy Impact Assessment Guidelines", Xamax Consultancy Pty Ltd, February 1998. http://www.xamax.com.au/DV/PIA.html.
    • (1998) Privacy Impact Assessment Guidelines
    • Clarke, R.1
  • 22
    • 70349797065 scopus 로고    scopus 로고
    • ICO
    • "Where some of the information is subject to commercial or security sensitivity, that information can be separated into an appendix, which can be distributed less widely and/or subject to clear confidentiality constraints.. There may be resistance within the organisation to providing some of this information to stakeholders.. On the other hand stakeholder trust needs to be achieved." ICO, PIA Handbook, op. cit., pp. 33-34.
    • PIA Handbook , pp. 33-34
  • 23
    • 78549292872 scopus 로고    scopus 로고
    • Department of Homeland Security Washington, DC, June
    • Department of Homeland Security, Privacy Impact Assessments: The Privacy Office Official Guidance, Washington, DC, June 2010, p. 7. http://www.dhs.gov/ files/publications/gc-1209396374339.shtm.
    • (2010) Privacy Impact Assessments: The Privacy Office Official Guidance , pp. 7
  • 25
    • 78549232777 scopus 로고    scopus 로고
    • Office of the Privacy Commissioner, Auckland, June
    • Stewart, Blair, Privacy Impact Assessment Handbook, Office of the Privacy Commissioner, Auckland, June 2007, p. 14. http://privacy.org.nz/privacy-impact- assessment-handbook/.
    • (2007) Privacy Impact Assessment Handbook , pp. 14
    • Stewart, B.1
  • 26
    • 33646210646 scopus 로고    scopus 로고
    • Deloitte & Touche
    • Karol, Thomas J., A Guide To Cross-Border Privacy Impact Assessments, Deloitte & Touche, 2001. http://www.isaca.org/Knowledge-Center/Research/ ResearchDeliverables/Pages/AGuide-To-Cross-Border-Privacy-Impact-Assessments. aspx.
    • (2001) A Guide to Cross-Border Privacy Impact Assessments
    • Karol, T.J.1
  • 27
    • 72449185653 scopus 로고    scopus 로고
    • Privacy impact assessment in the design of transnational public health information systems: The BIRO project
    • Di Iorio, C.T., F. Carinci, J. Azzopardi et al., "Privacy impact assessment in the design of transnational public health information systems: the BIRO project", Journal of Medical Ethics, Vol. 35, 2009, pp. 753-761. http://jme.bmj.com/content/35/12/753.abstract.
    • (2009) Journal of Medical Ethics , vol.35 , pp. 753-761
    • Di Iorio, C.T.1    Carinci, F.2    Azzopardi, J.3


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.