On the Evaluation of Privacy Impact Assessment and Privacy Risk Assessment Methodologies: A Systematic Literature Review
Assessing privacy risks and incorporating privacy measures from the onset requires a comprehensive understanding of potential impacts on data subjects. Privacy Impact Assessments (PIAs) offer a systematic methodology for such purposes, which are closely related to Data Protection Impact Assessments...
Main Authors: | , , , |
---|---|
Format: | Article |
Language: | English |
Published: |
IEEE
2024-01-01
|
Series: | IEEE Access |
Subjects: | |
Online Access: | https://ieeexplore.ieee.org/document/10418587/ |
_version_ | 1797319568161505280 |
---|---|
author | Samuel Wairimu Leonardo Horn Iwaya Lothar Fritsch Stefan Lindskog |
author_facet | Samuel Wairimu Leonardo Horn Iwaya Lothar Fritsch Stefan Lindskog |
author_sort | Samuel Wairimu |
collection | DOAJ |
description | Assessing privacy risks and incorporating privacy measures from the onset requires a comprehensive understanding of potential impacts on data subjects. Privacy Impact Assessments (PIAs) offer a systematic methodology for such purposes, which are closely related to Data Protection Impact Assessments (DPIAs), particularly outlined in Article 35 of the General Data Protection Regulation (GDPR). The core of a PIA is a Privacy Risk Assessment (PRA). PRAs can be integrated as part of full-fledged PIAs or independently developed to support PIA processes. Although these methodologies have been identified as essential enablers of privacy by design, their effectiveness has been criticized because of the lack of evidence of their rigorous and systematic evaluation. Hence, we conducted a Systematic Literature Review (SLR) to identify published PIA and PRA methodologies and assess how and to what extent they have been scientifically validated or evaluated. We found that these methodologies are rarely evaluated for their performance in practice, and most of them have only been validated in limited studies. Most validation evidence is found with PRA methodologies. Of the evaluated methodologies, PIAs were the most evaluated, where case studies were the predominant evaluation method. These evaluated methodologies can be easily transferred to an industrial setting or used by practitioners, as they provide evidence of their use in practice. In addition, the findings in this study can be used to inform researchers of the current state-of-the-art, and practitioners can understand the benefits and current limitations of the methodologies and adopt evidence-based practices. |
first_indexed | 2024-03-08T04:08:51Z |
format | Article |
id | doaj.art-a47ef83ce2ce4418844862b4e863ce87 |
institution | Directory Open Access Journal |
issn | 2169-3536 |
language | English |
last_indexed | 2024-03-08T04:08:51Z |
publishDate | 2024-01-01 |
publisher | IEEE |
record_format | Article |
series | IEEE Access |
spelling | doaj.art-a47ef83ce2ce4418844862b4e863ce872024-02-09T00:01:30ZengIEEEIEEE Access2169-35362024-01-0112196251965010.1109/ACCESS.2024.336086410418587On the Evaluation of Privacy Impact Assessment and Privacy Risk Assessment Methodologies: A Systematic Literature ReviewSamuel Wairimu0https://orcid.org/0000-0003-1750-649XLeonardo Horn Iwaya1https://orcid.org/0000-0001-9005-0543Lothar Fritsch2https://orcid.org/0000-0002-0418-4121Stefan Lindskog3https://orcid.org/0000-0003-0778-4736Department of Mathematics and Computer Science, Privacy and Security (PriSec) Research Group, Karlstad University, Karlstad, SwedenDepartment of Mathematics and Computer Science, Privacy and Security (PriSec) Research Group, Karlstad University, Karlstad, SwedenDepartment of Mathematics and Computer Science, Privacy and Security (PriSec) Research Group, Karlstad University, Karlstad, SwedenDepartment of Mathematics and Computer Science, Privacy and Security (PriSec) Research Group, Karlstad University, Karlstad, SwedenAssessing privacy risks and incorporating privacy measures from the onset requires a comprehensive understanding of potential impacts on data subjects. Privacy Impact Assessments (PIAs) offer a systematic methodology for such purposes, which are closely related to Data Protection Impact Assessments (DPIAs), particularly outlined in Article 35 of the General Data Protection Regulation (GDPR). The core of a PIA is a Privacy Risk Assessment (PRA). PRAs can be integrated as part of full-fledged PIAs or independently developed to support PIA processes. Although these methodologies have been identified as essential enablers of privacy by design, their effectiveness has been criticized because of the lack of evidence of their rigorous and systematic evaluation. Hence, we conducted a Systematic Literature Review (SLR) to identify published PIA and PRA methodologies and assess how and to what extent they have been scientifically validated or evaluated. We found that these methodologies are rarely evaluated for their performance in practice, and most of them have only been validated in limited studies. Most validation evidence is found with PRA methodologies. Of the evaluated methodologies, PIAs were the most evaluated, where case studies were the predominant evaluation method. These evaluated methodologies can be easily transferred to an industrial setting or used by practitioners, as they provide evidence of their use in practice. In addition, the findings in this study can be used to inform researchers of the current state-of-the-art, and practitioners can understand the benefits and current limitations of the methodologies and adopt evidence-based practices.https://ieeexplore.ieee.org/document/10418587/Privacy impact assessmentdata protection impact assessmentgeneral data protection regulationprivacy by designprivacyreview |
spellingShingle | Samuel Wairimu Leonardo Horn Iwaya Lothar Fritsch Stefan Lindskog On the Evaluation of Privacy Impact Assessment and Privacy Risk Assessment Methodologies: A Systematic Literature Review IEEE Access Privacy impact assessment data protection impact assessment general data protection regulation privacy by design privacy review |
title | On the Evaluation of Privacy Impact Assessment and Privacy Risk Assessment Methodologies: A Systematic Literature Review |
title_full | On the Evaluation of Privacy Impact Assessment and Privacy Risk Assessment Methodologies: A Systematic Literature Review |
title_fullStr | On the Evaluation of Privacy Impact Assessment and Privacy Risk Assessment Methodologies: A Systematic Literature Review |
title_full_unstemmed | On the Evaluation of Privacy Impact Assessment and Privacy Risk Assessment Methodologies: A Systematic Literature Review |
title_short | On the Evaluation of Privacy Impact Assessment and Privacy Risk Assessment Methodologies: A Systematic Literature Review |
title_sort | on the evaluation of privacy impact assessment and privacy risk assessment methodologies a systematic literature review |
topic | Privacy impact assessment data protection impact assessment general data protection regulation privacy by design privacy review |
url | https://ieeexplore.ieee.org/document/10418587/ |
work_keys_str_mv | AT samuelwairimu ontheevaluationofprivacyimpactassessmentandprivacyriskassessmentmethodologiesasystematicliteraturereview AT leonardohorniwaya ontheevaluationofprivacyimpactassessmentandprivacyriskassessmentmethodologiesasystematicliteraturereview AT lotharfritsch ontheevaluationofprivacyimpactassessmentandprivacyriskassessmentmethodologiesasystematicliteraturereview AT stefanlindskog ontheevaluationofprivacyimpactassessmentandprivacyriskassessmentmethodologiesasystematicliteraturereview |