On the Evaluation of Privacy Impact Assessment and Privacy Risk Assessment Methodologies: A Systematic Literature Review

Assessing privacy risks and incorporating privacy measures from the onset requires a comprehensive understanding of potential impacts on data subjects. Privacy Impact Assessments (PIAs) offer a systematic methodology for such purposes, which are closely related to Data Protection Impact Assessments...

Full description

Bibliographic Details
Main Authors: Samuel Wairimu, Leonardo Horn Iwaya, Lothar Fritsch, Stefan Lindskog
Format: Article
Language:English
Published: IEEE 2024-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/10418587/
_version_ 1797319568161505280
author Samuel Wairimu
Leonardo Horn Iwaya
Lothar Fritsch
Stefan Lindskog
author_facet Samuel Wairimu
Leonardo Horn Iwaya
Lothar Fritsch
Stefan Lindskog
author_sort Samuel Wairimu
collection DOAJ
description Assessing privacy risks and incorporating privacy measures from the onset requires a comprehensive understanding of potential impacts on data subjects. Privacy Impact Assessments (PIAs) offer a systematic methodology for such purposes, which are closely related to Data Protection Impact Assessments (DPIAs), particularly outlined in Article 35 of the General Data Protection Regulation (GDPR). The core of a PIA is a Privacy Risk Assessment (PRA). PRAs can be integrated as part of full-fledged PIAs or independently developed to support PIA processes. Although these methodologies have been identified as essential enablers of privacy by design, their effectiveness has been criticized because of the lack of evidence of their rigorous and systematic evaluation. Hence, we conducted a Systematic Literature Review (SLR) to identify published PIA and PRA methodologies and assess how and to what extent they have been scientifically validated or evaluated. We found that these methodologies are rarely evaluated for their performance in practice, and most of them have only been validated in limited studies. Most validation evidence is found with PRA methodologies. Of the evaluated methodologies, PIAs were the most evaluated, where case studies were the predominant evaluation method. These evaluated methodologies can be easily transferred to an industrial setting or used by practitioners, as they provide evidence of their use in practice. In addition, the findings in this study can be used to inform researchers of the current state-of-the-art, and practitioners can understand the benefits and current limitations of the methodologies and adopt evidence-based practices.
first_indexed 2024-03-08T04:08:51Z
format Article
id doaj.art-a47ef83ce2ce4418844862b4e863ce87
institution Directory Open Access Journal
issn 2169-3536
language English
last_indexed 2024-03-08T04:08:51Z
publishDate 2024-01-01
publisher IEEE
record_format Article
series IEEE Access
spelling doaj.art-a47ef83ce2ce4418844862b4e863ce872024-02-09T00:01:30ZengIEEEIEEE Access2169-35362024-01-0112196251965010.1109/ACCESS.2024.336086410418587On the Evaluation of Privacy Impact Assessment and Privacy Risk Assessment Methodologies: A Systematic Literature ReviewSamuel Wairimu0https://orcid.org/0000-0003-1750-649XLeonardo Horn Iwaya1https://orcid.org/0000-0001-9005-0543Lothar Fritsch2https://orcid.org/0000-0002-0418-4121Stefan Lindskog3https://orcid.org/0000-0003-0778-4736Department of Mathematics and Computer Science, Privacy and Security (PriSec) Research Group, Karlstad University, Karlstad, SwedenDepartment of Mathematics and Computer Science, Privacy and Security (PriSec) Research Group, Karlstad University, Karlstad, SwedenDepartment of Mathematics and Computer Science, Privacy and Security (PriSec) Research Group, Karlstad University, Karlstad, SwedenDepartment of Mathematics and Computer Science, Privacy and Security (PriSec) Research Group, Karlstad University, Karlstad, SwedenAssessing privacy risks and incorporating privacy measures from the onset requires a comprehensive understanding of potential impacts on data subjects. Privacy Impact Assessments (PIAs) offer a systematic methodology for such purposes, which are closely related to Data Protection Impact Assessments (DPIAs), particularly outlined in Article 35 of the General Data Protection Regulation (GDPR). The core of a PIA is a Privacy Risk Assessment (PRA). PRAs can be integrated as part of full-fledged PIAs or independently developed to support PIA processes. Although these methodologies have been identified as essential enablers of privacy by design, their effectiveness has been criticized because of the lack of evidence of their rigorous and systematic evaluation. Hence, we conducted a Systematic Literature Review (SLR) to identify published PIA and PRA methodologies and assess how and to what extent they have been scientifically validated or evaluated. We found that these methodologies are rarely evaluated for their performance in practice, and most of them have only been validated in limited studies. Most validation evidence is found with PRA methodologies. Of the evaluated methodologies, PIAs were the most evaluated, where case studies were the predominant evaluation method. These evaluated methodologies can be easily transferred to an industrial setting or used by practitioners, as they provide evidence of their use in practice. In addition, the findings in this study can be used to inform researchers of the current state-of-the-art, and practitioners can understand the benefits and current limitations of the methodologies and adopt evidence-based practices.https://ieeexplore.ieee.org/document/10418587/Privacy impact assessmentdata protection impact assessmentgeneral data protection regulationprivacy by designprivacyreview
spellingShingle Samuel Wairimu
Leonardo Horn Iwaya
Lothar Fritsch
Stefan Lindskog
On the Evaluation of Privacy Impact Assessment and Privacy Risk Assessment Methodologies: A Systematic Literature Review
IEEE Access
Privacy impact assessment
data protection impact assessment
general data protection regulation
privacy by design
privacy
review
title On the Evaluation of Privacy Impact Assessment and Privacy Risk Assessment Methodologies: A Systematic Literature Review
title_full On the Evaluation of Privacy Impact Assessment and Privacy Risk Assessment Methodologies: A Systematic Literature Review
title_fullStr On the Evaluation of Privacy Impact Assessment and Privacy Risk Assessment Methodologies: A Systematic Literature Review
title_full_unstemmed On the Evaluation of Privacy Impact Assessment and Privacy Risk Assessment Methodologies: A Systematic Literature Review
title_short On the Evaluation of Privacy Impact Assessment and Privacy Risk Assessment Methodologies: A Systematic Literature Review
title_sort on the evaluation of privacy impact assessment and privacy risk assessment methodologies a systematic literature review
topic Privacy impact assessment
data protection impact assessment
general data protection regulation
privacy by design
privacy
review
url https://ieeexplore.ieee.org/document/10418587/
work_keys_str_mv AT samuelwairimu ontheevaluationofprivacyimpactassessmentandprivacyriskassessmentmethodologiesasystematicliteraturereview
AT leonardohorniwaya ontheevaluationofprivacyimpactassessmentandprivacyriskassessmentmethodologiesasystematicliteraturereview
AT lotharfritsch ontheevaluationofprivacyimpactassessmentandprivacyriskassessmentmethodologiesasystematicliteraturereview
AT stefanlindskog ontheevaluationofprivacyimpactassessmentandprivacyriskassessmentmethodologiesasystematicliteraturereview