Towards a principled approach for engineering privacy by design

Privacy by Design has emerged as a proactive, integrative, and creative approach for embedding privacy requirements into the early stages of the design of information and communication technologies, business practices, and physical designs and infrastructures. Yet, Privacy by Design is no `silver bu...

وصف كامل

التفاصيل البيبلوغرافية
المؤلفون الرئيسيون: Alshammari, M, Simpson, A
التنسيق: Report
اللغة:English
منشور في: Department of Computer Science, Oxford University 2016
_version_ 1826307621408210944
author Alshammari, M
Simpson, A
author_facet Alshammari, M
Simpson, A
author_sort Alshammari, M
collection OXFORD
description Privacy by Design has emerged as a proactive, integrative, and creative approach for embedding privacy requirements into the early stages of the design of information and communication technologies, business practices, and physical designs and infrastructures. Yet, Privacy by Design is no `silver bullet'. Challenges involved in engineering Privacy by Design include a lack of holistic, systematic and integrative methodologies that address the complexity and variability of privacy, and support the translation of its foundational principles into engineering activities. In some ways this is understandable: the approach was developed to take into account a range of sources and standards. However, a consequence is that its foundational principles are given at a high level of abstraction without accompanying methodologies and guidelines to elicit concrete privacy requirements and specify appropriate design decisions. In this report, we analyse three privacy requirements engineering methods from which we derived a set of criteria that meet these challenges. In essence, these criteria are in consonance with the foundational principles of Privacy by Design to aid software engineers in identifying activities that can lead to privacy harms in a concrete and meaningful manner, and specifying appropriate design decisions at an architectural level in a rational and positive-sum manner. To this end, we put forward a proposal for engineering Privacy by Design that can be developed upon these criteria.
first_indexed 2024-03-07T07:05:52Z
format Report
id oxford-uuid:2804dba5-78e8-459e-886b-dcad3f46dc89
institution University of Oxford
language English
last_indexed 2024-03-07T07:05:52Z
publishDate 2016
publisher Department of Computer Science, Oxford University
record_format dspace
spelling oxford-uuid:2804dba5-78e8-459e-886b-dcad3f46dc892022-05-12T16:19:43ZTowards a principled approach for engineering privacy by designReporthttp://purl.org/coar/resource_type/c_93fcuuid:2804dba5-78e8-459e-886b-dcad3f46dc89EnglishSymplectic Elements at OxfordDepartment of Computer Science, Oxford University2016Alshammari, MSimpson, APrivacy by Design has emerged as a proactive, integrative, and creative approach for embedding privacy requirements into the early stages of the design of information and communication technologies, business practices, and physical designs and infrastructures. Yet, Privacy by Design is no `silver bullet'. Challenges involved in engineering Privacy by Design include a lack of holistic, systematic and integrative methodologies that address the complexity and variability of privacy, and support the translation of its foundational principles into engineering activities. In some ways this is understandable: the approach was developed to take into account a range of sources and standards. However, a consequence is that its foundational principles are given at a high level of abstraction without accompanying methodologies and guidelines to elicit concrete privacy requirements and specify appropriate design decisions. In this report, we analyse three privacy requirements engineering methods from which we derived a set of criteria that meet these challenges. In essence, these criteria are in consonance with the foundational principles of Privacy by Design to aid software engineers in identifying activities that can lead to privacy harms in a concrete and meaningful manner, and specifying appropriate design decisions at an architectural level in a rational and positive-sum manner. To this end, we put forward a proposal for engineering Privacy by Design that can be developed upon these criteria.
spellingShingle Alshammari, M
Simpson, A
Towards a principled approach for engineering privacy by design
title Towards a principled approach for engineering privacy by design
title_full Towards a principled approach for engineering privacy by design
title_fullStr Towards a principled approach for engineering privacy by design
title_full_unstemmed Towards a principled approach for engineering privacy by design
title_short Towards a principled approach for engineering privacy by design
title_sort towards a principled approach for engineering privacy by design
work_keys_str_mv AT alshammarim towardsaprincipledapproachforengineeringprivacybydesign
AT simpsona towardsaprincipledapproachforengineeringprivacybydesign