Privacy impact assessment – a privacy protection improvement model?

  • A Privacy Impact Assessment (PIA) is a systematic risk assessment tool, enabling organizations to maintain compliance with data protection regulations, to manage privacy risks and to provide public benefits through the success of privacy-by-design efforts. An actual practical implementation of a PIA framework has been realized in the context of RFID applications encompassing detailed steps for the PIA process; a first successful review has been completed. The PIA also allows to introduce a pro-active mitigation of privacy risks through technical and organizational controls. The better the precautionary measures realize the relevant privacy objectives, the less likely will occur with the PIA process afterwards. The recent proposal for a far-reaching revision of the EU Data Protection Directive envisages to state a specific requirement to implement a PIA process. Indeed, since risks for privacy and non-disclosure of personal data are different in not identical circumstances, the protection measures should also be different, i.e. technology should assist in trying to achieve the (at least) second-best solution for the implementation of the data protection regime by a PIA. Insofar, privacy rules can be individualized and matched with the concrete needs in the given environment.

Download full text files

Export metadata

Additional Services

Share in Twitter Search Google Scholar
Metadaten
Author:Rolf H. Weber
URN:urn:nbn:de:hebis:30:3-248978
Parent Title (English):25th IVR World Congress: Law, Science and Technology Frankfurt am Main 15–20 August 2011 ; Paper Series ; 039
Series (Serial Number):25th IVR World Congress: Law, Science and Technology Frankfurt am Main 15–20 August 2011 ; Paper Series (039)
Publisher:Goethe-Univ.
Place of publication:Frankfurt am Main
Document Type:Conference Proceeding
Language:English
Year of Completion:2012
Year of first Publication:2012
Publishing Institution:Universitätsbibliothek Johann Christian Senckenberg
Release Date:2012/06/26
Tag:Code-based regulation; Data Protection Directive; PIA process; PIA taxonomy; RFID applications; privacy-by-design; risk assessment; risk design; self-regulation
HeBIS-PPN:344414647
Institutes:Rechtswissenschaft / Rechtswissenschaft
Dewey Decimal Classification:3 Sozialwissenschaften / 34 Recht / 340 Recht
Sammlungen:Universitätspublikationen
Licence (German):License LogoDeutsches Urheberrecht