Privacy Requirements and Realities of Digital Public Goods

被引:0
|
作者
Gopi, Geetika [1 ]
Maddi, Aadyaa [1 ]
Arasaratnam, Omkhar [2 ]
Fanti, Giulia [1 ]
机构
[1] Carnegie Mellon Univ, Pittsburgh, PA 15213 USA
[2] OpenSSF, San Francisco, CA USA
关键词
INCENTIVES;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In the international development community, the term "digital public goods" is used to describe open-source digital products (e.g., software, datasets) that aim to address the United Nations (UN) Sustainable Development Goals. DPGs are increasingly being used to deliver government services around the world (e.g., ID management, healthcare registration). Because DPGs may handle sensitive data, the UN has established user privacy as a first-order requirement for DPGs. The privacy risks of DPGs are currently managed in part by the DPG standard, which includes a prerequisite questionnaire with questions designed to evaluate a DPG's privacy posture. This study examines the effectiveness of the current DPG standard for ensuring adequate privacy protections. We present a systematic assessment of responses from DPGs regarding their protections of users' privacy. We also present in-depth case studies from three widely-used DPGs to identify privacy threats and compare this to their responses to the DPG standard. Our findings reveal serious limitations in the current DPG standard's evaluation approach. We conclude by presenting preliminary recommendations and suggestions for strengthening the DPG standard as it relates to privacy. Additionally, we hope this study encourages more usable privacy research on communicating privacy, not only to end users but also third-party adopters of user-facing technologies.
引用
收藏
页码:159 / 177
页数:19
相关论文
共 50 条
  • [41] Government in the metaverse: Requirements and suitability for providing digital public services
    Lnenicka, Martin
    Rizun, Nina
    Alexopoulos, Charalampos
    Janssen, Marijn
    TECHNOLOGICAL FORECASTING AND SOCIAL CHANGE, 2024, 203
  • [42] Enforcement of Privacy Requirements
    Krishnan, Padmanabhan
    Vorobyov, Kostyantyn
    SECURITY AND PRIVACY PROTECTION IN INFORMATION PROCESSING SYSTEMS, 2013, 405 : 272 - 285
  • [43] Enforcement of privacy requirements
    Krishnan, Padmanabhan
    Vorobyov, Kostyantyn
    COMPUTERS & SECURITY, 2015, 52 : 164 - 177
  • [44] Motivating Experts to Contribute to Digital Public Goods: A Personalized Field Experiment on Wikipedia
    Chen, Yan
    Farzan, Rosta
    Kraut, Robert
    Yeckehzaare, Iman
    Zhang, Ark Fangzhou
    MANAGEMENT SCIENCE, 2024, 70 (05) : 3264 - 3280
  • [45] Regulatory Angels and Technology Demons? Making Sense of Evolving Realities in Health Data Privacy for the Digital Age
    Rahimzadeh, Vasiliki
    AMERICAN JOURNAL OF BIOETHICS, 2022, 22 (07): : 68 - 70
  • [46] PRIVATE GOODS, CLUB GOODS, AND PUBLIC-GOODS AS A CONTINUUM
    ADAMS, RD
    MCCORMICK, K
    REVIEW OF SOCIAL ECONOMY, 1987, 45 (02) : 192 - 199
  • [47] The Sealed Letter: Safeguarding the Public System of Privacy Protection in a Digital World
    Church, Liam
    Moloney, Maria
    Bannister, Frank
    PROCEEDINGS OF THE 46TH ANNUAL HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES, 2013, : 1973 - 1982
  • [48] What is public health? public goods, publicized goods, and the conversion problem
    Anomaly, Jonathan
    PUBLIC CHOICE, 2023, 195 (1-2) : 43 - 53
  • [49] What is public health? public goods, publicized goods, and the conversion problem
    Jonathan Anomaly
    Public Choice, 2023, 195 : 43 - 53
  • [50] How Do Public Goods Providers Play Public Goods Games?
    Butler, Daniel M.
    Kousser, Thad
    LEGISLATIVE STUDIES QUARTERLY, 2015, 40 (02) : 211 - 240