Towards Formal Modeling of Privacy Policies of Enterprises

被引:0
|
作者
Manna, Asmita [1 ]
Sengupta, Anirban [2 ]
Mazumdar, Chandan [2 ]
机构
[1] Jadavpur Univ, Dept Comp Sci & Engn, Kolkata, India
[2] Jadavpur Univ, Ctr Distributed Comp, Kolkata, India
关键词
privacy requirement; privacy policy; privacy clause; formal representation;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Collection, storage and processing of personally identifiable information and other sensitive information by enterprises are leading to privacy concerns for individuals, in particular, and society, in general. As privacy has been declared as a fundamental right in many countries, authorities are implementing privacy laws and guidelines to be followed by enterprises. Similarly, enterprises are also designing their own privacy policies to assure their clients about privacy concerns. In this paper, privacy has been considered as a business requirement rather than security requirement, and a methodology for formal representation of privacy policies has been presented. Privacy policies of different types of enterprises have been analysed and common privacy clauses have been identified from those policies. The related vocabularies have been defined and clauses have been expressed using a formal language. Finally, a case study has been presented to illustrate the usefulness of this approach.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] Towards learning privacy policies
    Bandara, Arosha K.
    Russo, Alessandra
    Lupu, Emil C.
    EIGHTH IEEE INTERNATIONAL WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS - PROCEEDINGS, 2007, : 274 - 274
  • [2] Towards a Formal Language for Privacy Options
    Berthold, Stefan
    PRIVACY AND IDENTITY MANAGEMENT FOR LIFE, 2011, 352 : 27 - 40
  • [3] Towards Formal Semantics for ODRL Policies
    Steyskal, Simon
    Polleres, Axel
    RULE TECHNOLOGIES: FOUNDATIONS, TOOLS, AND APPLICATIONS, 2015, 9202 : 360 - 375
  • [4] Towards a conceptual model for privacy policies
    Mont, Marco Casassa
    Pearson, Siani
    Creese, Sadie
    Goldsmith, Michael
    Papanikolaou, Nick
    HP Laboratories Technical Report, 2010, (82):
  • [5] Towards scalable management of privacy obligations in enterprises
    Mont, Marco Casassa
    TRUST, PRIVACY, AND SECURITY IN DIGITAL BUSINESS, PROCEEDINGS, 2006, 4083 : 1 - 10
  • [6] POSTER: Towards Formal Verification of DIFC Policies
    Yang, Zhi
    Yin, Lihua
    Duan, Miyi
    Jin, Shuyuan
    PROCEEDINGS OF THE 18TH ACM CONFERENCE ON COMPUTER & COMMUNICATIONS SECURITY (CCS 11), 2011, : 873 - 875
  • [7] Towards formal specification and generation of autonomic policies
    Sterritt, R
    Hinchey, MG
    Rash, JL
    Truszkowski, W
    Rouff, CA
    Gracanin, D
    EMBEDDED AND UBIQUITOUS COMPUTING - EUC 2005 WORKSHOPS, PROCEEDINGS, 2005, 3823 : 1245 - 1254
  • [8] Towards negotiable privacy policies in Mobile Healthcare
    Sadki, Souad
    El Bakkali, Hanan
    FIFTH INTERNATIONAL CONFERENCE ON THE INNOVATIVE COMPUTING TECHNOLOGY (INTECH 2015), 2015, : 94 - 99
  • [9] An approach to formal desription of the user notification scenarios in privacy policies
    Kuznetsov, Mikhail
    Novikova, Evgenia
    Kotenko, Igor
    30TH EUROMICRO INTERNATIONAL CONFERENCE ON PARALLEL, DISTRIBUTED AND NETWORK-BASED PROCESSING (PDP 2022), 2022, : 275 - 282
  • [10] Towards an Information Type Lexicon for Privacy Policies
    Bhatia, Jaspreet
    Breaux, Travis D.
    8TH INTERNATIONAL WORKSHOP ON REQUIREMENTS ENGINEERING AND LAW (RELAW 2015), 2015, : 19 - 24