Assessing liability arising from information security breaches in data privacy

被引:3
|
作者
Mitrakas, Andreas [1 ]
机构
[1] European Network Secur Agcy ENISA, Adm Dept, Iraklion, Greece
关键词
D O I
10.1093/idpl/ipr001
中图分类号
D9 [法律]; DF [法律];
学科分类号
0301 ;
摘要
To counter threats, information security measures need to be employed in a way that adequately protects personally-identifiable data, and a privacy framework must be implemented. Assessing liability in an information security context is a means to reduce exacerbated social costs that are likely to arise. Apportioning costs between the information owner and information security service providers is also desirable because it may lead to reduced transaction costs, rendering the provision of information security services more attractive for both service providers and users. This paper reviews certain drivers and shortcomings associated with data privacy as it relates to cyber attacks, with a special focus on the European legal framework. It then briefly presents a liability assessment model that is adapted for the purpose of data privacy breaches of information security. Finally, a sample assessment is carried out of the liability of actors with regard to data privacy.
引用
收藏
页码:129 / 136
页数:8
相关论文
共 50 条